Install once. Every call finds its Route.

Add the KnoxCall SDK to your server once. Every call a vendor SDK makes to a provider you have a Route for goes through that Route.

The key never enters your process. Node, Python, Go, PHP and Ruby, and the Go agent for code you cannot change.

Install.

One line where your server starts. From then on the SDK watches every outbound call.

It asks KnoxCall which Routes are open to it, and keeps that answer fresh every minute and the moment a Route refuses a call.

Toggle.

Turn Intercept on for a Route in the dashboard. Off by default, per environment.

It takes effect within a minute, with no deploy. Turn it off and the traffic goes back where it went before.

Route.

Calls to that provider go through the Route. It adds the key on the way out.

Your overrides, rate limits, client rules and logs apply to a vendor SDK's calls exactly as they do to your own.

What happens to a call.

Every outbound request is decided in this order, and the first line that fits wins.

The Route means through the Route you configured. Ephemeral means through the ephemeral proxy. Direct means untouched.

  • A Route covers the host and pathThe RouteThrough that Route. It injects the stored key, so the placeholder your code holds never travels. Every control the Route has applies: overrides, rate limits, mTLS, logs.
  • You listed the host, and no Route covers it yetEphemeralThrough the ephemeral proxy, carrying the credential your process already holds. The moment you turn a Route on for that host, the next call uses the Route.
  • Anything elseDirectUntouched. KnoxCall's own hosts, anything that is not HTTP, a host you did not opt in, and the card-number endpoints the SDK routes around by default.
  • The kill switchOffOne environment variable, per process, no deploy. Everything goes direct until you turn it back on.

Which stacks.

The same server answer, read by every SDK, so a Route you toggle on takes effect for all of them.

  • NodeThe global fetch and the http module: axios, node-fetch, got, generated clients, the HubSpot client.
  • Pythonhttpx and urllib3, so requests and botocore too; aiohttp when you ask for it.
  • GoThe default transport, or a transport you hand to any client.
  • PHPA client or middleware you hand to any PSR-18 or Guzzle SDK.
  • RubyOpt in once: Faraday, rest-client, httparty and Net::HTTP.
  • The Go agentFor code you cannot change: a local proxy that reads the same manifest.

The browser and React packages for hosted fields are on npm as well: browser, React, and their source.

What it is, and is not.

Three things the docs say plainly, so the page does too.

Read the docs →
A convenience, not a boundaryIt reaches the HTTP seam your language has. Each SDK's docs say exactly what it does and does not reach.
Route mode is the custody pathThe credential stays in KnoxCall. Nothing in your process can print what it never held.
It fails closedIf KnoxCall is unreachable, a routed call errors rather than leaks. A host you listed can opt to go direct.

Store. Proxy. Revoke.

Free for seven days. No card. Your first call in minutes.

All systems operational