Share an API Key Without Sharing the Key

Every team that uses AI APIs ends up with the same problem. One person holds the OpenAI key, and everyone else gets it pasted into a chat. The key then lives in a dozen places, nobody can tell who used how much, and rotating it breaks everything at once.

Feen is my answer to that, and it is open source. You add a provider key once and it is stored encrypted with AES-256. Instead of passing the key around, you create a shared access token for it, and the token carries its own limits: a rate limit in requests per minute, a daily limit, an IP allowlist, a list of allowed models, and an expiry date.

The proxy is the point

Teammates call Feen's proxy endpoint with their token instead of the provider key. The request has the same shape as an OpenAI chat completion call, so existing client code needs little change. The README describes the storage as zero-knowledge, meaning the service never stores or sees the plain key.

What sits around it

The README lists support for OpenAI, Anthropic, Google AI, Azure OpenAI, Cohere, Mistral, Groq, Together AI, Replicate and Hugging Face, plus a custom option for any REST API. Around the core there is usage and cost analytics, an audit log of every access and change, role-based access for organizations, and a marketplace where access can be bought and sold. It runs on Node 20, PostgreSQL 14 and Redis 7, and starts with docker compose.

The idea I care about is small: sharing access should not mean sharing the secret. A limit and an expiry date on a token is a better default than a key in a chat message. The code is at github.com/yethikrishna/feen.

← back to the journal