DOCSPontx Hub
Public docsv1
On this pageCredentials and safety

Before you send / preview first

See the exact request before deciding to send it.

Learn how Pontx Hub handles API credentials, request previews, and mutation confirmation: website credentials stay in the session, while CLI and SDK credentials stay local.

01

Where credentials stay

API keys entered on the website stay in the current browser session. The CLI reads them from your local environment. Pontx does not save them to your account.

WebsiteCurrent session

API keys, OAuth tokens, and passwords are used only in this browser session.

CLI / SkillEnvironment variables

Keep credentials in local environment variables instead of command arguments.

AccountNot saved

Favorites and usage history never include credentials or provider responses.

02

Review the request first

Before sending, you can see the final URL, parameters, redacted headers, and body. A preview never contacts the API provider.

Review without sending
pontx-hub <api-product> preview [controller] <endpoint-name> --parameter value

# Check: method · host · path · query · redacted headers · body
HTTP methodHostResolved pathQueryRedacted headersBody
03

Confirm before changing data

Before creating, updating, or deleting data, Pontx asks you to confirm the request you just reviewed. Change any value and you will need to preview and confirm again.

1preview

Review the full request

2you confirm

Confirm what will change

3call --yes

Send what you reviewed

04

Only connect to listed APIs

To keep requests from being redirected somewhere unexpected, the website and CLI accept only service addresses reviewed in the catalog.

  • ✓The API, Endpoint, and service address must be listed in the catalog.
  • ✓Requests to local, private, or unsafe redirect destinations are blocked.
  • ✓Request time, request size, and response size all have limits.
  • ✓Some APIs cannot be called online, but their docs, previews, and code examples still work.
Back to Agent Skill setup and use ↗