Only the latest release receives security fixes.
Please do not open a public issue. Report it privately through GitHub security advisories. You can expect a first response within 7 days.
- Keys are passed in code and kept only in memory. The library never reads
.envfiles or environment variables, and never writes keys to disk or logs. - Only the routing key (
jev_api_keyoropenrouter_api_key) is sent over the network, over HTTPS, to jevai.org or openrouter.ai respectively. - Provider keys passed in
providers={...}are never sent anywhere. They are only returned to you byrouter.api_key_for(). - The first 8,000 characters of each task are sent to the routing service. Don't route prompts containing data you aren't allowed to share with Jev / OpenRouter.