Docs

One endpoint,
every model.

Tare is an OpenAI-compatible gateway in front of every model you use — ours and the ones you bring yourself. One base URL, one key, and every token accounted for.

OperationsCall Traces

Call Traces

What you send to a model and what it answers is call content. It is independent of usage records: usage (tokens, cost, the route that served the call) is always recorded, because the bill is built from it, while call content is not stored at all by default.

Disabled by default

A new account needs to do nothing. The switch under Call Traces in the console starts off, and while it is off the request_content / response_content columns are empty — the content was never stored, rather than stored and withheld.

[!NOTE] If the concern is that request bodies contain customer code and business data, the default configuration addresses it directly: none of that reaches the platform database.

After enabling

Retention1,000 most recent calls by default, configurable 1–100,000
EncryptionAES-256-GCM, with a key held separately from channel credentials
Storage regionSingapore
AccessThe account owner, at any time. Tare cannot read it without an explicit grant
At expirySwept nightly; content beyond the retention count is erased, oldest first (the usage row stays, those two columns go empty)

The content key is separate from the channel-credential key because the two rotate on different clocks: a leaked credential has to be replaced today, while rotating the content key means re-encrypting history.

[!WARNING] Encryption is not equivalent to technical inability to read. The key is held on Tare’s servers, so "Tare cannot read it" is a policy — a grant plus an audit trail, described below — not a physical constraint.

Platform access requires an explicit grant

Diagnosing an issue occasionally requires reading the content of specific calls. There is exactly one path to that: a time-bounded grant issued by the account owner from the console.

  • Grants last from 1 hour to 30 days. There is no "forever" option: an unbounded grant outlives the investigation.
  • Every read during the grant is written to the audit log, visible on the Audit page.
  • You can revoke early; expired grants lapse on their own.
  • Without a grant, the value returned to Tare is the string <withheld: customer has not granted access>.

Disabling

Storage can be disabled at any time. New calls stop storing content immediately; content already stored is not removed immediately — it is swept when it exceeds the retention count you set. To clear it now, set retention to 1 — only the single most recent call's content survives the next sweep.

API

The console switches map to these endpoints:

Code / Terminal
# current setting + grant status
curl https://tare.jamerly.ai/v1/content-settings \
  -H "Authorization: Bearer $TARE_API_KEY"

# turn storage on, keep the most recent 100 calls
curl -X PUT https://tare.jamerly.ai/v1/content-settings \
  -H "Authorization: Bearer $TARE_API_KEY" -H "Content-Type: application/json" \
  -d '{"enabled": true, "retentionCount": 100}'

# grant platform access for 24 hours
curl -X POST https://tare.jamerly.ai/v1/content-settings/grants \
  -H "Authorization: Bearer $TARE_API_KEY" -H "Content-Type: application/json" \
  -d '{"hours": 24, "reason": "investigating 502s"}'

[!WARNING] productLine may only be passed as a query parameter on the GET; writes take it in the body. The gateway in front of the service drops query strings on POST/PUT, so a parameter written there produces no error and no effect.

Docs last updated Sep 20, 2026, 06:31 (UTC+8)