Problem
The proxy creates a brand new OpenSecretClient on every single request in create_client_with_auth() (proxy.rs). This discards the session cache each time, forcing a full attestation handshake (nonce generation, GET /attestation/{nonce}, certificate chain verification, POST /key_exchange) on every request.
The OpenSecret SDK does cache the session after perform_attestation_handshake() — subsequent calls on the same client instance reuse the cached session key without re-attesting. But because the proxy throws away the client after each request, this caching never helps.
Impact
For agentic workloads making many sequential API calls, every single request pays the full attestation overhead: two extra HTTP round trips plus cryptographic verification. This adds latency and introduces extra failure surface on every call.
Proposed Fix
Cache OpenSecretClient instances in ProxyState keyed by API key. Create the client and perform attestation on first use, then reuse it for all subsequent requests from that key.
use dashmap::DashMap;
pub struct ProxyState {
pub config: Config,
pub clients: DashMap<String, Arc<OpenSecretClient>>,
}
The SDK is thread-safe (Arc<RwLock> internally) so sharing one client across concurrent requests is safe. The SDK also has built-in retry logic that re-attests automatically on session errors, so failure recovery is handled.
Problem
The proxy creates a brand new
OpenSecretClienton every single request increate_client_with_auth()(proxy.rs). This discards the session cache each time, forcing a full attestation handshake (nonce generation,GET /attestation/{nonce}, certificate chain verification,POST /key_exchange) on every request.The OpenSecret SDK does cache the session after
perform_attestation_handshake()— subsequent calls on the same client instance reuse the cached session key without re-attesting. But because the proxy throws away the client after each request, this caching never helps.Impact
For agentic workloads making many sequential API calls, every single request pays the full attestation overhead: two extra HTTP round trips plus cryptographic verification. This adds latency and introduces extra failure surface on every call.
Proposed Fix
Cache
OpenSecretClientinstances inProxyStatekeyed by API key. Create the client and perform attestation on first use, then reuse it for all subsequent requests from that key.The SDK is thread-safe (
Arc<RwLock>internally) so sharing one client across concurrent requests is safe. The SDK also has built-in retry logic that re-attests automatically on session errors, so failure recovery is handled.