Skip to content
This repository was archived by the owner on Sep 29, 2026. It is now read-only.
This repository was archived by the owner on Sep 29, 2026. It is now read-only.

Cache OpenSecretClient per API key to avoid attestation handshake on every request #32

Description

@AnthonyRonning

Problem

The proxy creates a brand new OpenSecretClient on every single request in create_client_with_auth() (proxy.rs). This discards the session cache each time, forcing a full attestation handshake (nonce generation, GET /attestation/{nonce}, certificate chain verification, POST /key_exchange) on every request.

The OpenSecret SDK does cache the session after perform_attestation_handshake() — subsequent calls on the same client instance reuse the cached session key without re-attesting. But because the proxy throws away the client after each request, this caching never helps.

Impact

For agentic workloads making many sequential API calls, every single request pays the full attestation overhead: two extra HTTP round trips plus cryptographic verification. This adds latency and introduces extra failure surface on every call.

Proposed Fix

Cache OpenSecretClient instances in ProxyState keyed by API key. Create the client and perform attestation on first use, then reuse it for all subsequent requests from that key.

use dashmap::DashMap;

pub struct ProxyState {
    pub config: Config,
    pub clients: DashMap<String, Arc<OpenSecretClient>>,
}

The SDK is thread-safe (Arc<RwLock> internally) so sharing one client across concurrent requests is safe. The SDK also has built-in retry logic that re-attests automatically on session errors, so failure recovery is handled.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions