{
  "schemaVersion": 1,
  "title": "How GateWay routes participating platforms",
  "description": "Understand the participating-platform route, computer proxy scope, credential behavior, ordered failover, and direct-connection boundary.",
  "source": "https://cairl.co/docs/guides/gateway",
  "contentRevision": "sha256:d17531979f377fe8ab1830e11875a21d03bba8e1188b3e99595c0a785c152e71",
  "content": "How GateWay routes participating platforms\n\nWhat GateWay is\n\nIf they're breached, there's less of you in it.\n\nGateWay routes participating-platform destinations through a CAIRL egress node. The participating set comes from CAIRL's service registry; it is not a separate list that an account or environment can widen. Every destination outside that set connects directly, with no CAIRL involvement.\n\nGateWay changes the connection address a participating platform sees. It does not hide you from a platform you sign in to.\n\nWhere the proxy setting applies\n\nFirefox can be configured for one profile. Chrome and Edge use the computer's proxy settings. On those browsers, other applications that honor the same settings also route participating-platform destinations through GateWay. Safari also uses the macOS proxy settings, but CAIRL has not yet qualified Safari’s support for the current TLS-to-proxy route; behavior can be uneven. Do not treat Safari as supported until that verification is complete. Destinations outside the participating set continue to connect directly.\n\nThis is not a network-wide service. Removing the configuration returns every destination to a direct connection.\n\nNodes and failover\n\nThe configuration contains one global ordered list: US East first and US West second. The second node is failover. The order is not selected for each caller and is not latency-based routing.\n\nWith the configuration applied, participating platforms fail closed. If the credential is invalid or every CAIRL node is unavailable, those destinations do not silently connect directly. They do not load until the route is restored or the configuration is removed.\n\nCredential behavior\n\nThe proxy credential has a handle and a one-time secret. Copy the secret when it is issued because it cannot be retrieved later. CAIRL stores only its hash. Rotating or revoking the credential invalidates the prior credential.\n\nThe first time a participating platform loads, the browser can ask for the handle and secret. Availability and setup are managed inside the CAIRL account.\n\nRelated resources\n\n- GateWay product page: https://cairl.co/products/gateway\n"
}
