Comparison · reviewed August 21, 2026

AI Gateway HQ vs. Cloudflare AI Gateway

Deterministic pre-dispatch reservations where a configured hard limit must behave like a hard limit.

  • Pre-dispatch control
  • Operator-ready evidence
  • Prompt storage off by default
Working sandbox capture
This is the product—not a concept rendering.A capture from the working test environment shows the controls and evidence described in this comparison. Open it full-size to inspect the interface.
Why teams choose AI Gateway HQ

Choose AI Gateway HQ when finance has said ‘stop at the boundary,’ not ‘report shortly after it.’ Cloudflare is attractive for edge distribution; AI Gateway HQ is purpose-built for conservative, attributable AI spend and policy decisions.

Strict mode atomically reserves organization and workload exposure before forwarding. Cloudflare documents real-time limits calculated from best-effort cost estimates and allows at most 20 spend-limit rules per gateway.

Capability evidence

Compare the operating boundary.

AI Gateway HQ entries describe implemented product behavior. Alternative entries summarize the linked first-party documentation—not anonymous review scores.

Decision areaWhat AI Gateway HQ deliversWhat Cloudflare AI Gateway documents
Gateway and routing

One OpenAI/Anthropic-compatible endpoint; encrypted multi-account BYOK pools; capability-first priority, weighted, request-cost, health, and request-aware provider-capacity selection; shared quota cooldowns and bounded, reason-coded fallback.

Edge-adjacent analytics, logging, caching, provider routing, DLP, and guardrail integrations across Cloudflare services.

Spend enforcement

Atomic organization-and-workload reservation before forwarding, strict rate and concurrency enforcement, explicit output caps, and settlement against supported provider-reported usage. Promotional credit cannot fund server-paid model exposure.

Real-time spend limits can split or filter by model, provider, identity, or custom metadata and can block or use a cheaper dynamic-route fallback. Cloudflare calls cost tracking a best-effort estimate and documents a 20-rule maximum per gateway.

Identity and governance

OIDC administration, mandatory MFA, built-in least-privilege roles, virtual workload keys, signed execution context, Observe/Shadow/Enforce policy, and local jailbreak, injection, exfiltration, encoding, and Unicode risk signals.

Cloudflare account controls plus DLP and Workers AI guardrails; it fits an existing Cloudflare security estate.

Deployment and evidence

WAF-protected AWS serverless deployment, tenant-bound KMS encryption, signed releases, payload-free request metadata by default, tamper-evident audit exports, and customer-approved time-bounded support access.

Globally operated Cloudflare service with persistent-log allowances tied to Workers plans, rather than a customer-run gateway package.

Public commercial model

A free BYOK proving tier, then $0.10 per 1,000 successful Flex requests with no percentage markup on inference purchased through customer-owned provider accounts; higher-control plans are scoped by operating requirements.

Core AI Gateway is free; separate platform meters apply, and Unified Billing lists a 5% fee.

When to consider Cloudflare AI Gateway

Consider Cloudflare when its global network, Workers platform, and existing Cloudflare security estate outweigh exact wallet enforcement.

Comparison method

Facts were reviewed from the linked first-party documentation and pricing pages on August 21, 2026. Public meters are not normalized: requests, logs, credits, infrastructure, and enterprise capacity are different units. Revalidate pricing and capabilities before purchasing.