AI Gateway HQ vs. OpenRouter
Enforce financially fail-closed company controls, then produce company-approved portfolio evidence without turning a sponsor relationship into a hidden parent tenant.
- Pre-dispatch control
- Operator-ready evidence
- Prompt storage off by default
Choose AI Gateway HQ when the operating question extends beyond model access: enforce the company boundary, stop at a real ceiling, explain each decision, and connect approved spend and outcome evidence across a portfolio. Choose OpenRouter when catalog breadth and marketplace access are the primary requirement.
Provider selection starts with tenant, workload, capability, data-region, policy, budget, and health eligibility. BYOK inference carries no percentage markup in the published model, and portfolio reporting independently scopes operations, finance, and outcome evidence while excluding prompts, credentials, payment details, and individual activity.
Compare the operating boundary.
AI Gateway HQ entries describe implemented product behavior. Alternative entries summarize the linked first-party documentation—not anonymous review scores.
One OpenAI/Anthropic-compatible endpoint; encrypted multi-account BYOK pools; capability-first priority, weighted, request-cost, health, and request-aware provider-capacity selection; shared quota cooldowns and bounded, reason-coded fallback.
A managed marketplace API whose current pricing page lists 400+ models and 70+ providers, with provider controls, a market-informed prompt router, model fallbacks, and a CLI harness for Codex, Claude Code, and OpenCode.
Atomic organization-and-workload reservation before forwarding, strict rate and concurrency enforcement, explicit output caps, and settlement against supported provider-reported usage. Promotional credit cannot fund server-paid model exposure.
Daily, weekly, monthly, and lifetime budgets are checked before routing, but OpenRouter documents possible in-flight overshoot, exclusion of BYOK spend, and no proactive email or webhook budget alerts in the reviewed docs.
OIDC administration, mandatory MFA, built-in least-privilege roles, virtual workload keys, signed execution context, Observe/Shadow/Enforce policy, and local jailbreak, injection, exfiltration, encoding, and Unicode risk signals.
Workspaces with independent keys, budgets, routing, members, and observability; guardrails cover model/provider restrictions, budgets, zero-data retention, sensitive data, and prompt injection. Enterprise adds SAML and managed policy enforcement.
WAF-protected AWS serverless deployment, tenant-bound KMS encryption, signed releases, payload-free request metadata by default, tamper-evident audit exports, and customer-approved time-bounded support access.
Hosted marketplace service with request logs, saved Activity views, an Analytics API, custom request classifiers, and agent evaluations rather than a documented customer-operated gateway data plane.
A free BYOK proving tier, then $0.10 per 1,000 successful Flex requests with no percentage markup on inference purchased through customer-owned provider accounts; higher-control plans are scoped by operating requirements.
Pay-as-you-go lists a 5.5% fee. BYOK includes up to $25,000/month of list-price inference on pay-as-you-go, then lists a 5% fee.
Consider OpenRouter when immediate access to its aggregated marketplace and very broad model availability matter more than strict pre-dispatch reservation, company-owned operating boundaries, and consented cross-company value reporting.
Facts were reviewed from the linked first-party documentation and pricing pages on August 25, 2026. Public meters are not normalized: requests, logs, credits, infrastructure, and enterprise capacity are different units. Revalidate pricing and capabilities before purchasing.