AI Gateway HQ vs. Portkey / Prisma AIRS AI Gateway
Hard budget reservations and metadata-minimized governance in one managed operating surface.
- Pre-dispatch control
- Operator-ready evidence
- Prompt storage off by default
Choose AI Gateway HQ when the gateway must prevent an unreserved request from reaching a provider and give finance, security, and operations one minimal-data evidence trail. Portkey remains a credible alternative for teams prioritizing its broader MCP, caching, and observability surface.
Every strict request reserves organization and workload exposure before a provider call; the ledger then records the route, reason, upstream attempts, cost, and settlement without storing prompt bodies by default.
Compare the operating boundary.
AI Gateway HQ entries describe implemented product behavior. Alternative entries summarize the linked first-party documentation—not anonymous review scores.
One OpenAI/Anthropic-compatible endpoint; encrypted multi-account BYOK pools; capability-first priority, weighted, request-cost, health, and request-aware provider-capacity selection; shared quota cooldowns and bounded, reason-coded fallback.
Universal API with broad providers, caching, MCP, retries, fallbacks, circuit breaking, load balancing, and canary routing.
Atomic organization-and-workload reservation before forwarding, strict rate and concurrency enforcement, explicit output caps, and settlement against supported provider-reported usage. Promotional credit cannot fund server-paid model exposure.
Budgets, rate limits, and usage/cost controls; the reviewed docs do not promise the same atomic pre-forward wallet reservation.
OIDC administration, mandatory MFA, built-in least-privilege roles, virtual workload keys, signed execution context, Observe/Shadow/Enforce policy, and local jailbreak, injection, exfiltration, encoding, and Unicode risk signals.
Enterprise SSO, RBAC, guardrails, and substantially broader current observability and administration.
WAF-protected AWS serverless deployment, tenant-bound KMS encryption, signed releases, payload-free request metadata by default, tamper-evident audit exports, and customer-approved time-bounded support access.
Managed and open-source/self-hosted options; Enterprise lists private/VPC deployment and data export.
A free BYOK proving tier, then $0.10 per 1,000 successful Flex requests with no percentage markup on inference purchased through customer-owned provider accounts; higher-control plans are scoped by operating requirements.
Free includes 10,000 logs and three-day retention; Production lists $49/month for 100,000 logs plus usage overage; Enterprise is custom.
Consider Portkey when an already-shipping MCP gateway or semantic cache is more important than deterministic prepaid enforcement.
Facts were reviewed from the linked first-party documentation and pricing pages on August 7, 2026. Public meters are not normalized: requests, logs, credits, infrastructure, and enterprise capacity are different units. Revalidate pricing and capabilities before purchasing.