Comparison · reviewed August 7, 2026

AI Gateway HQ vs. Portkey / Prisma AIRS AI Gateway

Hard budget reservations and metadata-minimized governance in one managed operating surface.

  • Pre-dispatch control
  • Operator-ready evidence
  • Prompt storage off by default
Working sandbox capture
This is the product—not a concept rendering.A capture from the working test environment shows the controls and evidence described in this comparison. Open it full-size to inspect the interface.
Why teams choose AI Gateway HQ

Choose AI Gateway HQ when the gateway must prevent an unreserved request from reaching a provider and give finance, security, and operations one minimal-data evidence trail. Portkey remains a credible alternative for teams prioritizing its broader MCP, caching, and observability surface.

Every strict request reserves organization and workload exposure before a provider call; the ledger then records the route, reason, upstream attempts, cost, and settlement without storing prompt bodies by default.

Capability evidence

Compare the operating boundary.

AI Gateway HQ entries describe implemented product behavior. Alternative entries summarize the linked first-party documentation—not anonymous review scores.

Decision areaWhat AI Gateway HQ deliversWhat Portkey / Prisma AIRS AI Gateway documents
Gateway and routing

One OpenAI/Anthropic-compatible endpoint; encrypted multi-account BYOK pools; capability-first priority, weighted, request-cost, health, and request-aware provider-capacity selection; shared quota cooldowns and bounded, reason-coded fallback.

Universal API with broad providers, caching, MCP, retries, fallbacks, circuit breaking, load balancing, and canary routing.

Spend enforcement

Atomic organization-and-workload reservation before forwarding, strict rate and concurrency enforcement, explicit output caps, and settlement against supported provider-reported usage. Promotional credit cannot fund server-paid model exposure.

Budgets, rate limits, and usage/cost controls; the reviewed docs do not promise the same atomic pre-forward wallet reservation.

Identity and governance

OIDC administration, mandatory MFA, built-in least-privilege roles, virtual workload keys, signed execution context, Observe/Shadow/Enforce policy, and local jailbreak, injection, exfiltration, encoding, and Unicode risk signals.

Enterprise SSO, RBAC, guardrails, and substantially broader current observability and administration.

Deployment and evidence

WAF-protected AWS serverless deployment, tenant-bound KMS encryption, signed releases, payload-free request metadata by default, tamper-evident audit exports, and customer-approved time-bounded support access.

Managed and open-source/self-hosted options; Enterprise lists private/VPC deployment and data export.

Public commercial model

A free BYOK proving tier, then $0.10 per 1,000 successful Flex requests with no percentage markup on inference purchased through customer-owned provider accounts; higher-control plans are scoped by operating requirements.

Free includes 10,000 logs and three-day retention; Production lists $49/month for 100,000 logs plus usage overage; Enterprise is custom.

When to consider Portkey / Prisma AIRS AI Gateway

Consider Portkey when an already-shipping MCP gateway or semantic cache is more important than deterministic prepaid enforcement.

Comparison method

Facts were reviewed from the linked first-party documentation and pricing pages on August 7, 2026. Public meters are not normalized: requests, logs, credits, infrastructure, and enterprise capacity are different units. Revalidate pricing and capabilities before purchasing.