Start free

See the control layer work before you connect or pay for anything.

Create a free workspace and use the Test Lab with synthetic traffic. No card or provider key is required. When you are ready for live AI, bring an API key you already control or prepay managed Amazon Bedrock.

  • Free account and Test Lab
  • No card or provider key to explore
  • Live spend remains opt-in
Working sandbox capture
Connect the first provider without exposing its key to the tool.The working setup flow distinguishes an API credential from a consumer subscription, encrypts the credential, and validates it before a route can use it.
Explore safely

I want to understand the product first

Create a free workspace, name the first use case, and open the Test Lab. Synthetic requests exercise real policy logic without calling or charging an AI provider.

  • No card, provider key, or provider charge
  • Safe scenarios for allowed, blocked, and rerouted requests
  • Add a live provider only when you choose
Create workspace and try the lab
Bring an API account

I already pay an AI provider directly

Connect a restricted OpenAI, Anthropic, Gemini, Azure, or compatible developer API key. Consumer ChatGPT, Claude, or Codex subscriptions are separate and do not expose reusable API credentials.

  • Provider credentials are encrypted and write-only
  • Your provider bills live model usage directly
  • Gateway budgets and policies govern in-scope traffic
Start with my provider
Use managed Bedrock

I do not have a provider API account

Add purchased credit by card, select an available Amazon Bedrock model, and start without opening a separate provider account. Promotional credit cannot fund AWS usage.

  • Card authorization and purchased credit required
  • Credit is reserved before each live request
  • Live managed usage stops when the balance reaches zero
Create workspace first
Already received a gateway key?

Keep your SDK or agent and replace its provider key and base URL with the expiring credentials supplied by your administrator.

Open client quickstarts
Guided setup

From sign-up to one governed request.

You do not need to understand AI routing to begin. The product starts with a safe simulation, asks what you want to control, and shows each live setting before you connect a provider or create spend.

  1. 01
    Create your workspace

    Use your work email, verify your identity, and name the company or project you want to control.

  2. 02
    Try the no-cost Test Lab

    See how budgets, policies, and routing decisions work with synthetic traffic. No prompt reaches an AI provider and no provider charge is created.

  3. 03
    Set the monthly ceiling

    Choose a conservative limit and whether the first route should favor lower cost, higher quality, or availability.

  4. 04
    Choose a live connection when ready

    Bring a restricted provider API key or prepay managed Amazon Bedrock. Purchased Bedrock credit stops at zero.

  5. 05
    Review the first decisions

    See what was allowed, blocked, spent, and routed—then accept or change the suggested controls before expanding use.

Use a restricted test provider credential first.

Production should use OIDC, KMS-backed encryption, durable storage, scoped provider accounts, and explicit budgets. Startup rejects an unsafe production configuration.

Review the trust boundary
Enterprise identity

Fit the product to your identity boundary.

Use a compatible OIDC provider for customer administrators and a separate staff identity boundary for company support. Built-in Owner, Administrator, Security, Finance, Operator, and Auditor roles keep common deployments self-service; contract-scoped federation and lifecycle requirements are reviewed before production rollout.

Human administratorsOIDC SSO and organization rolesWorkloads and agentsExpiring virtual keys and signed contextCompany supportSeparate IdP, grants, and audit store
AI Gateway HQ company staff

Customer support uses a separate restricted identity, storage, and audit boundary. Customer secrets and prompt or response bodies are structurally unavailable.

Authorized staff sign-in