Skip to main content
integration · ai-gateway

AI Gateway — Govern LLM Spend Across OpenAI, Anthropic, OpenRouter and Bedrock

What does the AI Gateway integration do?

ZopNight's AI Gateway supports four LLM providers: OpenAI, Anthropic, OpenRouter and AWS Bedrock. Each registers a curated set of models by default, and every request is metered against per-team virtual keys with hard USD budgets. ZopNight never sits in the request path.

Coverage by category

AI spend is the fastest-growing line on the cloud bill. ZopNight connects to your LLM providers (OpenAI, Anthropic, OpenRouter, and AWS Bedrock) and brings model usage under the same budgets, alerts and dashboards as the rest of your infrastructure, including hard caps through gateway virtual keys.

Live key checks, and Bedrock riding your AWS account

OpenAI, Anthropic and OpenRouter connect with an API key that ZopNight verifies live before saving (a revoked key can never sit green). Bedrock needs no key at all: it rides the AWS account you already connected, minting temporary credentials on demand. Optionally connect your LiteLLM-compatible AI gateway for per-team virtual keys with spend limits. Warnings fire at 80% and the gateway enforces the hard cap.

Paste a key, or point at a connected AWS account

  1. Settings > Integrations > AI Providers.
  2. Pick the provider and paste its API key (or, for Bedrock, choose the connected AWS account and region).
  3. Create budgets against providers or virtual keys and pick alert channels.

Budgets, alerts and the optional LiteLLM gateway

Live-verified provider connections. Per-provider and per-virtual-key budgets with warning/critical events to any notification channel. Bedrock via existing AWS credentials (no new secrets). Optional LiteLLM gateway integration.

Choosing between them

Pick by what you already have. If your spend is on one vendor, connect that vendor directly. OpenRouter is the multi-vendor path: a single credential reaching several model families, useful for comparing routing postures without provisioning accounts everywhere. Bedrock is worth connecting when AI spend should land on the AWS bill you already govern.

They are not exclusive: connect several and let the routing posture decide which serves each request.

What is shared across all four

Virtual keys with hard budgets, per-request cost attribution, three routing postures and the semantic cache behave identically regardless of provider. The provider choice affects which models are available and where the bill lands, not how governance works.

faq · ai-gateway

AI Gateway integration: common questions

Do my LLM prompts pass through ZopNight?

No. The gateway runs on hosted LiteLLM, which ZopNight configures, meters and budgets; prompt and completion bodies never reach ZopNight infrastructure. That is why per-request cost attribution works without anyone reading request bodies.

Do I need a new API key to connect Bedrock?

No. Bedrock rides the AWS account you already connected and mints temporary credentials on demand. OpenAI, Anthropic and OpenRouter each take an API key, which ZopNight verifies live before saving so a revoked key cannot sit green.

What happens when a virtual key reaches its budget?

It stops working. A warning event fires at 80% and the gateway enforces the hard cap, so the number is a limit rather than an alert.

no live rules

No active rule family targets AI Gateway — Govern LLM Spend Across OpenAI, Anthropic, OpenRouter and Bedrock today. Rules that used to are retired, and retired rules publish no pages and fire no findings. Scheduling and permissions coverage are unaffected.

Providers on the gateway

4 LLM providers connect through the gateway. Each page lists the models ZopNight registers by default, their tier, and how spend is attributed.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·