---
url: 'https://docs.workato.com/en/ai-gateway.md'
description: >-
  Model Gateway gives you one OpenAI-compatible API to authenticate LLM
  providers, route requests, and enforce policies across your applications.
---

# Model Gateway {: #ai-gateway :}

Model Gateway is a single point of control between your applications and LLM providers. Applications connect through one OpenAI-compatible API, and the gateway handles provider authentication, routing, and policy enforcement so your applications don't have to.

::: info FEATURE AVAILABILITY

Model Gateway is available to select customers. Contact your Customer Success Representative to confirm whether it is available in your workspace.

:::

The following diagram shows the path a request takes through Model Gateway:

```mermaid
flowchart LR
    A[Application] -->|Access key| B[Policy]
    B --> C[Route]
    C -->|Rules or default target| D[Provider and model]

    classDef default fill:#67eadd,stroke:#67eadd,stroke-width:2px,color:#000;
    classDef WorkatoBlue fill:#5159f6,stroke:#5159f6,stroke-width:2px,color:#fff;
    class D WorkatoBlue;
```

You can use Model Gateway to perform the following:

* **Issue scoped access keys to teams**: Generate access keys for each team, project, or application instead of sharing provider credentials. Revoke or rotate a key without touching downstream applications, and keep provider keys out of environment variables, configuration files, and CI pipelines.
* **Swap providers without rewriting applications**: Route Workato recipes, genies, copilots, and external applications through a single OpenAI-compatible API. Switch models without code changes in the calling applications.
* **Apply usage limits**: Define rate limits and token limits in a policy, then assign the policy to the access keys a team or application uses to cap how much they can consume.
* **Restrict access by IP address**: Allow or block requests from specific IP addresses or ranges in a policy.

## Key components {: #key-components :}

Model Gateway includes the following components:

* **Providers**: Connections to LLM services, such as Anthropic, OpenAI Compatible, Azure OpenAI, and AWS Bedrock, along with the credentials Model Gateway uses to authenticate. Providers are stored in a project and can be reused in genies.
* **Routes**: The targets that serve requests. A route resolves to a provider and model, either directly or through rules that match on tags, keys, parameters, or request complexity. Applications reference a route by its route ID.
* **Access keys**: Credentials that applications present to Model Gateway. Each access key grants access to one or more routes and attributes usage to a team or application.
* **Policies**: Reusable rate limits, token limits, and IP access restrictions that you assign to routes and access keys.
* **Dashboard**: Workspace-level visibility into request volume, token usage, and success and failure rates.

Refer to [Configure Model Gateway](/en/ai-gateway/configure.md) to add providers, create routes, issue access keys, and define policies, the [Route builder](/en/ai-gateway/route-builder.md) to define the rules a rule-based or intelligent route uses, or the [Model Gateway dashboard](/en/ai-gateway/monitor.md) to monitor traffic and token usage.

## How Model Gateway works {: #how-ai-gateway-works :}

Applications send a request to Model Gateway and authenticate with an access key. The access key determines which routes the application can use, and the route it names determines the provider and model that serves the request. When a policy applies, Model Gateway enforces its rate limits, token limits, and IP access restrictions before the request reaches the provider.

## Supported applications {: #supported-applications :}

Any client that's compatible with the OpenAI SDK can route through Model Gateway without code changes because the gateway exposes an OpenAI-compatible API. This includes Workato recipes, [genies](/en/agentic/agent-studio), copilots, and external applications. Model Gateway supports Server-Sent Events (SSE) end to end to allow streaming responses to render incrementally rather than waiting for the full payload.
