Open Source, Self-Hosted

AI Gateway & LLM Security

KrakenD AI Gateway - Universal LLM hub
  • Control who accesses what LLM, full audit trail included.

  • One endpoint for OpenAI, Claude, Gemini & more.

  • Cut LLM costs with smart routing, token quotas & automatic failover.

  • Block prompt injection & unsafe content before it hits your LLMs.

  • No vendor lock-in: self-hosted, declarative, GitOps native.

Get a Personalized Demo

Tell us about your AI infrastructure needs and get a personalized demo. Or write us at [email protected]

Self-hosted SOC2 & GDPR ready No data leaves your infra

I've chosen KrakenD because of its simplicity, statelessness, immutability, and performance.

Fabijan Bajo

Tech Lead Cloud Infrastructure, IBM

image AMC Networks logo
image Privalia-Veepee logo
image Hewlett Packard logo
image Letgo logo
image Universal logo
image America's Navy logo
image Oracle logo

One AI API Gateway, Every LLM

A single AI API Gateway endpoint for OpenAI, Claude, Gemini and more. Switch providers with zero code changes.

  • Unified interface: Same format, any LLM.
  • Built-in prompt templates: Pre-formatted per vendor.
  • Instant switching: No redeployments needed.
One AI API Gateway, Every LLM

Route Smarter, Spend Less

Route by user tier, content type, or budget. Automatic failover and cost optimization.

  • Rule-based routing: By headers, JWT claims, or custom logic.
  • Auto failover: Token limit hit? Next provider takes over.
  • Tier allocation: GPT-4 for premium, open-source for internal.
Route Smarter, Spend Less

Your APIs, Agent-Ready

Built-in MCP Server. Give AI agents secure access to your APIs with full gateway controls.

  • Native MCP: Real tools, not forwarded requests.
  • Multi-API composition: One tool, multiple backends.
  • Full gateway controls: Rate limiting, auth, transforms on every call.
Your APIs, Agent-Ready

LLM Security: Stop Threats Before They Reach Your Models

Enforce LLM security with real-time detection of prompt injection and unsafe content.

  • Real-time scanning: Detect and block threats instantly.
  • Prompt validation: Standardize structures across teams.
  • Conditional routing: Reject or redirect based on security analysis.
LLM Security: Stop Threats Before They Reach Your Models

LLM Gateway & API Security FAQ

Frequently Asked Questions

1. What is an AI Gateway?

An AI Gateway is a reverse proxy that sits between your applications and LLM providers such as OpenAI, Anthropic, or Google Gemini. It handles routing, authentication, rate limiting, cost control, and security enforcement in a single layer, so your teams interact with one unified endpoint regardless of which model they use.

2. Is KrakenD an open source AI Gateway?

Yes. KrakenD's AI Gateway features are built on top of the open source KrakenD API Gateway engine, freely available on GitHub. The Enterprise Edition adds advanced capabilities such as prompt caching, prompt guarding, and AI routing policies, with no usage-based or per-token fees.

3. Why use a self-hosted AI Gateway instead of a managed SaaS?

Self-hosting keeps your prompts and responses inside your own infrastructure, which is essential for compliance with GDPR, HIPAA, or internal data governance policies. It also eliminates per-request cloud fees and vendor lock-in, giving your team full control over performance, configuration, and data residency.

4. What's the difference between an AI Gateway and an LLM Gateway?

The terms are used interchangeably in most contexts. An LLM Gateway typically refers to a component that routes and manages traffic specifically to large language model APIs. An AI Gateway is a broader concept that also covers agent communication, MCP server exposure, and governance across the full AI stack. KrakenD covers both.

5. Can I use KrakenD with OpenAI, Claude, Gemini and other LLM providers?

Yes. KrakenD supports all major LLM providers out of the box, including OpenAI, Anthropic, Google Gemini, Mistral, Cohere, and Alibaba Qwen. You can configure failover chains, load balancing, and cost-based routing across providers from a single declarative configuration file, with no code changes required.

6. How does KrakenD handle LLM security and prompt injection?

KrakenD includes prompt and response guardrails that screen incoming requests for injection attempts and jailbreak patterns before they reach any model. You can also enforce JWT authentication, IP allowlists, and rate limits at the gateway level. Because everything runs inside your own perimeter, sensitive data never leaves your infrastructure.

7. Does KrakenD work with MCP Servers?

Yes. KrakenD acts as an MCP Server, exposing your existing REST APIs as structured tools that AI agents and Copilot-style assistants can consume directly. The setup is fully declarative, with no custom code required.

8. Is KrakenD suitable for enterprise AI governance?

Yes. KrakenD provides per-team quota enforcement, token usage tracking, audit logging, and prompt caching, giving platform and security teams the visibility and controls they need to govern AI usage across the organization. Everything runs inside your own environment, with no data leaving your perimeter.

9. How does KrakenD compare to LiteLLM?

LiteLLM is a Python library and lightweight proxy focused on providing a unified API surface across LLM providers, primarily for developer tooling. KrakenD is a production-grade API and AI Gateway: beyond LLM routing, it handles authentication, rate limiting, plugin extensibility, MCP exposure, and high-throughput API composition, all in a stateless compiled binary with no runtime dependencies.

10. Is KrakenD an alternative to OpenRouter?

OpenRouter is a managed cloud service that routes requests to hosted LLM APIs. KrakenD is a self-hosted alternative that provides the same multi-provider routing capabilities, with full control over your data, no per-token pricing, and the ability to add custom business logic through plugins. If data privacy or compliance is a requirement, self-hosting with KrakenD is the natural fit.

11. What's the difference between KrakenD and Vercel AI Gateway?

Vercel AI Gateway is designed for teams building on the Vercel platform, with a focus on JavaScript applications deployed in that ecosystem. KrakenD is platform-agnostic and deploys on any infrastructure (Kubernetes, Docker, bare metal, any cloud), supports backends in any language, and extends beyond LLM routing to cover the full API gateway and AI governance layer your organization needs.

Ready to take control of your AI traffic?

Get a personalized demo. No new infra. No vendor lock-ins.

Book a Demo This Week
Book a Demo This Week
Book a Demo This Week