SECTION 01 / QUOTATIONS
What each project says about itself
Quoted exactly, from the file linked after each block. Ellipses mark where a line was cut; nothing else was edited.
LiteLLM
Open Source AI Gateway for 100+ LLMs. Self-hosted. Enterprise-ready. Call any LLM in OpenAI format.
Production-ready gateway - virtual keys, spend tracking, guardrails, load balancing, and an admin dashboard out of the box
BerriAI/litellm · README.md (read 2026-09-26)
Portkey Gateway
Smart caching: Cache responses from LLMs to reduce costs and improve latency.
Manage MCP servers with enterprise auth & observability using MCP Gateway
Portkey-AI/gateway · README.md (read 2026-09-26; both lines link onward to Portkey's own docs)
Agent Router, formerly Envoy AI Gateway
Agent Router gives application teams one consistent, OpenAI-compatible API for every model and tool, from hosted providers to self-hosted inference and MCP servers. Platform teams keep credentials, routing, quotas, failover, and usage attribution in one place, enforced by Envoy and Envoy Gateway.
Envoy AI Gateway is now Agent Router, an Agentic AI Foundation project. Same code, same maintainers, same release cadence and Apache 2.0 license. Nothing you deploy is renamed:
envoyproxy/ai-gateway · README.md (read 2026-09-26). If you are searching for "Envoy AI Gateway", that rename is the reason both names appear in results.
Unified AI System (this project)
Self-hosted model routing gateway and agent control plane for OpenAI, Anthropic, Gemini and A2A agents behind one OpenAI-compatible API, protocol-first. MCP server security, governed tools, prompt enhancement, virtual-key budgets, cache, observability, audit chain and agent governance. Zero-key local first run; public preview.
Our own repository description, so Section 4 restates it as checkable items rather than leaving it as a claim.
SECTION 02
Licences as each project states them
- Unified AI System - Apache-2.0, one licence, whole repository.
- Agent Router - its README says "Apache 2.0 license" in the sentence about the rename, quoted above.
- Portkey Gateway - its
LICENSEfile opens with the MIT terms. - LiteLLM - its
LICENSEfile is split: the first line reads "Portions of this software are licensed as follows", i.e. different parts under different terms. That is worth reading before you assume one licence covers the whole tree, and it is the reason this bullet exists.
A licence is not a feature and does not tell you what a gateway does. It does tell you what you are agreeing to when you fork it into your infrastructure, so read the file rather than the badge.
SECTION 03 / THE USEFUL PART
Three questions to ask any gateway before agent traffic goes through it
- Can I see who spent what, after the fact, in a form I can hand to an auditor? Ask each project where that record lives, what its retention is, and whether it is tamper-evident. A dashboard is not a record.
- What happens when I run it with no provider credentials? Either it refuses, which is fine and should be said plainly, or it has a local mode you can demonstrate on a laptop in a meeting. Ask for the command and run it before you ask for the demo.
- How do I verify what the published artifact exposes, without trusting a document? For a gateway that exposes tools, this is the supply-chain version of question 1: the catalogue entry is prose, the image is the product.
These are not rhetorical. Each one is a question you can put to LiteLLM, Portkey, Agent Router or us, and a competent answer to any of them is a link to a command or a page of documentation, not a sentence.
SECTION 04 / ANSWERS FOR US
What we claim, and how to check each one
- Tamper-evident record. The gateway writes an append-only audit chain rather than a log you can edit; see the security index for what it covers and what it does not.
-
Runs with no credentials. The default provider is a local
fake, and one documented command starts it and prints the enhanced prompt.
The run reports its own state as
mode=fake,providerCalled=falseandcredentialRequired=false, which is what the evidence guide walks through field by field - including what those three fields do not establish. -
Verifiable artifact.
node tools/verify-image-roster.mjs 0.8.0reads the published image over plain HTTPS, checks every layer blob against the digest its manifest names, and prints the tool roster that image really contains. This page carries the measured readings for eight tags. - Both directions of MCP. It serves MCP, and it puts upstream MCP servers and OpenAPI 3 operations behind one governed surface - the OpenAPI-to-MCP guide is the concrete case, and terminal-first explains why the operator interface is a CLI rather than a console.
- Where we are smaller. We do not advertise 100+ or 200+ providers; the surfaces we document are the chat APIs and the MCP and A2A paths named in our own description above, and no number of providers is a quality claim anyway. The honest summary is that we are a Public Preview with single-digit stars, not the default choice for a large estate.
SECTION 05 / EXPIRY
How this page goes stale
Three ways, and they are all checkable. A project renames itself, as Envoy AI Gateway did. A sentence moves in a README, which you can verify against the file's history at the link above rather than against this page. Or our own surface changes and Section 4 stops describing the thing you can run today - which is why every claim there is attached to a command or a document in the repository instead of to a number.
If you find a quotation that no longer matches the linked file, that is a bug in this page: open an issue with the line and we will fix the date and the text, not the other way round.
A Public Preview of self-hosted software. Real providers are disabled by default, and no part of this page claims production readiness, L5 autonomy or AGI. The other three projects are named to help a reader find them; this page is not endorsed by, and does not speak for, any of them.