Gateways compared

Kong AI Gateway vs LiteLLM, Portkey, Cloudflare and OpenRouter

A sourced comparison of five AI gateway options, plus Swfte Connect as a disclosed entry, with who should pick each and what to check first.

An AI gateway sits between your application and model providers and adds routing, limits, logging and controls. The five options here are different kinds of product: a self-hosted open-source proxy (LiteLLM), a hosted gateway with an open-source core (Portkey), an API-gateway extension (Kong), an edge service (Cloudflare) and a hosted model router (OpenRouter). Every cell for the five vendors comes from a vendor-owned page read on 2026-10-07, and "not verified" marks what those pages did not state. Swfte makes Connect, which is listed too, so read that row as a vendor's own entry.

Last verified 2026-10-07. Sources are listed at the end of the page.

What is each gateway, and how is it deployed?

Licence is stated as the vendor states it. Where the pages read did not say, the cell says "not verified". Swfte Connect is made by the publisher of this page.

ProductWhat the vendor says it isDeploymentLicence or open-source status
LiteLLMAn OpenAI proxy server (LLM gateway) to call 100+ LLMs in a unified interface, track spend and set budgets per virtual key or user. A Python SDK exists too.Self-hosted, with Docker support.MIT for content outside the enterprise/ directory. Content in enterprise/ is under a separate licence. Enterprise features are under a commercial licence.
PortkeyA platform with a unified interface for AI models, plus observability. The open-source gateway adds routing, fallbacks, caching and guardrails.A managed service and an open-source gateway you host. The README mentions Docker, Node.js, Cloudflare Workers and Kubernetes. Private cloud is an enterprise option.The gateway repository is MIT licensed. The hosted platform is a commercial service.
Kong AI GatewayA control plane for AI-native applications, with connectivity and governance across LLM, MCP and agent-to-agent traffic.Konnect (Kong's cloud), self-hosted, or Kong Gateway. The pricing page lists dedicated cloud, serverless and hybrid gateways.Kong Gateway is Apache 2.0 per its README. Several AI plugins are marked "AI Gateway Enterprise" only. Whether AI Proxy ships in the open-source build: not verified.
Cloudflare AI GatewayA service for observing and controlling AI applications: analytics, caching, rate limiting, retry and fallback, and logging.Hosted on Cloudflare. The docs say it is available on all plans.Not verified. The pages read do not state an open-source edition.
OpenRouterA single API endpoint for hundreds of AI models that handles fallbacks and picks cost-effective options.Hosted service.Not verified. The docs read do not state a licence or an open-source edition.
Swfte Connect (disclosed)One OpenAI-compatible API with bring-your-own-key, routing and fallback chains, budgets and usage caps, content-policy detectors and audit events.Managed service, with customer data in AWS eu-west-1 (Ireland) per the trust page. A deployment in your own cloud is designed for and on request.No open-source claim is made.

Sources: docs.litellm.ai and the BerriAI/litellm repository; portkey.ai docs and the Portkey-AI/gateway repository; developer.konghq.com, konghq.com/pricing and the Kong/kong repository; developers.cloudflare.com/ai-gateway; openrouter.ai docs. Read on 2026-10-07.

Which gateway has an OpenAI-compatible API, fallback and caching?

ProductOpenAI-compatible APIRouting and fallbackCaching
LiteLLMThe README lists drop-in OpenAI compatibility.Load balancing, routing and fallbacks (failover).Built-in caching is listed.
PortkeyThe docs say it works with the OpenAI Python and Node SDKs.Fallbacks, conditional routing, load balancing, automatic retries and a circuit breaker are listed.Response caching is listed. The README says semantic caching is part of the enterprise version.
Kong AI GatewayAI Proxy accepts requests in standardised OpenAI formats and translates them to each provider.Routing and load balancing across providers. The AI Proxy Advanced plugin adds algorithms such as tiered failover and is marked Enterprise only.The AI Semantic Cache plugin serves similar prompts from a vector store and is marked Enterprise only.
Cloudflare AI GatewayAn OpenAI-compatible chat completions endpoint exists under the gateway address.Request retry and model fallback, plus dynamic routing.Serves requests from Cloudflare's cache instead of the provider.
OpenRouterThe docs describe OpenAI SDK use as a drop-in.A models array in priority order. The next model is tried on errors such as rate limits, downtime, moderation refusals and context length errors.Provider-side prompt caching with sticky routing to keep the cache warm. It is not an OpenRouter response cache.
Swfte Connect (disclosed)Yes: OpenAI-style chat completions.Tier fallback chains across providers, and per-workspace routing rules with a mandatory fallback chain.No caching claim is made on this page.

What budgets, guardrails, observability and MCP support does each document?

ProductBudgets and limitsGuardrails or content filteringObservabilityMCP support
LiteLLMBudgets and rate limits per virtual key or user.Guardrails and custom policies that modify requests and responses.Logging, alerting and metrics.An MCP gateway with one fixed endpoint, and access control by key, team and organisation. It lists streamable HTTP, SSE and stdio transports.
PortkeyBudget limits by cost or tokens, and rate limits.Guardrails that verify inputs and outputs against your checks.Monitoring of LLM requests, with log retention that depends on the tier.An MCP gateway with central authentication, access control and logging of each tool call. The page read does not state the plan it needs.
Kong AI GatewayAI Rate Limiting Advanced enforces token budgets and spend caps and is marked Enterprise only.Prompt protection against disallowed topics and prompt injection. Semantic prompt guard is Enterprise only, and the pricing page lists AWS Guardrails and Azure Content Safety plugins as enterprise.Audit logs, metrics exporters and OpenTelemetry.AI MCP Proxy proxies MCP servers and converts REST APIs into tools. It is marked Enterprise only and needs AI Gateway 3.12 or later.
Cloudflare AI GatewaySpend limits as cost-based budgets, scoped by model, provider or metadata, plus rate limiting.Guardrails that evaluate prompts and responses and flag or block. Data loss prevention is also listed.Analytics, logging and custom metadata.Not verified for AI Gateway. Cloudflare documents MCP server portals separately under Zero Trust, which centralise MCP servers on one endpoint with access policies.
OpenRouterGuardrails at workspace level include a budget limit in USD that resets daily, weekly or monthly.Model and provider allowlists, zero data retention enforcement, regex-based injection and jailbreak detection, and PII detection with redact or block.A Logs page for each generation (prompt and completion text only if you enable input and output logging), and Broadcast of traces to tools such as Datadog and Langfuse.OpenRouter publishes its own MCP server and an Agent SDK package for remote MCP servers. A gateway for governing third-party MCP servers: not verified.
Swfte Connect (disclosed)Workspace caps (daily tokens, monthly spend) and per-model caps, with an option to downgrade to a cheaper model at a cap. A concurrent-request limit applies.Content-policy rules with built-in secret and personal-data detectors, custom patterns and a redact action.An audit event stream and usage reads.The gateway resolves a workspace's MCP tools when a request uses tool calling. Per-tool allow and deny rules are designed for, not built.

How is each gateway priced, as published?

Prices are as each vendor publishes them on 2026-10-07. Check the vendor page before you rely on a figure.

ProductPricing model as publishedWhere to check
LiteLLMOpen source: $0, free and self-hosted. Enterprise: annual, sized to usage, no published price, sales-led. The page says it is never per token.litellm.ai/pricing
PortkeyOpen source: free, self-hosted. Developer: free, 10k recorded logs per month. Production: $49 per month, 100k recorded logs, $9 per additional 100k requests. Enterprise: custom.portkey.ai/pricing
Kong AI GatewayKonnect AI Management: Plus from $25 per month plus usage, with usage items such as requests and proxied models. Enterprise: custom, billed annually. Fully self-hosted gateways are a separate Gateway Enterprise offering with custom pricing.konghq.com/pricing
Cloudflare AI GatewayCore features are free. Guardrails are billed as Workers AI usage. Unified billing adds a 5% fee on credits purchased. Logging limits depend on when the account was created.developers.cloudflare.com/ai-gateway/reference/pricing
OpenRouterInference at each provider's list price. Platform fee on credits: 5.5% on Standard and 8% on Business, with discounts on Enterprise. With your own keys, the first $25,000 of list-price inference per month has no fee, then 5%.openrouter.ai/pricing
Swfte Connect (disclosed)Not restated here. See the Swfte pricing page.Swfte pricing page

Who should pick each gateway?

These are fit rules drawn from the documented features above. They are not scores or a ranking.

ProductConsider it whenCheck first
LiteLLMYou want a self-hosted, open-source proxy with an OpenAI-compatible API in your own infrastructure, and you can run and patch it.Which features sit under the commercial licence, and your own patching and release-pinning process.
PortkeyYou want either a gateway you host under an MIT licence or a hosted control plane with published self-serve tiers.Log limits and retention on the tier you need, and which MCP gateway features your plan includes.
Kong AI GatewayYou already run Kong for API traffic and want LLM and MCP traffic under the same control plane.Which plugins you need are Enterprise only: semantic cache, AI Proxy Advanced, AI Rate Limiting Advanced and AI MCP Proxy.
Cloudflare AI GatewayYou already use Cloudflare and want a hosted gateway whose core features are free.MCP handling is not verified for AI Gateway, guardrails are billed as usage, and logging limits depend on your account.
OpenRouterYou want one hosted key for many models and a published per-credit fee.Platform fees at your volume, and whether a hosted router in the request path fits your data-handling rules. This page does not assess that.
Swfte Connect (disclosed)You want one gateway alongside agents, MCP tools and approvals on one platform, and you accept a vendor-hosted gateway.Self-deployment is on request, no caching claim is made here, and no provider count is stated.

What do vendors publish about their own security incidents?

Check each vendor's security page before you adopt a gateway, because a gateway sees your prompts and provider keys. LiteLLM publishes security notices on its blog. Its post of 24 March 2026 says that litellm versions 1.82.7 and 1.82.8 on PyPI were compromised for about 40 minutes, that it believes the cause was a dependency in its CI scanning workflow, and that users of the official Proxy Docker image were not affected. It says a clean release, 1.83.0, followed on 30 March 2026. Read the vendor's own post for the full account.

This page links it because it is the vendor's own statement, not to rank anyone. We did not search the other vendors' sites for equivalent notices, so the absence of one here says nothing about them.

How do you compare gateways on your own workload?

  1. 1. Write your requirements

    List the providers you call, the controls you need (budgets, content filtering, MCP), where the gateway may run, and who will operate it.

  2. 2. Run the same prompts through each

    Use a small set of real prompts and the OpenAI-compatible endpoint of each candidate. Compare the logs each one gives you.

  3. 3. Break the primary provider

    Block your main provider and watch what each gateway does. Check that fallback works and that you can see it happened.

  4. 4. Check what is stored

    Find out whether prompts and responses are logged, where, and for how long. Some vendors store metadata only by default.

  5. 5. Price your volume

    Ask each vendor for a quote or use its published rates at your request volume. Include log retention and any plan limits.

  6. 6. Read security and licence terms

    Read the licence, the vendor's security page and its release process. See How to set up an LLM gateway for a walkthrough.

Where Swfte fits, and when you do not need it

Swfte Connect is the model gateway of the Swfte platform. This page lists it only with what Swfte can evidence: one OpenAI-compatible API, bring-your-own-key, routing and fallback chains, budgets and usage caps, content-policy detectors with a redact action, and an audit event stream. See Swfte Connect. Swfte does not score or rank any product here, including its own.

You do not need Connect if a gateway you already run meets your needs. If you run LiteLLM, Portkey or OpenRouter and they cover your controls, there is no reason to move. The alternatives pages for LiteLLM, Portkey and OpenRouter say when switching helps and when staying is right.

Sources and last verified

Every dated or technical fact on this page was read from the pages below on 2026-10-07. Anything that could not be confirmed is left out or marked as not verified.

Frequently asked questions

What is an AI gateway?

An AI gateway is a service between your application and one or more model providers. It gives your code one API, and adds controls such as routing, fallbacks, caching, budgets, content filtering and logging. Some also manage MCP servers. Products differ in whether you host them, whether they are open source and which controls need a paid tier.

Is LiteLLM open source?

Mostly. The LiteLLM repository licence says content outside the enterprise directory is available under the MIT licence, and content inside the enterprise directory is under a separate licence. Its README refers to features under a commercial licence, and its pricing page lists an open source tier at $0 and a sales-led Enterprise tier.

Does Kong AI Gateway support MCP?

Kong documents an AI MCP Proxy plugin that proxies MCP servers, converts REST APIs into MCP tools and exposes grouped tools as a managed MCP server. The plugin page says it is only available as part of the AI Gateway Enterprise offering and needs AI Gateway 3.12 or later, as read on 2026-10-07.

Is Cloudflare AI Gateway free?

The core features are free according to Cloudflare's pricing page: analytics, caching and rate limiting. Guardrails are billed as Workers AI usage, unified billing adds a 5% fee on credits purchased, and logging limits depend on when the account was created. Check the pricing page for the current terms before you plan costs.

Is OpenRouter an AI gateway?

It overlaps with one. OpenRouter is a hosted service with a single API endpoint for many models, fallbacks, guardrails and logs. It differs from a self-hosted proxy such as LiteLLM because requests pass through OpenRouter's service and you pay a published platform fee on credits. The docs read do not state an open-source edition.

Which AI gateway should I choose?

It depends on where you want to run it and which controls you need. Pick a self-hosted proxy if you want to operate it yourself, an extension of a gateway you already run if you use Kong or Cloudflare, or a hosted router if you want one key for many models. Test two candidates on your own prompts before committing.

Compare gateways on your own prompts, then choose

Deploy a model with Swfte Connect

One gateway, every provider, per-token cost visibility. Swap models without touching your code.