Route & failover
Project capabilities authorize provider families; Account Scheduling Profiles choose healthy upstream capacity and fail over without changing the key or funding decision.
Self-hosted multi-provider AI gateway
Koaiu pools Anthropic API keys, Claude Code OAuth, AWS Bedrock, GCP Vertex, OpenAI keys, and Codex OAuth behind one base URL — with model routing, automatic failover, prompt-cache optimization, and per-tenant metering on every request.
MIT licensed · Postgres + Valkey · Anthropic and OpenAI dialects, ingress and egress
curl https://gateway.example.com/v1/messages \
-H "x-api-key: $KOAIU_API_KEY" \
-H "anthropic-version: 2023-06-01" \
-H "content-type: application/json" \
-d '{
"model": "claude-3-5-sonnet",
"max_tokens": 256,
"messages": [{"role": "user", "content": "Hello, Koaiu!"}]
}'01Upstream surfaces
Credentials are sealed with AES-256-GCM at rest; the scheduler is surface-agnostic and per-surface adapters translate auth, URL, and body on the hot path.
anthropic_console_api_key
Console sk-ant-… keys against api.anthropic.com. Static, operator-rotated.
claude_code_oauth
Subscription-backed OAuth with prompt-cache mimicry for the cheapest cache buckets.
open_ai_api_key
Static sk-… keys against Responses, Chat Completions, and Embeddings routes.
open_ai_codex_oauth
ChatGPT OAuth (PKCE) on the Codex backend; short-lived tokens auto-refreshed.
grok_oauth_and_key
OAuth subscriptions and static API keys for Responses, Images, and Video generation.
gemini_api_and_vertex
AI Studio keys and Google Cloud Vertex AI service accounts with Responses translation.
anthropic_bedrock
SigV4-signed requests to bedrock-runtime, region pinned on the credentials.
openai_azure
Enterprise Azure OpenAI resources with custom deployment mapping.
openai_compatible
DeepSeek, Kimi Moonshot, Zhipu GLM, Ollama Cloud, and custom HTTPS gateways.
02Architecture Philosophy
Koaiu strictly decouples Authorization, Funding, and Execution. Callers authenticate against a Project, get metered against an authorized Billing Account, and execute through an optimal upstream pool without ever knowing the underlying credentials.
Multi-tenant workload boundaries, Bearer keys, capability grants, and concurrency limits.
One key unlocks all authorized model families
Workload quotas, IP allowlists, member roles
Chat, Messages, Responses, Embeddings, Images
4-way funding arbitration across Subscriptions, Wallets, Daily/Weekly Caps, and Price Books.
Subscription-first, Balance-first, or strict mode
Versioned subscription allowances and rate limits
Hard stops, soft alerts, and reservation locks
Multi-provider account pooling, priority targets, proxy health, and prompt caching.
Claude OAuth, Codex, Bedrock, Vertex, GLM, etc.
Automatic 429/5xx backoff and health probing
H2 ping, TLS profiles, prompt cache reuse
03Why a gateway
Project capabilities authorize provider families; Account Scheduling Profiles choose healthy upstream capacity and fail over without changing the key or funding decision.
Every request settles against a subscription window or Billing Account wallet — token-class precision, cache reads and creations split, spend caps and concurrency gates enforced pre-flight.
Live account status over SSE, request captures with diffs, Prometheus metrics, and an append-only audit event for every admin mutation.
04How it works
No SDK forks, no sidecar agents. The gateway is one binary in front of Postgres and Valkey; everything below happens in its admin surface.
Onboard upstream accounts of any of the nine supported kinds. Credentials are sealed with AES-256-GCM; cooldowns, quota probes, and load tracking keep the pool honest.
9 account kinds · priority + proxy per account
Bind members, payer Billing Accounts, capabilities, and Account Scheduling policy to Projects, then issue one key that can use every permitted provider family.
reveal-once · multi-provider · audit-logged
Point any Anthropic or OpenAI SDK at the gateway. Routing, failover, cache optimization, and metering happen per request — no client changes beyond the base URL.
base_url = https://gateway.example.com
05Plans & Monetization
Koaiu publishes no price list. The operator defines immutable plan versions, Project price books, and wallet controls. Exact terms and live usage appear in your portal after sign-in.
Plan-backed funding with versioned capability entitlements.
Pricing — set by your operator
Prepaid USD funding with explicit payer authorization.
Pricing — set by your operator
Eligible subscriptions first, then an optional wallet.
Pricing — set by your operator
Start routing
Postgres, Valkey, and the Koaiu binary. Auth, billing, scheduling, observability, and the audit log ship in the box — no SaaS lock-in to undo later.