KeylayerGet early access

API KEY SPEND CAPS FOR AI AGENTS

Hand out API keys. Keep the wallet.

Keylayer turns one OpenAI or Anthropic key into many scoped keys, each with its own spend cap, rate limit, expiry and kill switch.

Get early access

WHY KEYLAYER

Hard limits.
Not hope.

An agent stuck in a loop can burn a month of credits overnight, and a leaked key works for anyone until you rotate it. Keylayer gives every agent its own capped key, so a mistake stops at the limit you set.

Spend caps that hold

A dollar cap per day, week or month. In hard mode, a request that could break it never reaches the provider.

A key per agent

Every agent or app gets its own key with its own limits. Revoke one without touching the rest.

Kill switch included

Pause or revoke a key and its next request is refused. Or set an expiry and let it shut itself off.

Your SDK, unchanged

Keep the OpenAI or Anthropic SDK you already use. Change the base URL and the API key. Done.

HOW IT WORKS

Connect once. Hand out keys.

Keylayer sits between your code and the provider. Every request is checked against its key's limits, then forwarded with your real key attached. Your code never sees that key.

  1. 1

    Connect your key

    Add your provider key once. It's encrypted in the gateway and never shown again.

  2. 2

    Create scoped keys

    One per agent or app, each with its own caps, expiry and IP allowlist.

  3. 3

    Change two lines

    Point your SDK at gw.keylayer.dev and use the Keylayer key as its API key.

  4. 4

    Watch and adjust

    See spend per key. Tighten a limit or revoke a key whenever you like.

DASHBOARD

All your keys. One dashboard.

See every key you've handed out, what it's allowed to do and what it has spent. Change a limit and it takes effect within seconds.

  • Spend per key
  • Pause or revoke
  • Rotate the real key
  • No prompts stored

LIMITS

Eight ways to rein it in.

Combine any of these on a single key. Keys created from another key can never exceed its limits.

Limits you can set on a Keylayer key
Spend capA dollar limit per day, week or month. Hard mode refuses any request whose maximum cost won't fit, or can't be worked out up front. Estimated mode settles the real cost afterwards and can run over.
Request capA maximum number of requests per day, week or month.
Rate limitA maximum number of requests per minute.
ConcurrencyHow many requests can be in flight at once.
ExpiryThe date and time the key stops working.
IP allowlistOnly accept requests from the addresses and ranges you list.
Pause and revokeStops the key from its next request. A pause can be undone, a revoke can't.
Admin routesBuilt-in providers' routes for managing API keys, members and account settings are blocked by default.

PROVIDERS

Works with the SDK you already use.

Keylayer forwards each request to the provider as is, with your real key swapped in. Keep your SDK and change two lines.

Node.js with the official OpenAI SDK
import OpenAI from "openai";

const openai = new OpenAI({
  baseURL: "https://gw.keylayer.dev/v1",
  apiKey: process.env.KEYLAYER_KEY,
});

Hard or estimated spend caps

  • OpenAI
  • Anthropic
  • Google Gemini
  • Groq
  • Mistral

Estimated spend caps

  • OpenRouter
  • ElevenLabs
  • Hugging Face

Request caps

  • Replicate
  • Resend
  • GitHub
  • Your own HTTPS API

Your own API works on any domain you verify, on paid plans.

Rate limits, concurrency, expiry and IP allowlists work with every provider.

AT A GLANCE

Easy to adopt. Hard to misuse.

11
built-in providers
2
lines to change
0
prompts stored

FAQ

Straight answers.

What is Keylayer?

Keylayer is a gateway between your code and API providers like OpenAI and Anthropic. You add your real provider key once and create scoped keys from it, each with its own spend cap, rate limit, expiry and IP allowlist. Your agents and apps only ever hold the scoped keys.

How does a spend cap stop a runaway agent?

In hard mode, Keylayer works out the most a request could cost before forwarding it, from the request itself and the provider's prices, and holds that amount against the cap. If it doesn't fit, the request is refused and never reaches the provider. With a $50 daily cap, a loop that would have spent $6,000 overnight stops at $50.

If the maximum cost can't be worked out in advance, hard mode refuses the request. Estimated mode lets it through and settles the real cost afterwards, so it can go over.

Does Keylayer store my prompts or responses?

No. The activity log records which key called which provider and path, when, from which IP, the result, token counts and cost. It never stores request or response bodies, query string values or your keys.

Do I need a new SDK?

No. Keep the provider's own SDK or plain HTTP. Swap the provider's hostname for gw.keylayer.dev, keep the same paths, and use your Keylayer key as the API key.

How do I tell a Keylayer limit from a provider error?

Every error Keylayer returns itself carries a keylayer-error header with the reason, such as budget_exceeded, and its message starts with "Keylayer". Errors relayed from the provider never carry that header. The body keeps the provider's own error format, so your SDK raises its usual exception.

Can an agent get around its limits?

Not through Keylayer. Every request is checked against its key, and the built-in providers' routes for managing API keys and account settings are blocked by default. The way around Keylayer is your real provider key, so keep that out of your agents' hands.

What happens when I pause or revoke a key?

Its next request is refused. When you revoke a key, a response that's already streaming is cut off within about 10 seconds. Work the provider has already done can't be undone.

Which providers does Keylayer support?

OpenAI, Anthropic, Google Gemini, Groq, Mistral, OpenRouter, ElevenLabs, Hugging Face, Replicate, Resend and GitHub, plus your own HTTPS API on a domain you verify (paid plans). Dollar caps are available where Keylayer can price the request; the others use request caps.

When does Keylayer launch, and what will it cost?

It isn't open yet. Join the early access list and we'll email you when it opens. Plans and pricing will be announced at launch.

EARLY ACCESS

Put a cap
on it.

Keylayer opens soon. Leave your email and we'll tell you the moment early access starts.