Spend caps that hold
A dollar cap per day, week or month. In hard mode, a request that could break it never reaches the provider.
API KEY SPEND CAPS FOR AI AGENTS
Keylayer turns one OpenAI or Anthropic key into many scoped keys, each with its own spend cap, rate limit, expiry and kill switch.
Get early accessWHY KEYLAYER
An agent stuck in a loop can burn a month of credits overnight, and a leaked key works for anyone until you rotate it. Keylayer gives every agent its own capped key, so a mistake stops at the limit you set.
A dollar cap per day, week or month. In hard mode, a request that could break it never reaches the provider.
Every agent or app gets its own key with its own limits. Revoke one without touching the rest.
Pause or revoke a key and its next request is refused. Or set an expiry and let it shut itself off.
Keep the OpenAI or Anthropic SDK you already use. Change the base URL and the API key. Done.
HOW IT WORKS
Keylayer sits between your code and the provider. Every request is checked against its key's limits, then forwarded with your real key attached. Your code never sees that key.
Add your provider key once. It's encrypted in the gateway and never shown again.
One per agent or app, each with its own caps, expiry and IP allowlist.
Point your SDK at gw.keylayer.dev and use the Keylayer key as its API key.
See spend per key. Tighten a limit or revoke a key whenever you like.
DASHBOARD
See every key you've handed out, what it's allowed to do and what it has spent. Change a limit and it takes effect within seconds.
LIMITS
Combine any of these on a single key. Keys created from another key can never exceed its limits.
| Spend cap | A dollar limit per day, week or month. Hard mode refuses any request whose maximum cost won't fit, or can't be worked out up front. Estimated mode settles the real cost afterwards and can run over. |
|---|---|
| Request cap | A maximum number of requests per day, week or month. |
| Rate limit | A maximum number of requests per minute. |
| Concurrency | How many requests can be in flight at once. |
| Expiry | The date and time the key stops working. |
| IP allowlist | Only accept requests from the addresses and ranges you list. |
| Pause and revoke | Stops the key from its next request. A pause can be undone, a revoke can't. |
| Admin routes | Built-in providers' routes for managing API keys, members and account settings are blocked by default. |
PROVIDERS
Keylayer forwards each request to the provider as is, with your real key swapped in. Keep your SDK and change two lines.
import OpenAI from "openai";
const openai = new OpenAI({
baseURL: "https://gw.keylayer.dev/v1",
apiKey: process.env.KEYLAYER_KEY,
});Your own API works on any domain you verify, on paid plans.
Rate limits, concurrency, expiry and IP allowlists work with every provider.
AT A GLANCE
FAQ
Keylayer is a gateway between your code and API providers like OpenAI and Anthropic. You add your real provider key once and create scoped keys from it, each with its own spend cap, rate limit, expiry and IP allowlist. Your agents and apps only ever hold the scoped keys.
In hard mode, Keylayer works out the most a request could cost before forwarding it, from the request itself and the provider's prices, and holds that amount against the cap. If it doesn't fit, the request is refused and never reaches the provider. With a $50 daily cap, a loop that would have spent $6,000 overnight stops at $50.
If the maximum cost can't be worked out in advance, hard mode refuses the request. Estimated mode lets it through and settles the real cost afterwards, so it can go over.
No. The activity log records which key called which provider and path, when, from which IP, the result, token counts and cost. It never stores request or response bodies, query string values or your keys.
No. Keep the provider's own SDK or plain HTTP. Swap the provider's hostname for gw.keylayer.dev, keep the same paths, and use your Keylayer key as the API key.
Every error Keylayer returns itself carries a keylayer-error header with the reason, such as budget_exceeded, and its message starts with "Keylayer". Errors relayed from the provider never carry that header. The body keeps the provider's own error format, so your SDK raises its usual exception.
Not through Keylayer. Every request is checked against its key, and the built-in providers' routes for managing API keys and account settings are blocked by default. The way around Keylayer is your real provider key, so keep that out of your agents' hands.
Its next request is refused. When you revoke a key, a response that's already streaming is cut off within about 10 seconds. Work the provider has already done can't be undone.
OpenAI, Anthropic, Google Gemini, Groq, Mistral, OpenRouter, ElevenLabs, Hugging Face, Replicate, Resend and GitHub, plus your own HTTPS API on a domain you verify (paid plans). Dollar caps are available where Keylayer can price the request; the others use request caps.
It isn't open yet. Join the early access list and we'll email you when it opens. Plans and pricing will be announced at launch.
EARLY ACCESS
Keylayer opens soon. Leave your email and we'll tell you the moment early access starts.
We'll only email you about Keylayer.
You're on the list. We'll email you when early access opens.
That didn't go through. Please try again.