↓ Skip to main content
9 – 17 UHR +49 8031 3508270 LUITPOLDSTR. 9, 83022 ROSENHEIM
DE / EN

AI Gateway vs. OpenRouter: Hosted marketplace billed through one vendor, or an infrastructure component in your own tenant?

Tobias Jonas Tobias Jonas | | 12 min read

Key facts (as of 26 September 2026):

  • OpenRouter is, per its own documentation, an exclusively hosted service by OpenRouter, Inc. (New York) that, per the models overview, bundles more than 400 models and providers behind one endpoint and one bill; plan tiers such as Business and Enterprise determine SSO, SCIM and the data-region guardrails, among others.
  • The innFactory AI Gateway is deployed into the customer’s cloud tenant and bundles cost centers with per-member caps, budgets in euros and a companion that measures the agent time of Claude Code, Codex and OpenCode per repository, including subscription usage.
  • Per the documentation (as of 26 September 2026), OpenRouter’s budgets and metrics cover requests routed through OpenRouter and are kept in US dollars; a local companion measuring agent time per repository including subscription sessions is not described, whereas the innFactory AI Gateway ships that companion and displays budgets in euros at the ECB daily rate.
  • OpenRouter fits when you want many models with one key and one bill, want to operate nothing and requests may pass through OpenRouter’s infrastructure; the innFactory AI Gateway fits when data path and provider contracts are to stay in your own tenant and cost centers in euros plus agent time per repository are required.

OpenRouter describes itself on its home page as “A unified API for every major LLM. One endpoint, hundreds of models, with routing, fallbacks, and cost tracking across providers.” By its own account, the company started in early 2023 as an LLM marketplace; per the models overview, more than 400 models and providers now sit behind one endpoint. OpenRouter is a strong product for exactly this purpose: many models, one key, one bill, a broad ecosystem.

The innFactory AI Gateway solves a different problem. It is an infrastructure component deployed into your own cloud tenant that uses your own provider contracts — Azure OpenAI, Vertex AI with EU endpoint, AWS Bedrock, STACKIT or IONOS. Add budgets per cost center, seven roles, guardrails, an MCP proxy and a companion that measures the agent time of coding agents per repository.

The real decision is therefore not “which gateway has more features” but: hosted marketplace billed through one vendor — or a component in your own infrastructure where data path and contracts stay with you? Both are legitimate answers.

What OpenRouter is

Per its terms of service, the vendor is OpenRouter, Inc., based in New York; the terms are governed by the laws of the State of New York.

The gateway itself is not open source; we found no license statement for the hosted platform. The documentation distinguishes plan tiers such as Business and Enterprise, on which SSO, SCIM and the data-region guardrails depend.

Operating model: SaaS, self-hosting or infrastructure in your own tenant

OpenRouter is offered exclusively as a hosted service; a self-operated variant is not documented. Requests pass through OpenRouter’s infrastructure to the respective “Model Providers”. For Business and Enterprise customers, OpenRouter documents region-locked endpoints in the EU and the US; per the “Sovereign AI” page, prompts and completions are then processed entirely within the chosen region. The privacy policy also names possible transfers of personal data outside the EEA under standard contractual clauses; the terms of service reference a data processing agreement for organizations. Per OpenRouter, individual model providers may use data for training; Zero Data Retention can be enforced.

The innFactory AI Gateway is deployed into your own cloud tenant — Azure Container Apps or AKS as the reference path, or STACKIT or any Kubernetes cluster. innFactory does not host it as SaaS. The data path stays in your tenant, and model requests use your own provider accounts — Azure OpenAI, Vertex with EU endpoint, AWS Bedrock, STACKIT, IONOS, Mistral or Ollama. Data processing agreements are concluded directly with your providers.

Identity, SSO and roles

OpenRouter documents SSO via Okta, Microsoft Entra ID, Google Workspace or any custom SAML provider, available on Enterprise plans. SCIM group mappings likewise require an Enterprise plan and an active SSO connection. Two organization roles are documented: admins and members.

The innFactory AI Gateway authenticates via Microsoft Entra ID or generic OIDC (Keycloak, AWS Cognito). There are seven roles: Owner, Admin, Auditor, Finance, Security, Member and Guest — guests outside the allowed e-mail domains get no proxy access. IdP groups map to six roles; cost centers have their own administrators. All of this is in every license tier. SAML and SCIM are currently not included; we say that openly.

Cost control and AI FinOps

OpenRouter documents budgets per API key, per workspace with daily through lifetime windows (Enterprise) and per organization member via guardrails. Limits are hard stops: “Requests are rejected when the limit is reached.” All documented caps and cost fields are in US dollars. Every response includes a usage object with token classes and the charged cost field; aggregated usage exports as CSV or PDF. No dedicated cost-center dimension is documented; attribution works through workspaces, keys and free-form trace metadata.

The innFactory AI Gateway has four independent budget gates: organization (monthly), cost center (monthly plus daily and weekly windows, as a pool or per user with per-member caps), user and API key. An exhausted gate returns HTTP 402 with error code E4006 — or, if configured, a budget fallback model instead of a rejection; per-member caps are always hard stops. Add per-model caps, rate limits and alerts at 80 and 90 percent. Costs are broken down to cost center, repository and billing source (gateway or subscription). Display is in euros at the ECB daily rate; model prices come from ai-prices.eu and are reviewed by an administrator before use. Every buffered response carries the header x-aigateway-response-cost; Insights and CSV export provide the reports.

Coding agents, subscriptions and agent time

OpenRouter’s cookbook documents integrations for Claude Code, Claude Desktop, Codex CLI, Codex Desktop, Cursor, OpenCode, OpenClaw and Hermes Agent. Ori is OpenRouter’s own CLI wrapper (“Ori Harness runs the agent CLI you already use on OpenRouter”); per the vendor, the organization’s allowlists, budgets and workspace permissions apply to every agent on one bill. OpenRouter’s budgets and metrics cover requests routed through OpenRouter. According to OpenRouter’s documentation (as of 26 September 2026), a local companion that measures agent time per repository and also captures sessions on the tool’s subscription is not described.

In the innFactory AI Gateway’s proxy mode, developers clone admin templates for six tools — Claude Code, Codex, OpenCode, Cowork, VS Code Continue and VS Code Copilot (BYOK) — into their own setup with their own key and cost center; aigw run claude|codex|opencode launches the tool with a short-lived proxy token. The aigw companion, a background service on Linux, macOS and Windows, reads the local session logs of Claude Code, Codex and OpenCode and reports agent time, LLM time and token classes per repository and cost center. It detects whether a session ran through the gateway or on the tool’s subscription (Claude Max, Codex plan); subscription usage is valued at list price but never billed or budgeted. Rollout: device-code login or enrollment tokens via Intune, macOS policy or Linux script. To be candid: the binaries are not code-signed yet, and the companion does not cover Cursor, Windsurf or Cline.

Providers, dialects and models

Here OpenRouter is clearly broader: per the models overview, more than 400 models and providers behind one endpoint, with default load balancing and model fallbacks in priority order. Documented inbound endpoints: OpenAI-compatible chat completions, the Responses API, Anthropic Messages, embeddings and rerank.

The innFactory AI Gateway knows 13 provider types — OpenAI, Azure OpenAI, Azure AI Foundry, Anthropic (direct or via Vertex) and Gemini (AI Studio or Vertex including the EU endpoint), Mistral, AWS Bedrock, STACKIT, IONOS, Ollama, LM Studio, ElevenLabs and any OpenAI-compatible endpoint. It accepts three inbound dialects — OpenAI, Anthropic and Gemini — plus realtime WebSockets, audio, embeddings, images, moderations, OCR and files/batches. OpenRouter’s catalog is broader; connecting European providers through the customer’s own accounts is our focus.

Governance: guardrails, MCP, routing and Flow Builder

Per the documentation, OpenRouter’s guardrails combine budget, model and provider allowlists, Zero Data Retention per model group, data regions, regex-based prompt-injection detection, PII detection with redaction or blocking, and custom regex filters; a shadow mode is not documented. OpenRouter runs its own remote MCP server for models, prices, credits and documentation. Routing offers the Auto Router and Pareto Router, plus response caching and, with Broadcast, tracing to 19 named destinations with a privacy mode per destination. A visual flow builder is not documented; per the vendor, alerting is handled by the connected destinations.

The innFactory AI Gateway ships nine guardrail rule types — secret detection, PII blocking or redaction, banned keywords, token and cost limits, Azure Content Safety, prompt injection, denied topics, groundedness and external webhooks. Rules can run in shadow mode, redact mid-stream and leave audit rows. The MCP proxy offers eight upstream auth modes, access policies, toolsets and guardrails on tool arguments. Routing: auto-router by prompt complexity, aliases, cross-provider fallbacks, deployment groups. The Flow Builder is a visual graph with nine strategies, guardrail nodes that branch on pass, block or fail, and event triggers for webhooks; a flow is callable like a model and bills the same budgets.

What OpenRouter does better

  • Catalog breadth: per the models overview, more than 400 models and providers behind one key.
  • Coding-agent cookbook with eight documented integrations plus Ori as its own CLI wrapper.
  • Enterprise identity with SAML SSO and SCIM group mapping — we have neither today.
  • Observability: 19 trace destinations, plus CSV and PDF export.
  • Its own remote MCP server with live model and price data.
  • No operations: no containers, no database, no rollout — one account, one key.

When OpenRouter is the right choice

  • You want many models from different vendors with one key and one bill.
  • You have no provider contracts and do not want any.
  • You want to operate nothing and requests may pass through OpenRouter’s infrastructure — with an EU region option on Business and Enterprise plans.
  • You need SAML SSO and SCIM today.
  • Your traces should reach Datadog, Grafana or LangSmith without your own integration.

When the innFactory AI Gateway is the right choice

  • Data path and contracts stay with you: own tenant, own accounts at Azure OpenAI, Vertex EU, Bedrock, STACKIT or IONOS.
  • You want cost centers with pool or per-user budgets, budget fallback instead of rejection and display in euros.
  • You want agent time for Claude Code, Codex and OpenCode per repository — including on subscriptions.
  • You need guardrails with shadow mode and an MCP proxy with access policies and named toolsets.
  • You run or plan CompanyGPT and want to maintain budgets, roles and guardrails once.

Comparison at a glance

CriterionOpenRouter (per documentation, as of 26 September 2026)innFactory AI Gateway
Operating modelHosted service; self-hosting not documentedIn your own tenant (Azure, STACKIT, Kubernetes)
Data pathThrough OpenRouter to the model providers; EU in-region routing on Business/EnterpriseIn the customer tenant, own provider accounts
IdentitySSO and SCIM on Enterprise plans; two organization rolesEntra ID / OIDC in every license; seven roles; SAML/SCIM currently not included
BudgetsPer key, workspace (Enterprise), member; hard stopsOrganization, cost center, user, key; 402/E4006 or fallback model
Currency and per-request costUSD; usage object with cost fieldDisplay in EUR at ECB rate; header x-aigateway-response-cost
Coding agentsCookbook for eight tools; Ori wrapper; metrics for routed requestsSix proxy setups; companion for agent time per repository incl. subscriptions
GuardrailsBudget, allowlists, ZDR, data regions, prompt injection, PII; shadow mode not documentedNine rule types, shadow mode, mid-stream redaction
ObservabilityBroadcast to 19 destinations; CSV/PDF exportPrometheus, Langfuse, audit log, alerts at 80/90 %; CSV
Visual routingAuto Router, Pareto Router; flow builder not documentedFlow Builder with nine strategies, guardrail and webhook nodes

Conclusion

OpenRouter and the innFactory AI Gateway answer different questions. OpenRouter is a hosted marketplace: one account, one key, one bill, and behind it a catalog we do not offer at this breadth. Anyone who wants many models without running anything is well served there — with an EU region option on the Business and Enterprise plans and enforceable Zero Data Retention.

The innFactory AI Gateway is an infrastructure component for organizations that want to keep data path, provider contracts and cost responsibility in their own hands — with cost centers in euros, roles without an Enterprise threshold and a companion for agent time per repository. The question is where your responsibility should sit.

Natively integrated with CompanyGPT, one reusable stack

The AI Gateway is natively integrated with CompanyGPT: the same budgets, cost centers and guardrails apply to chat, agents and add-ons. Identity via Entra ID or Keycloak, cost centers, guardrails and the MCP registry are one stack reused across CompanyGPT, the gateway and every application that runs through the gateway — maintained once, effective everywhere. The gateway also runs standalone. See all comparisons and the AI Gateway overview.

Sources

Retrieved on 26 September 2026:

  • OpenRouter home page — https://openrouter.ai/
  • OpenRouter About — https://openrouter.ai/about
  • OpenRouter Quickstart — https://openrouter.ai/docs/quickstart
  • OpenRouter Terms of Service — https://openrouter.ai/terms
  • OpenRouter Privacy Policy — https://openrouter.ai/privacy
  • OpenRouter Enterprise — https://openrouter.ai/enterprise
  • Sovereign AI / in-region routing — https://openrouter.ai/docs/guides/features/sovereign-ai
  • Guardrails — https://openrouter.ai/docs/guides/features/guardrails
  • Guardrails: Sensitive Info — https://openrouter.ai/docs/guides/features/guardrails/sensitive-info
  • Zero Data Retention — https://openrouter.ai/docs/guides/privacy/zdr
  • SSO — https://openrouter.ai/docs/guides/features/sso
  • SCIM Group Mappings — https://openrouter.ai/docs/guides/features/scim-mappings
  • Workspaces — https://openrouter.ai/docs/guides/features/workspaces
  • Provisioning API Keys — https://openrouter.ai/docs/features/provisioning-api-keys
  • Usage Accounting — https://openrouter.ai/docs/use-cases/usage-accounting
  • Activity Export — https://openrouter.ai/docs/cookbook/administration/activity-export
  • Broadcast — https://openrouter.ai/docs/guides/features/broadcast
  • Coding agents cookbook — https://openrouter.ai/docs/cookbook/coding-agents/
  • Claude Code integration — https://openrouter.ai/docs/cookbook/coding-agents/claude-code-integration
  • Claude Desktop integration — https://openrouter.ai/docs/cookbook/coding-agents/claude-desktop-integration
  • Codex CLI — https://openrouter.ai/docs/cookbook/coding-agents/codex-cli
  • Codex Desktop — https://openrouter.ai/docs/cookbook/coding-agents/codex-desktop
  • Cursor integration — https://openrouter.ai/docs/cookbook/coding-agents/cursor-integration
  • OpenCode integration — https://openrouter.ai/docs/cookbook/coding-agents/opencode-integration
  • OpenClaw integration — https://openrouter.ai/docs/cookbook/coding-agents/openclaw-integration
  • Hermes Agent integration — https://openrouter.ai/docs/cookbook/coding-agents/hermes-integration
  • Ori Harness — https://openrouter.ai/docs/guides/ori/harness
  • Models overview — https://openrouter.ai/docs/guides/overview/models
  • OpenRouter MCP Server — https://openrouter.ai/docs/guides/overview/mcp-server
  • Response Caching — https://openrouter.ai/docs/guides/features/response-caching
  • Rerank — https://openrouter.ai/docs/api/api-reference/rerank/create-rerank
  • Embeddings — https://openrouter.ai/docs/client-sdks/typescript/api-reference/embeddings
  • Provider Selection — https://openrouter.ai/docs/guides/routing/provider-selection
  • Model Fallbacks — https://openrouter.ai/docs/guides/routing/model-fallbacks
  • Auto Router — https://openrouter.ai/docs/guides/routing/routers/auto-router
  • Pareto Router — https://openrouter.ai/docs/guides/routing/routers/pareto-router

Note on the information: All statements about other vendors’ products are based on their publicly available documentation as of the stated date. Vendors continuously develop their products, features and terms — the vendor’s current information always prevails. If any statement appears outdated or incorrect to you, please drop us a line at info@innfactory.ai; we will review and correct it promptly. This comparison does not replace legal or data-protection advice in individual cases.

Further reading

Tobias Jonas
Written by

Tobias Jonas

Co-CEO, M.Sc.

Tobias Jonas, M.Sc. ist Mitgründer und Co-CEO der innFactory AI Consulting GmbH. Er ist ein führender Innovator im Bereich Künstliche Intelligenz und Cloud Computing. Als Co-Founder der innFactory GmbH hat er hunderte KI- und Cloud-Projekte erfolgreich geleitet und das Unternehmen als wichtigen Akteur im deutschen IT-Sektor etabliert. Dabei ist Tobias immer am Puls der Zeit: Er erkannte früh das Potenzial von KI Agenten und veranstaltete dazu eines der ersten Meetups in Deutschland. Zudem wies er bereits im ersten Monat nach Veröffentlichung auf das MCP Protokoll hin und informierte seine Follower am Gründungstag über die Agentic AI Foundation. Neben seinen Geschäftsführerrollen engagiert sich Tobias Jonas in verschiedenen Fach- und Wirtschaftsverbänden, darunter der KI Bundesverband und der Digitalausschuss der IHK München und Oberbayern, und leitet praxisorientierte KI- und Cloudprojekte an der Technischen Hochschule Rosenheim. Als Keynote Speaker teilt er seine Expertise zu KI und vermittelt komplexe technologische Konzepte verständlich.

LinkedIn