Know exactly who spent what. Cap it before it burns.
NetBird attaches token and dollar budgets to every policy, attributes each request to the real person or agent behind it, and denies anything over the cap at the network layer, before it costs you.
Spend control and attribution in one place
The budgets, the attribution, and the audit trail all live on the same access policy.
Budget & token caps
Set dollar and token limits per group and per individual, with reset windows. Requests over the cap are denied at the network level
Per-identity attribution
Every request is tied to the real caller, a person's email or an agent's name, so spend maps to teams and people instead of one shared key.
Runaway-agent protection
A looping or compromised agent hits its budget and gets a 429 instead of running up an unbounded bill. Containment is automatic.
SIEM & finance export
Stream the access log, with identity, model, tokens, cost, latency, and status, to your SIEM or finance tooling for reporting.
How it works
Connect your identity provider
NetBird syncs users and groups from Okta, Entra ID, Google Workspace, or any OIDC IdP. Those groups become the unit you attribute cost to and cap spend against.
Attach budgets to a policy
On any policy, set token and dollar caps, for the whole group and per individual, with reset windows. No gateway required; the limits live on the NetBird policy itself.
Every request lands in the access log
As people and agents call AI through NetBird, each request is logged with identity, model, tokens, cost, latency, and status, attributed to the real caller behind it.
Caps enforce themselves
When a group or individual crosses its budget, the next request is denied with a 429, catching a runaway agent or a surprise spike before it becomes a bill.
Export for finance and security
Stream the log to your SIEM or finance stack. Chargeback by team, spot the models driving cost, and give finance and security the same single source of truth.
See who's spending what — and cap it — in under 10 minutes.
Get Started FreeFrequently asked questions
How does NetBird control AI API costs?
NetBird attaches token and dollar budgets to network policies. Because every request flows through NetBird tied to a real identity, spend is metered per group and per individual, and any request over the cap is denied at the network layer before it adds to your bill.
Can I set spending limits per team or per person?
Yes. Each policy carries both a group budget and a per-individual budget, in tokens and in dollars, with configurable reset windows (for example $10,000 per group and $500 per person, resetting every 30 days).
How does NetBird attribute AI spend to specific users or agents?
Access is tied to your identity provider, so each request names the real caller: a person's email or an agent's name plus their IdP groups. The access log records identity, model, tokens, cost, latency, and status for every call, so cost maps to people and teams instead of one shared key.
What happens when a team or agent exceeds its budget?
The next request is denied with an HTTP 429 response and a 'Budget exceeded' reason, instead of continuing to spend. This automatically contains a runaway or looping agent before it runs up an unbounded bill.
Does AI cost control require a gateway like LiteLLM?
No. Budget and token limits live inside NetBird on the network policy, so they apply whether you front an existing gateway such as LiteLLM or point directly at providers. There is no separate billing layer to run.
Can I export AI usage and cost data for finance and security?
Yes. The full access log, covering identity, model, provider, tokens, cost, latency, and status, can be streamed to your SIEM or finance tooling for chargeback, forecasting, and reporting.