Bring your own gateway

Keep the LiteLLM, Cloudflare, or Vercel gateway you already run. NetBird takes it off the public internet and puts it behind tunnels tied to your identity provider, so you can cut off access in seconds. Switching over takes one base URL.

LiteLLMLiteLLM
Cloudflare AI GatewayCloudflare AI Gateway
Vercel AI GatewayVercel AI Gateway
OpenRouterOpenRouter
Vertex AIVertex AI
Amazon BedrockAmazon Bedrock
vLLMvLLM
Your custom gateway

How it works

01

Keep your gateway where it is

Your LiteLLM, Cloudflare, or Vercel gateway keeps doing what it already does: routing, caching, retries, fallbacks, model mapping. NetBird doesn't replace any of it.

02

Put NetBird in front of it

Agent Network gives the gateway a private endpoint inside your network, reachable only over policy-gated WireGuard tunnels. The gateway comes off the public internet.

03

Identity is stamped as headers

Every request arrives carrying the real caller's identity, email or agent name plus IdP groups, as headers your gateway can read for its own routing and logging.

04

Migrate with one base-URL change

Point clients at the NetBird endpoint instead of the gateway's public URL. No key to paste, nothing else to rewrite. The switch is a single base URL, in about 10 minutes.

Wrap your existing gateway in identity-aware access in 10 minutes.

Get Started Free

Frequently asked questions

Does NetBird replace my existing AI gateway?

No. NetBird sits in front of the gateway you already run and leaves its routing, caching, retries, fallbacks, and model mapping untouched. It adds the network and identity layer most gateways lack, rather than replacing the gateway.

Which AI gateways work with NetBird?

Any gateway that speaks HTTP works, including LiteLLM, Cloudflare AI Gateway, Vercel AI Gateway, OpenRouter, and custom in-house gateways.

How long does it take to put NetBird in front of my gateway?

About 10 minutes. Migration is a single base-URL change: you point clients at the private NetBird endpoint instead of the gateway's public URL. There is no key to paste and nothing else to rewrite.

How does NetBird pass identity to my gateway?

Each request arrives carrying the real caller's identity, email or agent name plus IdP groups, stamped as headers your gateway can read for its own routing, attribution, and logging.

Does my gateway stay exposed to the public internet?

No. Once NetBird fronts it, the gateway is reachable only over policy-gated WireGuard tunnels tied to your identity provider. There is no public URL or open port to attack, and access can be revoked within seconds.