Bring your own gateway
Keep the LiteLLM, Cloudflare, or Vercel gateway you already run. NetBird takes it off the public internet and puts it behind tunnels tied to your identity provider, so you can cut off access in seconds. Switching over takes one base URL.
How it works
Keep your gateway where it is
Your LiteLLM, Cloudflare, or Vercel gateway keeps doing what it already does: routing, caching, retries, fallbacks, model mapping. NetBird doesn't replace any of it.
Put NetBird in front of it
Agent Network gives the gateway a private endpoint inside your network, reachable only over policy-gated WireGuard tunnels. The gateway comes off the public internet.
Identity is stamped as headers
Every request arrives carrying the real caller's identity, email or agent name plus IdP groups, as headers your gateway can read for its own routing and logging.
Migrate with one base-URL change
Point clients at the NetBird endpoint instead of the gateway's public URL. No key to paste, nothing else to rewrite. The switch is a single base URL, in about 10 minutes.
Wrap your existing gateway in identity-aware access in 10 minutes.
Get Started FreeFrequently asked questions
Does NetBird replace my existing AI gateway?
No. NetBird sits in front of the gateway you already run and leaves its routing, caching, retries, fallbacks, and model mapping untouched. It adds the network and identity layer most gateways lack, rather than replacing the gateway.
Which AI gateways work with NetBird?
Any gateway that speaks HTTP works, including LiteLLM, Cloudflare AI Gateway, Vercel AI Gateway, OpenRouter, and custom in-house gateways.
How long does it take to put NetBird in front of my gateway?
About 10 minutes. Migration is a single base-URL change: you point clients at the private NetBird endpoint instead of the gateway's public URL. There is no key to paste and nothing else to rewrite.
How does NetBird pass identity to my gateway?
Each request arrives carrying the real caller's identity, email or agent name plus IdP groups, stamped as headers your gateway can read for its own routing, attribution, and logging.
Does my gateway stay exposed to the public internet?
No. Once NetBird fronts it, the gateway is reachable only over policy-gated WireGuard tunnels tied to your identity provider. There is no public URL or open port to attack, and access can be revoked within seconds.