Keyless employee access to AI providers
Engineers live in coding agents like Claude Code and Codex, backed by Vertex AI and AWS Bedrock. Instead of long-lived API keys that leak into dotfiles and CI secrets, NetBird ties access to groups in your identity provider.
One private endpoint, every provider behind it
Engineers point Claude Code, Codex, or any other agent at a single NetBird base URL.
How it works
Connect your identity provider
NetBird syncs users and groups from Okta, Entra ID, Google Workspace, or any OIDC IdP, so your existing org structure becomes the source of truth for who can reach what.
Get a private endpoint
Agent Network gives you a private endpoint inside your network. It's reachable only when users are connected to NetBird and authenticated through your IdP, never from the public internet.
Add your providers behind it
The endpoint is a secure access layer in front of your backends. Add Anthropic, OpenAI, Vertex AI, and Amazon Bedrock, or an existing gateway like LiteLLM. Teams keep using one endpoint while you manage routing centrally.
Authorize by group, not by key
NetBird's policy engine maps groups from your IdP to the providers it may reach. Set token and dollar budgets per policy, and optionally pass user or group identity upstream for full attribution.
Point your agent at the endpoint
Engineers configure Claude Code, Codex, or any other tool with the base URL NetBird provides, with no key to paste. They connect, the tunnel opens, and they're working. Remove them from the IdP group and access drops within seconds.
Give your engineers AI access without handing out a single API key.
Get Started FreeFrequently asked questions
How do engineers access AI providers without API keys?
Engineers point their tools at a single private NetBird endpoint as the base URL, with no key to paste. The tunnel opens once they're connected and authenticated through your identity provider, and NetBird handles provider access on their behalf.
Which AI providers and coding tools are supported?
Engineers can reach providers like Anthropic, OpenAI, Google Vertex AI, and AWS Bedrock, plus gateways such as LiteLLM, Cloudflare, and Vercel, through tools like Claude Code and Codex, all behind one endpoint.
How is access granted and revoked?
Access follows your identity-provider groups. Add someone to the right group and they get access immediately; remove them and access drops within seconds, with no key to rotate and no cleanup ticket.
Which identity providers does NetBird work with?
NetBird syncs users and groups from Okta, Microsoft Entra ID, Google Workspace, Keycloak, Authentik, or any OIDC identity provider, making your existing org structure the source of truth for AI access.
Can we still attribute AI usage and cost to individuals?
Yes. Because every request carries the real caller's identity, usage and cost map to people and teams rather than one anonymous shared key, and you can set token and dollar limits per policy.