Skip to main content
Governance covers the admin side of the LangWatch AI Gateway: who can call which model, on which budget, and what record is kept of it. Members get a personal key without seeing a provider secret. Admins set the providers, the routing policies and the budgets once for the whole organization.

Pages in this section

Personal keys

Sign in from the LangWatch CLI and get a personal virtual key that Claude Code, Codex, Cursor, Gemini CLI and OpenCode use.

Admin setup

Add a model provider, create a routing policy, mint the first virtual key, set a budget and invite members, in order.

Routing policies

Decide once which providers and models a key can reach. Virtual keys point at the policy.

Retention

What the gateway stores, and which platform setting governs how long each record lives.

OCSF export

Pull governance events into your SIEM as OCSF records through a cursor-paginated API.

Architecture

The gateway service, the control plane routes, the change feed, the spend spool and the auth cache.

Audit log

Who did what, when, to which gateway resource.

RBAC

The gateway resources, the actions on them, and the default role mappings.
Last modified on September 6, 2026