Take Control of AI Agent Uncertainty
LangWatch gives you a continuous understanding of how your agents behave, with the evidence to approve deployments confidently, and the controls to govern them as they scale.
Govern every model, agent framework, and tool your teams already use
Sound familiar?
The governance gaps teams bring us.
As AI tools spread across every team, the same control problems come up in almost every customer conversation. The gateway is how we close them.
Nobody can see who is using which models, through which tools, or at what cost. Spend stays invisible until the bill arrives.
Keys are copied into laptops, CI, and dotfiles with no revocation story. One leak means rotating keys across the whole org.
Data quietly leaves through AI tools and their connectors, with no way to see or stop where it goes.
Model, tool, and budget rules sit in policy docs and contracts you cannot enforce technically.
When compliance asks who did what, there is no signed, exportable record to hand over.
Without per-team budgets, spend spikes and off-hours usage go unnoticed until they get expensive.
Two homes, one platform
Same data, two surfaces. No change to how people work.
LangWatch gives every developer a personal home for the AI tools they use, and gives admins one place to govern spend, policy, access and audit across all of it.
A governance home for the org
A bird’s-eye view of org-wide spend, top spenders, open anomalies, ingestion-source health and recent activity. Behind it: author routing policies, anomaly rules and the tool catalog, with a full audit log and CSV export.
A personal home for every tool
Sign in once with SSO and wrap any approved tool with one command. The portal shows the tools you are entitled to, issues per-provider virtual keys, and tracks your spend vs budget, model mix and daily cost. Every request lands in your own trace explorer.
What it covers
One control plane for every AI tool you run.
From the coding assistants on every laptop to the closed SaaS you can only ingest, it all routes through one gateway and lands in one place.
Claude Code, Codex, Cursor, Gemini CLI and opencode. The wrapper signs the user in, mints a personal virtual key, and routes every request through the gateway.
Per-user keys for Anthropic, OpenAI, Bedrock and Gemini. Drop into app config: same gateway, same budget, no secret in dotfiles.
Workato, Microsoft Copilot Studio, OpenAI Enterprise, the Anthropic Compliance API and S3 audit drops all land in the same trace store as everything else.
Admin-defined rules for spend spikes, geo mismatch and off-hours activity, all folded from one event stream.
Every event is OCSF v1.1 mapped and replayable to Splunk, Datadog Security, Sentinel and Elastic.
Every feature has a REST API, CLI and MCP server, so you can set up and run governance straight from Claude Code or any MCP-capable agent.
One revocable key per person, policy-bound. No provider secret in a dotfile.
Every request attributed and budgeted, per person, team, project and model.
Proxied or ingested, it all lands in one trace store and one SIEM feed.
What the gateway enforces on every call.
The same drop-in endpoint carries attribution, budget enforcement, guardrails, caching and fallback on every request. It runs in front of every call, at about 11 microseconds of gateway-side overhead at 5k requests per second.
Virtual keys
lw_vk_live_ keys scoped to org, team and project. Show-once, HMAC-hashed, rotatable, revokable within 60 seconds.
Hierarchical budgets
Caps at org, team, project, key or principal. Windowed, with soft-warn or hard-block semantics.
Inline guardrails
Run your evaluators on the request, response or each streaming chunk: allow, block or redact, with no app code change.
Tool, MCP and URL policy
Allow or block tool calls, MCP servers and outbound URLs by regex before the request ever leaves.
Caching passthrough
Anthropic cache_control is forwarded byte-for-byte, protecting your cache discount.
Automatic fallback
Per-key chains across providers on 5xx, timeout, 429 or open circuit. Client errors never trigger it.
Both ship in LangWatch. They solve different problems.
The gateway is the answer when policy, budgets and key custody matter. The SDK is the answer when you want zero-overhead traces of calls you’re already making.
Closed SaaS is ingested, not proxied. Still governed.
Tools that cannot route through a gateway, like Microsoft Copilot, OpenAI Enterprise and the Anthropic Compliance API, are pulled in via OTLP or audit-log drops into the same trace store. Proxied or ingested, everything is attributed, costed, retained on your policy, and exported to your SIEM the same way.
Control all agents in your organisation.
Virtual keys, budgets, fallback, caching and traces come with it. Cloud or self-hosted, your call.



