Any app, SDK or tool that talks to OpenAI can talk to Xcellerate AIG once you change two settings: the base URL and the API key. Teams on Anthropic's, Google's or AWS Bedrock's SDKs can keep them, because AIG answers in each vendor's own format. Every call then gets budgets, rate limits, guardrails, routing, failover and a log entry.
TL;DR
- Create one virtual key per app, team or agent.
- Point the client at the matching base URL:
/v1,/anthropic,/genai,/bedrockor/v1/mcp.- Check the first call in the logs. Your real provider keys never reach your clients.
Before you start
- An admin who can create virtual keys (Governance permission).
- At least one enabled provider in AIG and a synced model catalog.
- Network access from the app to
https://<your-gateway>(TLS, port 443). - A client that lets you set a custom base URL or endpoint.
Connect your app or tool
1. Create a virtual key
Go to Govern → Governance → Virtual keys and click New virtual key. Optionally limit providers and models, and set a budget, rate limit, expiry (from 30 minutes to never), MCP tools and an IP policy. Copy the sk-xc-… token straight away: it is shown once.
2. Point the client at AIG
| Client / SDK | Base URL | Key goes in |
|---|---|---|
| OpenAI SDKs, LangChain, LlamaIndex, Continue, Aider, Cursor, any OpenAI-compatible tool | https://<your-gateway>/v1 |
Authorization: Bearer |
| Anthropic SDK, Claude Code | https://<your-gateway>/anthropic |
x-api-key or Bearer |
| Google Gen AI SDK | https://<your-gateway>/genai |
x-goog-api-key or ?key= |
AWS Bedrock (boto3 bedrock-runtime) |
https://<your-gateway>/bedrock |
Authorization: Bearer (virtual key, not SigV4) |
| MCP clients (e.g. Copilot Studio) | https://<your-gateway>/v1/mcp |
Authorization: Bearer <virtual key> |
- Claude Code: set
ANTHROPIC_BASE_URLtohttps://<your-gateway>/anthropicandANTHROPIC_AUTH_TOKENto your virtual key. - Microsoft Copilot Studio: endpoint
https://<your-gateway>/v1/mcp, authentication "API key", headerAuthorization: Bearer <virtual key>. Tools appear asmcp__<server>__<tool>.
3. Use a model name from AIG
Take the model name from Connect → Models, for example openai/gpt-4o-mini, or the bare name if it is unique.
4. Check the first call
Send a request and open Traffic → Logs. The "Arrived as" filter shows which entry point the call used. Each response carries its request ID in the x-xc-request-id header.
What happens after you connect
GET /v1/modelslists only the models that key may call./v1covers chat completions (including streaming), embeddings, image generation, speech, transcription, rerank, models, responses, files, batches, feedback and MCP.- Routing can serve a request from a different provider than the client named; the response keeps the caller's format.
- Optional headers:
x-xc-tags(for exampleprod,checkout) for cost attribution,x-xc-agent-nameandx-xc-agent-run-idfor agent timelines,X-Request-Idandtraceparentto join your own logs and traces.
Good to know
- Streamed requests need
stream_options: {"include_usage": true}to be priced. - Bedrock SDK clients must replace the SigV4 Authorization header with the virtual key, for example with a boto3 event hook. Only invoke and invoke-with-response-stream are served.
- Gemini function calls arrive whole, not streamed. Anthropic streams report input tokens at the end.
- Provider beta endpoints are not modelled. A per-key, per-provider pass-through exists but is off by default.
- In free mode: up to 5 active virtual keys and 5 requests per key per day.
- Chat front-ends such as Open WebUI have no dedicated integration. Connect them like any OpenAI-compatible client.
Troubleshooting
- 401 "Incorrect API key provided." or "This API key has expired.": the key is unknown, revoked or expired.
- 403 "This API key is not permitted to use the model '…'.": the model is outside the key's scope. A guardrail block also returns 403.
- 404 "The model '…' does not exist or you do not have access to it.": check the name on the Models screen.
- 402 or 429: the key's budget or rate limit is used up; wait for the retry-after time.
Errors on /anthropic and /genai come back in that vendor's own error format.
Read more about one API for every model, virtual keys and request logs.
Want your team's AI tools to run through one governed gateway? Talk to us about AIG.
