Back to all features

Virtual keys and governance

Companies, teams and keys under control

Issue virtual keys under a companies-and-teams hierarchy instead of sharing raw provider secrets. Each key carries its own permissions, budgets and model access, and can be rotated or revoked without touching your provider accounts.

Included

Why it matters

  • Real provider credentials never leave the vault

  • Give each team exactly the access it needs

  • Rotate or revoke a key instantly, with no code changes

What's included

Companies and teams

Model your organisation as companies and teams, with keys that inherit the right limits and permissions.

Scoped access

Each key reaches only the providers and models you allow; anything else is a clear 403, not a confusing failure.

Rotation and revocation

Retire or rotate keys on demand without disrupting other teams or leaking provider secrets.

Vault-backed secrets

Provider credentials sit in a vault backend with rotation, never exposed to the applications calling the gateway.

Ready to see it in action?

Talk to our team and we'll show you how Xcellerate AIG fits your stack.

Get started for free