AXIGATE FINOPSDocs
Start free
Use cases ›

Put a team on one gateway

Run one gateway on a shared server and send everyone's agents through it. The whole team shares one set of limits and one record, and each person has a key of their own.

You will learn

  • How to start a gateway the whole team can reach
  • How to give each person their own key
  • How each person sends their agent through it
  • Where the shared gateway's limits can live

Where this works

You don't need a plan to read on.
Free editionyour own machinesHosted FreehostedTeamhostedBusinesshosted
Run one gateway for the whole team
Give each person their own key

Start the shared gateway

Pick a server every computer on the team can reach and install AxiGate on it. Make the keys file first (the next step shows how): the commands below won't start without it.

Make a key for the shared server on Connect a gateway and start the gateway with it, so a record of every call it serves lands in your workspace, which becomes the team's dashboard. The key is shown once, when you make it.

On the shared server
AXIGATE_INGEST_KEY=<the key from Connect a gateway> axigate-finops gateway --listen 0.0.0.0:8787 --gateway-keys ./keys.toml --max-spend-per-run 5 --ingest-url https://<your workspace>/api/ingest

In your own workspace this is Connect a gateway. Start free to get one.

Give each person a key

The keys file lists each person by name, with a secret of their own. The gateway serves only calls that carry one of those secrets.

keys.toml
[keys]
alice = "<a long random secret>"
bob = "<another long random secret>"

Make each secret with the first command below, and give every person a different one. Then make the file readable by you alone: the gateway refuses a file others can read.

On the shared server
openssl rand -hex 24
chmod 600 keys.toml

To add or remove someone, edit the file. The gateway picks up the change within seconds, with no restart.

Send each person's agent through it

On each person's computer, install AxiGate and start the agent like this, with their key and the server's address. Put their own agent's command in place of claude.

On each person's computer
axigate-finops run --gateway http://<server>:8787 --gateway-key <their key> -- claude

Their agent keeps its own provider key. The gateway key is added on the way out, and the shared gateway takes it off before the call reaches the provider.

Limits live on the shared gateway, so everyone is held to the same ones: run refuses --max-spend there. Your own code can still give one run a tighter limit, as Stop a runaway shows.

Keep the options in one file

Instead of a long command, the shared gateway's limits can live in an axigate.toml in the folder it starts in: one per line, by the option's name without the dashes. Both serve and gateway read it, and an option typed on the command line wins over the file.

axigate.toml
max-spend-per-run = 5
max-calls-per-run = 200
max-spend-per-key-day = 50

The amounts are examples. Key limits explains the last one.

Recap

  • Start one gateway on a shared server with a keys file: serve on your own machines, or gateway with a key made for it on Connect a gateway on the hosted service.
  • Give each person their own secret. Edit the file to add or remove someone; no restart.
  • Each person sends their agent through the shared gateway with their key. Limits are set once, on the gateway.
  • The shared gateway's limits can live in axigate.toml; addresses, secrets, the provider and watch only stay on the command line.