megachangelog
Feature

AI Gateway - Prevent Unified Billing fallback for BYOK third-party providers

AI Gateway now supports requiring provider credentials for third-party requests, preventing automatic fallback to Cloudflare-managed Unified Billing credentials. You can enforce this at the gateway level or per-request using the byok_only setting or cf-aig-no-wholesale header.

AI Gateway can now require credentials for third-party provider requests. Credentials must accompany the request or be stored on the gateway. This setting prevents fallback to Unified Billing with Cloudflare-managed credentials.

Turn on Require provider credentials in your gateway settings. To use the API, set byok_only to true in the request body of a PUT request to update the gateway:

{
	"byok_only": true
}

To require provider credentials for one third-party request, set the cf-aig-no-wholesale header to true. This header cannot relax the gateway setting.

Requests without applicable credentials then return an HTTP 400 response. Workers AI requests remain allowed, and the setting does not change their configured billing mode.

For configuration details and request-level controls, refer to Prevent Unified Billing fallback for BYOK third-party providers.

ai-gatewaybillingbyokcredentialsapi

Source: original entry ↗