Beta: The LLM Gateway is in beta.
Prerequisites
- Your Organization admin has enabled the gateway and completed any required provider setup.
- You have a workspace-scoped LangSmith API key with
gateway:invokeandworkspaces:readpermissions. - For bring-your-own-key models, your workspace has the corresponding provider secret. Gateway Credits models do not require a provider secret.
Claude Code CLI
Choose the authentication method that matches how your organization pays for Anthropic usage.Use a workspace provider key
Point Claude Code at the standard Messages endpoint and use a provider-prefixed model ID:/v1/messages to ANTHROPIC_BASE_URL. The gateway uses the anthropic/ prefix to resolve the workspace’s Anthropic provider secret.
Use Claude subscription OAuth
Claude Code Plus and Max users can send their saved Anthropic OAuth credential through the gateway. This mode is available to all organizations and does not require anANTHROPIC_API_KEY in workspace provider secrets.
Log in to Claude Code with your subscription, then configure the gateway:
anthropic-beta header automatically.
The LangSmith API key authenticates the gateway request and remains subject to gateway permissions and policies. The gateway forwards the OAuth bearer to Anthropic, so Anthropic bills the call to the user’s Claude subscription instead of the workspace provider key.
Codex CLI
Codex uses the Responses API. Add the following to~/.codex/config.toml to call the hosted Kimi K3 model with Gateway Credits through the standard endpoint:
model with its provider-prefixed ID, such as openai/gpt-5.4-mini.
Gemini CLI
Gemini CLI sends Google’s native Generate Content requests, which the standard endpoint does not expose. Follow Direct model access to configure the/gemini route, then run:
Deep Agents Code
Use the OpenAI-compatible client with the standard endpoint, then pass the hosted model slug through theopenai integration:
openai:, for example, openai:anthropic/claude-opus-5. For provider-native integrations and model IDs, see Direct model access.
Company-wide deployment
For organizations rolling the gateway out to all developers, distribute the configuration through mobile device management or a shared shell profile. Distribute:- The standard gateway base URL for each client.
- A workspace-scoped LangSmith API key per user or team, depending on your policy granularity.
- The model IDs approved for each coding agent.
- The Codex
config.tomlif your organization uses Codex.
Verify the setup
After configuring a coding agent, make a test call and confirm that:- The call succeeds and the agent receives a response.
- A trace appears in the
gatewayorgateway-<short_api_key>-<api_key_id>tracing project in your LangSmith workspace.
403, check that your API key’s role includes gateway:invoke and workspaces:read. If a bring-your-own-key call fails with a 400 mentioning a missing provider key, ask your organization admin to add the provider’s key to workspace secrets.
Next steps
- Gateway Credits: call hosted models without a provider secret.
- Direct model access: configure provider-native routes for coding agents that require them.
- Spend policies: set cost limits on developer LLM usage.
- Traces, Engine, and access control: understand where gateway traces appear.
Connect these docs to Claude, VSCode, and more via MCP for real-time answers.

