AI Gateway Apps
Everything that calls your AI Gateway goes through an app. There are two kinds:
| Kind | Who calls it | Key | Budget |
|---|---|---|---|
| App | Software: a service, an agent, or a feature in a larger codebase | One API key per app | The app's own, plus its pool's and the gateway's |
| User App | People, from their everyday tools such as Claude Code or Codex | Each person's own personal API key | Per person, plus the gateway's |
A support chatbot on your website is one app; the batch job that summarizes tickets overnight is another. An engineer who wants to use Claude Code through the gateway doesn't need an app of their own: they create a personal key and call the project's User App.
The rest of this page covers apps. Each app belongs to a pool, which groups apps and controls dashboard access to them. Access to AI providers is governed separately by the user's Zuplo account and Zuplo project roles. A Zuplo account contains one or more projects, and the AI Gateway is the Zuplo project that contains these providers, pools, and apps. See Role Permissions.
Each app has three things of its own:
- An API URL—the endpoint the app's code calls, shown in full at the top of
the app page. Expand it to see the ready-to-paste URL for each service the
gateway mounts under the app—Chat Completions (
v1/chat/completions), Responses (v1/responses), and Messages (v1/messages)—and copy the one your client needs. The Universal API lists which providers serve each endpoint. The gateway attributes requests made to this URL to the app, tracking usage independently per app. - An API key—authenticates the app's requests when the gateway runs the authentication policy.
- A policy chain—the ordered policies that run on the app's requests: model access, app-specific budgets, caching, guardrails, and custom policies. The chain starts out empty unless the app's pool has a policy template.
API Keys
Each app has its own API key, which the gateway validates when the
authentication policy applies. The key is
optional: the gateway attributes usage by app ID, resolving it either from a
validated key or from the {app_id} segment of the request URL, so an app
without authentication still tracks usage independently.
To find an app's API key, open the Apps tab of your AI Gateway project in the Zuplo Portal and select the app. The key lives on the app's API Key tab.
Rotate keys to revoke access
An issued app API key authenticates gateway traffic by the key itself. Changing a user's dashboard permissions or removing them from a pool doesn't invalidate the key. To revoke access, rotate the app's API key and update authorized clients with the new value.
Additional Resources
- Creating & Editing Apps - How to create, configure, and delete apps.
- User Apps - How people call the gateway with a personal API key.
- Creating & Editing Pools - How to create and edit pools.
- Role Permissions - Details on Zuplo account, Zuplo project, and AI Gateway pool roles.