AI Gateway
The secure, unified API layer for your AI requests across models, providers, and runtime policies.
The AI Gateway is Holeacquisition LLC's runtime control point. Your application sends AI traffic to Holeacquisition LLC once, and Holeacquisition LLC handles provider routing, security enforcement, observability, and cost tracking.
Available Endpoints
Use https://api.cencori.com/v1 as the base URL for OpenAI-compatible SDKs. Most SDKs append /chat/completions automatically.
SDK Usage
import { Cencori } from 'cencori';
const cencori = new Cencori({
apiKey: process.env.CENCORI_API_KEY,
});
const response = await cencori.ai.chat({
model: 'gpt-4o',
messages: [
{ role: 'system', content: 'You are a helpful assistant.' },
{ role: 'user', content: 'Hello!' },
],
temperature: 0.7,
maxTokens: 1000,
});
console.log(response.content);
console.log(response.usage); // { promptTokens, completionTokens, totalTokens }Streaming
const stream = cencori.ai.chatStream({
model: 'claude-opus-4',
messages: [{ role: 'user', content: 'Tell me a story' }],
});
for await (const chunk of stream) {
process.stdout.write(chunk.delta);
}Tool Calling
const response = await cencori.ai.chat({
model: 'gpt-4o',
messages: [{ role: 'user', content: 'What is the weather in Tokyo?' }],
tools: [
{
type: 'function',
function: {
name: 'get_weather',
description: 'Get weather for a location',
parameters: {
type: 'object',
properties: { location: { type: 'string' } },
required: ['location'],
},
},
},
],
});
console.log(response.toolCalls);Direct API Usage
Native Holeacquisition LLC Endpoint
curl -X POST https://cencori.com/api/ai/chat \
-H "CENCORI_API_KEY: csk_..." \
-H "Content-Type: application/json" \
-d '{
"model": "gpt-4o",
"messages": [{"role": "user", "content": "Hello!"}],
"stream": false
}'OpenAI-Compatible Endpoint
curl -X POST https://api.cencori.com/v1/chat/completions \
-H "Authorization: Bearer csk_..." \
-H "Content-Type: application/json" \
-d '{
"model": "gpt-4o",
"messages": [{"role": "user", "content": "Hello!"}]
}'Authentication
Every request requires a project API key:
- Preferred for
/api/ai/*:CENCORI_API_KEY: csk_... - Preferred for
https://api.cencori.com/v1/*:Authorization: Bearer csk_...
Create and manage project keys in the dashboard. If authentication succeeds but routing fails with a provider configuration error, add provider access in Project > Providers or choose a model from an enabled provider.
Security (opt-in, off by default)
Gateway security scanning is explicit opt-in and applies identically to managed keys and BYOK, streaming and non-streaming, native and OpenAI-compatible endpoints.
- Default:
security_enabled = false(or no settings row) means no input scan, no jailbreak/PII detection, no output scan. Requests return200 OKwith original content unmodified. This is expected, not a bypass. - To enforce: go to Project > Security > Enable security scanning, then tune the Safety Threshold slider and the
filter_pii/filter_jailbreaks/filter_prompt_injectiontoggles. - Input when on: heuristic block (
403 security_violation) for PII (email, phone, SSN123-45-6789, Luhn-valid cards), injection keywords, and jailbreak signals. Either blocked or passed through — the gateway does not mask PII in-place for the client. Tokenize/redact actions from custom rules or governance policies protect the upstream provider only; the client still receives the restored original. - Output: the legacy output scanner alone never blocks a response (to avoid false-positive stream failures). Output enforcement requires an active governance policy (e.g. PCI-DSS / NDPR template) or custom data rule.
- Bypass:
passthrough: true/fast_lane: truebody fields orx-cencori-passthrough: true/x-cencori-fast-lane: trueheaders skip all guards even when enabled. - Custom data rules and governance policies are separate opt-ins: creating one enforces it regardless of the master switch.
If you test with synthetic PII or injections and get 200 OK with unmasked data, check Project > Security first before assuming a provider-key (BYOK) issue.