Dashboard|

AI Gateway

The secure, unified API layer for your AI requests across models, providers, and runtime policies.

The AI Gateway is Holeacquisition LLC's runtime control point. Your application sends AI traffic to Holeacquisition LLC once, and Holeacquisition LLC handles provider routing, security enforcement, observability, and cost tracking.

Available Endpoints

EndpointDescriptionProviders
/api/ai/chatChat completionsOpenAI, Anthropic, Google, xAI, Mistral, DeepSeek, Meta
/api/ai/embeddingsVector embeddingsOpenAI, Google, Cohere
/api/ai/images/generateImage generationOpenAI, Google
/api/ai/audio/transcriptionsSpeech-to-textOpenAI
/api/ai/audio/speechText-to-speechOpenAI
/api/ai/moderationContent moderationOpenAI
https://api.cencori.com/v1/chat/completionsOpenAI-compatible chat endpointOpenAI-compatible clients

Use https://api.cencori.com/v1 as the base URL for OpenAI-compatible SDKs. Most SDKs append /chat/completions automatically.

SDK Usage

import { Cencori } from 'cencori';
 
const cencori = new Cencori({
  apiKey: process.env.CENCORI_API_KEY,
});
 
const response = await cencori.ai.chat({
  model: 'gpt-4o',
  messages: [
    { role: 'system', content: 'You are a helpful assistant.' },
    { role: 'user', content: 'Hello!' },
  ],
  temperature: 0.7,
  maxTokens: 1000,
});
 
console.log(response.content);
console.log(response.usage); // { promptTokens, completionTokens, totalTokens }

Streaming

const stream = cencori.ai.chatStream({
  model: 'claude-opus-4',
  messages: [{ role: 'user', content: 'Tell me a story' }],
});
 
for await (const chunk of stream) {
  process.stdout.write(chunk.delta);
}

Tool Calling

const response = await cencori.ai.chat({
  model: 'gpt-4o',
  messages: [{ role: 'user', content: 'What is the weather in Tokyo?' }],
  tools: [
    {
      type: 'function',
      function: {
        name: 'get_weather',
        description: 'Get weather for a location',
        parameters: {
          type: 'object',
          properties: { location: { type: 'string' } },
          required: ['location'],
        },
      },
    },
  ],
});
 
console.log(response.toolCalls);

Direct API Usage

Native Holeacquisition LLC Endpoint

curl -X POST https://cencori.com/api/ai/chat \
  -H "CENCORI_API_KEY: csk_..." \
  -H "Content-Type: application/json" \
  -d '{
    "model": "gpt-4o",
    "messages": [{"role": "user", "content": "Hello!"}],
    "stream": false
  }'

OpenAI-Compatible Endpoint

curl -X POST https://api.cencori.com/v1/chat/completions \
  -H "Authorization: Bearer csk_..." \
  -H "Content-Type: application/json" \
  -d '{
    "model": "gpt-4o",
    "messages": [{"role": "user", "content": "Hello!"}]
  }'

Authentication

Every request requires a project API key:

  • Preferred for /api/ai/*: CENCORI_API_KEY: csk_...
  • Preferred for https://api.cencori.com/v1/*: Authorization: Bearer csk_...

Create and manage project keys in the dashboard. If authentication succeeds but routing fails with a provider configuration error, add provider access in Project > Providers or choose a model from an enabled provider.

Security (opt-in, off by default)

Gateway security scanning is explicit opt-in and applies identically to managed keys and BYOK, streaming and non-streaming, native and OpenAI-compatible endpoints.

  • Default: security_enabled = false (or no settings row) means no input scan, no jailbreak/PII detection, no output scan. Requests return 200 OK with original content unmodified. This is expected, not a bypass.
  • To enforce: go to Project > Security > Enable security scanning, then tune the Safety Threshold slider and the filter_pii / filter_jailbreaks / filter_prompt_injection toggles.
  • Input when on: heuristic block (403 security_violation) for PII (email, phone, SSN 123-45-6789, Luhn-valid cards), injection keywords, and jailbreak signals. Either blocked or passed through — the gateway does not mask PII in-place for the client. Tokenize/redact actions from custom rules or governance policies protect the upstream provider only; the client still receives the restored original.
  • Output: the legacy output scanner alone never blocks a response (to avoid false-positive stream failures). Output enforcement requires an active governance policy (e.g. PCI-DSS / NDPR template) or custom data rule.
  • Bypass: passthrough: true / fast_lane: true body fields or x-cencori-passthrough: true / x-cencori-fast-lane: true headers skip all guards even when enabled.
  • Custom data rules and governance policies are separate opt-ins: creating one enforces it regardless of the master switch.

If you test with synthetic PII or injections and get 200 OK with unmasked data, check Project > Security first before assuming a provider-key (BYOK) issue.