Back to vendors
P

Portkey

Also known as: Prisma AIRS AI Gateway

Visit site
Entry priceFree Developer plan · Production $49/mo · open source gateway free to self-hostFull pricing detail

AI gateway, now presented as Prisma AIRS AI Gateway: one API to many model providers with routing, caching and guardrails, plus MCP and agent gateways, full request and tool-call logging, and enterprise governance.

Portkey is an AI gateway: a control plane between an organization's applications and agents and the models and tools they call. Palo Alto Networks acquired Portkey in 2026, and portkey.ai now announces that Portkey is Prisma AIRS AI Gateway, generally available for enterprises, while still selling Portkey's own plans.

The gateway puts many model providers behind one Universal API, so teams switch or mix models through routing configs instead of rewriting integrations, with fallbacks, retries, load balancing, conditional routing, circuit breakers and simple and semantic caching. The same configs run canary tests, sending a share of production traffic to a new model or prompt. Around the model traffic, the MCP Gateway gives agents one authenticated route to internal and external MCP servers, injecting credentials and checking per-user access for each tool, and the Agent Gateway proxies registered A2A agents with the same access control.

Every request and tool call is logged with its user, parameters, response, cost and latency, with traces, feedback scores and metadata, and guardrails check inputs and outputs and deny, flag, retry or fall back on a failed check.

Admins set budgets and rate limits per key, workspace or provider, and Enterprise adds SSO, SCIM, audit logs, logs and OpenTelemetry export, private cloud and VPC hosting, and SOC 2 Type 2 and HIPAA support. A free Developer plan and a $49 a month Production plan are self-serve, Enterprise is custom, and the open source gateway can be self-hosted free. Portkey governs and records agent traffic; it does not run agents, keep their memory or index the customer's documents.

Vendor details

Canonical URL

https://portkey.ai

Category

Agent infrastructure

Funding status

Part of Palo Alto Networks since its 2026 acquisition; portkey.ai presents Portkey as Prisma AIRS AI Gateway while still selling Portkey plans.

Company status

acquired

Use cases & customers

Primary use cases

model routing and failoverMCP and agent gatewayLLM observability and cost trackingguardrails and governance

Target customers

AI platform teamsSecurity and governance teams overseeing agent traffic

Deployment options

SaaSself-hostedcloud

Integrations

One Universal API across many model providers, including private deployments on AWS, GCP and Azure. The MCP Gateway fronts internal and external MCP servers with OAuth, bring-your-own auth, identity forwarding and JWT validation, and the Agent Gateway fronts A2A agents. Logs and analytics export through OpenTelemetry, SCIM works with Okta and Microsoft Entra, and partner guardrails plug into the gateway.

In practice

Your apps each integrate a different model provider, and switching is a rewrite every time. Portkey gives you one gateway in front of hundreds of providers, so you route or swap models, with automatic fallbacks, without changing your code.

Your agents are quietly burning through tokens and you have no single view of the spend. Portkey logs every model and tool call with cost and latency, and enforces rate limits and budget guardrails to stop runaway usage.

Security needs control over agent traffic without slowing developers down. Portkey acts as a control plane that routes, monitors, and governs every AI request, flagging or blocking non-compliant behavior in real time.

Agentic Index coverage score

7.5 / 14 capabilities · 54%

Integrations & Tool Calling Full

Agents authenticate once to Portkey's MCP Gateway, which sits between them and MCP servers: for each tool call the gateway checks that user's access to the server and tool, then injects the upstream credentials (OAuth, API keys or custom headers, with external identity providers such as Okta and Auth0), with servers and individual tools provisioned per workspace and user. Agents therefore take authenticated action in outside systems through the gateway.

Sourcedocs.portkey.ai/docs/product/mcp-gatewayread 2026-09-22

Workflow Orchestration Not documented

The Agent Gateway is a proxy between agent clients and the customer's own agent servers, handling authentication, access control and observability for registered A2A agents; the agents and their steps run on the customer's servers. Portkey documents no workflow definition or agent execution of its own, so nothing in it sequences or branches agent steps.

Sourcedocs.portkey.ai/docs/product/agent-gatewayread 2026-09-22

Knowledge Grounding & RAG Not documented

Embedding and file requests route through Portkey to providers and responses are cached, but no retrieval structure that Portkey maintains over the customer's documents is documented; routing embedding calls builds none.

Sourceportkey.ai/pricingread 2026-09-22

Human Oversight & Guardrails Partial

Inputs and outputs pass through Portkey Guardrails, which act on the verdict automatically, denying the request, flagging it and letting it through, retrying or falling back, and the MCP Gateway applies content filters per server, per user tool provisioning and rate limits on tool calls; org and workspace admins can enforce guardrails, budgets and rate limits. These are customer controlled constraints on what an agent may do. No step where a person reviews, approves or must validate before an agent action commits is documented.

Sourcedocs.portkey.ai/docs/product/guardrailsread 2026-09-22

Security, Identity & Governance Full

Security @ Portkey documents SSO through OIDC on enterprise plans, fine-grained role-based access control, encrypted storage of provider keys, TLS 1.2+ in transit and AES-256 at rest, and states compliance with SOC 2, ISO 27001, GDPR and HIPAA with regular third-party audits and penetration tests, linking the Trust Center at trust.portkey.ai; the pricing page names SOC 2 Type 2 and custom BAAs on Enterprise, and the docs cover SCIM for Okta and Microsoft Entra, audit logs, JWT authentication and API key rotation.

Sourcedocs.portkey.ai/docs/product/enterprise-offering/security-portkeyread 2026-09-22

Observability & Auditability Full

Portkey records what agents did through it: the MCP Gateway logs every tool call with the user, parameters and response, filterable by server, user or time range, and model requests carry logs, traces, feedback, custom metadata, filters and alerts on every plan (pricing page), with retention stated per plan. Enterprise adds audit logs, logs export and OpenTelemetry export.

Sourcedocs.portkey.ai/docs/product/mcp-gatewayread 2026-09-22

Memory & State Persistence Not documented

The documented features are routing, caching, observability, guardrails, prompt management and the MCP and agent gateways. No memory layer with a stated scope and lifetime that persists an agent's state or a user's context across sessions is documented, and a response cache is not one.

Sourceportkey.ai/pricingread 2026-09-22

Deployment & Data Residency Full

The pricing page lists private cloud deployment, VPC hosting and data isolation on Enterprise, and an open source gateway the customer hosts itself; the docs cover hybrid deployments on the customer's AWS (EKS, ECS, Marketplace), GCP and Azure (AKS, ACA), air gapped deployment, and a Gateway URLs setting that points the dashboard at the customer's own self hosted AI and MCP gateways. Customers can deploy into an environment they name, though some options sit on Enterprise.

Sourceportkey.ai/pricingread 2026-09-22

Prebuilt Agents, Templates & Packs Not documented

Nothing ready made ships for a buyer to adopt, whether agents, workflows, templates or role specific agents: the Prompt Library holds the customer's own templates, the Skills Registry shares skills the team writes, and the prebuilt assets are guardrail checks and partner guardrail integrations, which constrain agents rather than do work.

Sourcedocs.portkey.ai/docs/product/guardrailsread 2026-09-22

Triggers & Channel Coverage Not documented

Work reaches agents through Portkey when a client sends a request: model, MCP and A2A calls are all made by the caller, and the Agent Gateway proxies them to the customer's agent servers. No schedule, event, webhook or inbound queue that starts an agent run is documented. As a gateway that waits for callers, it never wakes an agent on its own.

Sourcedocs.portkey.ai/docs/product/agent-gatewayread 2026-09-22

Model Flexibility & Routing Full

Model choice sits with the customer: Portkey's Universal API puts many model providers behind one interface, and routing configs the customer writes set providers, model overrides, fallbacks, load balancing weights, retries, conditional routing and circuit breakers, with support for private model deployments on AWS, GCP and Azure.

Sourceportkey.ai/pricingread 2026-09-22

APIs, SDKs & MCP Extensibility Full

Developers get Portkey's own API and SDKs: the Feedback page shows the same call through the Node and Python SDKs and the REST API, the docs index links a published OpenAPI specification, prompts are served through a Prompt API, and the Agent Gateway acts as a server to downstream agent clients for registered A2A agents.

Sourcedocs.portkey.ai/docs/product/observability/feedbackread 2026-09-22

Testing, Debugging & Optimization Full

Canary testing sends a set share of production traffic to a new model or prompt through a routing config, on every plan, and each request carries guardrail verdicts (pass or fail per check, counted in the log drawer) and weighted feedback scores sent through the Feedback API, analyzable by metadata. Guardrails can deny, retry or fall back on a failed check. Together that gives a documented way to evaluate a change with readable, comparable results.

Sourcedocs.portkey.ai/docs/product/ai-gateway/canary-testingread 2026-09-22

Browser & Computer Use Not documented

Portkey documents no browser, desktop or remote computer session that it runs for an agent; its gateway routes model calls, including provider computer-use tools whose actions the customer's own code carries out. It wires in no headless fetch or third party browser engine either.

Sourceportkey.ai/pricingread 2026-09-22

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

Free Developer plan · Production $49/mo · open source gateway free to self-host

usage

Free tier

Included quota

Dev: 10K recorded logs a month with basic observability and gateway features. Production: 100K logs with $9 per additional 100K (up to 3M), 30 day retention, guardrails, RBAC, semantic caching. Enterprise: 10M+ logs, custom retention, SSO, private cloud/hybrid/airgapped deployment.

What is public

Portkey publishes self-serve pricing: a free Developer plan, Production at $49 a month with a published overage, and custom Enterprise with private cloud, VPC and data isolation options. The open source gateway self-hosts free with no request limit.

Billing mechanics

Flat plan fee bundles a monthly recorded log allowance; additional logs bill in $9 per 100K increments. Model/provider costs are the customer's own since Portkey is a routing layer.

Cost watchouts

Billing is on recorded logs: requests keep flowing past the plan's log allowance, but logs beyond it are not recorded, which leaves traffic unobserved on an undersized plan. Log retention is 3 days on Developer and 30 days on Production; longer retention, SSO and data residency options are Enterprise only.

Variable cost rationale

Log volume metering scales with traffic, but the $9 per 100K overage is modest; the bigger swing is the jump to Enterprise for retention and compliance.

Additional watchouts

Buyers outside the Palo Alto Networks ecosystem should weigh how Prisma AIRS integration priorities shape the standalone product roadmap.

Overage / add-ons

Production: $9 for every additional 100K requests, up to 3M a month; Developer: no overage, logs past 10K are not recorded

Sales call required

Mixed (some tiers require a call)

Free / trial

Developer plan free forever (10K recorded logs a month); open source gateway free to self-host

Lowest paid plan

Production $49/mo (100K recorded logs, $9 per additional 100K)

Commercial notes

Acquired by Palo Alto Networks (announced Apr 30, 2026, closed May 29, 2026) to serve as the AI Gateway for Prisma AIRS. Prior: $15M Series A (Feb 2026, Elevation/Lightspeed). Routes to 1,600+ models across providers; 2025 Gartner Cool Vendor in LLM Observability.

Key ambiguities

Enterprise pricing is unpublished. portkey.ai now announces that Portkey is Prisma AIRS AI Gateway under Palo Alto Networks while still selling the Portkey plans above; packaging may change.

Missing data

Enterprise pricing unpublished; post acquisition plan roadmap unconfirmed.

Agentic Index verified 2026-09-22

Alternatives to Portkey

The closest documented capability profiles to Portkey among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Arcade7.5 / 14Matches Portkey across all 14 documented capabilities
  • Kong8.5 / 14Adds documented Knowledge Grounding & RAG
  • Freeplay8.0 / 14Adds documented Triggers & Channel Coverage
  • Metorial8.0 / 14Adds documented Triggers & Channel Coverage
  • Stacklok8.0 / 14Adds documented Prebuilt Agents, Templates & Packs
  • Clawvisor6.5 / 14Fuller documented coverage on Human Oversight & Guardrails

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.