Concepts
Gateway
The gateway sits between your agents and the model providers, and applies your policies and budgets to every request.
The gateway is the address your agents send their model requests to. It speaks the same request formats as the major model providers, so an agent only needs a new base URL and its Clovie key.
What happens to a request
For every request, the gateway:
- Identifies the agent from its agent key.
- Checks the agent may run. A disabled or archived agent, or one stopped by a kill switch, is turned away.
- Applies your policies. Each policy that applies to the agent can allow the request, block it, redact it or hold it for a person to approve. Policies in monitor mode only record what they would have done.
- Checks budgets and limits. If a budget in enforce mode is exhausted, the request is blocked or moved to a lower-cost model, depending on how you set it up.
- Forwards the request to the model provider with your provider key, and streams the answer back.
- Records the outcome: the decision, the reason, the tokens used and the cost.
Your agent sees a normal provider response, or a clear error that says which check stopped the request and why.
Request formats
The gateway accepts three request formats, so most SDKs work without changes:
| Format | Path | Typical SDKs |
|---|---|---|
| Chat Completions | /v1/chat/completions | OpenAI SDKs, LangChain, most frameworks |
| Messages | /v1/messages | Anthropic SDKs, Claude-based tools |
| Responses | /v1/responses | OpenAI Responses API |
Streaming works in all three formats. See Connect an agent for examples.
Models
An agent asks for a model by name, for example gpt-4o or anthropic/claude-sonnet-5. It can only use models your organization has enabled in AI Governance → Models → Catalog. If you set a Default Model on the agent, the agent can send auto as the model name and the gateway uses the default.
Keys and credentials
Two kinds of keys are involved, and they never mix:
- Agent keys identify your agents to the gateway. Agents hold them.
- Provider keys are your accounts with model providers. Only Clovie holds them, and the gateway uses them to call the provider. See Provider credentials.
When the gateway cannot check a request
If Clovie cannot evaluate your policies for a moment, your organization decides what happens: let traffic continue and raise an alert (the default), or reject requests until checks are back. You choose this per organization, so teams with strict security needs can fail closed.
Where the gateway runs
With Clovie SaaS, your agents use Clovie's hosted gateway. With a self-hosted install, the gateway runs in your own network, so requests never leave it on the way to your models. See Choose SaaS or self-hosted.