Your AI users shouldn't need API keys
How we put identity-aware access in front of a model gateway so developers sign in with their directory account instead of holding API keys. We did not want our internal users establishing individual relationships with external model providers. Personal accounts and provider-issued credentials would allow AI traffic to bypass our organization's access controls, approved-model policies, and compliance requirements. Instead, we introduced an open source model gateway as the shared entry point for AI traffic. It gave us centralized model access, routing, and provider credential management — but created another problem: authenticating our users. The gateways we evaluated generally offered directory integration and single sign-on only in their enterprise editions — with pricing beyond what our budget could justify for this specific requirement. We needed something narrower: authenticate users with our existing directory and authorize models based on their groups or roles. Ga...