AI Gateway vs LLM Gateway for Claude in the EU (2026)
AI gateway or LLM gateway for Claude? We compare Claude apps gateway, LiteLLM, Portkey, Kong, Cloudflare, Azure APIM and Apigee on EU residency, budgets and price.
TL;DR
An AI gateway governs every AI call: models, MCP servers and agents. An LLM gateway is the subset that sits in front of model APIs. For Claude in the EU, the gateway choice matters less than where it runs, which Bedrock or Vertex profile it calls, and who stores the logs. Self-hosted options keep all three under your control.
AI gateway vs LLM gateway: what is the difference?
An LLM gateway is a proxy between your apps and model APIs: it holds the provider key, issues per-user credentials, enforces budgets and logs requests. An AI gateway is the broader category. It applies the same controls to model APIs, MCP tool servers and agent-to-agent APIs. Every AI gateway contains an LLM gateway; not every LLM gateway governs tools.
Microsoft draws the line clearly. Its AI gateway in Azure API Management covers language model APIs, remote MCP servers, A2A agent APIs and self-hosted models, and Microsoft states it is an extension of the existing API gateway, not a separate product. Kong and Apigee follow the same pattern: AI plugins or policies on top of an API gateway you may already run.
Anthropic uses the narrower term. The Claude Code docs define a gateway as “a proxy your organization runs between Claude Code and a model provider” and list five jobs: credentials, usage tracking, cost controls, audit logging and provider switching. That is an LLM gateway in the strict sense.
For an EU buyer the vocabulary is less important than three questions:
| Question | Why it matters for GDPR |
|---|---|
| Where does the gateway process run? | Prompts pass through it in clear text |
| Where are gateway logs stored? | Logs often contain full prompts and responses |
| Which upstream profile does it call? | global. Bedrock profiles route worldwide |
If a product answers all three with “in your EU account”, it is fit for personal data. If it answers any of them with “on our platform”, you need a processor contract under Art. 28 GDPR and a look at the subprocessor list.
Which gateway products handle Claude via Bedrock or Vertex?
All seven products we checked can route Claude through Amazon Bedrock. They differ in who operates them, whether budgets cost extra, and whether the data path can be pinned to the EU. Self-hosted gateways (Claude apps gateway, LiteLLM, Kong, Portkey open source) give you EU residency by deployment choice. SaaS gateways depend on the vendor’s regional controls.
| Product | Who runs it | EU residency of gateway and logs | Claude upstreams | Budgets and limits | License and price |
|---|---|---|---|---|---|
| Claude apps gateway | You (Linux container) | Your region, your Postgres | Bedrock, Google Cloud, Foundry, Anthropic API | Per-user and per-group spend limits | Part of the claude binary, no license fee |
| LiteLLM Proxy | You | Your region, your Postgres | Bedrock, Vertex, Anthropic and more | Key, team, provider budgets (need Postgres) | MIT outside enterprise/ |
| Portkey (now Prisma AIRS AI Gateway) | SaaS, hybrid or you | Hybrid: data plane in your VPC, control plane at Portkey | Bedrock, Anthropic, Vertex | Granular budgets on Enterprise | OSS gateway MIT; Production 49 USD per month |
| Kong AI Gateway | You or Konnect | Self-hosted, or Konnect EU geo | Anthropic, Bedrock, Gemini, Vertex | AI Rate Limiting Advanced is Enterprise only | Kong Gateway Apache 2.0 |
| Cloudflare AI Gateway | Cloudflare | Regional Services not supported for AI Gateway | Anthropic, Bedrock, Vertex | Request rate limits, up to 20 spend rules | Core features free |
| Azure API Management | Microsoft (your tenant) | Region of your APIM instance | Anthropic Messages (v2 tiers), Bedrock, Vertex schema | llm-token-limit per key |
APIM tier pricing |
| Apigee | Google (your org) | Region of your Apigee org | Any HTTP LLM backend | LLMTokenQuota, HTTP 429 |
Extensible policy, cost depends on license |
A few rows need context.
Claude apps gateway is Anthropic’s own self-hosted gateway, shipped inside the claude binary since v2.1.195. It serves Claude Code and Claude Desktop, not your own applications. It needs PostgreSQL 14 or later and an OIDC identity provider; SAML and LDAP are not supported. WebSearch and the 1-hour cache TTL do not work through it, and there is no admin UI.
LiteLLM is the general-purpose option for your own apps. We covered setup, budgets and the Bedrock EU model string in our LiteLLM EU gateway guide and do not repeat it here.
Portkey now carries the name Prisma AIRS AI Gateway under Palo Alto Networks. The hosted Developer plan keeps logs 3 days; Production keeps them 30 days. The hybrid deployment runs the gateway in your Kubernetes (v1.24 or later) but it must reach control.portkey.ai. Portkey’s docs did not name a control plane region on the pages we checked.
Cloudflare is the cheapest start: core features are free, Logpush includes 10 million requests and then costs 0.05 USD per million. The catch for EU data: Cloudflare’s compatibility table marks AI Gateway as not compatible with Regional Services, Customer Metadata Boundary support as in development, and log storage jurisdiction restrictions as not supported. We would not route personal data through it until that changes.
Kong splits features by license. The AI Proxy plugin (Kong Gateway 3.6 or later) carries no AI license badge on its plugin page. AI Rate Limiting Advanced, the PII Sanitizer and the AWS Guardrails plugin are “only available as part of our AI Gateway Enterprise offering”. Konnect has an EU geo, but authentication, billing and usage data are shared across geos.
Where does an EU gateway sit in the architecture?
The gateway sits inside your network, between clients and the cloud provider, and holds the only provider credential. Developers and apps get gateway credentials instead. The EU decision happens twice: where the gateway and its database run, and which inference profile it forwards to. Get either wrong and data leaves the EU.
The request path for Claude Code through a self-hosted gateway:
- The developer’s Claude Code sends a request to the gateway URL with a per-developer credential.
- The gateway authenticates the developer against your IdP and checks model access by group.
- The gateway applies budgets and rate limits and writes a usage record to its Postgres.
- It translates the Anthropic model ID into the provider ID, for example
eu.anthropic.claude-sonnet-5on Bedrock. - It forwards the call from an EU region with the organisation’s AWS role.
- Telemetry goes to your own OTLP collector, not to Anthropic.
| Component | Where it should run | What it stores |
|---|---|---|
| Gateway replicas | EU VPC, private IP | Nothing durable (stateless) |
| Postgres | Same EU region | Sign-in state, spend, audit records |
| Upstream | Bedrock eu. profile or Vertex EU region |
Model processing only |
| Logs and telemetry | Your EU log stack | Usage per user, optionally prompts |
The Sonnet 5 model card states the EU geo profile keeps data within EU regions, while global.anthropic.claude-sonnet-5 routes worldwide with no residency constraint. Anthropic says regional endpoints include a 10% premium over global for Sonnet 4.5 and later. A gateway that silently defaults to global saves 10% and breaks your residency promise.
The client side matters too. Claude Code accepts three gateway formats: Anthropic Messages via ANTHROPIC_BASE_URL, Bedrock InvokeModel via ANTHROPIC_BEDROCK_BASE_URL, and Vertex rawPredict via ANTHROPIC_VERTEX_BASE_URL. The compatibility guide requires forwarding anthropic-beta and anthropic-version unchanged. A gateway that allowlists today’s beta values breaks the next Claude Code release.
How do you configure a gateway for Claude in the EU?
Pin the region and the model mapping explicitly, because defaults point to the US. Claude apps gateway’s built-in catalog maps models to us. profiles, and its docs say a models block is required for non-US Bedrock regions. Cloudflare’s Bedrock example calls us-east-1. Treat every vendor sample as US until you change it.
A minimal Claude apps gateway config for Frankfurt:
listen:
host: 0.0.0.0
port: 8080
public_url: https://claude-gateway.internal.example.eu
oidc:
issuer: https://login.example.eu
client_id: claude-gateway
client_secret: ${OIDC_CLIENT_SECRET}
allowed_email_domains: [example.eu]
session:
jwt_secret: ${GATEWAY_JWT_SECRET}
ttl_hours: 1
store:
postgres_url: ${GATEWAY_POSTGRES_URL}
upstreams:
- provider: bedrock
region: eu-central-1
auth: {}
auto_include_builtin_models: false
models:
- id: claude-sonnet-5
label: Claude Sonnet 5 (EU)
upstream_model:
bedrock: eu.anthropic.claude-sonnet-5
Setting auto_include_builtin_models: false stops the gateway from offering US profiles next to your EU mapping. On Google Cloud, do not set region: global: the docs say Google then routes each request to any available region.
For a different gateway product, the Claude Code side looks like this when the gateway speaks Bedrock format:
export CLAUDE_CODE_USE_BEDROCK=1
export ANTHROPIC_BEDROCK_BASE_URL=https://llm-gateway.internal.example.eu/bedrock
export ANTHROPIC_DEFAULT_SONNET_MODEL=eu.anthropic.claude-sonnet-5
To stop developers bypassing the gateway, set allowedProviders to ["customEndpoint"] in managed settings with the gateway URL in its env block; that needs Claude Code v2.1.285 or later. API keys for apps that call the gateway are covered in our Claude API key guide, and EU model availability per region in the Amazon Bedrock EU guide.
Run it yourself or outsource?
Running a gateway yourself is cheap in licenses and expensive in attention. The software is free or bundled; the work is high availability, key rotation and upgrades that keep pace with Claude Code releases. Outsourcing makes sense when nobody owns that on-call duty. It makes no sense if you already operate Kong, APIM or Apigee for other APIs.
What in-house operation actually involves, based on the vendors’ own operations docs:
| Task | Why it recurs |
|---|---|
| Upgrades | Claude Code adds headers and body fields per release; a stale gateway breaks features |
| Postgres HA and backups | Claude apps gateway spend limits fail open during a Postgres outage by default |
| Capacity | One Claude apps gateway replica sends at most 256 upstream requests at once by default |
| Secret rotation | Gateway JWT secret, OIDC client secret, provider credentials |
| Model mapping | Each new Claude model needs an EU profile entry |
| Budget review | Caps per team drift as usage grows |
Our estimate, not a vendor figure: for a single-region gateway with two replicas and managed Postgres, plan a few hours per month of platform engineering plus an on-call rotation that already exists for other services. The roles are a platform engineer, an IdP admin for groups, and someone from finance who owns the budgets.
We would outsource when there is no 24/7 platform team, when Claude is business-critical for many users, or when audit evidence must be produced by a third party. We would keep it in-house when an API gateway team exists, because adding AI policies to Kong, APIM or Apigee is a configuration change, not a new system.
What to demand from a provider who runs the gateway for you:
- An SLA for the gateway endpoint and a committed upgrade window after each Claude Code release.
- A processor agreement under Art. 28 GDPR naming the EU region of the gateway, its database and its logs.
- A subprocessor list, including any vendor control plane (Portkey hybrid, Konnect) outside your account.
- An access model where the provider’s staff cannot read prompt logs by default, with break-glass logging.
- Exit terms: config as code in your repository, database export, and provider credentials that stay in your cloud account.
Vendor support is not the same as operation. Anthropic says it does not endorse, maintain or audit third-party gateway products, so for anything other than Claude apps gateway the compatibility risk sits with you or your operator. The broader provider and contract question is covered in our GDPR provider comparison.
FAQ
What is the difference between an AI gateway and an LLM gateway?
An LLM gateway proxies model API calls: keys, budgets, logging, routing. An AI gateway adds the same controls for MCP tool servers and agent APIs. Azure API Management, Kong and Apigee market AI gateways; LiteLLM and Claude apps gateway are LLM gateways in the strict sense.
How much does an AI gateway cost?
Claude apps gateway has no license or per-seat fee; you pay compute and Postgres. LiteLLM and Kong Gateway are open source, with paid enterprise features. Portkey Production costs 49 USD per month. Cloudflare’s core features are free, with Logpush at 0.05 USD per million requests beyond 10 million.
Is Cloudflare AI Gateway suitable for EU personal data?
Not yet, in our view. Cloudflare’s own compatibility table marks AI Gateway as not compatible with Regional Services, and log storage jurisdiction restrictions are not supported. Use it for non-personal workloads or wait for full Data Localization Suite support.
Claude apps gateway vs LiteLLM: which one should we pick?
Claude apps gateway for Claude Code and Claude Desktop fleets: it signs in through your IdP and tracks Claude Code releases. LiteLLM for your own applications and multi-provider routing. Many organisations will run both, since Claude apps gateway does not serve arbitrary app traffic.
Does a gateway keep Claude data in the EU automatically?
No. The gateway forwards to whatever profile it is configured with, and several vendor defaults point to us. profiles. Map every model to an eu. Bedrock profile or an EU Vertex region, and avoid global routing, which has no residency constraint.
Do budgets still work if the gateway database fails?
It depends on the product. Claude apps gateway spend limits fail open during a Postgres outage by default; you can switch to fail closed. Our LiteLLM guide shows its budgets do not cap anything without a database. Test the failure mode before you rely on a cap.
Sources
- Claude Code docs: Run Claude Code through a gateway (1 October 2026)
- Claude Code docs: Gateway compatibility guide (1 October 2026)
- Claude Code docs: Other LLM gateways (1 October 2026)
- Claude Code docs: Claude apps gateway (1 October 2026)
- Claude Code docs: Claude apps gateway deployment and operations (1 October 2026)
- Claude Code docs: Claude apps gateway configuration (1 October 2026)
- Microsoft Learn: AI gateway capabilities in Azure API Management (1 October 2026)
- Cloudflare AI Gateway pricing (1 October 2026)
- Cloudflare Data Localization Suite: product compatibility (1 October 2026)
- Cloudflare AI Gateway: spend limits (1 October 2026)
- Portkey pricing (1 October 2026)
- Portkey docs: hybrid deployment (1 October 2026)
- Portkey-AI/gateway on GitHub (1 October 2026)
- Kong docs: AI Proxy plugin (1 October 2026)
- Kong docs: AI Rate Limiting Advanced plugin (1 October 2026)
- Kong docs: Konnect geographic regions (1 October 2026)
- AWS: Guidance for Multi-Provider Generative AI Gateway (1 October 2026)
- Google Cloud: Apigee LLMTokenQuota policy (1 October 2026)
- AWS: Claude Sonnet 5 model card (1 October 2026)
- Anthropic: Claude on Amazon Bedrock, global vs regional endpoints (1 October 2026)
- BerriAI/litellm LICENSE (1 October 2026)
- GDPR (Regulation (EU) 2016/679) (1 October 2026)