Deploy agents faster. Optimize performance.
Cross-provider AI routing, inline policy enforcement, and cost-aware model selection under one control plane.
Get a demo
The Onyx Approach
Production agents need infrastructure that's secure by design. Agent-building platforms like Copilot Studio, Bedrock, and Agentforce deploy agents at scale, but they don't inspect prompts, enforce data controls, or catch when an agent acts outside its intended scope. Coding agents, custom applications, and internal LLM traffic face the same gap. Onyx is designed as the routing and enforcement layer for production agents: cross-provider routing, cost-aware model selection, and inline policy inspection on every request, alongside gateways teams already run like LiteLLM or Portkey.
Onyx adds the inline inspection that turns cross-provider routing into governed routing, and aligns cost-and-model selection with the security policy in one pass.

The Onyx Difference

Cost and security in one place
Route across LLMs to automate failover, minimize latency, and load-balance based on task complexity and cost. Every request is inspected against the same policy your security team already enforces, so cost-aware model selection and governance run through one path instead of one for cost and another for security.

Extends to the MCP Ecosystem
Every tool call an agent makes to an MCP server is evaluated against scope, identity, data class, and policy before the call lands. Coverage spans the MCP ecosystem, including servers using dynamic client registration and popular servers like GitHub, so new agents operate under policy from the first call.

Consistent Policy Enforcement
The same policy that governs a Copilot Studio agent governs a Bedrock agent, a coding agent, and a call to an MCP server. Security teams write policy once and see it enforced consistently across every path an agent takes, keeping the enforcement surface consistent as the agent stack keeps changing.
See Onyx Connect to Your Stack
Onyx drops in next to the identity, cloud, network, and endpoint tools your team already runs. Most environments produce a working AI inventory within 24 hours and an enforced governance policy on day one. To see real-time AI security across your stack...
schedule a demoConnects to the Tools You Already Run
Onyx fits into the AI infrastructure your team already runs: existing LLM gateways, model providers, agent-building platforms, and identity systems stay in place.
- Every request aligns with identity, platform, and model context in a single pass, giving security, cost, and governance teams one shared view
- The Onyx AI Gateway layers on top of your existing gateway to add inline policy inspection, or handles routing directly for teams that want a unified path.

Frequently Asked Questions
The Onyx AI Gateway is built for teams evaluating LiteLLM Enterprise or Portkey for production agent traffic. What ships by default: inline prompt inspection, tool-call policy enforcement, data-class controls, and agent-behavior guardrails on every request. Routing, cost-aware model selection, and cross-provider failover run through the same path, so security policy stays inside the request loop instead of alongside it. LiteLLM and Portkey handle routing; Onyx adds the enterprise guardrails that routing-only gateways don't.
The MCP Gateway governs the agent-to-tool surface. Every tool call an agent makes to an MCP server gets inspected and policy-enforced. Coverage spans the MCP ecosystem, including servers using dynamic client registration and popular servers like GitHub.
Five modes at the action layer: alert, block, mask, steer, or ask. Steer redirects the risky action toward a safe alternative without stopping the workflow. Ask routes the decision to a human in the loop when policy demands review.
