Which AI Tools Can an AI Gateway Govern? Developers, Employees, Apps, and Your Own Product
Last updated: October 2026
Tetrate Agent Router Enterprise governs every AI tool that lets your admin set the tool’s endpoint, which covers far more people than the developers who asked for the gateway.
The AI tools an AI gateway can govern fall into four groups. Developers use tools such as Claude Code, GitHub Copilot, and Cursor. Everyone else uses desktop and browser tools such as Claude Desktop and a company chat page. Your teams build apps and agents. And you may sell a product with AI features. The test for any single tool is one question. Does the tool let your admin choose the endpoint the tool sends requests to? If yes, Tetrate Agent Router Enterprise can govern the tool. Where a vendor picks the model, Agent Router Enterprise gives you a governed path to the same work, covered below.
Most companies buy a gateway for one group and find out later that the other three were spending money the whole time.
The Rule: If Your Admin Can Set the Endpoint, the Gateway Can Govern the Tool
A gateway sits in the request path. A tool’s requests reach the gateway only when the tool sends them there. That happens in one of three ways:
| How the tool connects | What your admin does | Examples |
|---|---|---|
| Base URL and API key | Changes two settings | Claude Code, Cursor, Codex, the OpenAI and Anthropic SDKs |
| Model provider plugin | Installs one extension | GitHub Copilot chat and agent mode in VS Code |
| Bring-your-own-model connection | Adds the gateway as a model source in the vendor’s console | Azure AI Foundry agents |
Once a tool’s requests pass through the gateway, the tool gets the same controls as every other tool. That means one key per person or app, cost by team and user, budgets, guardrails, and a request log. You don’t build a separate policy per tool.
Developers: Coding Agents and IDE Assistants Route Through One Gateway Key
Developers are where the gateway usually starts, because developers run the most tokens. The coding agents guide covers each tool, and the tare integrate command writes the config file for the most common ones.
| Tool | How the tool connects | Detail worth knowing |
|---|---|---|
| Claude Code | tare integrate claude-code | One profile reaches Anthropic, OpenAI, Gemini, and self-hosted models. Passthrough mode keeps a Claude Max subscription as the billing path and still logs every request. |
| GitHub Copilot in VS Code, chat and agent mode | The Tetrate VS Code extension | One key serves Copilot chat, agent mode, and every other extension that asks VS Code for a model |
| GitHub Copilot CLI | Three environment variables, per GitHub’s custom model guide | Pick a model that supports tool calling and streaming |
| Cursor | Base URL setting, plus a .cursorrules file for generated code | |
| Codex, Aider, Cline, Continue | tare integrate <tool> | The command backs up the old config and makes one test call |
Roy Prins wrote up what this looks like for a developer: developers create their own keys. They get a priced, approved model list inside VS Code without filing a ticket. That’s the developer on-ramp in practice.
Two tips. Start with Copilot chat and agent mode, because that’s where developers send the heavy model work. And turn on bring-your-own-model in your Copilot Business or Enterprise policy before you set a rollout date.
Everyone Else: Claude Desktop and a Company Chat Page Give Citizen AI Builders a Governed Path
Marketing, finance, and legal teams use AI every day. They’re citizen AI builders: people who build with AI without writing code. Their spend shows up on expense reports, not in your engineering budget, and nobody files a ticket with you first.
Two tools put that work on the gateway:
| Tool | How the tool connects | Detail worth knowing |
|---|---|---|
| Claude Desktop, Cowork and Code tabs | Gateway mode, set by tare integrate claude-cowork or by an admin | Gateway mode puts every Cowork and Code request in your logs and budgets |
| A company chat page | A web chat your IT team hosts, such as Open WebUI, pointed at the gateway | Any tool with an OpenAI-compatible endpoint setting works the same way, per the app integration guide |
Roy Prins’ Claude Desktop post walks through the desktop setup. David Wang’s post on keeping marketers away from Fable shows what you learn once marketing’s traffic is on the gateway. The short version: marketing usually spends far less than engineering, so measure before you cap anyone.
Microsoft Copilot Is Several Products, and Most of Them Can Route Through the Gateway
“Copilot” names several Microsoft products, and each one connects to the gateway in its own way. Start by listing which Copilot products your teams use.
| Microsoft product | Routes through the gateway? | How |
|---|---|---|
| GitHub Copilot in VS Code, chat and agent mode | Yes | The Tetrate VS Code extension, or Microsoft’s custom endpoint setting for the chat window |
| GitHub Copilot CLI | Yes | Three environment variables |
| Azure AI Foundry agents | Yes | Foundry’s bring-your-own-model connection, generally available since April 2026, for prompt agents |
| Copilot Studio agent tools | Yes | Add the gateway’s MCP profile URL as an MCP server in Copilot Studio |
| Copilot Studio prompts | Through Foundry | Copilot Studio calls a Foundry model, and Foundry calls the gateway. Test the path with one agent first. |
| Custom engine agents for Microsoft 365 | Yes | Your agent uses your models, and the gateway routes those models, per Microsoft’s custom engine agent guide |
| Visual Studio 2026 | In preview | Version 18.10 and later, per Microsoft’s Visual Studio announcement. VS Code is the production path today. |
Two setup tips. Make your gateway reachable from Microsoft’s cloud, because Copilot Studio calls the MCP URL from there. And connect Foundry prompt agents, which use the Chat Completions API that the gateway connection expects.
The Apps and Agents Your Teams Build Change One Base URL
Apps built on the OpenAI SDK, the Anthropic SDK, LangChain, Vercel AI SDK, Pydantic AI, or CrewAI move to the gateway with two changes: the base URL and the API key. The integrations reference lists the full set. David Wang’s meta-provider post explains why this layer matters once you run several agent tools and several model families. The gateway is the one place that sees all of them.
Agents also call tools. The MCP gateway puts those tool calls on the same path. You get an approved server catalog, and each agent gets a profile that exposes only the tools the agent needs. Each profile can include up to 32 tools, per the MCP profile guide.
Your Own Product: Per-Customer AI Cost and Limits for a SaaS Vendor
If you sell a product with AI features, the same gateway can sit between your product and the model providers. Roy Prins’ explainer on AI gateways covers this case: tag every request with a customer ID so you can bill or cap each customer by usage.
Agent Router Enterprise gives you three ways to do that:
| Method | How the method works | Docs |
|---|---|---|
| A customer header on each request | Your app sends x-tars-customer, and the gateway records the value on every request | OpenTelemetry reference |
| A tag on the API key | Each key carries a tag such as customer=acme, and usage reports filter by tag | API tags |
| A key and budget per customer | Each large customer gets a key, and a budget on the key caps that customer’s spend | Set budgets |
Two tips. Give each customer that needs a spending cap a dedicated API key, because budgets attach to keys, teams, and teammates. And set the customer header on every call, so every request carries the customer ID.
For the full setup, including plan-based model access and pricing, see per-customer AI cost for SaaS.
Browser AI: Company Chat Pages and Web Apps Route Through the Gateway
Browser access follows the same rule. A web app your team builds sends requests from its own backend, and the backend points at the gateway. The chat app quickstart shows the pattern: the browser calls your backend, your backend calls the gateway, and the API key never reaches the browser.
For staff who want a chat window in the browser, host a company chat page such as Open WebUI and point the page at the gateway. Make that page faster to get than a personal account, and staff will use the company path, with the same budgets and logs as every other tool.
Where a Vendor Picks the Model, Bring Your Own Models Through a Governed Path
Some AI tools come with a model the vendor chooses. For each of those, Agent Router Enterprise gives your teams a governed way to do the same work with your own approved models.
| If your teams use | Give them governed AI through |
|---|---|
| Microsoft 365 Copilot in Word, Excel, Teams, and Outlook | A custom engine agent, or a Foundry agent published to Microsoft 365, with models routed through the gateway |
| GitHub Copilot code suggestions | Copilot chat and agent mode through the Tetrate VS Code extension |
| ChatGPT or claude.ai on personal accounts | A company chat page, or Claude Desktop in gateway mode |
| A SaaS tool with its own built-in model | The vendor’s bring-your-own-model option, pointed at the gateway |
How to Get Started
Every tool on this page connects to Agent Router Enterprise today, and Visual Studio 2026 support is in preview. Start with the coding agents guide for developers and the app integration guide for everything else. To see the tools on one gateway, request a demo.
Agent Router Enterprise
Frequently asked questions
Which AI tools can an AI gateway govern? An AI gateway can govern any AI tool that lets an admin set the endpoint the tool sends requests to. Examples are Claude Code, GitHub Copilot chat and agent mode in VS Code, Cursor, and Claude Desktop. Azure AI Foundry agents, company chat pages, and apps built on the OpenAI or Anthropic SDKs work too.
Can an AI gateway govern GitHub Copilot? Yes. Copilot chat and agent mode in VS Code route through the Tetrate VS Code extension, and the Copilot CLI routes through three environment variables. Both get the same budgets, logs, and approved models as every other tool.
How do I use my own approved models inside Microsoft 365? Build a custom engine agent, or publish an Azure AI Foundry agent to Microsoft 365, and route that agent’s models through the gateway. Your teams then reach governed models inside Teams and Microsoft 365.
Can an AI gateway govern AI used in a browser? Yes. A company chat page or a web app your team builds calls the gateway from the app’s backend. Every browser request then gets the same budgets, logs, and approved models as other tools.
Who in a company uses an AI gateway? Developers use the gateway through Claude Code, GitHub Copilot, and Cursor. Non-developers use Claude Desktop or a company chat page. The apps and agents your teams build use the gateway too, with the same budgets and cost reports.
Can a SaaS company use an AI gateway to track AI cost per customer? Yes. The app sends a customer header with each request, or each customer gets a tagged API key. A budget on a customer’s key caps that customer’s spend.
Related reading
- Keeping Marketers Away From Fable, on governing non-developer AI use
- Enabling agentic developers, on developer self-service
- AI Cost Visibility, on cost by team, user, and customer
Learn more about Tetrate Agent Router Enterprise — enterprise AI agent routing with policy, cost controls, and audit across every gateway.