Skip to content

Envoy AI Gateway becomes Agent Router and joins the Agentic AI Foundation

Learn more

Which AI Tools Can an AI Gateway Govern? Developers, Employees, Apps, and Your Own Product

Last updated: October 2026

Tetrate Agent Router Enterprise governs every AI tool that lets your admin set the tool’s endpoint, which covers far more people than the developers who asked for the gateway.

The AI tools an AI gateway can govern fall into four groups. Developers use tools such as Claude Code, GitHub Copilot, and Cursor. Everyone else uses desktop and browser tools such as Claude Desktop and a company chat page. Your teams build apps and agents. And you may sell a product with AI features. The test for any single tool is one question. Does the tool let your admin choose the endpoint the tool sends requests to? If yes, Tetrate Agent Router Enterprise can govern the tool. Where a vendor picks the model, Agent Router Enterprise gives you a governed path to the same work, covered below.

Most companies buy a gateway for one group and find out later that the other three were spending money the whole time.

The Rule: If Your Admin Can Set the Endpoint, the Gateway Can Govern the Tool

A gateway sits in the request path. A tool’s requests reach the gateway only when the tool sends them there. That happens in one of three ways:

How the tool connectsWhat your admin doesExamples
Base URL and API keyChanges two settingsClaude Code, Cursor, Codex, the OpenAI and Anthropic SDKs
Model provider pluginInstalls one extensionGitHub Copilot chat and agent mode in VS Code
Bring-your-own-model connectionAdds the gateway as a model source in the vendor’s consoleAzure AI Foundry agents

Once a tool’s requests pass through the gateway, the tool gets the same controls as every other tool. That means one key per person or app, cost by team and user, budgets, guardrails, and a request log. You don’t build a separate policy per tool.

Developers: Coding Agents and IDE Assistants Route Through One Gateway Key

Developers are where the gateway usually starts, because developers run the most tokens. The coding agents guide covers each tool, and the tare integrate command writes the config file for the most common ones.

ToolHow the tool connectsDetail worth knowing
Claude Codetare integrate claude-codeOne profile reaches Anthropic, OpenAI, Gemini, and self-hosted models. Passthrough mode keeps a Claude Max subscription as the billing path and still logs every request.
GitHub Copilot in VS Code, chat and agent modeThe Tetrate VS Code extensionOne key serves Copilot chat, agent mode, and every other extension that asks VS Code for a model
GitHub Copilot CLIThree environment variables, per GitHub’s custom model guidePick a model that supports tool calling and streaming
CursorBase URL setting, plus a .cursorrules file for generated code
Codex, Aider, Cline, Continuetare integrate <tool>The command backs up the old config and makes one test call

Roy Prins wrote up what this looks like for a developer: developers create their own keys. They get a priced, approved model list inside VS Code without filing a ticket. That’s the developer on-ramp in practice.

Two tips. Start with Copilot chat and agent mode, because that’s where developers send the heavy model work. And turn on bring-your-own-model in your Copilot Business or Enterprise policy before you set a rollout date.

Everyone Else: Claude Desktop and a Company Chat Page Give Citizen AI Builders a Governed Path

Marketing, finance, and legal teams use AI every day. They’re citizen AI builders: people who build with AI without writing code. Their spend shows up on expense reports, not in your engineering budget, and nobody files a ticket with you first.

Two tools put that work on the gateway:

ToolHow the tool connectsDetail worth knowing
Claude Desktop, Cowork and Code tabsGateway mode, set by tare integrate claude-cowork or by an adminGateway mode puts every Cowork and Code request in your logs and budgets
A company chat pageA web chat your IT team hosts, such as Open WebUI, pointed at the gatewayAny tool with an OpenAI-compatible endpoint setting works the same way, per the app integration guide

Roy Prins’ Claude Desktop post walks through the desktop setup. David Wang’s post on keeping marketers away from Fable shows what you learn once marketing’s traffic is on the gateway. The short version: marketing usually spends far less than engineering, so measure before you cap anyone.

Microsoft Copilot Is Several Products, and Most of Them Can Route Through the Gateway

“Copilot” names several Microsoft products, and each one connects to the gateway in its own way. Start by listing which Copilot products your teams use.

Microsoft productRoutes through the gateway?How
GitHub Copilot in VS Code, chat and agent modeYesThe Tetrate VS Code extension, or Microsoft’s custom endpoint setting for the chat window
GitHub Copilot CLIYesThree environment variables
Azure AI Foundry agentsYesFoundry’s bring-your-own-model connection, generally available since April 2026, for prompt agents
Copilot Studio agent toolsYesAdd the gateway’s MCP profile URL as an MCP server in Copilot Studio
Copilot Studio promptsThrough FoundryCopilot Studio calls a Foundry model, and Foundry calls the gateway. Test the path with one agent first.
Custom engine agents for Microsoft 365YesYour agent uses your models, and the gateway routes those models, per Microsoft’s custom engine agent guide
Visual Studio 2026In previewVersion 18.10 and later, per Microsoft’s Visual Studio announcement. VS Code is the production path today.

Two setup tips. Make your gateway reachable from Microsoft’s cloud, because Copilot Studio calls the MCP URL from there. And connect Foundry prompt agents, which use the Chat Completions API that the gateway connection expects.

The Apps and Agents Your Teams Build Change One Base URL

Apps built on the OpenAI SDK, the Anthropic SDK, LangChain, Vercel AI SDK, Pydantic AI, or CrewAI move to the gateway with two changes: the base URL and the API key. The integrations reference lists the full set. David Wang’s meta-provider post explains why this layer matters once you run several agent tools and several model families. The gateway is the one place that sees all of them.

Agents also call tools. The MCP gateway puts those tool calls on the same path. You get an approved server catalog, and each agent gets a profile that exposes only the tools the agent needs. Each profile can include up to 32 tools, per the MCP profile guide.

Your Own Product: Per-Customer AI Cost and Limits for a SaaS Vendor

If you sell a product with AI features, the same gateway can sit between your product and the model providers. Roy Prins’ explainer on AI gateways covers this case: tag every request with a customer ID so you can bill or cap each customer by usage.

Agent Router Enterprise gives you three ways to do that:

MethodHow the method worksDocs
A customer header on each requestYour app sends x-tars-customer, and the gateway records the value on every requestOpenTelemetry reference
A tag on the API keyEach key carries a tag such as customer=acme, and usage reports filter by tagAPI tags
A key and budget per customerEach large customer gets a key, and a budget on the key caps that customer’s spendSet budgets

Two tips. Give each customer that needs a spending cap a dedicated API key, because budgets attach to keys, teams, and teammates. And set the customer header on every call, so every request carries the customer ID.

For the full setup, including plan-based model access and pricing, see per-customer AI cost for SaaS.

Browser AI: Company Chat Pages and Web Apps Route Through the Gateway

Browser access follows the same rule. A web app your team builds sends requests from its own backend, and the backend points at the gateway. The chat app quickstart shows the pattern: the browser calls your backend, your backend calls the gateway, and the API key never reaches the browser.

For staff who want a chat window in the browser, host a company chat page such as Open WebUI and point the page at the gateway. Make that page faster to get than a personal account, and staff will use the company path, with the same budgets and logs as every other tool.

Where a Vendor Picks the Model, Bring Your Own Models Through a Governed Path

Some AI tools come with a model the vendor chooses. For each of those, Agent Router Enterprise gives your teams a governed way to do the same work with your own approved models.

If your teams useGive them governed AI through
Microsoft 365 Copilot in Word, Excel, Teams, and OutlookA custom engine agent, or a Foundry agent published to Microsoft 365, with models routed through the gateway
GitHub Copilot code suggestionsCopilot chat and agent mode through the Tetrate VS Code extension
ChatGPT or claude.ai on personal accountsA company chat page, or Claude Desktop in gateway mode
A SaaS tool with its own built-in modelThe vendor’s bring-your-own-model option, pointed at the gateway

How to Get Started

Every tool on this page connects to Agent Router Enterprise today, and Visual Studio 2026 support is in preview. Start with the coding agents guide for developers and the app integration guide for everything else. To see the tools on one gateway, request a demo.

Agent Router Enterprise

Tetrate Agent Router Enterprise routes AI agent traffic across providers and your own models, with policy, cost controls, and audit on every request — in cloud, on-prem, or edge.

Learn more

Frequently asked questions

Which AI tools can an AI gateway govern? An AI gateway can govern any AI tool that lets an admin set the endpoint the tool sends requests to. Examples are Claude Code, GitHub Copilot chat and agent mode in VS Code, Cursor, and Claude Desktop. Azure AI Foundry agents, company chat pages, and apps built on the OpenAI or Anthropic SDKs work too.

Can an AI gateway govern GitHub Copilot? Yes. Copilot chat and agent mode in VS Code route through the Tetrate VS Code extension, and the Copilot CLI routes through three environment variables. Both get the same budgets, logs, and approved models as every other tool.

How do I use my own approved models inside Microsoft 365? Build a custom engine agent, or publish an Azure AI Foundry agent to Microsoft 365, and route that agent’s models through the gateway. Your teams then reach governed models inside Teams and Microsoft 365.

Can an AI gateway govern AI used in a browser? Yes. A company chat page or a web app your team builds calls the gateway from the app’s backend. Every browser request then gets the same budgets, logs, and approved models as other tools.

Who in a company uses an AI gateway? Developers use the gateway through Claude Code, GitHub Copilot, and Cursor. Non-developers use Claude Desktop or a company chat page. The apps and agents your teams build use the gateway too, with the same budgets and cost reports.

Can a SaaS company use an AI gateway to track AI cost per customer? Yes. The app sends a customer header with each request, or each customer gets a tagged API key. A budget on a customer’s key caps that customer’s spend.


Learn more about Tetrate Agent Router Enterprise — enterprise AI agent routing with policy, cost controls, and audit across every gateway.

Decorative CTA background pattern background background
Tetrate logo in the CTA section Tetrate logo in the CTA section for mobile

Ready to enhance your
network

with more
intelligence?