Reviewed August 2026
Portkey is now called Prisma AIRS AI Gateway, following its acquisition by Palo Alto Networks. The new name is a mouthful, but it does make the product's ambition clearer. This is not really an OpenRouter replacement, and it was never built to be one.
Portkey was founded in 2023 by Rohit Agarwal and Ayush Garg around the idea that AI integrations would eventually need an administration layer. As more teams connected more applications to more models, somebody would need to control who could use what, where data could go, how much could be spent, and what happened when a provider failed.
That is still the best way to understand the product. Routing is part of Portkey, but routing sits inside a much broader system for access control, observability, governance, security, and cost management.
Our testing found that Portkey is a solid enterprise control plane with a specific customer in mind. It is powerful, configurable, and serious about the operational details. It is also more administrative than the simpler gateways in ModelRouter's test set. Whether that feels reassuring or excessive will depend almost entirely on the organization buying it.
Portkey is not really a model marketplace
The AI routing category gets flattened too easily. Products can expose similar API endpoints while solving quite different problems.
OpenRouter is useful partly because it makes model access feel like a marketplace. Fund one account, pick from a large catalog, and start experimenting. Portkey takes a more managed approach. Teams configure providers, credentials, approved models, routing rules, budgets, and access policies. The Universal API covers more than 1,600 models, but the catalog is an administrative abstraction rather than a shelf of models waiting to be sampled.
That distinction explains a lot about the product. Portkey can handle fallbacks, retries, load balancing, caching, traffic shaping, circuit breakers, quotas, and regional routing. Those are real routing capabilities, but they are not the whole pitch. The larger pitch is that an organization gets one place to administer its AI traffic.
For a small team that just wants easier access to multiple models, this can feel like a lot. For a large company with many teams, internal applications, provider contracts, and security requirements, it starts to make much more sense.
The agent control plane is the interesting bet
Portkey's enterprise focus becomes more convincing when you think about agents rather than ordinary chat requests.
A conventional model gateway sits between an application and a model provider. An agent can reach much further. It might query internal data, call MCP tools, update a customer record, send a message, or take an action in another enterprise system. At that point, model access is only one part of the problem. The organization also needs to know which agent is acting, what it is allowed to do, what data it can send, and how the action will be audited later.
Prisma AIRS AI Gateway is being positioned as the central enforcement point for that traffic. It can apply identity, least-privilege access, budgets, guardrails, and logging across LLM, MCP, and agent-to-agent interactions.
This is where Portkey feels most differentiated. Automatic model selection is useful, but centralized control over agents and AI applications is the reason a large enterprise is likely to buy the product.
Security covers most of the enterprise checklist
From a security and privacy perspective, Portkey covers a lot of the bases that enterprise buyers will expect. Its offering includes SOC 2, ISO 27001, GDPR, and HIPAA programs, along with custom BAAs for healthcare organizations. It supports encryption in transit and at rest, KMS integrations, fine-grained RBAC, SSO, key rotation, audit logs, isolated workspaces, configurable retention, and several private deployment options.
Portkey says it undergoes recurring third-party audits, compliance checks, and penetration testing. The product also includes PII redaction and inline guardrails, with controls that can be applied to prompts and responses at different points in a request.
This stuff can sound like a feature checklist until you work with a company where one missing item stops procurement completely. HIPAA support is not a nice bonus for a healthcare buyer. A BAA, SSO, a retention policy, or a private deployment option can be the difference between a product being evaluated and being rejected before the technical team gets involved.
One thing Portkey does not emphasize as strongly is a platform-wide no-training commitment or a preference for zero-data-retention providers. Privacy-first routers tend to make those promises central to the product. Portkey's emphasis is different: give the enterprise the controls, deployment choices, and policies to construct the environment it needs.
That is a credible approach, but buyers should still confirm retention and training terms for the exact model providers and routes they intend to use. A gateway's compliance posture does not automatically determine what every upstream provider does with data.
Getting started required more clicks than expected
The onboarding experience was functional, but felt dated compared with simpler routers in this category.
Portkey generated an API key immediately after signup, suggesting that requests could begin at once. In practice, our reviewer still had to set up the Model Catalog, configure OpenAI, choose a model, and work through several screens of fine-grained controls.
The first smoke test exposed an annoying documentation edge case. The model used with the example request did not support the chat-completions interface, so the request kept failing. It was not obvious at first that the model was the problem. Once the model was switched manually, the request worked.
None of this was disastrous. The tested flow went from signup to a successful request in roughly five to ten minutes. But other gateways do a better job of making the first request feel immediate. Portkey asks you to make decisions that can feel unnecessary when you are only trying to test the API.
The other side of that friction is control. The extra screens exist because the product expects somebody to administer the gateway. Once requests were running, the analytics were near real-time and impressively detailed. The review could inspect usage, latency, cost, errors, retries, and cache status at the request level.
Portkey is not difficult so much as administrative. It assumes that somebody wants to own this layer, configure the defaults, and decide how the rest of the organization should use it.
Performance was solid
Portkey performed well in ModelRouter's initial controlled benchmark.
Across 30 matched requests to the same OpenAI model, the Portkey route added a median 43.59 ms to time to first token, or 6.97%, compared with calling OpenAI directly. Median total-request overhead was 40.03 ms. All 30 Portkey requests succeeded, and no retries or cache hits affected the measurements.
That is a strong initial result. The gateway stayed close to the direct provider path while still applying its access layer.
It is also a deliberately narrow result. The test covered one model, one minimal-output workload, and one time window. Portkey's underlying BYOK route was confirmed through the account configuration rather than fully attested in the inference response. Repeat runs across more workloads and regions are needed before treating the result as a general performance ranking.
Palo Alto Networks advertises sub-millisecond routing latency and 99.999% availability for Prisma AIRS AI Gateway. Those platform figures are useful context, but they are not the same as end-to-end response latency, which is still dominated by the selected model and upstream provider.
The strongest features are not all self-serve
There is an important pricing caveat in any Portkey evaluation: many of the capabilities that make the product stand out require an Enterprise plan.
Portkey has a free developer tier and a $49-per-month production tier. Those plans include the core gateway, observability, routing, caching, and basic guardrail functionality. Advanced compliance, data isolation, SSO, granular governance, custom retention, VPC hosting, data-lake exports, custom guardrail hooks, and some higher-volume configurations sit behind custom enterprise pricing.
That does not make the lower tiers bad, but it means buyers should evaluate the plan they can actually purchase rather than compare against one combined feature list. Advanced guardrails can also involve third-party security and evaluation partners. Teams should understand which services are native, which are integrations, and what those choices mean for latency, data handling, pricing, availability, and contractual coverage.
For a small team, the additional configuration and control-plane cost may not create enough value over a lightweight gateway or direct provider integrations. Enterprise economics are different. Centralizing access policies, audit logs, guardrails, observability, budgets, and compliance can be much cheaper than rebuilding them across every internal application.
Who should consider Portkey?
Portkey is a good fit for large or regulated organizations that want AI access to be managed as infrastructure.
It is especially compelling when many teams, models, agents, and internal systems need to operate under common rules. Healthcare, financial services, and other regulated industries are obvious candidates, as are companies that need private deployment, strict data controls, organizational access policies, or formal auditability.
It is less compelling for a small team whose main goal is to try lots of models through one account or automatically chase the cheapest inference route. Portkey can route traffic, but that is only one part of the product, and specialized routers may provide a more direct experience for those needs.
The Palo Alto Networks acquisition should help with the audience Portkey already wanted to serve. Palo Alto brings established security relationships, procurement pathways, support operations, and credibility with enterprise buyers. For companies already buying through Palo Alto, that may matter as much as any individual gateway feature.
There is still some transition risk. Buyers should verify which Portkey plans, interfaces, deployment modes, support processes, and service commitments have moved into Prisma AIRS and which legacy pieces remain during the integration.
Verdict
Portkey is a strong enterprise control plane and a good example of why not every AI gateway should be judged as an OpenRouter competitor.
The product gives up some simplicity in exchange for configurability, governance, and organizational control. That tradeoff was evident during onboarding. There were more screens and more setup than a smoke test required, and the documentation pointed toward an incompatible model. Even so, the tested flow produced a successful request within ten minutes, the analytics were excellent once traffic started flowing, and gateway performance was solid.
For companies that do not need the enterprise machinery, Portkey will probably feel heavier than necessary. For companies that do need it, the so-called bells and whistles are often the requirements that decide whether a product can be used at all.
That puts Prisma AIRS AI Gateway in a good position. If Palo Alto Networks can preserve Portkey's model breadth and gateway performance while smoothing out the onboarding experience, it should have a real opportunity with customers whose security, governance, and compliance needs are too specific for a lightweight router.
Evidence and sources
- Palo Alto Networks: Prisma AIRS AI Gateway general availability
- Portkey official company information
- Portkey enterprise offering
- Portkey security documentation
- Portkey pricing
Product and pricing claims were checked on August 16, 2026. The category scores are editorial assessments. Performance figures come from the local controlled benchmark and retain the limitations described above.