Skip to main content

Admin Guide

For platform admins: turn self-service on for an app, choose the credential mode, decide who can do what, and track how it is used.

New to self-service? Start with the Overview. For the developer's side, see the Developer Guide.

Where to configure it​

Open Settings > AI Gateway > LLM Gateway, choose an app, then Settings > Self-Service (under Optimization & policy). Turn on the Self-service switch; when it is off, nobody can see or manage the app from self-service. Self-Service stays app-managed when the Policy Engine is on.

Changes apply when you select Save settings.

Choose a credential mode​

ModeUsers receiveUse it when
Shared Parent Key (default)The existing app keyOne credential for a team is fine and per-user attribution is not required.
Named User API KeysA personal key each user createsYou need per-user attribution, per-user revocation, and one key per machine.

In the V1 console the mode is the Credential Mode tab of the app's Self-Service settings:

Switching to named keys stops the parent key

Once an app uses Named User API Keys, the bare parent key is no longer accepted for it. Move existing integrations to named keys before you switch.

Grant capabilities​

CapabilityGrants
Viewer accessSee the app in the Self-Service portal.
Settings request accessSubmit settings changes for admin approval. Implies viewer access unless a viewer rule denies the user.
Direct settings updateChange the app's settings from the portal with no approval step.
API key visibilityView and copy key values in the portal. Without it, users manage key metadata but the value stays hidden.
All-logs visibilitySee all of the app's logs and usage, not just the user's own.

For each capability, choose who gets it:

To grantSet
EveryoneAllow all users on
Specific people or groupsAllow emails and Allow smart groups (comma-separated)
Everyone except someAllow all users on, plus Deny emails or Deny smart groups
NobodyLeave everything empty

A denied entry always wins over an allowed one. The chip next to each capability shows the result: Everyone, Listed only or Nobody yet. Smart groups let you manage membership in one place instead of pasting emails into every app.

Deny by default

An app with no self-service access configured is closed to everyone until you grant a capability.

Direct update vs request access​

Settings request accessDirect settings update
Who applies the changeAn admin, after reviewThe user, immediately
Approval queueYes, in the app's Audit LogNo
Recorded in config historyYes, once approvedYes, when saved
Best forMost developersA few trusted app owners

Grant Direct settings update sparingly. The change is still versioned in Config History and can be rolled back, but nobody approves it first. Self-service settings themselves are admin-only, so no user can grant themselves access.

Smart groups​

Smart groups are reusable, named groups of users managed for your tenant. Add one (for example engineering) to an allow or deny list, and removing someone from the group removes their access across every app that references it.

Review change requests​

Requests from users with Settings request access land in the app's Settings > Audit Log, filterable by status (pending, approved, rejected, failed, stale). See Audit Log for the approval workflow. Your own direct edits as an admin apply immediately and skip the queue.

Track usage​

The Self-service usage button on the Settings > AI Gateway > LLM Gateway page opens a tenant-wide report of who can do what in each app, and whether they use it.

TabShows
UsersEach user's roles (view, request, direct, API key, all logs), apps, keys, requests, estimated cost and last request. Expand a user for the app-by-app grid.
ApplicationsEach app's credential mode (Personal keys or Main app key), users per role (or Everyone), keys, requests and estimated cost.
Change historyEvery settings change submitted through self-service, with requester, change path, status and reviewer.

The report covers the last 30 days by default (up to 366 days). By default it includes apps with self-service configuration, personal keys or change requests in the window; select Include every active app to widen it. Estimated cost leaves out models with no configured price.

Revoke access​

Removing a user or smart group hides the app and stops new keys. It does not invalidate keys already issued:

  • Named User API Keys: revoke the individual named key. The key stops working and its record is kept for audit.
  • Shared Parent Key: rotate the app key, since every allowed user holds the same value.

Permissions​

Configuring self-service and approving or rejecting change requests both require the LLM Gateway - Update permission.