Admin Guide
For platform admins: turn self-service on for an app, choose the credential mode, decide who can do what, and track how it is used.
New to self-service? Start with the Overview. For the developer's side, see the Developer Guide.
Where to configure it
Open Settings > AI Gateway > LLM Gateway, choose an app, then Settings > Self-Service (under Optimization & policy). Turn on the Self-service switch; when it is off, nobody can see or manage the app from self-service. Self-Service stays app-managed when the Policy Engine is on.
Changes apply when you select Save settings.
Choose a credential mode
In the V1 console the mode is the Credential Mode tab of the app's Self-Service settings:
Once an app uses Named User API Keys, the bare parent key is no longer accepted for it. Move existing integrations to named keys before you switch.
Grant capabilities
For each capability, choose who gets it:
A denied entry always wins over an allowed one. The chip next to each capability shows the result: Everyone, Listed only or Nobody yet. Smart groups let you manage membership in one place instead of pasting emails into every app.
An app with no self-service access configured is closed to everyone until you grant a capability.
Direct update vs request access
Grant Direct settings update sparingly. The change is still versioned in Config History and can be rolled back, but nobody approves it first. Self-service settings themselves are admin-only, so no user can grant themselves access.
Smart groups
Smart groups are reusable, named groups of users managed for your tenant. Add one (for example engineering) to an allow or deny list, and removing someone from the group removes their access across every app that references it.
Review change requests
Requests from users with Settings request access land in the app's Settings > Audit Log, filterable by status (pending, approved, rejected, failed, stale). See Audit Log for the approval workflow. Your own direct edits as an admin apply immediately and skip the queue.
Track usage
The Self-service usage button on the Settings > AI Gateway > LLM Gateway page opens a tenant-wide report of who can do what in each app, and whether they use it.
The report covers the last 30 days by default (up to 366 days). By default it includes apps with self-service configuration, personal keys or change requests in the window; select Include every active app to widen it. Estimated cost leaves out models with no configured price.
Revoke access
Removing a user or smart group hides the app and stops new keys. It does not invalidate keys already issued:
- Named User API Keys: revoke the individual named key. The key stops working and its record is kept for audit.
- Shared Parent Key: rotate the app key, since every allowed user holds the same value.
Permissions
Configuring self-service and approving or rejecting change requests both require the LLM Gateway - Update permission.