Skip to main content

Where to Begin

Ordered setup paths, a task index by goal, and a map of how the rest of the documentation is arranged.


Which product

Three products end at the same place, a working gateway serving a routed request. They differ in tier and in where the data plane runs.

Developers

Agent Router Service

Multi-tenant and hosted by Tetrate. Nothing to install.

10 minute Quickstart →
Teams

Enterprise, Fully Managed

A dedicated instance with operator controls, hosted end to end by Tetrate.

Fully Managed →
Teams

Enterprise, Self-Hosted Data Plane

The same controls, with AI traffic kept on customer-managed infrastructure.

Self-Hosted Data Plane →

Where the choice is still open, the feature comparison on the welcome page sets Service against Enterprise, and the flowchart under Still choosing a product walks the deployment constraints.


First time here

Each path runs from requirements through installation to a first routed request. Working down a column is the shortest route to a working deployment.

Agent Router Service

Nothing to install. Sign in and route a request.

  1. 10 minute Quickstart
  2. Developer Console quickstart
  3. Make an AI API call
  4. Guides for Developers

Enterprise, Fully Managed

Tetrate provisions and hosts everything. Onboarding configures it.

  1. Fast track evaluation
  2. Management Plane onboarding
  3. Admin Console quickstart
  4. Enterprise guides

Enterprise, Self-Hosted Data Plane

Read the requirements first. The install runs in a customer-managed cluster.

  1. Prerequisites
  2. Self-Hosted onboarding
  3. Data plane installation
  4. Gateway Installation
  5. Admin Console quickstart

For a self-hosted install, Prerequisites is the page to read before anything else. It covers the Kubernetes version, the connections a cluster needs, what a security review will ask for, and which version to install.


Find a task

Nine areas cover the operational surface.

Most requested tasks

TaskGuide
Set up single sign-onConfigure SSO
Map identity provider claims to rolesConfigure SSO role mapping
Drive access from existing Entra ID groupsMap Entra groups to functions
Check what each role is allowed to doManage roles and permissions
Add developers and issue them keysOnboard developers and issue keys
Add a provider and enable its modelsProvision models and providers
Use AWS Bedrock modelsProvision AWS Bedrock models
Add a self-hosted or custom modelCustom and self-hosted models
Let callers supply their own provider keyUse your own provider credentials
Send requests to several providers through one endpointRoute requests across providers
Fail over automatically when a provider errorsImprove resilience with fallbacks
Split traffic between two modelsReduce cost with traffic splitting
Route on a logical model nameApply advanced routing rules
Point an application or coding assistant at the gatewayIntegrate the gateway with an app
Decide between budgets, rate limits, and tagsChoose the right cost control for each workload
Cap what a team can spendSet a budget and track spend against it
Attribute cost to an app or projectKnow what every app and project actually costs
Charge spend back to the teams that caused itSplit the AI bill across the teams that caused it
Stop a runaway workloadStop runaway workloads before they burn the budget
Contain a leaked API keyContain a leaked key before it drains the budget
Get alerted when spend spikesGet alerted to cost spikes as they happen
Understand what guardrails doAbout guardrails
Redact personal data from promptsDetect and redact sensitive data
Block prompt injectionDetect and block prompt injection
Protect coding-assistant trafficProtect coding-assistant traffic
Give agents a single MCP endpointAggregate MCP servers into a profile
Control which MCP servers are reachableGovern MCP server access
Create a projectCreate and delete a project
Provision a gatewayProvision a gateway for a project
Issue a project-scoped API keyIssue a project-scoped API key
Add or remove project UsersManage project Users and access
Install a data plane in a clusterData plane installation
Investigate one requestMonitor traffic and usage
Get the first readings out of analyticsSee where AI spend is going
Send traces and metrics to Grafana or DatadogExport telemetry to observability
Review who changed whatAudit Agent Router activity
Export audit records to a SIEMExport audit decisions to SIEM
Keep data in a particular regionConfigure data residency

Anything not listed is usually fastest to reach through the search box in the top navigation, which indexes the full text of every page.


How these docs are organized

The sidebar has four sections below this page.

SectionWhat it holdsGo here when
Agent Router ServiceQuickstarts and developer guides for the multi-tenant hosted productAn application or agent is being pointed at the gateway
Agent Router EnterpriseOperator guides, plus the Fully Managed and Self-Hosted install pathsAgent Router is being run and governed for a team
Product & ArchitecturePlanes and components, data flows, network and security, key concepts, evaluation materialThe design has to be understood or explained to someone else
ReferencesGateway and management APIs, the CLI, the SDK, providers, glossary, best practicesAn exact name, value, or schema is needed

Anything phrased as a goal ("keep team spend inside a ceiling") is a guide and lives under Service or Enterprise. Anything phrased as a thing ("audit log events", "OpenTelemetry traces and metrics") is reference material and lives under References.


Look something up


Still choosing a product?

The flowchart picks a path from the deployment constraints, chiefly where the data is allowed to go.

Flowchart for choosing between the three Agent Router deployment paths