API gateway with OSS core and enterprise AI tier · Verified August 16, 2026

TrustedRouter vs Kong AI Gateway

Kong AI Gateway runs AI plugins on the Apache-2.0 Kong Gateway core or on Konnect, governing LLM, MCP, and A2A traffic with your own provider keys. TrustedRouter is a hosted model marketplace with a hardware-attested prompt path and no durable prompt logs on realtime inference.

Compare details
8decision dimensions
8official sources
1base URL to try TR
Choose Kong AI Gateway when

Its operating model is the feature.

Choose Kong when you already run Kong or Konnect, when prompts must stay on data planes you operate, or when you need gateway-level MCP and A2A governance: OAuth 2.1, tool-level ACLs, and token exchange over agent traffic.

Choose TrustedRouter when

Privacy needs evidence.

Choose TrustedRouter when you want one key across roughly 49 providers billed at provider cost + 5.5% per token, with privacy you can verify: a gateway attested on three clouds and realtime inference that keeps no durable prompt or output logs.

DimensionKong AI GatewayTrustedRouter
DeploymentSelf-hosted OSS/Enterprise Kong Gateway, or Konnect SaaS with Kong-run data planesHosted control plane, source-available (BUSL-1.1), with an attested API path
API surfaceOpenAI-format ai-proxy over routes you define; native Anthropic SDK support in 3.13OpenAI Chat Completions and Responses plus Anthropic Messages
Model access15+ providers via ai-proxy, BYO keys; no hosted marketplace or unified token billing500+ models across ~50 providers: prepaid, BYOK, and direct
Routing7 LB algorithms, fallback, circuit breakers in enterprise-only AI Proxy AdvancedProvider fallback plus auto, cheap, fast, free, ZDR, E2E, and EU routes with composable privacy and jurisdiction preferences
ObservabilityToken, cost, and latency per model via Prometheus/OTel; Grafana and Konnect dashboardsMetadata analytics and opt-in external broadcast
Prompt contentPayload logging off by default; prompts stay on self-run data planes in hybrid modeNo durable prompt or output logs on realtime inference; batch is opt-in encrypted retention
VerificationSOC 2 + PCI DSS 4.0 on Dedicated Cloud Gateways; enterprise AI plugins closed sourceLive gateway attestation on three clouds, bound to published source and release evidence
BillingKonnect Plus: $100/mo per LLM model (max 5) + plane fees; provider bills stay yoursPrepaid at provider price + 5.5% ($0.01/M floor), or BYOK

What Kong AI Gateway actually is

Kong AI Gateway is a set of AI plugins that run on Kong Gateway, the Apache-2.0 API gateway with roughly 44,000 GitHub stars and active development as of August 2026, and on Konnect, Kong's hosted control plane. You can self-host, run your own data planes under Konnect in hybrid mode, or let Kong operate Serverless and Dedicated Cloud Gateways. In every mode you bring your own provider accounts and keys: there is no model marketplace and no unified token billing. The ai-proxy plugin speaks OpenAI-format to 15+ providers, including OpenAI, Azure OpenAI, Anthropic, Bedrock, Vertex AI, Mistral, and self-hosted vLLM or Ollama.

The release pace is fast. From October 2025 to April 2026, versions 3.12 through 3.14 added an MCP proxy with OAuth 2.1 resource-server flows, tool-level ACLs, circuit breakers, dynamic model routing keyed on the request body, and an Agent Gateway governing A2A traffic with RFC 8693 token exchange. Kong governs LLM, MCP, and A2A traffic more broadly than any other gateway we compare against.

Where Kong is genuinely strong

Three things stand out. First, operational maturity: platform teams already know how to run Kong, and a deep catalog of existing plugins for authentication, rate limiting, and transforms composes directly with AI routes. Second, the default privacy posture for self-hosters is strong: prompts flow through data planes you run, payload logging is off by default (log_payloads: false), and Kong documents that Konnect control-plane telemetry carries service-level metrics only, with no customer data. Third, compliance surface: Dedicated Cloud Gateways carry SOC 2 and PCI DSS 4.0, and Konnect offers six control-plane geos (AU, EU, ME, US, IN, SG). If your requirement is that prompts never leave infrastructure you operate, and you have the platform team to run it, self-hosted Kong is a legitimate answer.

The line between free and enterprise

Exactly six AI plugins ship in the Apache-2.0 repo: ai-proxy, ai-prompt-guard, ai-prompt-template, ai-prompt-decorator, and the request and response transformers. The differentiating features sit in the proprietary ai_gateway_enterprise tier: AI Proxy Advanced (the seven load-balancing algorithms, cross-provider fallback, circuit breakers), semantic caching, semantic prompt guarding, RAG injection, and PII sanitization. Free ai-proxy routes one model per route. The semantic features also need infrastructure you provision, meaning Redis/Valkey or Postgres with pgvector plus an embeddings model, and the PII sanitizer requires a separate Docker service pulled from Kong's private registry.

On price, the bases differ from ours, so compare carefully. Konnect Plus (as of August 2026, konghq.com/pricing) meters AI Gateway at $100 per month per unique LLM model, capped at five, on top of control-plane fees of $25 to $500 per month by gateway type and $200 per additional million API requests. Beyond five models you are into custom-priced Enterprise contracts, billed annually. Your model usage bills separately with your providers at your negotiated rates. TrustedRouter pricing for text and embeddings is a per-token fee: provider cost + 5.5% with a $0.01 per million token floor, and no seat or subscription fees. A per-model subscription and a per-token percentage are not comparable without your traffic shape; run your own volumes through both.

What TrustedRouter does differently

The trust model is the load-bearing difference. Kong's answer to who sees your prompts is deployment topology: run the data plane yourself and the question mostly disappears — though the enterprise AI plugins that touch prompts, such as the PII sanitizer and semantic cache, are closed source, so you cannot audit them, and there is no build attestation of what is running. Our answer is evidence on a hosted path: the gateway serving api.trustedrouter.com runs inside TEEs on GCP, AWS, and Azure, each publishing a live attestation endpoint that binds the running build to published source and release digests. A verifier script and Sigstore signatures are at trust.trustedrouter.com, and the boundary is documented at /security. Realtime inference keeps no durable prompt or output logs; what we retain is metadata — ids, model, token counts, latency, cost, region, key hash — listed at /privacy.

The second difference is the marketplace. One key covers 550+ model routes across roughly 49 providers (as of August 2026, live at /models) with prepaid billing, so there are no per-provider accounts to open. Privacy is routable: trustedrouter/zdr restricts to providers with contractual or policy zero-data-retention, trustedrouter/e2e to confidential-compute providers with end-to-end encryption, trustedrouter/eu to EU-focused providers, and per-request preferences compose with any of them.

What we do not claim

Our attestation covers our gateway, not the model providers behind it. Downstream handling rests on contractual and policy commitments we track per provider, except on trustedrouter/e2e routes, where the provider's own confidential-compute and E2EE mechanisms apply. Kong's core is genuinely open source under Apache-2.0; our gateway and control plane are source-available under BUSL-1.1, converting to Apache-2.0 four years after each release, with Apache-2.0 and MIT SDKs. Every line that touches your prompt is public, but the platform is not OSI open source. We are young: our repos went public between late April and early May 2026 and published benchmark history starts in June 2026. We have no published SOC 2 or HIPAA certification today; Kong's Dedicated Cloud Gateways do carry SOC 2 and PCI DSS 4.0. And Kong's MCP and A2A governance — tool-level ACLs, token exchange, agent-traffic policy — goes deeper than anything we ship; we support MCP (docs) but do not offer gateway-level agent-protocol governance.

Moving between them

Kong's AI ingress is already OpenAI-format on routes you defined, so client code mostly repoints the base URL and swaps Kong consumer credentials for TrustedRouter keys; model aliases configured in Kong plugins remap to ids on /models. Gateway-side policy does not travel: semantic caches, prompt guards, RAG injection, per-consumer AI rate limits, and MCP ACLs must be recreated on our side or consciously dropped. A common middle path keeps Kong for non-AI API traffic and points only the AI routes at TrustedRouter as an upstream. Start with one streamed request against trustedrouter/zdr and compare output, latency, provider selection, and billed usage before moving volume.

Migration shape

Start with one real request.

Kong's AI ingress is already OpenAI-format, so clients repoint the base URL and swap Kong consumer keys for TrustedRouter keys; Kong model aliases remap to ids on /models. Gateway-side policy does not carry over: semantic caches, prompt guards, RAG injection, and MCP ACLs must be recreated or dropped.

Keep the first test small, stream the response, and compare output, latency, provider selection, and billed usage before moving production traffic.

Agent setup Run a small eval

TrustedRouter sideOpenAI SDK
from openai import OpenAI

client = OpenAI(
    base_url="https://api.trustedrouter.com/v1",
    api_key="sk-tr-v1-...",
)

with client.chat.completions.create(
    model="trustedrouter/zdr",
    messages=[{"role": "user", "content": "Reply PONG"}],
    stream=True,
) as response:
    for chunk in response:
        print(chunk.choices[0].delta.content or "", end="")
Official evidence

Sources checked August 16, 2026

Report a change
All gateways

Questions

We already run Kong for API traffic. Is there a reason to add TrustedRouter?

Staying on Kong is defensible: if you have Konnect Enterprise and a platform team, the marginal cost of AI routes on an existing estate is low, and self-run data planes keep prompts on your infrastructure. TrustedRouter adds what Kong does not have: a hosted marketplace with one key across roughly 49 providers, per-token billing at provider cost + 5.5%, and an attested gateway with no durable prompt or output logs on realtime inference. Some teams keep Kong for API traffic and point only AI routes at TrustedRouter as an upstream.

Which has the stronger privacy story?

They use different mechanisms. Self-hosted Kong keeps prompts on machines you run, with payload logging off by default; if you can operate that, it is a genuinely strong posture, though the enterprise AI plugins are closed source and there is no build attestation. TrustedRouter is hosted: realtime inference keeps no durable prompt or output logs, and the gateway build is attested on GCP, AWS, and Azure against public source. Our attestation stops at the gateway; downstream providers are covered by policy-tier claims, except trustedrouter/e2e routes to confidential-compute providers.

What does each actually cost?

Kong: six basic AI plugins are free and Apache-2.0 if you self-host; Konnect Plus adds $100/month per unique LLM model (max five) plus control-plane fees of $25 to $500/month and $200 per extra million requests; Enterprise is custom, billed annually. Model usage bills separately with your providers. TrustedRouter: provider cost + 5.5% per token with a $0.01/M floor and no subscription; BYOK is supported, with no separate published BYOK fee. The bases differ, a per-model subscription versus a per-token percentage, so run your own volumes.

Workspace access

Sign in

Choose a sign in method to access your TrustedRouter workspace.

By signing in you agree to the terms of service and privacy policy.