Documentation

AI Gateway Setup

Connect OpenAI, Anthropic, OpenRouter or AWS Bedrock to the ZopNight AI Gateway. Lists the exact key type or AWS access each provider needs, and how your developers point their tools at the gateway.

The AI Gateway sits between your developers and your AI providers. You connect a provider once. Your developers then use a ZopNight virtual key instead of the provider key. Each virtual key has its own budget and list of allowed models, and every request shows up in AI spend reports.

Before you start

NeedDetail
A ZopNight AdminOnly Admins connect providers and manage models. Editors create virtual keys.
A provider accountOpenAI, Anthropic, OpenRouter, or an AWS account with Bedrock.
For Bedrock: a connected AWS accountConnected under Cloud Accounts with read and write access.
Outbound HTTPS for your developersTheir tools call https://api.zop.dev/ai-gateway. Nothing calls into your network.

Access to grant

OpenAI, Anthropic and OpenRouter

Each provider needs one API key. Before saving it, ZopNight makes one read call with the key, and rejects a key the provider refuses.

ProviderKey to createMinimum access
OpenAIA project API keyAll, or Restricted with the two permissions below
AnthropicA standard API keyA normal key from the Claude Console
OpenRouterA standard API keyA normal key

For an OpenAI Restricted key, turn on these two, as named in OpenAI's permission list:

  • List models — Read. Without it the key is rejected when you connect.
  • Model capabilities — Request. This is what lets the gateway call chat completions.

For Anthropic, use a normal API key. An Admin key (sk-ant-admin…) is for the Admin API, not for calling models.

The connect check calls:

The key is stored encrypted. It is never shown again in ZopNight or sent to your developers.

AWS Bedrock

Bedrock needs no key. ZopNight uses the role it already has in your connected AWS account. It gets short-lived AWS credentials from that role and refreshes them before they expire.

IAM actionWhyGranted on
bedrock:ListFoundationModelsFind usable modelsEvery connection
bedrock:ListInferenceProfilesFind cross-region IDsEvery connection
bedrock:InvokeModelCall a modelRead and write only

The list actions are in the ZopNight role's read policy. InvokeModel is in its write policy.

Action names are from Actions, resources, and condition keys for Amazon Bedrock.

You also need the models available in your AWS account. See Access Amazon Bedrock foundation models:

  • Amazon Nova models work as soon as Bedrock is available in your account.
  • Anthropic Claude models need the one-time First Time Use form first. The first call to a third-party model also starts an AWS Marketplace subscription. The role making that first call needs aws-marketplace:Subscribe, aws-marketplace:Unsubscribe and aws-marketplace:ViewSubscriptions. The ZopNight role has none of these, so let someone with those rights make the first call.
  • ZopNight's default models use cross-region IDs (us., eu. or apac., based on your region). Models you add under Manage models can also be global. profiles. These need access to the model in every Region of the profile. If a Service Control Policy blocks some of those Regions, requests fail.

Set it up

  1. Connect a provider

    Open Settings → Integrations → AI Providers and click Connect on the provider tile. Enter the API key. For Bedrock, pick the AWS account and the Region instead. Click Connect. ZopNight checks the key and adds a default set of models. The toast says how many were added.

  2. Add or remove models (optional)

    For OpenRouter and Bedrock, open the tile menu and choose Manage models. Add a model by picking it from the list or entering its ID.

  3. Create a virtual key

    Open AI Estate → Inference Keys and click Create virtual key. Give it a name, the models it may use, and a budget. The key is shown once. Copy it.

  4. Point your tools at the gateway

    Use the gateway address and the virtual key in place of the provider's. The key screen shows ready-made snippets for Claude Code, the OpenAI SDK and cURL.

Claude Code · bash
export ANTHROPIC_BASE_URL=https://api.zop.dev/ai-gateway
export ANTHROPIC_AUTH_TOKEN=<your virtual key>
export ANTHROPIC_MODEL=<a model name from the key>
export ANTHROPIC_DEFAULT_HAIKU_MODEL=<the same model name>
claude
OpenAI SDK · python
from openai import OpenAI

client = OpenAI(base_url="https://api.zop.dev/ai-gateway", api_key="<your virtual key>")

Spend appears under AI Estate → AI Gateway.

Disconnect and remove access

Settings → Integrations → AI Providers → Disconnect removes the provider, its models, and the stored key or AWS credentials from ZopNight.

  • Virtual keys stay, but requests to the removed models fail.
  • ZopNight does not revoke anything at the provider. Delete the API key in the provider's console.
  • For Bedrock, the short-lived AWS credentials expire within an hour.

Troubleshooting

ProblemCause and fix
<provider> rejected this API key, e.g. OpenAI rejected this API keyFor an OpenAI Restricted key, turn on List models. For Anthropic, use a normal API key.
Bedrock requests return access deniedThe AWS connection is read-only, or the request streams. See the warnings above.
Claude on Bedrock fails on first useComplete the First Time Use form and the Marketplace subscription in AWS.
Connect is greyed outYou need the Admin role. Ask an Admin to connect the provider.