An LLM API gateway with budget-limited tokens for your LLM API keys
Overview This gateway is created to (1) keep real API keys completely away from the client, and (2) provide fine-grained budget control functionality. Real upstream API keys (DeepSeek, OpenAI, Anthropic) live only in the Cloudflare worker's secrets — they do not need to be set at the client. On each request, the gateway looks up the token from D1 database, verifies it's unexpired, from an allowed IP, and under budget, then substitutes in the real upstream secret and forwards the request.
- ▪Overview This gateway is created to (1) keep real API keys completely away from the client, and (2) provide fine-grained budget control functionality.
- ▪Real upstream API keys (DeepSeek, OpenAI, Anthropic) live only in the Cloudflare worker's secrets — they do not need to be set at the client.
- ▪On each request, the gateway looks up the token from D1 database, verifies it's unexpired, from an allowed IP, and under budget, then substitutes in the real upstream secret and forwards the request.
Opening excerpt (first ~120 words) tap to expand
Overview This gateway is created to (1) keep real API keys completely away from the client, and (2) provide fine-grained budget control functionality. Real upstream API keys (DeepSeek, OpenAI, Anthropic) live only in the Cloudflare worker's secrets — they do not need to be set at the client. Instead, you create an opaque token scoped to: a single provider — the token only works against the provider it was created for an expiration time an IP allowlist — checked against CF-Connecting-IP, which Cloudflare's edge sets from the real TCP connection and a client cannot spoof a spending budget (in USD) Point your client's base URL at the gateway and use the opaque token in place of a real API key.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at GitHub.