Free tools Windows power users keep installed
One-click scans. No signup required.
Route an AI agent’s model or tool calls through a trusted gateway, not directly to each provider. The agent authenticates to the gateway with a scoped client credential; the gateway checks authorization, supplies the upstream credential from its own configuration or credential provider, forwards the request, and returns the response. This separates the credential the agent uses from the provider or tool secret it should not receive.
How the request flows
- Point the agent client at the gateway. Configure the gateway base URL and the model or tool identifier that the gateway recognizes. LiteLLM documents these as reusable client settings alongside a virtual key: LiteLLM documentation.
- Authenticate the agent to the gateway. Issue a credential for the agent or workload. For LiteLLM, clients can use a virtual key or sign-in token; AWS Bedrock AgentCore Gateway documents inbound OAuth JWT and IAM SigV4 options, as well as authenticate-only and no-auth modes. See LiteLLM client documentation and AgentCore Gateway documentation.
- Authorize the requested model or tool. Authentication establishes who is calling; authorization determines what that caller may invoke. Configure permissions for the particular model, tool, team, or target. LiteLLM documents key- and team-based access to MCP servers, including denial when a key has not been granted access: LiteLLM MCP documentation.
- Attach the upstream credential at the gateway boundary. Store provider credentials in the gateway’s provider configuration or use a target credential provider. AgentCore supports credential providers for API key or OAuth credentials; IAM authorization can sign requests. LiteLLM’s documented flow uses the gateway’s provider credentials to call upstream model providers. The agent should not need those upstream secrets.
- Forward and observe the request. The gateway routes the authorized request to the selected provider or tool and returns its response. Monitor request outcomes, authorization failures, and usage using the controls available in the chosen deployment. LiteLLM documents request logging and spend tracking: LiteLLM gateway logging documentation.
These are two separate authentication hops: agent to gateway, then gateway to provider or tool. Keeping them distinct makes it possible to rotate an upstream secret without distributing it to every agent, while gateway permissions control which callers can use which routes.
Choose a gateway based on the job
| Option | Best aligned with | Documented characteristics | Check before choosing |
|---|---|---|---|
| LiteLLM self-hosted gateway | Unified model-provider routing, virtual keys, budgets, and gateway-based model access | OpenAI-compatible gateway interface; provider keys held in gateway configuration; client uses a virtual key or sign-in token; MCP access can be granted by key or team. Client and gateway docs; MCP access docs. | Provider and protocol compatibility, hosting and patching responsibility, identity integration, authorization granularity, logging, and operational controls. |
| Amazon Bedrock AgentCore Gateway | Managed agent, tool, or model gateway in AWS | Inbound authorization options include OAuth JWT, IAM SigV4, authenticate-only, or no-auth. Targets can use credential providers; inference targets select a provider based on the request model. AgentCore Gateway documentation. | AWS integration, target types, identity model, credential-provider support, and environment and operational requirements. |
| HashiCorp Vault Agent or Proxy | Delivering or mediating secrets from Vault to applications | Vault Agent can authenticate and provide secrets; Vault Proxy can sit between Vault and an application to simplify authentication or cache requests. Their documented feature sets differ. Vault Agent and Proxy documentation. | Whether the need is secret delivery or API/model routing, deployment model, Vault authentication method, caching, and edition constraints. Vault’s Agentic IAM feature is described as an Enterprise offering on its product page: Vault Agentic IAM. |
A secret-management proxy is not automatically a model-routing gateway, and a model gateway is not automatically a general-purpose secret broker. Choose the component that governs the request surface you need to control; some architectures may use both.
Implementation and security checks
- Keep upstream secrets out of agent code and configuration. Place long-lived provider credentials on the gateway side or in a dedicated credential provider. Give the agent only the gateway credential needed for its work.
- Scope access deliberately. Limit gateway credentials to the models, tools, teams, and budgets the workload needs. Do not treat successful authentication as permission to use every route.
- Verify protocol and request compatibility. Check the exact client and route before rollout. LiteLLM’s client guidance describes route and client-specific compatibility limitations; its MCP reference notes that a negotiated protocol version does not establish support for every optional capability: client guidance and MCP documentation.
- Test both allowed and denied calls. Confirm an authorized request reaches the intended target and a caller without a grant is denied. In particular, verify that a gateway key lacking access to a protected MCP server cannot invoke it.
- Inspect logs, traces, and errors for secret exposure. A gateway’s presence does not by itself establish that every deployment redacts sensitive values. Review what is recorded, who can access it, and how credentials are protected in diagnostics.
What to validate before rollout
Start with one representative agent and one model or tool route. Confirm the client uses the gateway endpoint and identifier, the gateway authenticates the intended workload, and its authorization policy permits only the intended target. Then verify the gateway can use its upstream credential, the request and response work with the client’s protocol, and denied requests fail closed. Finally, review usage and diagnostic records in the actual deployment rather than assuming logging or redaction behavior from a product name alone.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.

