Home/Docs

User Guide

How to set up API keys, proxy keys, rules, and connect your IDE to Iron LLM Gateway.

Overview

Iron LLM Gateway sits between your IDE / application and AI providers (OpenAI, Anthropic, GitHub Copilot). Instead of giving each tool your real API key, you create a proxy key in the dashboard and point your tools at the gateway URL.

IDE / App→Iron LLM Gateway→OpenAI / Anthropic / Copilot
Uses rpk_... proxy key
Logs, PII scan, rules engine
Forwards with real provider key

Step 1 – Add Provider API Keys

Provider API keys are your real credentials (OpenAI, Anthropic, etc.). They are stored encrypted (AES-256-GCM) and never exposed through the proxy. Only admins can manage them.

1

Go to API Keys

Open /keys in the dashboard. Click Add Key.

2

Fill in the form

Provider
openai, anthropic, google, copilot, azure, bedrock
Name
Friendly label, e.g. "Production OpenAI"
API Key
Your real provider key — stored encrypted
Routing Code
Optional. Used to route to a specific key (e.g. "fast", "cheap")
3

Save

The key is encrypted immediately on save. You can have multiple keys per provider for load balancing.

ℹThe gateway routes requests using the first active key for each provider. If you set a routing code, you can target a specific key by adding ?code=yourcode to the proxy URL.

Step 2 – Create a Proxy Key

Proxy keys (rpk_...) are what you give to your IDE or application. They never expire unless you delete them, and you can create as many as you need.

1

Go to Proxy Keys

Open /proxy-keys. Click Create Key.

2

Name your key

Give it a descriptive name like "VS Code", "Cursor", or "CI Pipeline".

3

Copy the key immediately

⚠The full rpk_... key is shown only once at creation time. Copy it now — it cannot be retrieved later (only the SHA-256 hash is stored).
bash
# Example proxy key
rpk_A1B2C3D4E5F6G7H8I9J0K1L2M3N4O5P6Q7R8S9T0U1V2W3X4

Step 3 – Connect Your IDE

Paste your proxy key below, select your tool, then copy the config.

opencodeCustom provider via @ai-sdk/openai-compatible
Continue~/.continue/config.json (VS Code / JetBrains)
CursorEnvironment variables picked up by Cursor
Claude CodeANTHROPIC_BASE_URL + ANTHROPIC_API_KEY
.envAny SDK: OpenAI, Anthropic, LangChain, etc.
.opencode.jsonjson
{
  "$schema": "https://opencode.ai/config.json",
  "provider": {
    "iron-gateway": {
      "npm": "@ai-sdk/openai-compatible",
      "name": "Iron LLM Gateway",
      "options": {
        "baseURL": "https://llm-gateway-api.ironcode.cloud/v1/llm",
        "apiKey": "xxxx"
      },
      "models": {
        "code/model-name": {
          "name": "Add provider keys with routing codes first"
        }
      }
    }
  }
}
✓Logs, costs, and PII detections are recorded in real-time. View them at /logs and /usage.

Rules & PII Detection

Every request is scanned for sensitive data before being forwarded. You can configure behavior in /rules.

Built-in PII patterns (always active)

OpenAI API keys (sk-...)
Anthropic API keys (sk-ant-...)
AWS access keys (AKIA...)
GitHub tokens (ghp_...)
JWT tokens
PEM private keys
Database connection URLs
Passwords in common formats

Add a custom rule

Go to /rules → New Rule. Fill in:

FieldDescription
PatternRegex to match in request/response body
Action"block" — reject request, or "replace" — redact matched text
Severitylow / medium / high / critical (for log filtering)
SalienceEvaluation priority — higher number runs first
ℹRules are hot-reloaded from the database — no restart needed. Changes take effect within seconds.

Usage & Logs

GitHub Copilot

To route requests through the Copilot proxy, you need to authorize the gateway with your GitHub account. This uses GitHub's Device Flow (no redirect needed).

1

Go to API Keys → Add Key (Copilot)

Open /keys and select copilot as the provider.

2

Complete GitHub Device Flow

The dashboard will show a one-time code. Visit github.com/login/device and enter it to authorize.

3

Use the Copilot endpoint

json
{
  "apiBase": "https://llm-gateway-api.ironcode.cloud/v1/copilot",
  "apiKey": "rpk_your_proxy_key",
  "model": "gpt-4o"
}
✓You can add multiple Copilot accounts using different routing codes for load balancing across accounts.