LiteLLM vs Portkey

Both can run the gateway in your infrastructure. The difference is where the control plane lives — and who owns it next year.

LiteLLM and Portkey are the two shortlist options for teams that want a self-hosted data plane with real governance. LiteLLM is fully self-hosted and open-core. Portkey is hybrid: the gateway runs in your infrastructure, the control plane is SaaS. That split decides the rest — where your configuration and logs live, and what happens to your gateway when the vendor changes hands.

Three gateways, five criteria

Each of the first two columns is a one-line read of the corresponding comparison page. The GateLLM column is our own position, not a third-party assessment — weigh it accordingly.

CriterionLiteLLMPortkey (Prisma AIRS)GateLLM
DeploymentSelf-hosted OSSHybrid: gateway self-hosted, control plane SaaSFully self-hosted (Docker / Helm), no vendor control plane
Billing anchorFree OSS; Enterprise usage-priced$49/mo + $9 per 100k recorded logsPer-instance license; no token markup, no per-seat fee
Protocol entrypointsOpenAI-centricOpenAI-compatibleFour ingress x four egress (OpenAI / Anthropic / Gemini / DashScope)
GovernanceSSO (5-user cap) / RBAC in EnterpriseRBAC / SSO / SCIM / guardrailsSSO / SCIM / RBAC + per-key-group ACL and budget caps
Vendor independenceIndependent (BerriAI)Acquired by Palo Alto Networks (2026-05-29)Independent (Fluxon LLC)

When LiteLLM, when Portkey, when neither

Choose LiteLLM if you want the whole system — data plane and control plane — inside your own boundary, and you are prepared to operate it. Nothing about your routing or your logs then depends on a vendor being reachable.

Choose Portkey if you want governance features (RBAC, SSO, SCIM, guardrails) without building the control plane yourself, and a SaaS control plane is acceptable for your data classification. It is the faster path to governed multi-provider routing.

Neither, if you are not yet at the point where governance or failover is a real requirement. Both are infrastructure you have to run and pay for; a direct provider integration is the honest answer until multi-provider failover, per-team cost attribution or compliance controls become the constraint.

LiteLLM vs Portkey: common questions