LiteLLM vs Portkey
Both can run the gateway in your infrastructure. The difference is where the control plane lives — and who owns it next year.
LiteLLM and Portkey are the two shortlist options for teams that want a self-hosted data plane with real governance. LiteLLM is fully self-hosted and open-core. Portkey is hybrid: the gateway runs in your infrastructure, the control plane is SaaS. That split decides the rest — where your configuration and logs live, and what happens to your gateway when the vendor changes hands.
Three gateways, five criteria
Each of the first two columns is a one-line read of the corresponding comparison page. The GateLLM column is our own position, not a third-party assessment — weigh it accordingly.
| Criterion | LiteLLM | Portkey (Prisma AIRS) | GateLLM |
|---|---|---|---|
| Deployment | Self-hosted OSS | Hybrid: gateway self-hosted, control plane SaaS | Fully self-hosted (Docker / Helm), no vendor control plane |
| Billing anchor | Free OSS; Enterprise usage-priced | $49/mo + $9 per 100k recorded logs | Per-instance license; no token markup, no per-seat fee |
| Protocol entrypoints | OpenAI-centric | OpenAI-compatible | Four ingress x four egress (OpenAI / Anthropic / Gemini / DashScope) |
| Governance | SSO (5-user cap) / RBAC in Enterprise | RBAC / SSO / SCIM / guardrails | SSO / SCIM / RBAC + per-key-group ACL and budget caps |
| Vendor independence | Independent (BerriAI) | Acquired by Palo Alto Networks (2026-05-29) | Independent (Fluxon LLC) |
When LiteLLM, when Portkey, when neither
Choose LiteLLM if you want the whole system — data plane and control plane — inside your own boundary, and you are prepared to operate it. Nothing about your routing or your logs then depends on a vendor being reachable.
Choose Portkey if you want governance features (RBAC, SSO, SCIM, guardrails) without building the control plane yourself, and a SaaS control plane is acceptable for your data classification. It is the faster path to governed multi-provider routing.
Neither, if you are not yet at the point where governance or failover is a real requirement. Both are infrastructure you have to run and pay for; a direct provider integration is the honest answer until multi-provider failover, per-team cost attribution or compliance controls become the constraint.