Documentation
BYOK and Connect OpenRouter
Connect OpenRouter is the preferred user-funded path. The end user completes OpenRouter's connection ceremony, and the application passes the resulting ephemeral credential only on the inference request.
User-funded traffic is accepted only for features whose server-owned key_policy allows
it. The application still sends the stable feature ID; it cannot use a user credential
to choose a different provider, model, or output ceiling.
Weirgate never stores or logs X-User-Provider-Key. A user-funded request settles zero
Weirgate units and attributes zero provider cost to the app owner while retaining
non-content operational metering with key_source=user, token counts, and latency.
Developer-funded features reject a user-key header so callers cannot evade the application's allowance policy. Provider availability is exposed by the authenticated feature catalog and evaluated before reserve.
Raw direct-provider user-key routes are not the public path. OpenAI, Anthropic, Google, and xAI credentials must not be pasted into the application for direct routing.