Agent execution sandbox
An isolated environment where agents can run code and call internal tools without holding standing credentials to production systems.
Provides the shared way to build with models here — access, evaluation, guardrails and cost control — so product teams do not each solve it alone.
An isolated environment where agents can run code and call internal tools without holding standing credentials to production systems.
One endpoint for every model we use, with per-team quotas, cost attribution, audit logging and failover between providers.
Direct provider API keys stop working on 2 November
A shared way to measure whether a prompt or model change actually improved anything, before it reaches customers.
From 2 November the provider keys held by individual teams are revoked. Calls made directly to a provider will fail with a 401; calls through the gateway are unaffected.
Switching over is a base URL change and a different key. The quickstart has the exact diff for each SDK we support.
We particularly want to hear from teams already running agents against internal APIs, and from Security on the credential model.
Two product teams have contributed graded examples. We need more, and from more domains — if your team has a task with known-good answers, talk to us.
Teams using models in production should move now rather than in October — the gateway gives you retry handling and a cost breakdown you do not currently have.