Request Access → Roll out ChatGPT, Claude Code, Codex, VS Code, or the apps and agents you build yourself, to the whole company in under a day. Your identity provider decides which models each team can call, and every request stays inside a boundary that's FedRAMP Equivalent, assessed at High.
Connect Microsoft Entra ID, Okta, Google Workspace, or any OpenID Connect provider. Map each group to a policy once. From then on, people get the right models the first time they sign in, with no ticket and no per-key setup.
The Portal builds each package from your organization's model policy. Consus installs nothing and runs nothing on your network. You push the files with the device management you already use.
Every key, every dollar, and every policy, visible to your admins.
Set monthly budgets per org or per key and watch spend accrue in real time. Know what's left and when it resets.
Tokens routed, total requests, error-free rate, and P95 latency across 1, 7, 30, and 90-day windows, per key and per org.
Every key has a named owner, set when it's created and never reassigned. Issue, limit, or revoke in seconds, and see every key by person.
Groups arrive from your identity provider as people sign in. Assign each one a policy, and their keys follow.
Set an org-wide ceiling by compliance level or by model. Nothing outside it can be called, by any key.
Packages for eight tools on macOS and Windows, built from your model policy, with a note for your team.
They sign in with your identity provider. Their group already maps to a policy, so their first key can call exactly the models it should.
Disable them in your IdP. Revoke their keys in the Portal, or from your offboarding script with the Management API. By Monday there's nothing to clean up.
Revoke it in seconds. Pull its request history from the logs API and know exactly what it was used for.
Their tools never listed it. If they call it anyway, the gateway refuses and tells them to contact their administrator.
The key hits its monthly cap and the gateway stops serving it. The worst case is the budget you set, not the invoice you find.
A flat access fee, zero token markup, and usage at provider list price, capped by the budgets you set. The forecast is arithmetic.
Your organization's management key can't run inference. It runs everything around it: issue and revoke keys, set limits, and read spend and request logs, scoped to your organization alone. Wire it into onboarding, offboarding, your SIEM, or the monthly report your assessor asks for.
POST /v1/keys Create a key with a named owner and a monthly limitDELETE /v1/keys/{id} Revoke a key instantlyGET /v1/keys?owner= List every key a person ownsPATCH /v1/keys/{id}/limit Raise or lower a key's monthly limitGET /v1/org Org caps, model ceiling, and month-to-date spendGET /v1/spend Monthly spend and tokens per keyGET /v1/logs Every request: model, tokens, cost, latency, statusKeys created here follow the same model policy as keys created in the Portal. Logs are metadata only; the gateway never stores prompts or responses.
Read the Management API docs →# A new engineer starts
curl -X POST "https://api.consus.io/v1/keys" \
-H "x-api-key: $CONSUS_MANAGEMENT_KEY" \
-d '{"owner": "dev@example.com", "label": "dev-laptop",
"requested_monthly_limit_usd": 50}'
# They leave: revoke the key
curl -X DELETE "https://api.consus.io/v1/keys/a1b2c3d4e5" \
-H "x-api-key: $CONSUS_MANAGEMENT_KEY"
# The assessor asks what it was used for
curl "https://api.consus.io/v1/logs?api_key_id=a1b2c3d4e5" \
-H "x-api-key: $CONSUS_MANAGEMENT_KEY"
{
"request_id": "9c5b2f1a-8d3e-4b6a-9f21-0e7c44aa1b55",
"api_key_id": "a1b2c3d4e5",
"model": "gpt-5.4:itar",
"input_tokens": 1204,
"output_tokens": 356,
"cost": 0.00897,
"latency_ms": 2841,
"status": "200"
}:itar that names the boundary the request runs in. See the compliance posture.No platform to deploy, no seats to provision. Your developers keep the tools they already use. Consus sits underneath as the compliant inference layer, and the admin controls come with it.
Every agreement carries a 99.9% uptime SLA. Support tiers scale with your program, up to a shared channel with the engineers who built the gateway. Full terms live in the Cloud Service Agreement.
US-based defense contractors only. Access is granted after a company review and contract. No self-serve.