ManyLayers speaks the OpenAI API to your applications and the native API to each provider. You bring the provider account and its credential; the gateway translates the request, authenticates upstream, and returns an OpenAI-shaped response whichever provider served it.

Two ways to add a provider

WhereProvider typesWhat it servesBest for
Console: Gateway → Providers (https://app.manylayers.io/ui/gateway/providers)34/v1/chat/completions, plus /v1/responses and /v1/messages, which are translated to chat. Embedding, rerank and speech models registered on an account are served on /v1/embeddings, /v1/rerank, /v1/audio/speech and /v1/audio/transcriptions.Workspace teams managing their own accounts and keys
gateway.yaml models[]20Every endpoint the provider supports, including /v1/completions, images, moderation, files, fine-tuning and realtimeOperators, and anything the console does not serve
Requests that carry a workspace-bound key resolve models from the workspace’s console providers only; models[] in gateway.yaml serves keys bound to no workspace and the endpoints above that a console account cannot serve. See Model resolution.
Azure OpenAI can be selected in the console, but a workspace provider row has no place for a deployment name, so requests to it fail with provider_unavailable. Configure Azure in gateway.yaml. Every other console type, including Bedrock and Vertex, is served from the console.

Provider types

provider_type is the id used by the API and by gateway.yaml. The default base URL is what the console fills in when you leave the field empty.
Provider (provider_type)Default base URLCredentialIn gateway.yaml
OpenAI (openai)https://api.openai.comAPI keyyes
Anthropic (anthropic)https://api.anthropic.comAPI keyyes
Azure OpenAI (azure)none, your resource URLAPI keyyes (only here)
Google Gemini (gemini)https://generativelanguage.googleapis.comAPI keyyes
Google Vertex (vertex)https://aiplatform.googleapis.com (express mode), or built from project and regionAPI key, service account, external account, or the gateway’s own Google identityyes
AWS Bedrock (bedrock)built from the account’s regionaccess key pair, assumed role, or Bedrock API keyyes
AWS Bedrock Mantle (bedrock_mantle)https://bedrock-mantle.{region}.api.awssame AWS methodsconsole only
AWS Claude Platform (aws_claude_platform)https://aws-external-anthropic.{region}.api.awssame AWS methods, plus a Claude workspace id (wrkspc_…)console only
AWS SageMaker (sagemaker)built from the account’s regionaccess key pair or assumed roleconsole only
Databricks (databricks)none, your workspace URLpersonal access token or service principalconsole only
Cohere (cohere)https://api.cohere.comAPI keyyes
TypeSafe AI (typesafe)https://api.typesafe.aiAPI keyyes
Mistral AI (mistral)https://api.mistral.aiAPI keyyes
Groq (groq)https://api.groq.com/openaiAPI keyyes
DeepSeek (deepseek)https://api.deepseek.comAPI keyyes
Together AI (together)https://api.together.xyzAPI keyyes
Perplexity AI (perplexity)https://api.perplexity.aiAPI keyyes
xAI (xai)https://api.x.aiAPI keyyes
Fireworks AI (fireworks)https://api.fireworks.ai/inferenceAPI keyyes
OpenRouter (openrouter)https://openrouter.ai/apiAPI keyyes
Cerebras (cerebras)https://api.cerebras.aiAPI keyyes
AI21 Labs (ai21)https://api.ai21.com/studioAPI keyyes
SambaNova (sambanova)https://api.sambanova.aiAPI keyyes
DeepInfra (deepinfra)https://api.deepinfra.comAPI keyconsole only
Baseten (baseten)https://inference.baseten.coAPI keyconsole only
Wafer (wafer)https://pass.wafer.aiAPI keyconsole only
Ollama (ollama)console: https://ollama.com; gateway.yaml: http://localhost:11434optionalyes
Self-Hosted Model (self_hosted)none, always your server’s URLoptionalno
Snowflake Cortex (snowflake_cortex)none; the console builds it from the Snowflake account identifierprogrammatic access tokenconsole only
Cloudera (cloudera)none; each model has its own endpointworkload token or CDP access keyconsole only
ElevenLabs (elevenlabs)https://api.elevenlabs.ioAPI keyconsole only
Deepgram (deepgram)https://api.deepgram.comAPI keyconsole only
Cartesia (cartesia)https://api.cartesia.aiAPI keyconsole only
Smallest AI (smallest)https://waves-api.smallest.aiAPI keyconsole only
Only self_hosted and ollama may be saved without a credential; every other type needs one, except that a Vertex account can use the gateway’s own Google identity and an AWS assumed-role account can be assumed with the gateway’s own AWS identity. A pasted key is checked against the provider’s key format when the account uses the default endpoint (it is skipped when you set your own base URL): OpenAI keys start with sk-, Anthropic sk-ant- (Admin keys are refused), xAI xai-, Cerebras csk-, and Google Gemini accounts accept both the older AIza… keys and the newer AQ.… AI Studio keys.
In gateway.yaml, only twelve OpenAI-wire presets get a default upstream_url: mistral, groq, deepseek, together, perplexity, xai, fireworks, openrouter, cerebras, ai21, sambanova and ollama. For openai, anthropic, gemini, cohere and typesafe, set upstream_url explicitly. The ollama preset defaults to http://localhost:11434, unlike the console’s https://ollama.com.

How requests reach each provider

FamilyProvider typesBehaviour
OpenAI wireopenai, mistral, groq, deepseek, together, fireworks, openrouter, cerebras, xai, ai21, sambanova, ollama, baseten, wafer, self_hosted, snowflake_cortex, cloudera, bedrock_mantleThe body is forwarded unchanged. Whether the call succeeds depends on whether that upstream implements the endpoint or parameter. deepinfra is the same under /v1/openai.
Translatedanthropic, aws_claude_platform, gemini, vertex, bedrock, cohere, perplexity, sagemaker, databricks, typesafeThe gateway rewrites the request and response. See the endpoint table below.
AzureazureThe path becomes /openai/deployments/{upstream_model}/… with an api-version query (default 2024-06-01).
Speech onlyelevenlabs, deepgram, cartesia, smallestServe /v1/audio/speech and /v1/audio/transcriptions only, translated to the provider’s own API. They serve no chat models.
EndpointServed by
Chat (/v1/chat/completions)every type except the speech-only ones
EmbeddingsOpenAI-wire types, azure, gemini, vertex, bedrock, cohere, databricks
Rerankcohere (translated to Cohere’s v2 rerank); openai, azure and OpenAI-wire types are forwarded to {base}/v1/rerank
Text-to-speech and transcriptionopenai, azure, and the four speech-only types
Image generation, edits and variationsgateway.yaml openai and azure models only; the console cannot register image models
Files, fine-tuning, realtimegateway.yaml openai and azure models only
  • A translated provider that cannot serve an endpoint at all (for example /v1/completions to Anthropic) is refused by the gateway without an upstream call, and the error names the endpoints it does serve.
  • Moderation is forwarded to a gateway.yaml openai or azure model. For any other model, or no model, the gateway answers itself from its PII and prompt-firewall scoring.
  • Bedrock embeddings take one input per upstream call, so the gateway fans a batch out and reassembles one OpenAI response.
  • TypeSafe answers typed questions: every request must set response_format to a json_schema, and stream: true is refused.
  • Perplexity is translated to its Agent API; Sonar model names map to Agent API presets.

Parameter support on translated providers

Native-format adapters honour only what they can translate. A parameter that would change the result and cannot be honoured is refused with a 400 (code unsupported_parameter) naming it in error.param, never silently dropped. Inert values (n: 1, tool_choice: "auto", parallel_tool_calls: true, a zero penalty) always pass.
Parameteranthropic, aws_claude_platformgemini, vertexcoherebedrockperplexitytypesafe
tools, forced tool_choiceyesyesyesyes——
parallel_tool_calls: falseyes—————
response_format json_object—yesyesyes——
response_format json_schema—yesyesyesyesrequired
n > 1—yes————
seed—yesyes———
logprobs: true—yesyes———
presence_penalty, frequency_penalty—yesyes———
logit_bias——————
reasoning_effortyesyesyesyesyes—
Gemini, Vertex, Bedrock and Cohere also refuse image or document parts they cannot send (for example a remote image URL to Bedrock, which takes inline bytes only), naming the part. OpenAI-wire providers, azure, databricks and sagemaker are not checked: the body goes upstream as sent.

Authentication upstream

ProviderHow the gateway authenticates
openai, cohere, typesafe, databricks, snowflake_cortex, cloudera, smallest and OpenAI-wire typesAuthorization: Bearer <key> (omitted when there is no credential)
azureapi-key: <key>
anthropicx-api-key: <key> plus anthropic-version
geminix-goog-api-key: <key>
vertexexpress mode: x-goog-api-key; project mode: an OAuth access token minted from the service account or external account, or from the gateway’s own Google identity when the account has no credential
bedrock, bedrock_mantle, sagemaker, aws_claude_platformAWS SigV4 with an access key pair ACCESS_KEY:SECRET_KEY[:SESSION_TOKEN], or the role’s temporary credentials for an assumed role; a Bedrock API key (ABSK… or bedrock-api-key-…) is sent as a bearer token. SageMaker has no API keys.
elevenlabsxi-api-key
deepgramAuthorization: Token <key>
cartesiaX-API-Key plus a date-based Cartesia-Version the account may pin
The caller’s own Authorization header is never forwarded.

Adding a provider in the console

Open Gateway → Providers and choose a provider from the gallery (Add other providers once one is connected). The setup has two steps:
  1. Configure Account. Give the account a name (unique in the workspace; a second account of the same provider serves its models as account/model), a base URL where the type needs one, and a credential: paste the key, or give a reference such as ${OPENAI_API_KEY} or ${vault:secret/data/llm#openai} (see Credentials). Bedrock-family accounts ask for an AWS region, Vertex for a Google Cloud project and region (leave the project empty for express mode with an API key), and Claude Platform on AWS for the Claude workspace id. Test Credentials checks the account before you save.
  2. Models Selection. Pick the models the account serves from the provider’s own listing, or add one manually with Add Model Manually. See Model selection.
Requests then use the model name you registered. Disabling or deleting a model, or the account, stops resolving it immediately.

gateway.yaml examples

gateway.yaml
models:
  - logical_name: gpt-4o
    provider: openai
    upstream_url: https://api.openai.com
    upstream_model: gpt-4o
    upstream_api_key: ${OPENAI_API_KEY}
    input_price_per_1k: 0.0025
    output_price_per_1k: 0.01
The gateway rewrites the path to /openai/deployments/{upstream_model}/... and adds api-version (default 2024-06-01, set per upstream with api_version).
gateway.yaml
models:
  - logical_name: gpt-4o-azure
    upstreams:
      - provider: azure
        url: https://my-resource.openai.azure.com
        model: gpt-4o-prod          # your deployment name
        api_key: ${AZURE_OPENAI_API_KEY}
        api_version: 2024-06-01
In the console: type Anthropic, base URL left empty, paste the key.
gateway.yaml
models:
  - logical_name: claude-sonnet
    provider: anthropic
    upstream_url: https://api.anthropic.com
    upstream_model: claude-sonnet-4-5
    upstream_api_key: ${ANTHROPIC_API_KEY}
In gateway.yaml, Vertex uses express mode: an API key in x-goog-api-key, calls to {upstream_url}/v1/publishers/google/models/{model}. Project-scoped Vertex accounts (service account, external account or the gateway’s Google identity) are set up in the console.
gateway.yaml
models:
  - logical_name: gemini-flash
    provider: gemini
    upstream_url: https://generativelanguage.googleapis.com
    upstream_model: gemini-2.0-flash
    upstream_api_key: ${GEMINI_API_KEY}      # AIza… or AQ.… AI Studio key
  - logical_name: gemini-vertex
    provider: vertex
    upstream_url: https://aiplatform.googleapis.com
    upstream_model: gemini-2.0-flash
    upstream_api_key: ${VERTEX_API_KEY}
Requests use the Converse API and are signed with SigV4. aws_region is required. The key is ACCESS_KEY:SECRET_KEY[:SESSION_TOKEN], or a Bedrock API key.
gateway.yaml
models:
  - logical_name: claude-bedrock
    provider: bedrock
    upstream_url: https://bedrock-runtime.us-east-1.amazonaws.com
    upstream_model: anthropic.claude-3-5-sonnet-20241022-v2:0
    upstream_api_key: ${AWS_ACCESS_KEY_ID}:${AWS_SECRET_ACCESS_KEY}
    aws_region: us-east-1
gateway.yaml
models:
  - logical_name: command-r-plus
    provider: cohere
    upstream_url: https://api.cohere.com
    upstream_model: command-r-plus
    upstream_api_key: ${COHERE_API_KEY}
  - logical_name: rerank
    provider: cohere
    upstream_url: https://api.cohere.com
    upstream_model: rerank-v3.5
    upstream_api_key: ${COHERE_API_KEY}
Omit upstream_url and the preset default is used. In the console, choose the type and paste the key.
gateway.yaml
models:
  - logical_name: llama-fast
    provider: groq
    upstream_model: llama-3.3-70b-versatile
    upstream_api_key: ${GROQ_API_KEY}
Neither a credential nor, in gateway.yaml, a URL is required for a local Ollama. The console’s Ollama type defaults to https://ollama.com instead; set the base URL to point it at your own server.
gateway.yaml
models:
  - logical_name: llama-local
    provider: ollama               # defaults to http://localhost:11434
    upstream_model: llama3.2
In the console, self_hosted has no default address: the account or each model names its server’s URL, with the server recorded as vLLM, Ollama, SGLang or TGI. A URL ending in /v1 is accepted. In gateway.yaml, serve a self-hosted server as a plain OpenAI-wire model with an explicit URL.
gateway.yaml
models:
  - logical_name: llama-internal
    provider: openai
    upstream_url: http://vllm.internal:8000
    upstream_model: meta-llama/Llama-3.1-8B-Instruct
Every request must carry response_format: {"type": "json_schema", ...}; each schema property is a question. Answers come back as JSON in choices[0].message.content, with probabilities in a typesafe field beside choices.
gateway.yaml
models:
  - logical_name: jev
    provider: typesafe
    upstream_url: https://api.typesafe.ai
    upstream_model: jev
    upstream_api_key: ${TYPESAFE_API_KEY}

Model entry fields (gateway.yaml)

FieldDescription
logical_nameThe name clients send as model and see in /v1/models. Required and unique.
aliasesExtra names that resolve to this model.
providerOne of the 20 gateway.yaml types. Default openai.
upstream_url, upstream_model, upstream_api_keySingle-endpoint shorthand. Keys support ${ENV}, ${ENV:-default} and ${vault:path#key}. Use either this or upstreams[], not both.
upstreams[]Several endpoints for one model: url, model, api_key, weight (default 1), provider, api_version (Azure), region (Bedrock). See Routing.
aws_regionBedrock region, copied to upstreams that do not set region.
encodingTokenizer for counting. Default cl100k_base.
input_price_per_1k, output_price_per_1k, cached_input_price_per_1k, cache_write_price_per_1k, media_pricesPricing; see Budgets & cost tracking.
pii_output_modepassthrough (default) or buffer.
cacheCache responses even when temperature is not 0.

Next steps

Model resolution

How a requested name becomes a provider call.

Virtual models

Put fallback, weighting and canaries behind one model name.

Credentials

Gateway keys for callers and how provider credentials are stored.

Budgets & cost tracking

How prices become spend and limits.