Back to guides
Compare·September 12, 2026·8 min read

Portkey alternatives (2026) — what the Palo Alto acquisition changes, and what it doesn't

Palo Alto Networks announced on April 30, 2026 that it intends to acquire Portkey, which is to become the AI gateway inside Prisma AIRS. Nothing announced ends the product and the gateway is open source — but an independent infrastructure vendor and a module in a security suite are different things to depend on. This is the honest map of alternatives.

Last reviewed on .

Portkey is a hosted control plane over provider accounts you hold yourself — routing, fallbacks, guardrails, caching and observability behind one endpoint (its site). The reason this search exists in 2026 is on the record: Palo Alto Networks announced on April 30, 2026 that it intends to acquire Portkey, and Portkey is to become the AI gateway inside Prisma AIRS, Palo Alto's AI security platform. That does not make Portkey a bad product or an expiring one — but it does change what it is, from independent infrastructure to a component of a security suite, and that is a legitimate thing to re-evaluate against.

Bias declared: Kunavo is our product, and it is not a like-for-like Portkey replacement — we hold the upstream provider credentials, Portkey routes through yours. That difference decides most of this page, so it is stated before the list rather than buried in it.

What the acquisition does and does not change

The facts, from Palo Alto's own announcement and investor filing: $140 million in cash and replacement awards, announced April 30, 2026, expected to close in Palo Alto's fiscal Q4 2026, with Portkey positioned as the AI gateway for Prisma AIRS.

  • Not changed: the product runs, the gateway is open source, and nothing announced ends the service. There is no migration emergency here, and any page telling you otherwise is selling something.
  • Changed: the category. An independent infrastructure vendor and a module inside a cybersecurity platform have different roadmaps, different pricing logic and different ideas about who the customer is. Gartner already files the category page under Prisma AIRS AI Gateway rather than Portkey — the renaming has started in the analyst layer.
  • Depends who you are: if you are already a Palo Alto customer this is probably an upgrade — one vendor, one contract, a security story your CISO already bought. If you chose Portkey as neutral infrastructure sitting between you and every model provider, the thing you chose is becoming something else.

Worth noting as context rather than alarm: Helicone was acquired by Mintlify in March 2026 and is now in maintenance mode. Two independent gateway and observability vendors consolidated into larger platforms inside two months is a pattern in this category, and "will this vendor still be independent in two years" has become a real selection criterion.

The short list

AlternativeWho holds the provider accountPick it for
LiteLLM (self-hosted)YouOpen source you run; the closest like-for-like
Portkey gateway, self-hostedYouKeeping exactly what you have, minus the vendor question
TrueFoundryYouHosted BYO-key with enterprise support and SLAs
HeliconeYouObservability only — but read its own status first
Cloudflare AI GatewayYouCaching, rate limits and analytics, nothing else
KunavoThe gatewayDropping the provider accounts as well as the control plane
OpenRouterThe gatewaySame, with the longest model tail

1. LiteLLM — the like-for-like open-source swap

LiteLLM covers the core of what most teams use Portkey for — one OpenAI-compatible endpoint over your own provider keys, with routing and fallbacks — as software you deploy. It is the default answer to "open source, self-hosted, BYO key", and the trade is operational: you run it, patch it and own its blast radius. The LiteLLM roundup covers that trade honestly, including the March 2026 supply chain incident and what LiteLLM changed afterwards.

2. Self-hosting Portkey's own gateway

The option most of these listicles skip, because none of them benefits from you taking it: Portkey's gateway is open source, so running it yourself keeps the exact routing behaviour and config you already have while removing the dependency on what the commercial product becomes. If your objection to the acquisition is strategic rather than technical, this is the smallest possible move.

3. TrueFoundry — hosted BYO-key with a support contract

Occupies position 1 on this search with its own post-acquisition guide. It is an enterprise AI gateway sold on deployment flexibility, SLAs, governance and audit controls (its product page). We have not evaluated it, so this is a category pointer rather than a recommendation — and worth reading with the knowledge that the company ranking first for "Portkey alternatives" is the company selling one.

4. Helicone — check its status before you move to it

It appears on most Portkey lists and covers the observability half rather than the routing half. It was also acquired by Mintlify in March 2026 and is in maintenance mode — security patches, bug fixes and new model support, with active feature development ended. Moving from one acquired vendor to another acquired vendor is a specific choice; make it deliberately.

5. Cloudflare AI Gateway — the thin option

Response caching, rate limiting, retries and analytics in front of your own provider keys, and nothing more. If you only ever used a fraction of Portkey, this is a much smaller thing to depend on. Kunavo vs Cloudflare AI Gateway

6. Kunavo and OpenRouter — the different arrangement

Both hold the upstream provider credentials, so there are no provider accounts to manage — and no way to route your own. This is the right move only if holding the accounts was itself a burden you wanted to drop. Kunavo lists most models under the providers' official rates — Claude Sonnet 4.6 at $1.20 / $6.00 per 1M tokens against Anthropic's $3.00 / $15.00, though a few models, Claude Sonnet 5 among them, sit at list, with image, video and music models on the same key. Kunavo vs Portkey puts the two arrangements side by side.

If you have negotiated provider rates, stop here. Committed-spend or enterprise pricing at Anthropic, OpenAI or Google is worth more than anything a reseller can list, and it only survives on a BYO-key tool. That makes categories 1–5 your real list and this section a non-option.

When to stay on Portkey

  • You are a Palo Alto Networks customer. Consolidating on one vendor with one contract and one security posture is a real benefit, and the acquisition works in your favour.
  • Your migration cost is higher than your concern. Nothing has ended. Re-evaluating at renewal is a defensible plan.
  • You use the guardrails and governance features specifically. They are the part of the product least replicated by the open-source alternatives, and the part most likely to get investment under a security-platform owner.

The full pattern — what any gateway should handle for you, and what to interrogate before switching — is in the four categories of LLM gateway.

FAQ

What is the best Portkey alternative?

It depends on whether you want to keep holding your own provider accounts. If yes — the arrangement Portkey is built around — the like-for-like replacements are LiteLLM self-hosted, or another hosted BYO-key control plane such as TrueFoundry. If the provider accounts were themselves the burden, a resold-access gateway such as Kunavo or OpenRouter removes them as well as the control plane, which is a different arrangement rather than a substitute. Decide that first; it eliminates most of the list.

Was Portkey acquired?

Palo Alto Networks announced on April 30, 2026 that it intends to acquire Portkey, for $140 million in cash and replacement awards per its investor filing, with the deal expected to close in Palo Alto's fiscal Q4 2026. Portkey is to become the AI gateway for Prisma AIRS, Palo Alto's AI security platform. The product is running and the gateway remains open source; what changed is the category it sits in.

Do I need to migrate off Portkey because of the acquisition?

Not as an emergency. Nothing in the announcement ends the product, and the gateway is open source, so a self-hosted path exists regardless of what happens to the commercial offering. The question worth asking is about fit rather than continuity: an independent infrastructure vendor and a module inside a cybersecurity platform have different roadmaps, pricing logic and support models. If you bought Portkey as neutral infrastructure, re-evaluate. If you are already a Palo Alto customer, this likely improves your position.

What is the open-source alternative to Portkey?

LiteLLM is the closest: a self-hosted OpenAI-compatible proxy over your own provider keys, covering the routing and fallback core of what Portkey does. Portkey's own gateway is open source too, so self-hosting it is a legitimate answer to the acquisition question. Both put the operational burden back on you — what that burden actually is is worth reading before committing.

Is Kunavo a Portkey alternative?

Only if you are willing to change arrangement. Portkey routes requests through provider accounts you hold; Kunavo holds the upstream credentials and bills you for usage, so there are no provider accounts to manage — and no way to route your own. If you have negotiated rates at Anthropic, OpenAI or Google, those only survive on a BYO-key tool, and Kunavo is the wrong category. If holding the accounts was itself the thing you wanted to stop doing, it replaces both layers at once.

What should I check before replacing an LLM gateway?

Four things, in this order: which provider accounts the replacement expects you to hold, whether it speaks the API shapes your clients use (OpenAI chat completions and Anthropic Messages are different wires), whether prompt caching is supported for the workloads where cached input dominates the bill, and what actually happens on upstream failure — the routing chain, the timeout, and whether a failed request is billed. Feature tables rarely answer the last one.