MLflow AI Gateway vs Helicone

The question that decides it: Do you need per-user request analytics badly enough to adopt a platform whose owner is offering migration help?

Our verdict

Choosing today, and especially if you self-host: MLflow AI Gateway, because it is still shipping and its self-hosted build routes to every provider it documents. If you specifically need per-user and per-property request analytics on a hosted service with SOC 2 Type II and a HIPAA BAA, and you can accept a maintained-not-extended product: Helicone.

Why

These two reached the same place from opposite directions. MLflow started in 2018 as experiment tracking and added a gateway to the server that already held your traces, so a gateway request becomes an MLflow trace with no extra instrumentation. Helicone started in 2023 as LLM request observability and added a gateway in front of the logging it already did, so the request is the primary object and the analytics hang off it. The economics are close enough to ignore: both are Apache-2.0, both charge zero token markup, both charge $0 per seat, and both record deployment as hosted or self-hosted. Helicone's paid tiers exist for the platform rather than the routing — Hobby free with one seat, 10,000 requests a month, 1 GB of storage and 7-day retention, then Pro at $79 a month and Team at $799 — while MLflow has no paid tier at all.

The deciding question turns out not to be lineage but momentum. Mintlify announced its acquisition of Helicone on 2026-03-03 and put the product into maintenance mode: security updates, bug fixes and new models keep shipping, Helicone says the services remain live for the foreseeable future, and Mintlify says it will work closely with every customer to support a smooth migration to another platform. The dates in the record are consistent with that. The latest tagged GitHub release is 2025-08-21, the hosted changelog stops at 26 November 2025, and the standalone Rust gateway repository was last pushed 2025-11-21. MLflow's latest release in the same record is dated 2026-08-26. This is not a reason to write Helicone off — it is a reason to be honest that you would be adopting a product whose owner has offered to help you leave it, and the signup flow still advertises a free trial, so the status is easy to miss.

If you self-host, provider coverage inverts against the star counts. Helicone's hosted registry returned 111 models across 21 provider endpoints, and its docs describe the gateway as 100+ providers; the self-hosted build supports OpenAI and Anthropic only, with Vertex AI, AWS Bedrock and Azure OpenAI explicitly not supported, and port 8585 carries no proxy authentication so firewall restriction is required. MLflow enumerates 14 providers in its docs tables — including Azure OpenAI, AWS Bedrock and Vertex AI — and self-hosting is the first-class path, by pip or an official OCI Helm chart, with the same 14 available either way. So Helicone's 6,109 stars against MLflow's 27,777 tell you very little here, not least because those 27,777 are for all of mlflow/mlflow and not a measure of gateway adoption. MLflow publishes no model total, and points at the provider dropdown instead of a number.

What is left is a genuine trade between logging depth and enforcement. Helicone logs prompt and completion bodies by default, attributes cost per user through a Helicone-User-Id header and per property through Custom Properties, and ships sessions, HQL, alerts and a public model registry with per-endpoint pricing; it records config-as-code as supported, exact-match caching, SOC 2 Type II, a HIPAA BAA, GDPR and a choice of US or EU region. MLflow is quieter by default: logging is opt-in per endpoint and off until you enable usage tracking, at which point full payloads are recorded as traces in your own database, and cost attribution is per endpoint, provider and model rather than per user. Enforcement runs the other way. Helicone records guardrails and PII redaction as absent, its one request-path control being an opt-in Helicone-Moderations-Enabled header that a client can simply omit, while MLflow ships LLM-judge Safety, PII and Custom guardrails with Block or Sanitize actions — subject to the streaming caveat below. Neither is the choice if you want declarative endpoint management on the MLflow side, which records config-as-code as unsupported.

Which one, concretely

Choose MLflow AI Gateway if

  • You already run MLflow and want gateway traffic to land as traces in the same server, with no second system to deploy
  • You self-host and need Azure OpenAI, AWS Bedrock or Vertex AI, which the Helicone self-hosted build does not support
  • You want a project that shipped a release on 2026-08-26 rather than one in maintenance mode
  • You want logging off by default, enabled per endpoint, with payloads staying in your own database

Choose Helicone if

  • You need per-user and per-property cost attribution, via Helicone-User-Id and Custom Properties
  • You want a hosted gateway with SOC 2 Type II, a HIPAA BAA, GDPR and a US or EU region choice
  • You want exact-match response caching, which MLflow does not offer in any form
  • You want config-as-code for routing, which MLflow records as unsupported

What catches people out

Side by side

7 of 18 fields differ, marked with a dot. Every figure links to the vendor page it came from. Blank values read Not published rather than No — silence from a vendor is not a negative answer.

Field MLflow AI Gateway Helicone
Ease of leaving Derived score, higher is easier 84/100 Some work to leave 100/100 Easy to leave
What kind of product Category Open source Managed gateway
Who runs it Deployment model Managed or self-host Managed or self-host
Licence Licence Apache-2.0 Apache-2.0
Models available Models available Not published ~100
Model providers reachable Upstream providers 14–100 20–100
Markup on model prices Token markup None None
Fee to add funds Credit purchase fee None Not published
Monthly cost per person Seat fee None None
GitHub stars GitHub stars 27,777 6,109
Usage dashboards and logs Observability Yes Yes
Content guardrails Content guardrails Yes No
Strips personal data PII redaction Yes No
Response caching Response caching Not published Yes
Settings can live in version control Declarative config-as-code No Yes
How long they keep it Default content retention (days) Not published 7 days
SOC 2 audited SOC 2 audited Not published Yes
Will sign a HIPAA agreement HIPAA BAA Not published Yes
What gets logged Logged content Your choice Full prompts and responses

for MLflow AI Gateway and for Helicone. Want more fields, or a third option in the mix? Open these two in the full comparison tool.

Common questions

Is Helicone still safe to build on?

It is live, but not being extended. Mintlify announced the acquisition on 2026-03-03 and put Helicone into maintenance mode: security fixes, bug fixes and new models continue, Helicone says services remain live for the foreseeable future, and Mintlify has offered migration support to another platform. The latest tagged release is 2025-08-21 and the hosted changelog stops at 26 November 2025.

Is MLflow AI Gateway deprecated?

No. It was deprecated and renamed MLflow Deployments Server in 2.9.x, and 2.17.0 on 2024-10-11 explicitly reversed both the deprecation and the naming. Separately, MLflow 3.0 removed the standalone deployment server application and the start-server CLI, so the gateway now runs inside mlflow server rather than as its own process. The record shows a release dated 2026-08-26.

Which one self-hosts better?

MLflow, mostly on provider coverage. Both publish self-hosting, and Helicone documents a local binary, Docker, Kubernetes with Helm and cloud installs, but its self-hosted build supports OpenAI and Anthropic only and leaves port 8585 without proxy authentication. MLflow self-hosts by pip or an official OCI Helm chart with TLS, ingress, Prometheus metrics and RBAC from 3.13.0, and exposes all 14 documented providers.