MLflow AI Gateway vs Helicone
The question that decides it: Do you need per-user request analytics badly enough to adopt a platform whose owner is offering migration help?
Our verdict
Choosing today, and especially if you self-host: MLflow AI Gateway, because it is still shipping and its self-hosted build routes to every provider it documents. If you specifically need per-user and per-property request analytics on a hosted service with SOC 2 Type II and a HIPAA BAA, and you can accept a maintained-not-extended product: Helicone.
Why
These two reached the same place from opposite directions. MLflow started in 2018 as experiment tracking and added a gateway to the server that already held your traces, so a gateway request becomes an MLflow trace with no extra instrumentation. Helicone started in 2023 as LLM request observability and added a gateway in front of the logging it already did, so the request is the primary object and the analytics hang off it. The economics are close enough to ignore: both are Apache-2.0, both charge zero token markup, both charge $0 per seat, and both record deployment as hosted or self-hosted. Helicone's paid tiers exist for the platform rather than the routing — Hobby free with one seat, 10,000 requests a month, 1 GB of storage and 7-day retention, then Pro at $79 a month and Team at $799 — while MLflow has no paid tier at all.
The deciding question turns out not to be lineage but momentum. Mintlify announced its acquisition of Helicone on 2026-03-03 and put the product into maintenance mode: security updates, bug fixes and new models keep shipping, Helicone says the services remain live for the foreseeable future, and Mintlify says it will work closely with every customer to support a smooth migration to another platform. The dates in the record are consistent with that. The latest tagged GitHub release is 2025-08-21, the hosted changelog stops at 26 November 2025, and the standalone Rust gateway repository was last pushed 2025-11-21. MLflow's latest release in the same record is dated 2026-08-26. This is not a reason to write Helicone off — it is a reason to be honest that you would be adopting a product whose owner has offered to help you leave it, and the signup flow still advertises a free trial, so the status is easy to miss.
If you self-host, provider coverage inverts against the star counts. Helicone's hosted registry returned 111 models across 21 provider endpoints, and its docs describe the gateway as 100+ providers; the self-hosted build supports OpenAI and Anthropic only, with Vertex AI, AWS Bedrock and Azure OpenAI explicitly not supported, and port 8585 carries no proxy authentication so firewall restriction is required. MLflow enumerates 14 providers in its docs tables — including Azure OpenAI, AWS Bedrock and Vertex AI — and self-hosting is the first-class path, by pip or an official OCI Helm chart, with the same 14 available either way. So Helicone's 6,109 stars against MLflow's 27,777 tell you very little here, not least because those 27,777 are for all of mlflow/mlflow and not a measure of gateway adoption. MLflow publishes no model total, and points at the provider dropdown instead of a number.
What is left is a genuine trade between logging depth and enforcement. Helicone logs prompt and completion bodies by default, attributes cost per user through a Helicone-User-Id header and per property through Custom Properties, and ships sessions, HQL, alerts and a public model registry with per-endpoint pricing; it records config-as-code as supported, exact-match caching, SOC 2 Type II, a HIPAA BAA, GDPR and a choice of US or EU region. MLflow is quieter by default: logging is opt-in per endpoint and off until you enable usage tracking, at which point full payloads are recorded as traces in your own database, and cost attribution is per endpoint, provider and model rather than per user. Enforcement runs the other way. Helicone records guardrails and PII redaction as absent, its one request-path control being an opt-in Helicone-Moderations-Enabled header that a client can simply omit, while MLflow ships LLM-judge Safety, PII and Custom guardrails with Block or Sanitize actions — subject to the streaming caveat below. Neither is the choice if you want declarative endpoint management on the MLflow side, which records config-as-code as unsupported.
Which one, concretely
Choose MLflow AI Gateway if
- You already run MLflow and want gateway traffic to land as traces in the same server, with no second system to deploy
- You self-host and need Azure OpenAI, AWS Bedrock or Vertex AI, which the Helicone self-hosted build does not support
- You want a project that shipped a release on 2026-08-26 rather than one in maintenance mode
- You want logging off by default, enabled per endpoint, with payloads staying in your own database
Choose Helicone if
- You need per-user and per-property cost attribution, via Helicone-User-Id and Custom Properties
- You want a hosted gateway with SOC 2 Type II, a HIPAA BAA, GDPR and a US or EU region choice
- You want exact-match response caching, which MLflow does not offer in any form
- You want config-as-code for routing, which MLflow records as unsupported
What catches people out
- Helicone's self-hosted build supports OpenAI and Anthropic only, and port 8585 has no proxy authentication. Budget for a firewall rule, and check your providers are on the supported pair before committing.
- Helicone's Omit Logs feature stops storage but the request and response are still sent to Helicone's backend. If the requirement is that content never leaves your boundary, self-host or use MLflow.
- Helicone's Hobby plan drops logs above 10 logs per minute, which can silently truncate agent traces. Do not evaluate agent workloads on the free tier and infer coverage from it.
- MLflow's post-LLM guardrails are not triggered for streaming requests, and usage tracking is opt-in per endpoint. An endpoint added without either enabled is unlogged and unguarded on streaming traffic.
Side by side
Interpret these fields: How much does an LLM gateway lock you in? · LLM gateway compliance: SOC 2, HIPAA and evidence · How LLM gateway failover actually works
7 of 18 fields differ, marked with a dot. Every figure links to the vendor page it came from. Blank values read Not published rather than No — silence from a vendor is not a negative answer.
| Field | MLflow AI Gateway | Helicone |
|---|---|---|
| Ease of leaving Derived score, higher is easier | 84/100 Some work to leave | 100/100 Easy to leave |
| What kind of product Category | Open source | Managed gateway |
| Who runs it Deployment model | Managed or self-host | Managed or self-host |
| Licence Licence | Apache-2.0 | Apache-2.0 |
| Models available Models available | Not published | ~100 |
| Model providers reachable Upstream providers | 14–100 | 20–100 |
| Markup on model prices Token markup | None | None |
| Fee to add funds Credit purchase fee | None | Not published |
| Monthly cost per person Seat fee | None | None |
| GitHub stars GitHub stars | 27,777 | 6,109 |
| Usage dashboards and logs Observability | Yes | Yes |
| Content guardrails Content guardrails | Yes | No |
| Strips personal data PII redaction | Yes | No |
| Response caching Response caching | Not published | Yes |
| Settings can live in version control Declarative config-as-code | No | Yes |
| How long they keep it Default content retention (days) | Not published | 7 days |
| SOC 2 audited SOC 2 audited | Not published | Yes |
| Will sign a HIPAA agreement HIPAA BAA | Not published | Yes |
| What gets logged Logged content | Your choice | Full prompts and responses |
for MLflow AI Gateway and for Helicone. Want more fields, or a third option in the mix? Open these two in the full comparison tool.
Common questions
Is Helicone still safe to build on?
It is live, but not being extended. Mintlify announced the acquisition on 2026-03-03 and put Helicone into maintenance mode: security fixes, bug fixes and new models continue, Helicone says services remain live for the foreseeable future, and Mintlify has offered migration support to another platform. The latest tagged release is 2025-08-21 and the hosted changelog stops at 26 November 2025.
Is MLflow AI Gateway deprecated?
No. It was deprecated and renamed MLflow Deployments Server in 2.9.x, and 2.17.0 on 2024-10-11 explicitly reversed both the deprecation and the naming. Separately, MLflow 3.0 removed the standalone deployment server application and the start-server CLI, so the gateway now runs inside mlflow server rather than as its own process. The record shows a release dated 2026-08-26.
Which one self-hosts better?
MLflow, mostly on provider coverage. Both publish self-hosting, and Helicone documents a local binary, Docker, Kubernetes with Helm and cloud installs, but its self-hosted build supports OpenAI and Anthropic only and leaves port 8585 without proxy authentication. MLflow self-hosts by pip or an official OCI Helm chart with TLS, ingress, Prometheus metrics and RBAC from 3.13.0, and exposes all 14 documented providers.