New API vs LLM Gateway
The question that decides it: Do you want to run the gateway yourself and bill the people behind it, or hand the running of it to someone with an attestation?
Our verdict
Metering or charging your own users on infrastructure you control: New API, because its quota, top-up and subscription machinery has no equivalent here. Wanting a gateway in production this week with SOC 2 Type II, an official Helm chart and a free self-hosted escape hatch: LLM Gateway, and treat the 5% credit fee as the price of not operating it.
Why
The licences and the token economics are identical, which is what makes the rest of the comparison legible. Both are AGPL-3.0, both charge zero markup on tokens, both charge $0 per seat, and both ship a console for users, keys and spend rather than being bare proxies. Deployment is where they part. New API is self-host only — Docker Compose for production, a single container, 1Panel and BaoTa one-click installs, and a cluster mode that scales behind an external Nginx or HAProxy — with no vendor-hosted tier on any page and no vendor in the request path. LLM Gateway offers both: the whole platform self-hosts free forever from one Docker image, or you use the hosted service and pay a flat 5% when you buy credits, plus 1.5% on international cards, with BYOK free on the free plan and no seats, minimums or subscription. If you were never going to hand your traffic to a vendor, that 5% is not a cost you would ever pay, and New API's deployment story is the more complete one.
Community scale is the headline asymmetry and it buys less than it looks like. New API has 47,090 stars, 11,229 forks and 1,318 open issues, was last pushed 2026-09-01, and is unambiguously active — but the shipping line is still v1.0.0-rc.30, published 2026-08-31, after nearly three years, its docs changelog trailed at rc.25 when checked, and the project's own documentation says it is primarily intended for personal learning and research, that stability is not guaranteed, and that official technical support may not be provided under the open-source licence. LLM Gateway has 601 stars, is operated by Polar Lights LLC, a Delaware company that publishes no funding or ownership information, and released v1.14.0 on 2026-08-24 on a weekly minor cadence. It also carries SOC 2 Type II, independently examined, an enterprise DPA and a status page. New API publishes no SOC 2, no ISO 27001, no HIPAA BAA and no GDPR DPA at all, and its acceptable-use policy pushes identity management, log retention and filing duties onto the deployer. On paper, the small project is the one you can put in front of procurement.
Infrastructure and integration follow the same line, and this is where LLM Gateway earns its place. It publishes an official Helm chart as an OCI artifact on GitHub Container Registry deploying the gateway, API, UI and worker against PostgreSQL and Redis, Terraform modules on the Enterprise plan that provision EKS, RDS, ElastiCache, networking and secrets, a hosted MCP server at api.llmgateway.io/mcp exposing chat, image generation and model listing to Claude Code, Codex and Cursor, and a first-party Vercel AI SDK provider. New API documents none of that: no Kubernetes or Helm, no Terraform, no MCP, no OpenTelemetry, and routing configuration lives in the console database rather than in Git. What it has instead is API surface. One New API instance serves three dialects — an eleven-endpoint OpenAI surface covering chat, completions, embeddings, image generation and edits, audio transcription and speech, rerank, responses, a realtime WebSocket and models, plus native Anthropic Messages and native Gemini v1beta — while LLM Gateway documents OpenAI Chat Completions and the Anthropic Messages endpoint, with embeddings, audio, batch and the Responses API not documented on the pages checked. On counts, LLM Gateway states 200+ models across 40+ providers against New API's 100+ models and 30+ providers, both sides publishing floors rather than counted lists.
Then there is what each does with governance, and both answers are partial. New API's strength is access control rather than content policy: tokens are first-class virtual keys with expiry, remaining quota, an unlimited-quota flag, model restrictions and an IP allowlist, auto-disabling when the quota runs out, with group multipliers, three-tier ratios at 1 USD to 500,000 quota points, pre-consumption reconciled after the call, and EPay, Stripe, Creem and Waffo top-ups, redemption codes and subscription plans around it. What it does not publish is any PII, injection or custom-policy engine — only a blocked-word facility whose matching mode, default state and returned error are all undocumented. LLM Gateway advertises guardrails, PII redaction and content moderation enforced at the gateway, but the governance tier is where the open core bites: audit logs, region pinning and per-project routing customisation are Enterprise, code in the repository's ee/ directory needs a separate commercial licence, and enterprise features require a signed licence in production with a seven-day grace period once it expires. New API's AGPL exemption is likewise a commercial licence arranged by email at an unpublished price. Retention differs in kind rather than degree: New API has no vendor-side copy at all and a Log Retention Days setting you choose, while LLM Gateway defaults to metadata-only with full payload retention billed at $0.01 per million tokens.
Which one, concretely
Choose New API if
- You are charging or metering your own users, and want quotas, top-ups, redemption codes and subscription plans in the gateway itself
- You want three request dialects on one instance: an eleven-endpoint OpenAI surface, native Anthropic Messages and native Gemini v1beta
- You want no vendor in the request path and no vendor fee under any circumstances
- You want embeddings, audio, rerank and realtime endpoints documented rather than absent
Choose LLM Gateway if
- You need SOC 2 Type II, an enterprise DPA and a status page to get the gateway approved
- You want a real Kubernetes path: an official OCI Helm chart for gateway, API, UI and worker, with Terraform modules on Enterprise
- You want a hosted option now and a free self-hosted escape hatch later, from the same codebase and one Docker image
- You want a hosted MCP server and a first-party Vercel AI SDK provider rather than building both
What catches people out
- New API's RELAY_TIMEOUT defaults to 0, meaning no timeout, and the docs warn that setting it too low produces requests the upstream charges for but New API never bills. Pick a value deliberately.
- New API carries 14 GitHub-reviewed advisories for the repository in 2026, including CVE-2026-71479, a CVSS 9.1 quota integer overflow that allowed self-crediting and was confirmed exploited in the wild on 2026-07-06. Track releases closely if you run it.
- LLM Gateway's own pages disagree on retention: the data-retention page says 30 days, the activity API reference says 3 days free and 90 on Pro, and the repository advertises 90 against 3. Confirm the number for your plan in writing.
- LLM Gateway's hosted service may route some requests through stealth providers whose identity is not publicly disclosed. If you need to name every subprocessor, self-host or ask for the list.
Side by side
Interpret these fields: How much does an LLM gateway lock you in? · LLM gateway compliance: SOC 2, HIPAA and evidence · How LLM gateway failover actually works
5 of 17 fields differ, marked with a dot. Every figure links to the vendor page it came from. Blank values read Not published rather than No — silence from a vendor is not a negative answer.
| Field | New API | LLM Gateway |
|---|---|---|
| Ease of leaving Derived score, higher is easier | 84/84 Some work to leave | 72/88 Some work to leave |
| What kind of product Category | Open source | Open source |
| Who runs it Deployment model | Self-host only | Managed or self-host |
| Licence Licence | AGPL-3.0 | AGPL-3.0 |
| Models available Models available | 100+ | ~200 |
| Model providers reachable Upstream providers | 30+ | ~40 |
| Markup on model prices Token markup | None | None |
| Fee to add funds Credit purchase fee | Not published | 5% |
| Monthly cost per person Seat fee | None | None |
| GitHub stars GitHub stars | 48,314 | 1,643 |
| Can use your own provider accounts BYOK supported | Yes | Yes |
| Separate keys per team or app Virtual keys | Yes | Not published |
| Spending limits Budget controls | Yes | Yes |
| Content guardrails Content guardrails | Yes | Yes |
| SOC 2 audited SOC 2 audited | Not published | Yes |
| How long they keep it Default content retention (days) | Not published | 30 days |
| What gets logged Logged content | Metadata only | Metadata only |
| Free tier Free tier | The whole product: "New API adopts the GNU AGPLv3 open-source license" and is free to deploy and use provided the licence is honoured; there is no feature-gated tier ([Project Introduction](https://www.newapi.ai/en/docs/guide/wiki/basic-concepts/project-introduction)). | $0 forever: no seats or minimums, BYOK free, 3 free models limited to 20 req/min, 30-day data retention; hosted credits carry a 5% platform fee. |
for New API and for LLM Gateway. Want more fields, or a third option in the mix? Open these two in the full comparison tool.
Common questions
Is LLM Gateway free if I self-host it?
Yes for the core. The whole platform ships as one Docker image under AGPL-3.0, described as free forever with no credit fee and no BYOK metering, and the same codebase powers the hosted service. The limits are licensing rather than price: code in the repository ee/ directory requires a separate commercial licence, and enterprise features need a signed licence in production, with a seven-day grace period once it expires.
Which one has the bigger catalogue?
LLM Gateway on the published figures, though neither number is a counted list. Its pricing page states 200+ models across 40+ providers, while its own open-source page says 280+ models and 35+ providers. New API's homepage claims 100+ models and 30+ providers as floors, and in practice the catalogue on any instance is whatever channels the operator configures, since there is no public models endpoint to count from.
Can New API be hosted for me?
No. It is self-host only, and the project frames that as the point: open source as the covenant, self-hosted as the ground. Documented methods are Docker Compose, a single container, 1Panel, BaoTa app-store installs, cluster deployment and local development, with a database and optionally Redis alongside. There is no vendor tier, no SLA and no status page, which is consistent with software-only distribution.