LiteGate gives people one simple page to create and manage their own governed LiteLLM API key. Users do not need the LiteLLM administrator dashboard, and administrators do not need to hand out the master key.
- Sign in with SSO or a local account.
- Click once to create a personal key and copy it.
- See the models, budget, spend and rate limits that apply.
- Regenerate a credential without resetting accumulated spend.
- Leave without loading the full LiteLLM administration or raw usage-log UI.
SSO groups can map users to existing LiteLLM teams automatically, so the key inherits the intended team budget and model policy.
Optional administrator and operations tools
LiteGate also includes local-user management, team policy and member movement, administrator-only bulk key editing, an automation API, audit history, readiness checks, metrics, and verified backup/restore tooling. These controls are kept out of the normal user's key page.
| Capability | User | Administrator | Automation agent |
|---|---|---|---|
| Create, inspect, and regenerate a personal key | Yes | Yes | Via API |
| Manage local users and roles | No | Yes | Yes |
| List installation-wide keys | No | Yes | Yes |
| Bulk-edit key settings | No | Yes | Yes |
| Manage LiteLLM teams and move members | No | Yes | Yes |
Bulk key editing is administrator-only in both the UI and /api/v1. Trusted
agents authenticate with the installation-wide management_api_key; they do not
need a shared human password.
People / automation agents
|
v
LiteGate (React + FastAPI)
|-- OIDC provider
|-- SQLite local-user store
`-- LiteLLM management API
|
v
LiteLLM virtual keys
LiteGate is an access layer, not a LiteLLM replacement. LiteLLM remains responsible for virtual keys, models, budgets, usage, and request routing.
Requirements: Docker with Compose, a reachable LiteLLM instance, and its master key.
git clone https://github.com/brtydse100/litegate.git
cd litegate/deploy/docker-composeEdit config.yaml:
litellm_url: "http://host.docker.internal:4000"
litellm_master_key: "sk-your-litellm-master-key"
jwt_secret: "replace-with-a-long-random-secret"
# Bootstrap administrator; replace before first use.
local_auth_username: "admin"
local_auth_password: "replace-with-a-strong-password"
root_url: "http://localhost"Start LiteGate from the prebuilt GitHub package:
docker compose -f docker-compose.image.yml up -dThis pulls the multi-architecture ghcr.io/brtydse100/litegate:latest package.
To pin a release, set LITEGATE_VERSION, for example
LITEGATE_VERSION=2.6.1. You can also build locally from source:
docker compose up --buildOpen http://localhost. Local accounts persist in the
litegate-data Docker volume. Replace every sample secret before using LiteGate
outside a local test environment.
| Guide | Contents |
|---|---|
| Documentation index | Entry point for all guides |
| Features and access model | User, admin, bulk-edit, and operational behavior |
| Authentication | OIDC, local users, roles, and automation agents |
| Configuration | Settings, environment variables, and key defaults |
| Deployment | Docker Compose, offline use, Kubernetes, and Helm |
| API v1 | Authentication, key endpoints, bulk updates, and local users |
| Development | Local setup, tests, architecture, and project layout |
Once deployed, interactive API documentation is available at /api/docs, with
ReDoc at /api/redoc and the OpenAPI document at /api/openapi.json.
LiteGate verifies OIDC token signatures and claims, uses browser-bound signed OIDC state, keeps portal sessions in HttpOnly cookies, and stores local passwords as salted PBKDF2-SHA256 hashes. Account status and local roles are rechecked on authenticated requests. Key-changing operations and administrative mutations are rate limited with disabled controls during cooldowns, credential regeneration carries prior key spend, bulk updates use bounded concurrency, and the included Nginx configuration adds common browser security headers.
For production, use HTTPS, restrict access to configuration and secrets, rotate the management API key if exposed, and back up the local-user database or volume. See Authentication and security for the complete behavior and trust boundaries.
cd backend && ruff format --check --diff . && python -m pytest
cd ../frontend && npm run lint && npm run format:check && npm run typecheck && npm test && npm run buildSee the development guide for environment setup and local development commands.
