Skip to main content
Two minutes from zero to a governed call. In Python, use the first-party egisai client — one import, zero wiring. From any other language, call the API directly (or point any OpenAI-compatible client at the Gateway).

Prerequisites

An EgisAI account on a plan with the Gateway enabled.
An Egis API key (Dashboard → API Keys → Create key). Keys begin with egis_live_.
A provider API key — OpenAI in the snippets below; Anthropic (claude-… models) and Google (gemini-… models) work the same way, since the Gateway routes by model name.

1. Connect

Your provider key stays exactly where it always was — in the Authorization header — and is forwarded to the provider untouched. Your Egis key rides in X-Egis-Api-Key (egisai.Client sets both for you).
The dashboard’s Gateway page (under Developers) has copyable snippets for more languages — Go, Java, C#/.NET, PHP, Ruby — all plain HTTP calls with no third-party dependency.
Both keys are secrets. Use environment variables or a secrets manager — never hardcode them as in these snippets.

Connect without custom headers (BYOK vault)

Some platforms — Cursor, n8n, low-code builders — only let you set a base URL and an API key. They can’t add the X-Egis-Api-Key header. For those, store your provider keys once and connect with only your Egis key:
1

Store your provider keys

On the dashboard’s Model Center page, open Provider keys and add the key for each provider you use (OpenAI, Anthropic, …) — one per provider. They’re encrypted at rest; we keep only the last four characters for display. (Owners and admins only.)
2

Point the platform at the Gateway

Set the base URL to https://app.egisai.co/v1/agent and the API key to your Egis key (egis_live_…). That’s it — no headers.
The Gateway routes by model name, so one stored key per provider covers every model from that provider. If no key is stored for the request’s provider, the call returns an OpenAI-shaped error with code: "egis_no_provider_key" telling you which provider to configure.

2. See the call on the dashboard

Open the Requests page. Your call appears within seconds, marked with a gateway channel icon. The Gateway page (under Developers) also shows a live “last call received” status — useful for confirming connectivity during setup.

3. Watch a policy fire

Create a policy on the Policies page — for example, a PII scan set to sanitize on the Request phase — then send a prompt containing a fake SSN:
The SSN is masked before the payload leaves the Gateway; the provider sees only the masked text, and the audit row records the sanitization (count and mask shape — never the original value). A block verdict on the request phase returns an OpenAI-shaped error with code: "egis_policy_blocked" and HTTP 400 — the provider is never called, and no tokens are spent.

Naming your agent

By default the Gateway derives agent identity from the system prompt, so distinct system prompts appear as distinct agents automatically. To name an agent explicitly with egisai.Client:
From other languages (or a bring-your-own client), the same thing is one more header:
And when egisai.init() is active, the usual context API sets the header per call — it wins over the client-level default:
The rest of the set_context fields travel the same way, so the run’s Context section fills in exactly like it does for SDK-audited traffic:

What’s next

Streaming

How stream: true interacts with response-phase policies.

Limits & behavior

Error shapes, failure modes, and current limitations.