The model-gateway command group activates AgentKit Model Gateway and manages model providers and consumers that access models through a unified gateway. The top-level alias is mgw.
Model Gateway creates or uses cloud gateway resources and stores model provider API keys. Confirm the account, region, gateway mode, and key source before running these commands. Do not save real API keys in repositories, scripts, or shell history.
model-gateway activate
Activate Model Gateway. If a Model Gateway already exists in the current region, the command returns the existing resource. If the resource is in a failed state, the command reports an error. After creating a gateway, the CLI waits until it becomes available.
model-gateway provider create
Create a model provider. A provider contains the upstream base URL, protocol, one or more API keys, and the model names exposed through the gateway.
model-gateway provider list
List model providers under the current Model Gateway.
model-gateway provider show
Show details for a model provider.
model-gateway provider update
Update a model provider. Pass at least one of --base-url, --api-key, --model, or --protocol. --api-key replaces the provider API key list; --model replaces the model list.
model-gateway provider delete
Delete a model provider.
Deleting a provider affects consumers that depend on that provider or its model authorizations. Confirm the name and authorization scope first; use --yes to skip confirmation only in automation.
model-gateway consumer create
Create a consumer. A consumer receives an API key for accessing Model Gateway, and can have model authorization scope and token rate limits.
--allow-model can be only a provider name, which allows all models under that provider, or <provider>/<model>, which allows only the named model.
model-gateway consumer list
List consumers under the current Model Gateway.
model-gateway consumer show
Show consumer details, including API keys, authorization scope, and rate limits.
model-gateway consumer update
Update a consumer’s model authorization scope or token rate limits. Pass at least one of --allow-model, --tpm, or --tpd. --allow-model replaces the existing authorization scope.
model-gateway consumer delete
Delete a consumer.
Deleting a consumer invalidates its API keys. Confirm that the application has already switched away from this consumer or stopped using it.
model-gateway show-example
Generate a calling example from a provider and consumer. The command reads the provider access URL, protocol, accessible model, and consumer API key, then prints the selected example type.
The agentkit example prints model environment variables that can be applied to the current project, such as MODEL_AGENT_NAME, MODEL_AGENT_API_BASE, and MODEL_AGENT_API_KEY.