The gateway sits behind Cloudflare Access. Before any request reaches an AI model provider, the user must authenticate against the organization's existing identity provider (IdP) . When the request arrives through an Access-protected custom domain, Cloudflare validates the user and device posture and writes the verified Access user ID into request metadata as cf.user_id .
This replaces blind, shared API keys that made it impossible to attribute requests to specific people or systems . IT teams now know exactly who prompted which model, at what time, and from which device.
Once identities are attached, the gateway unlocks granular cost management:
Identity alone isn't enough — enterprises also need guardrails:
Cloudflare is extending identity-aware controls to autonomous agents:
The service is available now in open beta. As Dane Knecht, Cloudflare's CTO, summarized: "Teams get the freedom to work with any AI model they choose. IT gets the real-time visibility, guardrails, and budget controls they actually need" .