By API7.ai Team
Last updated: August 2026
Kong AI Gateway and Portkey put governed APIs in front of LLM providers, but the vendor context changed in 2026. Palo Alto Networks completed its acquisition of Portkey, and the commercial Portkey offering is now the generally available Prisma AIRS AI Gateway. This guide compares Kong with both the Portkey OSS gateway and that commercial path.
Kong adds AI plugins to a general-purpose gateway with self-hosted, hybrid, and Konnect options. Portkey still provides an MIT-licensed gateway, while its commercial offering is now the GA Prisma AIRS AI Gateway. Compare Kong edition boundaries with both the Portkey OSS scope and the current Prisma AIRS contract; do not treat those two Portkey paths as one product.
Kong layers AI plugins onto a general-purpose API gateway. Portkey provides an MIT gateway, while the commercial Portkey offering is now the GA Prisma AIRS AI Gateway.
| Dimension | Kong | Portkey |
|---|---|---|
| Best for | AI plugins on a general-purpose API gateway | OSS AI gateway or Prisma AIRS evaluation |
| Core & runtime | Lua on OpenResty; AI plugins on Kong Gateway | MIT TypeScript gateway; commercial path now tied to Prisma AIRS |
| Open-source license | Apache-2.0 core; advanced AI Enterprise | MIT gateway; commercial capabilities separate |
| Provider coverage | Multiple documented providers | Multiple documented providers |
| Semantic routing | ✓ Enterprise (AI Proxy Advanced) | OSS: conditional; Prisma AIRS: semantic routing |
| Ensemble / fusion | — Not documented | — Not documented |
| Caching | Semantic cache (edition-dependent) | Simple + semantic; verify current tier |
| MCP gateway | AI MCP Proxy (Enterprise) | ✓ Documented |
| Self-host / VPC | Docker/K8s, hybrid, Konnect SaaS | OSS self-host; managed/private options require current offer review |
| SSO / SCIM | Enterprise/Konnect | Commercial offering; verify current tier |
Kong AI Gateway is a set of AI plugins on Kong Gateway, a mature general-purpose API gateway (Apache-2.0 core, Lua/OpenResty), running self-hosted, hybrid, or via the managed Konnect SaaS.
Kong AI Gateway is a set of AI plugins layered on Kong Gateway, a mature general-purpose API gateway (Apache-2.0 core, Lua on OpenResty). It routes to 15+ LLM providers and can run self-hosted, hybrid, or through the managed Konnect SaaS control plane.
Language
Lua (OpenResty)
License
Apache-2.0 core + Enterprise AI plugins
Form factor
API gateway + AI plugins; Konnect SaaS
Best for
AI plugins on a general-purpose gateway
Portkey provides an MIT-licensed TypeScript AI gateway. After Palo Alto Networks completed the acquisition in May 2026, the commercial Portkey offering became the generally available Prisma AIRS AI Gateway.
Portkey provides an MIT-licensed TypeScript AI gateway. Palo Alto Networks completed its acquisition of Portkey in May 2026, and the commercial Portkey offering is now the generally available Prisma AIRS AI Gateway. Buyers should map OSS and commercial responsibilities separately.
Language
TypeScript (Node.js)
License
MIT gateway; commercial offer separate
Form factor
OSS gateway + GA Prisma AIRS offering
Best for
Teams evaluating OSS and commercial paths
See Palo Alto Networks' acquisition announcement and the current Prisma AIRS overview and its general-availability announcement before making a commercial comparison.
Both expose open-source gateway code and separate commercial capabilities, but Portkey's acquisition means the OSS gateway and Prisma AIRS commercial portfolio must be evaluated as distinct scopes.
| Feature | Kong | Portkey |
|---|---|---|
| Core & runtime | AI plugins on Kong Gateway (Apache-2.0 core, Lua/OpenResty) | MIT TypeScript gateway; hosted and commercial capabilities now need Prisma AIRS/Portkey offer mapping |
| Provider coverage | 15+ providers (OpenAI, Azure OpenAI, Bedrock, Anthropic, Gemini, Vertex, Cohere, Mistral, and more) | Provider and model catalog documented by Portkey; verify live catalog and Prisma AIRS coverage |
| Routing | AI Proxy (single provider/model) in OSS; multi-model load balancing, semantic routing & failover via AI Proxy Advanced (Enterprise) | Portkey OSS documents load balancing, fallback, retry, and conditional routing; Prisma AIRS documents semantic routing |
| Semantic routing | ✓ Enterprise (AI Proxy Advanced) | Not established in OSS docs; documented for Prisma AIRS GA |
| Ensemble / fusion | — Not documented | — Not documented |
| Caching | AI Semantic Cache (Enterprise) | Simple and semantic caching are documented; verify current product, edition, and data-isolation controls |
| Guardrails | AI Prompt Guard (regex) in OSS; AI Semantic Prompt Guard, AI PII Sanitizer, and provider guardrails (Azure Content Safety, AWS Guardrails, GCP Model Armor, Lakera) are Enterprise | Portkey and Prisma AIRS document guardrail capabilities; validate execution point, data path, and purchased tier |
| Rate limiting | Request-based in OSS; token- and cost-based via AI Rate Limiting Advanced (Enterprise) | Gateway rate and budget controls are documented; verify counter scope, failure behavior, and current tier |
| Observability | Kong analytics and logging plugins; deeper analytics via Konnect | Logging, tracing, and analytics are documented; retention and commercial ownership require current offer review |
| MCP gateway | AI MCP Proxy (Enterprise) | ✓ Documented (auth + access control for remote MCP) |
| LLM-as-judge | AI LLM-as-Judge (Enterprise) | — Not documented |
| Self-host / VPC | Self-host Docker/K8s (KIC), hybrid (data plane in your network), or Konnect SaaS | OSS gateway self-hosts; verify private, managed, and Prisma AIRS deployment options |
| Enterprise identity | SSO (OIDC/SAML) + RBAC via Enterprise/Konnect; SCIM for Konnect not documented | Commercial identity features are edition-dependent; confirm current Portkey/Prisma AIRS contract |
Open-source licenses do not define hosted, support, security, or enterprise pricing. Compare current quotes and published usage dimensions for the exact deployment.
Kong Gateway's core is free (Apache-2.0) and several AI plugins are free, while advanced AI and identity capabilities are edition-dependent. Konnect and Enterprise costs depend on the current plan and usage. The Portkey gateway is MIT-licensed, but hosted or private deployment, identity, retention, support, and Prisma AIRS capabilities are commercial questions. Review the current Portkey pricing page for its current plans. Palo Alto Networks documents Prisma AIRS AI Gateway metering by LLM, MCP, and A2A token consumption through Software NGFW credits for its SaaS and Hybrid offerings; review the current licensing guidance and request an estimate for the intended deployment. Build a total-cost model that also includes provider tokens, gateway traffic, data transfer, storage, observability, support, infrastructure, and migration.
Choose Kong when its general-purpose gateway and edition model fit. Evaluate Portkey OSS for self-hosting, and evaluate Prisma AIRS separately when commercial AI security and support are required.
The decision is now three-way: Kong's gateway and editions, the MIT Portkey gateway, and the generally available Prisma AIRS AI Gateway.
If you already operate Kong, test the required AI plugins and edition boundaries on your traffic. If you want the Portkey OSS gateway, validate the repository, release, provider adapters, and operational ownership you will support. If you need a commercial Portkey path, treat Prisma AIRS as a separate procurement and data flow review. Also compare other candidates with the same source-backed checklist; see all AI gateway comparisons.
Portkey vs LiteLLM · AISIX vs LiteLLM · All AI gateway comparisons
Ready to get started?
For more information about full API lifecycle management, please contact us to Meet with our API Experts.

