New

Announcing AISIX: The AI-Native AI Gateway for LLMs and AI AgentsLearn More

Learn More

Kong AI Gateway vs Portkey: Which AI Gateway in 2026?

By API7.ai Team

Last updated: August 2026

Kong AI Gateway and Portkey put governed APIs in front of LLM providers, but the vendor context changed in 2026. Palo Alto Networks completed its acquisition of Portkey, and the commercial Portkey offering is now the generally available Prisma AIRS AI Gateway. This guide compares Kong with both the Portkey OSS gateway and that commercial path.

TL;DR

Kong adds AI plugins to a general-purpose gateway with self-hosted, hybrid, and Konnect options. Portkey still provides an MIT-licensed gateway, while its commercial offering is now the GA Prisma AIRS AI Gateway. Compare Kong edition boundaries with both the Portkey OSS scope and the current Prisma AIRS contract; do not treat those two Portkey paths as one product.

  • Teams standardizing on a general-purpose API gateway: Kong AI Gateway
  • Teams evaluating OSS AI gateway and broader AI security paths: Portkey / Prisma AIRS
  • At a glance
  • What is Kong AI Gateway?
  • What is Portkey?
  • Feature comparison
  • Pricing
  • When to use each
  • Bottom line
  • FAQ

Kong AI Gateway vs Portkey at a glance

Kong layers AI plugins onto a general-purpose API gateway. Portkey provides an MIT gateway, while the commercial Portkey offering is now the GA Prisma AIRS AI Gateway.

DimensionKongPortkey
Best forAI plugins on a general-purpose API gatewayOSS AI gateway or Prisma AIRS evaluation
Core & runtimeLua on OpenResty; AI plugins on Kong GatewayMIT TypeScript gateway; commercial path now tied to Prisma AIRS
Open-source licenseApache-2.0 core; advanced AI EnterpriseMIT gateway; commercial capabilities separate
Provider coverageMultiple documented providersMultiple documented providers
Semantic routing✓ Enterprise (AI Proxy Advanced)OSS: conditional; Prisma AIRS: semantic routing
Ensemble / fusion— Not documented— Not documented
CachingSemantic cache (edition-dependent)Simple + semantic; verify current tier
MCP gatewayAI MCP Proxy (Enterprise)✓ Documented
Self-host / VPCDocker/K8s, hybrid, Konnect SaaSOSS self-host; managed/private options require current offer review
SSO / SCIMEnterprise/KonnectCommercial offering; verify current tier

What is Kong AI Gateway?

Kong AI Gateway is a set of AI plugins on Kong Gateway, a mature general-purpose API gateway (Apache-2.0 core, Lua/OpenResty), running self-hosted, hybrid, or via the managed Konnect SaaS.

Kong AI Gateway is a set of AI plugins layered on Kong Gateway, a mature general-purpose API gateway (Apache-2.0 core, Lua on OpenResty). It routes to 15+ LLM providers and can run self-hosted, hybrid, or through the managed Konnect SaaS control plane.

Language

Lua (OpenResty)

License

Apache-2.0 core + Enterprise AI plugins

Form factor

API gateway + AI plugins; Konnect SaaS

Best for

AI plugins on a general-purpose gateway

Pros

  • AI plugins on a mature, general-purpose API-gateway platform
  • Self-host, hybrid, or managed Konnect SaaS control plane
  • Semantic routing, semantic cache, and MCP proxy (Enterprise)
  • 15+ LLM providers behind one API

Cons

  • Free AI surface is thin: OSS AI Proxy handles a single provider/model
  • Multi-model LB, semantic routing/cache, token/cost limits are Enterprise
  • Semantic/PII guardrails, MCP, LLM-as-judge, SSO/RBAC are Enterprise

What is Portkey?

Portkey provides an MIT-licensed TypeScript AI gateway. After Palo Alto Networks completed the acquisition in May 2026, the commercial Portkey offering became the generally available Prisma AIRS AI Gateway.

Portkey provides an MIT-licensed TypeScript AI gateway. Palo Alto Networks completed its acquisition of Portkey in May 2026, and the commercial Portkey offering is now the generally available Prisma AIRS AI Gateway. Buyers should map OSS and commercial responsibilities separately.

Language

TypeScript (Node.js)

License

MIT gateway; commercial offer separate

Form factor

OSS gateway + GA Prisma AIRS offering

Best for

Teams evaluating OSS and commercial paths

Pros

  • MIT-licensed gateway with documented self-hosting
  • Provider routing, fallback, caching, and observability features
  • Documented MCP and guardrail integrations
  • Commercial security portfolio through Prisma AIRS

Cons

  • OSS docs confirm conditional routing, not semantic-intent routing
  • OSS, hosted Portkey, and Prisma AIRS boundaries require mapping
  • Pricing, identity, retention, and private deployment are contract-dependent

See Palo Alto Networks' acquisition announcement and the current Prisma AIRS overview and its general-availability announcement before making a commercial comparison.

Kong AI Gateway vs Portkey: feature comparison

Both expose open-source gateway code and separate commercial capabilities, but Portkey's acquisition means the OSS gateway and Prisma AIRS commercial portfolio must be evaluated as distinct scopes.

FeatureKongPortkey
Core & runtimeAI plugins on Kong Gateway (Apache-2.0 core, Lua/OpenResty)MIT TypeScript gateway; hosted and commercial capabilities now need Prisma AIRS/Portkey offer mapping
Provider coverage15+ providers (OpenAI, Azure OpenAI, Bedrock, Anthropic, Gemini, Vertex, Cohere, Mistral, and more)Provider and model catalog documented by Portkey; verify live catalog and Prisma AIRS coverage
RoutingAI Proxy (single provider/model) in OSS; multi-model load balancing, semantic routing & failover via AI Proxy Advanced (Enterprise)Portkey OSS documents load balancing, fallback, retry, and conditional routing; Prisma AIRS documents semantic routing
Semantic routing✓ Enterprise (AI Proxy Advanced)Not established in OSS docs; documented for Prisma AIRS GA
Ensemble / fusion— Not documented— Not documented
CachingAI Semantic Cache (Enterprise)Simple and semantic caching are documented; verify current product, edition, and data-isolation controls
GuardrailsAI Prompt Guard (regex) in OSS; AI Semantic Prompt Guard, AI PII Sanitizer, and provider guardrails (Azure Content Safety, AWS Guardrails, GCP Model Armor, Lakera) are EnterprisePortkey and Prisma AIRS document guardrail capabilities; validate execution point, data path, and purchased tier
Rate limitingRequest-based in OSS; token- and cost-based via AI Rate Limiting Advanced (Enterprise)Gateway rate and budget controls are documented; verify counter scope, failure behavior, and current tier
ObservabilityKong analytics and logging plugins; deeper analytics via KonnectLogging, tracing, and analytics are documented; retention and commercial ownership require current offer review
MCP gatewayAI MCP Proxy (Enterprise)✓ Documented (auth + access control for remote MCP)
LLM-as-judgeAI LLM-as-Judge (Enterprise)— Not documented
Self-host / VPCSelf-host Docker/K8s (KIC), hybrid (data plane in your network), or Konnect SaaSOSS gateway self-hosts; verify private, managed, and Prisma AIRS deployment options
Enterprise identitySSO (OIDC/SAML) + RBAC via Enterprise/Konnect; SCIM for Konnect not documentedCommercial identity features are edition-dependent; confirm current Portkey/Prisma AIRS contract

Pricing comparison

Open-source licenses do not define hosted, support, security, or enterprise pricing. Compare current quotes and published usage dimensions for the exact deployment.

Kong Gateway's core is free (Apache-2.0) and several AI plugins are free, while advanced AI and identity capabilities are edition-dependent. Konnect and Enterprise costs depend on the current plan and usage. The Portkey gateway is MIT-licensed, but hosted or private deployment, identity, retention, support, and Prisma AIRS capabilities are commercial questions. Review the current Portkey pricing page for its current plans. Palo Alto Networks documents Prisma AIRS AI Gateway metering by LLM, MCP, and A2A token consumption through Software NGFW credits for its SaaS and Hybrid offerings; review the current licensing guidance and request an estimate for the intended deployment. Build a total-cost model that also includes provider tokens, gateway traffic, data transfer, storage, observability, support, infrastructure, and migration.

When to use Kong AI Gateway vs Portkey

Choose Kong when its general-purpose gateway and edition model fit. Evaluate Portkey OSS for self-hosting, and evaluate Prisma AIRS separately when commercial AI security and support are required.

Choose Kong AI Gateway if you…

  • Already run (or want) a general-purpose API gateway like Kong
  • Want AI plugins alongside your existing API traffic
  • Are prepared to buy Enterprise for advanced AI and identity

Choose Portkey / Prisma AIRS if you…

  • Want to self-host the MIT Portkey gateway and validate its current scope
  • Want to evaluate Prisma AIRS for a broader commercial AI security program
  • Can map data flow, identity, retention, support, and migration across the current offerings

Bottom line

The decision is now three-way: Kong's gateway and editions, the MIT Portkey gateway, and the generally available Prisma AIRS AI Gateway.

If you already operate Kong, test the required AI plugins and edition boundaries on your traffic. If you want the Portkey OSS gateway, validate the repository, release, provider adapters, and operational ownership you will support. If you need a commercial Portkey path, treat Prisma AIRS as a separate procurement and data flow review. Also compare other candidates with the same source-backed checklist; see all AI gateway comparisons.

Frequently asked questions

Related comparisons

Portkey vs LiteLLM · AISIX vs LiteLLM · All AI gateway comparisons

Ready to get started?

For more information about full API lifecycle management, please contact us to Meet with our API Experts.

Contact Us