Contact Us

The enterprise-grade AI Gateway for security-conscious teams. Protect your data, govern spend, and account for usage.

Read Documentation→

Product

  • Features
  • Security
  • Pricing
  • Docs

Company

  • About Us
  • Blog
  • Playground
  • Contact Us

© 2026 Shim. All rights reserved.

Trust · Care · Precision
SecurityPrivacy PolicyTerms of Service
Contact Us

The enterprise-grade AI Gateway for security-conscious teams. Protect your data, govern spend, and account for usage.

Read Documentation→

Product

  • Features
  • Security
  • Pricing
  • Docs

Company

  • About Us
  • Blog
  • Playground
  • Contact Us

© 2026 Shim. All rights reserved.

Trust · Care · Precision
SecurityPrivacy PolicyTerms of Service
Contact Us
Back to Blog|Home
Comparison

Portkey Alternatives After the Palo Alto Acquisition

Palo Alto Networks is acquiring Portkey. Evaluate LiteLLM and SHIM as portkey alternatives based on your actual need: routing, observability, or data privacy.

July 13, 20269 min read

On April 30, 2026, Palo Alto Networks announced its intent to acquire Portkey, the AI gateway company processing trillions of tokens per month. Portkey will become the AI Gateway for Prisma AIRS, serving as what the press release calls "the central nervous system that can monitor, route, and secure every AI transaction across the enterprise."

That is a clear direction. It is also a direction that points away from the lean, developer-centric proxy that many teams adopted Portkey for in the first place.

If you are evaluating portkey alternatives, the acquisition sharpens the question. The broader Portkey becomes inside PANW's security stack, the less precisely it fits any single use case. What follows is a breakdown of what Portkey does today, what the acquisition changes, and which alternatives match three distinct buyer profiles.

How Portkey Works Today

Portkey sits between your application and your LLM providers. Instead of calling OpenAI or Anthropic directly, your app sends requests through Portkey, which handles routing, failover, observability, and caching without requiring you to rewrite core logic. It offers a unified API to 250+ models and bundles gateway routing, real-time observability, prompt management, and governance tools into a single product. The open-source gateway component has 5k+ GitHub stars, though the full platform is proprietary.

That scope is both the product's strength and the reason the acquisition creates friction. Portkey tries to be the AI proxy, the observability layer, the prompt manager, and the governance tool all at once. For teams that only need one or two of those capabilities, a purpose-built tool often fits better.

Is Portkey Free?

Portkey offers three tiers. The free Developer plan provides 10k recorded logs per month with 3-day retention. It is explicitly described as not suitable for production workloads.

The Production plan costs $49/month for 100k logged requests, with $9 per additional 100k. There is an important carve-out: the Production tier is not recommended for organizations requiring custom security controls or data residency guarantees. For those requirements, you need Enterprise, which is custom-priced.

That data residency exclusion matters. If you operate in a regulated environment and your compliance team asks where your LLM request logs are stored, the Production plan does not give you a clean answer.

What the Acquisition Changes

The deal has since closed, and Palo Alto Networks says it will continue to support existing and new Portkey customers. Portkey's CEO described the move as establishing "the AI Gateway as the foundational layer of the secure AI enterprise."

Read that framing carefully. The announcement uses the word "enterprise" seven times, ten if you count "enterprises." "Developer" appears twice, both times in reassurances that security "never comes at the expense of developer speed."

TrueFoundry's post-acquisition guide notes that acquisitions in this space often bring "pricing changes, roadmap shifts, and support transitions" for teams running production workloads. The pattern is familiar: a developer-friendly tool gets acquired for its distribution, the acquirer folds it into a platform sale, and the standalone product gradually becomes an on-ramp rather than a destination.

That does not mean Portkey will disappear tomorrow. It means the roadmap now serves Prisma AIRS first, and independent developer needs second. If your use case aligns with enterprise AI security, the acquisition might be a net positive. If it does not, you are building on a product whose priorities just shifted.

Alternative 1: LiteLLM (Self-Hosted Provider Unification)

For teams whose primary need is calling multiple LLM providers through a single interface without vendor lock-in, LiteLLM is the most direct replacement.

LiteLLM is an open-source Python SDK and proxy server that calls 100+ LLM APIs in OpenAI-compatible format, with cost tracking, guardrails, load balancing, and logging. You self-host it, so a change of ownership at the vendor cannot change what runs in your stack. Its maintainer, BerriAI, does sell a commercial license for enterprise features, but the core proxy lives on your infrastructure either way.

That self-hosting requirement is the trade-off. You own the infrastructure, the scaling, and the ops burden. For teams with the engineering capacity to run their own proxy, this is freedom. For teams that chose Portkey specifically to avoid that operational overhead, LiteLLM solves one problem by creating another.

Where LiteLLM fits: teams that want provider unification with zero lock-in, are comfortable self-hosting, and do not need a managed compliance layer. For a deeper breakdown of what works and what breaks, see the full LiteLLM alternatives comparison.

Alternative 2: SHIM (Privacy-First Middleware)

For teams where PII handling and regulatory compliance drive the architecture, SHIM differs structurally from Portkey in how it treats data protection.

SHIM applies supported PII placeholder processing before executing its native provider routes. Review the documented detector coverage and test it against your own data before treating it as a compliance control.

SHIM applies its tenant and PII controls before executing a supported native provider request. It does not include a semantic cache or select a different provider route, and its latency should be measured with representative traffic.

Two specifics worth noting:

  • Compliance coverage. Portkey covers GDPR, SOC 2, ISO, and HIPAA. SHIM also addresses KVKK, Turkey's data protection law, with built-in Turkish PII patterns. If you serve Turkish users, this is not optional.
  • Caching. SHIM does not provide semantic response caching. If your workload needs it, evaluate a cache layer with explicit retention and correctness controls.

Pricing is also different. SHIM starts at $29/month with predictable pricing. Portkey uses usage-based pricing per recorded log, which scales unpredictably under high-volume agentic workloads.

How to Choose: Three Buyer Profiles

The portkey alternatives landscape splits into three buyer profiles. Matching the right one saves you from over-buying a platform or under-building your stack.

NeedBest fitWhy
Pure observability and tracingLangfuse, HeliconePurpose-built for traces and evals. Open-source options available.
Provider unification, zero lock-inLiteLLMSelf-hosted, open-source, 100+ LLM APIs. You own everything.
Privacy-first, regulated dataSHIMMandatory PII pipeline, KVKK + GDPR, predictable pricing from $29/month.

The Palo Alto acquisition accelerates a trend that was already underway: the case for specialized tools over do-everything platforms. Portkey tried to be the routing layer, the observability layer, the prompt manager, and the governance tool in one product. That breadth made it useful for prototyping. It also made it replaceable by any combination of tools that does one of those jobs better.

Pick the profile that matches your constraint, not the platform that promises the most features. The gateway that governs what you actually need to govern will always outperform the one that governs everything loosely.

Back to all articlesGet Started Free

The enterprise-grade AI Gateway for security-conscious teams. Protect your data, govern spend, and account for usage.

Read Documentation→

Product

  • Features
  • Security
  • Pricing
  • Docs

Company

  • About Us
  • Blog
  • Playground
  • Contact Us

© 2026 Shim. All rights reserved.

Trust · Care · Precision
SecurityPrivacy PolicyTerms of Service