Preview. LiteLLM is off until a platform administrator turns it on for your organization, so it doesn’t appear under Add a provider until then. To try it on OpenWork Cloud, contact the OpenWork team. On a self-hosted deployment, a platform admin turns on AI Gateway: LiteLLM for the organization in Den
/admin, or an operator turns it on for the whole install with the Helm value config.features.litellm.Pick how keys work
Which mode fits
Whatever the mode, people’s apps hold one AI Gateway key, never a LiteLLM key. See How a prompt reaches a model for the full request path.How LiteLLM maps to OpenWork
Embedding, image and audio models are skipped. Model names, context limits, prices and capabilities come from LiteLLM’s
/model_group/info. OpenWork leaves out facts LiteLLM does not know, such as models missing from its price list.
Set it up
1
Add the provider
In OpenWork Cloud, go to AI Gateway → AI Providers → Add a provider → LiteLLM. Enter your proxy URL, for example
https://litellm.example.com, with or without /v1.2
Choose the key mode and paste the key
Paste the organization key, or an admin key if each person uses their own key. OpenWork checks the key with your proxy before saving. Keys are write-only and never shown again.
3
Choose who gets access
With one organization key, these people and teams can use the models. With per-person keys, they are the people allowed to connect their own key.
4
People connect their key (per-person keys only)
In the OpenWork app, people choose the LiteLLM provider and select Connect. A browser page asks for their LiteLLM key. OpenWork checks it and grants the group that matches the key’s models.
How each mode works
One organization key
Everyone shares the organization key’s models and LiteLLM budget. OpenWork prices each request from LiteLLM’s model prices, so per-person reports and OpenWork spend limits work as they do for other providers. In LiteLLM, all usage shows under the one key.Each person’s own key
The admin key is used only to read LiteLLM. For a key without a team, LiteLLM lists every model on the proxy but only serves the ones its owner may use, so OpenWork checks the owner’s own model list and grants just those. Each request uses the person’s own key, so LiteLLM’s user, team and key budgets apply and LiteLLM’s logs show the real person. OpenWork logs tokens but not cost. If LiteLLM later rejects a key, the next sync revokes it and the person sees Connect again.OpenWork creates keys
People do nothing. Spend lands in LiteLLM on the right person and team, and OpenWork logs tokens but not cost.Keys OpenWork creates
LiteLLM stores only a hash of each key, so OpenWork cannot read anyone’s existing key. Instead it finds each allowed person’s LiteLLM user by their OpenWork email and creates new keys for them. Choose what each person gets:- One per LiteLLM team: a key for each LiteLLM team they belong to, so each team’s models and budget apply, and spend lands on that team. Someone in no team gets one key that follows their own LiteLLM user settings. In OpenWork, their models are grouped by team.
- Copy their existing key: a copy of their oldest active key, with the same team, models, model aliases, tags and expiry. Key-level budgets and rate limits are not copied, because a copy would double the allowance. Team and user budgets still apply. For someone with no key to copy, choose Use their teams or Show an error.
Keep models in sync
Select Sync models on the provider page after you change models, teams or keys in LiteLLM. A sync:- refreshes the model list and prices
- with per-person keys, rechecks every connected key, moves people to the group that matches their key, and revokes keys LiteLLM now rejects
- with keys OpenWork creates, creates keys for newly allowed people, follows team changes, replaces copies whose original key changed, and deletes keys of people who lost access
- removes the models of people you no longer allow to connect
Troubleshooting
Requirements and limits
- Your proxy must be reachable from OpenWork over HTTPS on a public host. For a private or self-hosted proxy, the operator must allow its origin with
GATEWAY_EGRESS_ALLOWED_ORIGINSon both Den and the gateway. - To change the proxy URL or key mode, add a new LiteLLM provider.
- Signing in through your identity provider (LiteLLM’s JWT auth) is not supported. Use LiteLLM virtual keys.
- API:
POST /v1/inference-providers/litellm(modeorg,memberorissued),POST /v1/inference-providers/{id}/litellm/sync,PATCH /v1/inference-providers/{id}/litellmto replace the key or change how keys are created, andPUT /v1/inference-providers/{id}/litellm/member-keyfor a person’s own key.