Cloudflare AI Gateway vs. Aperture by Tailscale
AI models and agents continue to change rapidly, but some dynamics are becoming clear:
- Fierce competition and shifting regulations mean that today’s best, most powerful AI model might not be tomorrow’s best, most powerful AI model.
- Different models are useful for different tasks—not every request requires you to use (or to pay for) the latest-and-greatest.
- Costs are going up. You can’t count on lighter users (and venture capital money) subsidizing subscription costs for more active users. And businesses need to be able to track and control those costs.
- Businesses also need to be able to prove that they’re getting something for their money—not just using AI for the sake of using AI.
One solution to all of these problems is an AI gateway like Aperture by Tailscale. An AI gateway is a centralized routing layer that sits between users and third-party AI providers like OpenAI and Anthropic. It can store API keys, measure usage, estimate costs, set cost and usage quotas to control costs, and allow users to easily swap between providers and models based on what they need at the time. They also let administrators and security, risk, and compliance teams see who is using what, how they’re using it, and how much they’re using it.
And because Aperture works with whatever identity provider you’re already using, it’s easy to add that extra layer of visibility without getting in the way of your users. You grant them access to the tools they need, and they can continue to use those tools as they already do, all without needing to keep track of API keys or other shared credentials.
Aperture and Cloudflare AI Gateway offer many similar features, but each system comes with its own pros and cons. We’ll compare the features of both products so you can decide which best suits your needs.
Comparison matrix
| Aperture by Tailscale | Cloudflare AI Gateway | |
|---|---|---|
| Supported LLM providers | OpenAI, Anthropic, Google, Amazon Bedrock, self-hosted providers, and more | OpenAI, Anthropic, Google, Amazon Bedrock, and more |
| Supported identity providers for single sign-on | Google, AzureAD, GitHub, Okta, OneLogin, and more | Google, AzureAD, GitHub, Okta, LinkedIn, and more. |
| Centralized API key management | Yes | Yes |
| Unified chat interface | Yes | No |
| Cost control/usage metering/rate limiting features | Set cost limits for users and/or groups of users. Different limits can be set for different models. | Set spend-based and/or time-based limits for each individual model. Can limit usage on a per-user or group basis, but only with custom tags. |
| MCP support | MCP server proxying allows multiple MCP servers to be aggregated into a single endpoint | Cloudflare AI Gateway MCP Server allows MCP clients to access information about gateways and logs |
| Logging | Yes, with zero-retention mode | Yes, with optional zero-retention mode |
| Guardrails | Yes (learn more) | Yes |
| FedRAMP authorized | Usable within properly scoped boundaries (learn more) | Yes |
| Caching | No | Yes, but can only cache and re-use responses when users give the exact same prompt to the exact same model |
Similarities between Aperture and Cloudflare AI Gateway
Both Aperture and Cloudflare AI Gateway allow you to store various AI API keys centrally so you don’t have to manage handing out an individual key to everyone who needs one (or revoking keys when they’re no longer needed). Your users can still use the same apps they’re already familiar with to access these models; the role of an AI gateway is to serve as a mostly-invisible layer for facilitating connections.
Both Aperture and Cloudflare also help you avoid getting locked into a single AI vendor’s ecosystem, allowing you to pick and choose which models are available and how much money your users can spend on them.
And both services offer robust logging, along with zero-retention modes if you want to ensure that you aren’t storing your users’ queries or the models’ responses. And both offer guardrails to keep sensitive information from being transmitted to third-party AI providers in the first place.
Aperture’s advantages
The main advantage of Aperture is its identity-based controls. Aperture uses the same identity layer as Tailscale, so controlling access permissions and other settings can be done based on individual user IDs, groups of users that you’ve set up, or a device’s tags. To make setup easier, Aperture can actually re-use any groups you’ve already configured in Tailscale or SCIM groups from your identity provider. You’re in full control of which users and groups can access which models, and what their usage and spending limits are.
And because each request and response is attributed to an individual user or client device, Aperture also makes it easy to reconstruct and analyze LLM interactions with its robust telemetry logging. Of course, if you’re concerned about your users’ privacy, Aperture can also be set not to retain any logs at all.
Cloudflare’s limitations
Cloudflare does support identity-based spend limits, rate limits, and logging, but only if you configure it to pass that information along using custom metadata tags. But this data is supplied by the app making the request and isn’t necessarily verified through your identity provider; Cloudflare’s product also doesn’t allow you to create access control rules for specific models.
Differences between Aperture and Cloudflare AI Gateway
Cloudflare AI Gateway does offer a couple of features that may be beneficial for some use cases.
One is FedRAMP compliance, for users or businesses handling US federal government data. Many FedRAMP-certified cloud service providers (CSPs) could use Tailscale today within properly scoped boundaries (Find out more here.), but Tailscale itself is not yet FedRAMP authorized.
Another Cloudflare feature of note is content caching. Cloudflare AI Gateway can save both prompts and responses so that when your users make specific requests, they can get the model-provided answer without having to actually use (or pay for) the LLM again. Caching sounds useful as a cost-controlling feature, but as implemented, it’s quite limited. Responses can only be cached for the exact same requests made to the exact same versions of the exact same models. “When is Mother’s Day” wouldn’t cache a response for “what day is Mother’s Day,” and it would also cache separate responses if you asked “When is Mother’s Day” of different versions of GPT and/or Claude.
Cloudflare says it’s working on a more flexible version of the caching feature, but it’s not available as of this writing.
The bottom line
Cloudflare AI Gateway and Aperture by Tailscale are both trying to solve the same basic problems. If you’re already bought into Cloudflare’s ecosystem, Cloudflare does make it easy to enable and try out its other services, including AI Gateway.
But if you want an AI gateway with identity-based authentication and permissions baked in by default, try Aperture by Tailscale.