Skip to content
CortexDocs
Smart Router · Egress Gateway

Egress Gateway

Connect an AI client to your organization's managed gateway without installing Cortex Defender on the client device.

  • Connect by URLUse your organization's endpoint
  • No Defender requiredYour client connects directly
  • Managed providersProvider credentials stay on the gateway
A configured path from CLI to provider
RequestCLI clientConfigured connection
ConnectionCortex GatewayConfigured provider path
InferenceAI providerReturns the response
Captured telemetry syncs to the workspace separately from provider traffic.
An app or AI tool sends requests through Egress Gateway. This connection path does not by itself choose a model; Smart Router applies only when configured for eligible requests.

Egress Gateway is a shared connection path for AI requests. An app or AI tool connects to the gateway, which validates the caller's personal capture token and forwards the request through the organization's configured provider path. Cortex Defender does not need to run on the client device.

How Egress Gateway works

1
An organization-approved app or AI tool sends a request to the complete Egress Gateway URL supplied by the organization.
2
Egress Gateway validates the personal capture token and resolves the organization's enabled provider configuration for the request.
3
The configured provider receives the request and its response returns through Egress Gateway.
4
When capture is configured, Cortex can attribute the activity to the owner of the personal capture token.

A successful model response establishes gateway forwarding. An activity record under the expected user separately establishes capture attribution.

What you need

Before connecting a client, obtain:

  • The complete gateway URL from your organization, including its path convention
  • A personal capture token
  • A client configuration your organization has qualified for its gateway request path
  • An explicit model identifier enabled for your organization

Your organization manages the provider credentials on the gateway. Do not supply a provider API key from the client.

Smart Router is optional

Egress Gateway can forward a client-selected model without Smart Router. To have Smart Router choose and apply a route, the organization needs managed Router configuration and an eligible client and request path. A generic forwarded request does not establish that Smart Router applied a decision.

See Use Smart Router through Defender or Egress Gateway for the two connection paths and the evidence needed for an applied route.

Continue with Egress Gateway

Was this helpful?