Getting started
Get your personal credential, connect an existing SDK or AI tool, and verify your first Gateway request.
Gateway connects your SDK or AI tool to organization-managed model providers. Your administrator supplies the endpoint and enables the models you can request. A local Cortex Defender installation and a Cortex Atlas subscription are not required for shared Gateway forwarding.
Headless first
Gateway is headless first. Engineers and agents can work through authenticated APIs, CLI and MCP interfaces; the dashboard provides a visual way to inspect and configure the same workspace. Sign-in and organization permissions gate access. Use the CLI or MCP connection enabled for your organization; your administrator supplies its setup details.
For a direct API or SDK connection, follow the credential and request steps below. A local Defender installation is not required for shared Gateway forwarding.
Product screens
The provider setup guide shows the provider selector, configuration form and configured connections beside their instructions. The example screen below shows configured provider connections with stored credentials hidden.
Before you begin
You need a Cortex account, the organization-issued Gateway URL for your client, and an enabled model. Ask your administrator for the URL and the exact model ID. Provider credentials stay on Gateway; they are separate from your personal credential.
Administrators configuring upstream access can start with Connect a provider.
Credentials
- Sign in to Cortex and open your profile.
- Select Settings.
- Under Devices & tokens, select Generate token in Personal tokens.
- Store the new personal
cct_capture token in your approved secret manager.
The personal token identifies your activity. Keep it out of source control, shared configuration, screenshots and client logs. Generate a replacement and revoke the exposed token if necessary.
CORTEX_API_KEY holds this personal token. In the examples, replace <CORTEX_API_KEY> with that value. Administrator-created cgw_ virtual keys record ownership and policy metadata; they are not the supported serving credential.
Send your first request
- Set
CORTEX_BASE_URLto the organization-issued URL for your selected client. For curl this is a complete request URL; OpenAI and Codex use an SDK base ending in/gateway/v1; Anthropic uses an SDK base ending in/gateway. - Set
CORTEX_API_KEYto your personal token. Use your client's approved secret-loading mechanism. - Replace
<organization-enabled-model>with an exact model on your organization's pricing sheet whose provider is enabled. The model catalog lists base catalog IDs; it does not establish account access. - Run the example for your client. Do not append a Gateway path to an issued URL that already includes it.
First request
Use your existing client with Cortex credentials
Set CORTEX_BASE_URL to the organization-issued URL for the selected client and CORTEX_API_KEY to your cct_ personal capture token.
Replace <organization-enabled-model> with a model on your organization's pricing sheet whose provider is enabled. These examples verify forwarding. Auto Router requires managed configuration and a qualified client and request path, such as Codex using Responses.
cURL base URLUse the complete request URL exactly as issued.
curl "$CORTEX_BASE_URL" \
--request POST \
--header "Authorization: Bearer $CORTEX_API_KEY" \
--header "Content-Type: application/json" \
--data '{
"model": "<organization-enabled-model>",
"messages": [{"role": "user", "content": "Summarize these release notes in one sentence."}]
}'Response shape
{
"id": "chatcmpl_01",
"object": "chat.completion",
"model": "<response-reported-model>",
"choices": [{"message": {"role": "assistant", "content": "A concise release-note summary."}}],
"usage": {"prompt_tokens": 23, "completion_tokens": 8, "total_tokens": 31}
}Verify the result
A successful provider response confirms forwarding. If Cortex Atlas is enabled, separately check that the request appears under your account, using the client and test time. A response alone does not verify ingestion or complete capture coverage.
For automatic routing on a qualified path, inspect routing decision evidence. These baseline examples request an explicit model; they do not activate Auto Router.
If the request fails, use the current errors and limits. Share the client name, response status and approximate test time with your administrator, never the token.
Continue
- Connect an SDK or AI tool for client-specific configuration.
- Choose a model for exact IDs and base catalog rates.
- Manage budgets for configured controls and their request-path boundaries.
- Inspect usage and spend for captured reporting.
Deployment paths
Shared Egress Gateway forwards requests through your organization's endpoint. Endpoint Defender Gateway handles qualified paths through a managed Cortex Defender installation. Choose the relevant deployment before configuring routing; the endpoint paths are not interchangeable.