Skip to content
CortexDocs
Gateway · Connect a provider

Connect a provider

Distinguish upstream provider credentials from client tokens, and verify configured provider access.

Configure a provider

Provider credentials allow Gateway to call an upstream account. An organization administrator manages these credentials; members send their personal capture token from the client.

Providers and cloud platforms

Cortex supports the major model-provider and cloud ecosystem, including Microsoft Azure, Google Cloud, AWS and Amazon Bedrock, Snowflake, Fireworks, OpenAI, Anthropic, xAI, Google, Perplexity and Cursor. Cloud platforms, model providers and AI tools have different roles; your organization's configured endpoints and account permissions determine the models available to you.

  • Microsoft AzureCloud AI platform
  • Google Cloud (GCP)Cloud AI platform
  • AWSCloud platform
  • Amazon BedrockManaged model serving
  • SnowflakeCloud AI platform
  • FireworksModel serving
  • OpenAIModel provider
  • AnthropicModel provider
  • xAIModel provider
  • GoogleGemini models
  • CursorAI tool and models
  • PerplexityModel provider

For the complete model scope, including open-weight and self-hosted models, see Choose a model. The enrolled-device selector illustrated below lists its current connection choices; it is not the complete Gateway provider or model catalog.

Before you configure a connection

You need the organization's Admin role, a provider account, its approved endpoint and a company API key. Use the organization's live view, not a sample or fixture view. This enrolled-device console procedure requires Cortex Atlas enabled for the organization; shared Egress forwarding does not. This console configuration is delivered to enrolled Cortex Defender devices; shared Egress provider wiring remains part of the managed deployment.

The model catalog and your account permissions are separate. A listed model does not establish enabled access, region, data-retention terms or a negotiated price.

Choose a provider

The provider selector offers Anthropic, OpenAI, Google Gemini, Grok (xAI), Fireworks and Perplexity. Cortex Router is a separate routing endpoint option.

Choose an upstream provider for enrolled devicesOpen in Cortex

Choose the upstream provider for the account you are connecting.

Configure a provider

  1. Open Gateway → Providers for the intended organization.
  2. Select Add provider, or open the existing provider's Edit provider action.
  3. Choose the provider for the upstream account.
  4. Confirm Endpoint URL and enter the Company key. An enabled connection requires a stored company key. When editing, leave the key blank to preserve the existing stored value.
  5. Review Provider enabled. Expand Advanced request settings only if your deployment requires added headers or stripped request fields.
  6. Select Save provider. The dialog closes after a successful save and the provider list refreshes. Confirm the endpoint and enabled state on the saved row.
Configure a provider endpoint and company credentialOpen in Cortex

Leave the company key blank to keep its stored value, or enter a replacement before saving.

Example provider connections with stored credentials hiddenOpen in Cortex

Confirm the saved provider's credential and enabled state in the refreshed list.

Changes reach enrolled devices when they next check for configuration updates. Cortex Router changes require those devices to restart; saving alone does not prove delivery or forwarding.

Connection fields

FieldWhat to confirm
ProviderThe upstream account to call, rather than a routing strategy
Endpoint URLThe endpoint approved for that provider account and deployment
Company keyThe provider key held on Gateway, separate from the member's personal token
Provider enabledWhether this connection is configured for use
Connection checkThe credential and configuration that were checked

Verify provider access

  1. Confirm that the saved connection belongs to the intended organization and uses the approved provider endpoint.
  2. Expand the saved provider row and select Test connection. The connection must be enabled and have a stored key. Confirm the returned status and check time. The result applies to the saved configuration checked. If the configuration changed, refresh it before checking again.
  3. On an enrolled Defender device, use a supported AI tool through its configured provider path and send a test request. Use a model that the provider account can access.
  4. Verify the returned provider response. Check captured activity separately if Atlas is enabled.

Credential acceptance does not prove model generation, account model access, region or retention terms. If the credential is rejected, edit the saved provider, replace the company key, save and test again. For a shared Egress deployment, provider wiring and the organization pricing-sheet mapping are separate setup steps. Use its first request; if that request returns provider_not_configured, have an administrator review the managed provider configuration.

Continue

Was this helpful?