Skip to main content

LiteLLM vs Portkey vs Helicone: Which AI Gateway for Production Traffic

LiteLLM, Portkey, and Helicone AI Gateway compared on license terms, real cost at volume, and maintenance activity, now that Portkey is owned by Palo Alto Networks.

AgentsIndex's profile

Written by AgentsIndex

Editorial team••6 min read

The short answer

For most teams, LiteLLM is the default: free, self-hosted, MIT-licensed at its core, and still the most active of the three by a wide margin. Reach for Helicone's AI Gateway instead if you want a purpose-built, low-latency Rust proxy and can live with GPL-3.0 on that specific component. Evaluate Portkey only with the understanding that you are no longer buying from an independent routing startup — you're buying into Palo Alto Networks' Prisma AIRS security platform, and the product, the pricing, and the roadmap now answer to that.

That last point is the one thing in this comparison that changed the calculus, so it's worth establishing before anything else.

Portkey isn't a startup anymore — it's a Palo Alto Networks product line

Palo Alto Networks announced its intent to acquire Portkey on 30 April 2026 and closed the deal on 29 May 2026, folding it into Prisma AIRS, its AI security platform, as "the control plane to monitor, orchestrate, and govern autonomous agents at scale." (Palo Alto Networks press release) Portkey's own marketing site confirms the rebrand isn't cosmetic: the "Portkey vs LiteLLM" comparison page routes every "Talk to Us" and "Schedule a call" button to paloaltonetworks.com/ai-security/ai-gateway, tagged utm_campaign=prisma_airs (portkey.ai/pricing). Portkey's own pricing page now literally states "Portkey is now PRISMA AIRS AI Gateway."

The plans themselves are unchanged for now — Developer (free forever, 10k logged requests/month, 3-day log retention), Production ($49/month, 100k logged requests then $9 per additional 100k, 30-day retention), and Enterprise (custom, SOC 2 Type 2, HIPAA, private cloud) — but the sales motion for anything beyond self-serve now leads to a cybersecurity vendor's enterprise team, not a small routing company. If what you actually want is a lightweight open-source proxy you fully control, that's a different vendor relationship than what Portkey is becoming. If what you want is agent governance backed by a company that also sells network security to the Fortune 500, Prisma AIRS is a legitimate answer to a question most indie gateways can't address — it's just not the same product category anymore.

One nuance worth keeping straight: Portkey's underlying open-source gateway code (Portkey-AI/gateway, MIT-licensed, 13,054 GitHub stars as of today) is still maintained and still merging PRs — the most recent merge landed 25 May 2026, the day the acquisition closed (github.com/Portkey-AI/gateway). It's the hosted product and its commercial direction that changed, not the open-source repo's licensing.

The license terms are not identical, and that matters at production

All three call themselves open source somewhere on their site. Only one of them is unqualified about it.

LiteLLM (BerriAI/litellm) is 59,363 GitHub stars as of today and the top-level repository is MIT — genuinely permissive, no strings. But the enterprise/ subdirectory carries its own separate license file, and it is not MIT: the BerriAI Enterprise License states plainly that code under that directory "may only be used in production" if you hold a paid subscription or other agreement with BerriAI, and forbids copying, merging, publishing, distributing, sublicensing or selling it otherwise (raw license text, verified today). Enterprise features — SSO/SCIM, OIDC/JWT auth, RBAC by key/team/org, air-gapped deployment, 24/7 SLA-backed support — sit behind that carve-out (litellm.ai/enterprise). The core gateway — routing, virtual keys, budgets, provider fallback — is fully MIT and free to self-host indefinitely; you only hit the enterprise license if you need the governance layer a larger org typically wants.

Helicone's AI Gateway is a separate repository from Helicone's main observability platform, and the two are licensed differently. The main Helicone app (Helicone/helicone) is Apache-2.0, 6,170 stars. The AI Gateway (Helicone/ai-gateway) — the Rust-based proxy that actually routes and load-balances your LLM traffic — is GPL-3.0, and that's a recent, deliberate change: the repo's commit history shows it moved from Apache-2.0 to GPL-3.0 on 21 November 2025, with the commit message "Replace Apache License 2.0 with GNU General Public License v3.0" (commit on GitHub). GPL-3.0 is copyleft: if you distribute a modified version of the gateway, you're obligated to release your modifications under GPL-3.0 too. Running it unmodified as an internal service doesn't trigger that obligation — GPL-3.0 doesn't have AGPL's network-use clause — but it's a materially different commitment than the MIT core of LiteLLM or the Apache-2.0 of Helicone's own observability platform, and worth flagging to legal before you fork it.

Portkey's hosted product has no GitHub link in our records because there isn't a self-hostable equivalent of the product you'd actually be evaluating — the open-source Portkey-AI/gateway repo is MIT, but it's the routing engine, not the observability/governance dashboard Portkey sells. If open licensing across the whole stack is the requirement, Portkey was never really in this race; LiteLLM and Helicone's Gateway are.

What each one actually costs to run

Self-hosting removes the license fee but not the engineering cost of running a proxy in production; hosted removes the ops burden but adds a metered bill. Here's what each vendor actually publishes, checked today:

  • LiteLLM: the gateway itself is $0 whether self-hosted or not — there's no metered request pricing. Enterprise support and governance features are "Get In Touch" custom pricing, not published.
  • Portkey: Free up to 10k logged requests/month. Production is $49/month for 100k logged requests, then $9 per additional 100k. At 2 million requests/month that's $49 + (19 × $9) = $220/month, on top of whatever compute you're already paying the model providers.
  • Helicone: Hobby is free for 10,000 requests/month and 1GB storage. Pro is $79/month with "usage-based pricing" beyond the free allotment, priced through a calculator on their site rather than a published flat rate — the vendor doesn't quote a fixed per-request overage number the way Portkey does (helicone.ai/pricing).

If the whole reason you're looking at a gateway is to cut cost and avoid vendor lock-in, paying nothing but your own infrastructure bill for LiteLLM is hard to beat — which is presumably why NVIDIA, AT&T, Netflix, and Okta are cited as users on LiteLLM's own site (litellm.ai) and why it dwarfs the other two on GitHub activity.

Which one is actually still being built

Stars are a lagging indicator; commit and merge activity tells you who's still working on it.

  • LiteLLM: last push today (2026-09-22, per GitHub API), 5,196 open issues — a large number, but consistent with a project fielding contributions at scale rather than one going quiet.
  • Helicone's AI Gateway: last commit 30 July 2025, 13 open issues, 631 stars. That's over a year without a commit on the gateway repo specifically — worth checking again before you commit if it still matters to you, since a proxy sitting in your request path is not somewhere you want unpatched CVEs piling up quietly. (Helicone's main observability platform, by contrast, pushed as recently as 25 July 2026, per our records — it's the Gateway component specifically that looks stalled.)
  • Portkey's open-source gateway: last merged PR 25 May 2026 — the day the acquisition closed — with 275 open issues on a 13,054-star repo. Still active, just now under different corporate ownership.

The decision

Default to LiteLLM if you want a free, actively maintained, self-hosted gateway with a real community behind it, and you're comfortable that the enterprise governance layer (SSO, RBAC, air-gapped deployment) is a paid add-on rather than free.

Choose Helicone's AI Gateway if raw proxy performance is the deciding factor — its own benchmarks claim sub-5ms P95 latency and ~64MB memory footprint against a "typical setup" baseline of 60–100ms and ~512MB (helicone.ai/gateway; these are the vendor's own numbers, not independently verified) — and your legal team is fine with GPL-3.0 on that one component. Note it's a separate, less actively committed repo than Helicone's main observability product.

Consider Portkey/Prisma AIRS only if what you actually need is agent governance under a cybersecurity vendor's umbrella — SOC 2, HIPAA, VPC hosting, and a sales team that reports up through Palo Alto Networks. If you came looking for an independent, developer-first routing layer, that's no longer quite what's on offer.

Share: