LiteLLM Enterprise
Give every team access to AI. Keep control of who uses what, and what it costs.
LiteLLM Enterprise is the open-source AI Gateway plus single sign-on, audit logs, delegated admin roles, and support from the engineers who build it. It runs in your cloud, so prompts and responses never leave your environment.
- SOC 2 Type II audited
- Self-hosted in your VPC
- For teams with 100+ users or 10+ production AI use cases
What you get on top of open source
Enterprise is a license key on the same Gateway image you may already run. Nothing to migrate: each layer includes everything below it.
What changes for your organization
Who is Enterprise for?
For teams running LiteLLM at scale (100+ users or 10+ production AI use cases) that need SSO, audit logs, fine-grained access control, and professional support on top of open source. SSO is free for up to 5 users; beyond that, an Enterprise license is required. Engineers evaluating a trial can follow the Production rollout guide, and teams already on open source can start with Moving from OSS.
Full feature list
Everything below is enabled by the license key. Each item links to its setup guide.
Security and access
- SSO for the Admin UI. Okta, Azure AD, Google Workspace, and any OIDC/SAML provider
- JWT-based Authentication. Authenticate requests with your identity provider's tokens
- Audit Logs with retention policies. Track every admin action and key-level change
- Role-Based Access Control. Organizations, teams, and user roles
- Public and private route controls. Restrict admin routes and lock down surface area
- IP address-based access control lists. Restrict proxy access to specific CIDR ranges
- Key Rotations. Automate rotation for virtual keys
- Secret Managers. AWS KMS, AWS Secrets Manager, Azure Key Vault, Google KMS, Google Secret Manager, HashiCorp Vault, CyberArk, or a custom secret manager
- AI Hub. Share a public, branded page of available models, MCP servers, agents, and skills
Governance and cost
- Multi-tenant Architecture. Organizations, teams, projects, and keys
- Project Management. Group keys by application or use-case, with a budget, owners, rate limits, a model allowlist, and an isolated spend view. See the UI walkthrough
- Tag-based Budgets. Budgets and spend tracking by custom tag
- Model-specific Budgets per Virtual Key. Different limits per model, per key
- Temporary Budget Increases. Time-boxed spend bumps without permanent changes
- Soft Budget Email Alerts. Warn teams before they hit hard limits
- Generate Spend Reports. Programmatic access to spend by key, team, tag, or model
Observability and compliance
- SOC 2 Type II. Audited controls; request the report through the Trust Center
- Team-Based Logging. Route each team's logs to their own Langfuse project or callback
- Disable logging per team. GDPR-friendly opt-out at the team level
- Log export to GCS / Azure Blob. Durable storage for compliance
- Guardrails per key/team. Secret redaction, content moderation, banned keywords
- Enforced required params. Reject requests missing required metadata
Operations and branding
- Custom Swagger branding. Set your own title, description, and filtered routes on the API docs page
- Custom email branding. Your logo and colors on system emails
- Max request/response size limits. Protect the proxy from runaway payloads
- Team-managed models. Let teams bring their own keys and fine-tunes
Which guardrails need a license?
The OSS guardrail framework includes custom guardrails and Presidio for PII masking. These built-in callback integrations require a LiteLLM Enterprise license: llmguard_moderations, llamaguard_moderations, hide_secrets, openai_moderations, google_text_moderation, lakera_prompt_injection, and aporia_prompt_injection.
Run it
Deploy the Docker image, or build from the pip package, on your own infrastructure. A license key enables the features above and includes a dedicated support channel.
LITELLM_LICENSE="eyJ..."
No data leaves your environment, and LiteLLM is SOC 2 Type II audited. Procurement is available through AWS and Azure Marketplace.
Pricing depends on your deployment size. Get in touch to scope it.
Support
Every license includes a dedicated Slack or Teams channel with the engineering team. With the optional 24/7 SLAs, the response time is 1 hour for Sev 0 and 72 hours for security patches. See Support and SLA for hours, the full severity table, and custom SLAs.
Version support
LiteLLM supports the four most recent stable minor lines, and Enterprise and open source share one image and one version number. See Version support.
FAQ
How do I set up and verify an Enterprise License?
Add the license key to your environment, then restart the proxy.
LITELLM_LICENSE="eyJ..."
Open http://<your-proxy-host>:<port>/. The API docs page should show Enterprise Edition in the description. If it does not, confirm the key is correct and unexpired, and that the proxy was fully restarted.
Is LiteLLM SOC 2 compliant?
Yes. LiteLLM is SOC 2 Type II audited. Request the current report through the LiteLLM Trust Center. For data handling, vulnerability reporting, and the rest of the security review, see Data Security, Legal, and Compliance FAQs.
Can we buy through AWS or Azure Marketplace?
Yes. You can buy an Enterprise license through AWS Marketplace or Azure Marketplace, or directly by invoice. See Procurement Options.
Where can I read more about data security and compliance?
How is pricing structured?
Pricing is based on usage. Contact us for a quote tailored to your team.
How do I get day-0 support for new models without restarting?
Use Auto Sync New Models to pull the latest pricing and context-window data from GitHub on demand or on a schedule, with no restart required. Trigger a manual sync with POST /reload/model_cost_map, or schedule periodic syncs with POST /schedule/model_cost_map_reload?hours=6.