AI Studio Enterprise
Your AI studio.For the whole company.
AI Studio lives in the Otoroshi backoffice, for the administrators of your gateway. AI Studio Enterprise serves the same studio as a standalone application, for the teams building with AI, the product owners following their spend and the developers who just need a key.
AI Studio · Workspace
legal-assistants
Members
- JDjane.doe@acme.comowner
- NPnina.patel@acme.comeditor
- group: data-sciencemember
- SLsam.lee@acme.commember
- group: product-ownersviewer
Audit trail
- nina.patel@acme.com created the API key ci-bot2 min ago
- sam.lee@acme.com denied: providers.update (member)5 min ago
Your company login
Users sign in with your identity provider, through the authentication modules of Otoroshi (OpenID Connect, SAML, LDAP…). Nobody needs an Otoroshi account.
Members and roles in every workspace
Add members by email or by group of your directory, each with a role. Owner, editor, member or viewer.
Rights checked on every call
A user only sees the workspaces they belong to, and only what their role allows. A member sees their own usage, never the one of their colleagues.
Secrets kept on the server
Provider credentials never reach the browser. API keys are revealed only to the people who manage them, and every reveal is recorded.
An audit trail
Every change, every reveal and every refusal is kept, with who, when and from where.
The workspaces you already have
Enterprise builds the same Otoroshi entities. Your existing workspaces are ready to share, and the backoffice studio stays available to your gateway administrators.
Same studio
Every page of AI Studio.
Gated by your roles.
The front of AI Studio Enterprise is the AI Studio of the open-source LLM extension: workspaces, chat, models, API keys, guardrails, routing, logs and budgets are all here. Each page and each operation is checked against the permissions of the person, and the chat is relayed on their behalf. The email of a person identifies them everywhere, in the usage and the budgets of the gateway included.
- Chat on behalf of the person
- Usage and spend per person
- Personal API keys
- Look without spending

Roles
Everyone sees
what their role allows.
Give a role to a person, by email, or to a group of your identity provider. A role given to a group applies to everyone your identity provider puts in it.
Manages the workspace and its members.
Manages the configuration of the workspace and its API keys.
Chats and uses their own API keys, without seeing the configuration.
Follows the configuration and the activity, without spending.
For the whole studio
Administrators
Named by email or by group, they see every workspace, those nobody is a member of included, and give the roles.
Workspace creation
Reserved to the administrators, or open to everyone: your choice.
Editions
Every capability stays open source.
Enterprise adds the organization.
| AI StudioOpen source, in the Otoroshi backoffice | AI Studio EnterpriseStandalone application | |
|---|---|---|
| Workspaces, chat, models, keys, guardrails, routing, logs, budgets | ||
| Who uses it | The administrators of the gateway | Your whole organization |
| Login | Otoroshi backoffice | Your identity provider, no Otoroshi account |
| Members and roles in every workspace | ||
| Roles for the groups of your directory | ||
| Members see their own usage only | ||
| Secrets kept on the server, reveals recorded | ||
| Audit trail | ||
| License | Apache 2.0 | Commercial |
How it fits together
Next to your Otoroshi.
On your infrastructure.
Your users reach AI Studio Enterprise through an Otoroshi route that authenticates them. The application calls the studio API of the LLM extension with an account of its own: it never builds an Otoroshi entity itself.
Your users
Otoroshi route
Your authentication module, the identity of the person, the proof the request went through Otoroshi
AI Studio Enterprise
Permissions, secrets masked, audit, chat relayed on behalf of the person
PostgreSQL 14+
Members, conversations, audit, preferences
Otoroshi admin API
The studio API of the LLM extension, one source of truth for the entities
Docker or a single binary
A distroless image for linux/amd64 and arm64, or one executable for Linux, macOS and Windows.
Several instances
Run instances side by side: changes to a workspace are coordinated across them.
Ready to operate
Health, readiness and Prometheus metrics on a port of their own.
Safe by default
A missing or unsafe setting stops the server at startup, default secrets included.
FAQ
Frequently asked questions
Still have a question? Talk to our team.
Is AI Studio open source?
Yes. AI Studio is part of the Otoroshi LLM extension, under the Apache 2.0 license, and every capability of the studio remains in the open-source edition. AI Studio Enterprise adds what it takes to share it with your whole organization.
Do I need to migrate my workspaces?
No. Enterprise works on the same Otoroshi entities, through the studio API of the LLM extension. Your existing workspaces are ready to share, they only need members.
Which identity providers can my users sign in with?
Any authentication module of Otoroshi, such as OpenID Connect, SAML or LDAP. Roles can be given to a person, by email, or to a group of your directory.
Where does AI Studio Enterprise run?
On your infrastructure, next to your Otoroshi, behind a route of its own. It ships as a Docker image or as a single binary, and stores its data in PostgreSQL. Several instances can run side by side.
Is the backoffice studio still available?
Yes. The AI Studio of the Otoroshi backoffice keeps working for the administrators of your gateway.
How is AI Studio Enterprise licensed?
It is a commercial edition. Contact us for a demo and a quote adapted to your organization.
Share AI with your whole company.Keep control of it.
See AI Studio Enterprise running on your own workspaces, with your identity provider. We will set up a demo with you.