Option #1
Ship the key in the app
Anyone with a proxy tool extracts it in minutes. Your OpenAI bill becomes their OpenAI bill.
Insecure
Mobile AI security platform
Gate/AI verifies devices with attestation, injects provider secrets server-side, and caps each user's token spend. No API keys in your binary—and none demanded from your users.
Your Mobile App
Secure Enclave key · App Attest / Play Integrity
Gate/AI
Verify · DPoP bind · Rate limit · Inject secret
Attestation
Verified
DPoP
Bound
Rate limit
12 / 500
Secret
Injected
AI Provider
OpenAI · Anthropic · Gemini · Custom
The real choice
Mobile devs cope in one of two ways today. Both cost you users, money, or both.
Ship the key in the app
Anyone with a proxy tool extracts it in minutes. Your OpenAI bill becomes their OpenAI bill.
Insecure
Make users bring their own key
BYOK turns your onboarding into “go create an OpenAI account, generate a key, paste it here.” Most users bounce. The ones who stay file support tickets when their key breaks—and they're already paying for the AI, so why pay you?
User-hostile
The option that didn't exist—until now
Your key stays server-side. Users just use the app. Per-device token budgets cap what any single user can cost you—the cost control BYOK promised, without exporting the work to your users.
Secure. And it converts.
The platform
Gate/AI pairs cryptographic trust with real spend controls. No custom backend, no overnight pager duty.
App Attest, Play Integrity, and DPoP are orchestrated so every request is tied to a real device and binary.
Per-device and global rate limits, short-lived tokens, and usage budgets block abuse before it hits your AI bill.
Every call is recorded with context so you can debug, spot abuse, and watch spend from one simple dashboard.
Why now
Reverse engineering tools expose API keys in minutes. Gate/AI hardens every call so you can roll out AI safely—even if you do not run your own backend.
Result
Secrets stay in the cloud. Attack surface shrinks to zero.
How it works
01
iOS, Android, and cross-platform SDKs drop into your app without a custom backend.
02
Gate/AI verifies each install with attestation, provisions device-scoped keys, and issues DPoP-bound tokens.
03
Your app calls Gate/AI, we forward to OpenAI, Anthropic, or Gemini, and inject the secret on the fly.
Capabilities
Built for indie devs and small teams: every AI request visible in one place, with no infrastructure to stand up.
Cap each device's daily tokens and requests. You control your AI spend without asking users to bring a key.
Switch between OpenAI, Anthropic, Google Gemini, or custom LLMs without rebuilding your client.
API keys stay in Gate/AI. Tokens expire in minutes and are locked to a proven device.
Structured logs redact payloads, but keep enough context to trace abuse and performance bottlenecks.
We manage App Attest, Play Integrity, and the Secure Enclave/StrongBox lifecycle for you.
No servers to run, no key vault to configure, no pager. Ship your app and check the dashboard when you feel like it.
Start in minutes for free. Upgrade when you need more devices—no sales call. All plans include zero-trust security and cloud-based key management.
$0
USD
Per month
$4.99
$49.99
USD
Per month
Per year
$9.99
$99.99
USD
Per month
Per year
Need more than 500 devices per month or want help designing your rollout? Let's talk.
FAQ
Everything you need to know before shipping AI on mobile the right way.
A mobile AI gateway is a security and routing layer between your mobile app and AI providers. It keeps provider API keys out of your app, verifies devices, issues short-lived tokens, and enforces per-device policies so you can safely call LLM APIs from iOS and Android.
A regular AI gateway assumes trusted backend callers. A mobile AI gateway assumes untrusted clients, uses device attestation and sender-constrained tokens, and is designed so you don't need your own backend just to talk to AI providers.
For many apps, no. Gate/AI is designed so you can ship secure AI features from a purely client-side mobile app, while Gate/AI acts as the secure middle layer between your app and AI providers.
At a high level, 3 key security advances allow us to do this:
BYOK feels like it solves security and cost in one move—you never hold the key, and users pay for their own usage. But look at what it costs you:
With Gate/AI you keep your own key server-side and cap each device's daily token and request usage. That's the cost control BYOK promised—without pushing the work onto your users.
We wrote up the full argument in BYOK Is User Hostile.
These are the number of unique monthly devices that will make a request through Gate/AI's proxy service. This is not the same as the TOTAL number of monthly devices your app has. Your app has to make a request to Gate/AI in order to count towards your usage.
For example:
Yes, of course. We aren't going to nickel and dime you. Our overhead is around device verification. So that's how we are charging.
Ready to ship?
Create a free workspace, invite your teammates, and plug Gate/AI into your mobile app before lunch.