Dashboard
gateway_requests_total / gateway_request_duration_ms / gateway_tokens_total / gateway_cost_estimate_total · current stats are a 5m rate · auto-refreshes every 15s
Cache Management
Force stale entries out of the exact-match response cache (Gaps §6d) · scoped by tenant and/or model, at least one required · passive TTL expiry (5m) still applies either way
Recent Activity
live · updates every few secondsThe last few minutes of terminal requests, across every tenant — send a call from the Playground and watch it land here.
| Time | Tenant | Model | Upstream | Outcome | Latency | Tokens | Trace |
|---|---|---|---|---|---|---|---|
| waiting for traffic… | |||||||
Request rate by status
Token throughput by type
Top models (by request rate)
| Model | Req/s | Error % | p95 ms | Tokens/s |
|---|
Top tenants (by request rate)
No p95 column here: latency isn't tracked per tenant.
| Tenant | Req/s | Error % | Tokens/s |
|---|
Full observability suite
This dashboard is a quick, at-a-glance summary — these tools go deeper. The lists below are fetched live from each tool's own API, not hardcoded, so they can never silently go stale.
Routing & Channels
A candidate is a channel (service/port/label/region) · edits push live, no gateway restart
Default chain
Used for any model prefix with no dedicated route below.
| Service | Port | Label | Region |
|---|
Named routes
A route's own chain is tried for any model whose canonical id starts with its prefix (e.g. openai).
History
Every prior version, newest first · restoring produces a new (not destructive) entry
| Time | Actor |
|---|
Guardrail Policy
Content-safety and PII rules · edits push live, no plugin rebuild
Rules
A pattern rule matches a regular expression; a classifier rule names a heuristic services/guardrail already registers. block requires a policy reference (Contract v1 §5.2).
History
Every prior version, newest first · restoring produces a new (not destructive) entry
| Time | Actor |
|---|
Image PII (per tenant)
Whether images are OCR'd and scanned through the rules above, and what happens when a scan can't complete · unconfigured tenants default to on / block
Consumer Portal Branding (per tenant)
Display name + logo shown in that tenant's own Consumer Portal · unconfigured tenants show the default generic label · logo max 256KB, PNG/JPEG/SVG/WebP
Consumer Keys
Issue, rotate, or revoke a consumer's API key · changes take effect immediately, no restart
Issue a new key
Active & revoked keys
Credentials are encrypted at rest and shown only once, at issue time — this table shows each key's id, not its value.
| Consumer | Tenant | Status | Allowed models | Region | Key ID |
|---|
Team Members
Invite the first self-service login for an already-provisioned consumer — every teammate after that is invited from within their own portal, no further action needed here.
Active & revoked portal users
| Username | Consumer | Tenant override | Status | Created |
|---|
Operators
Issue, rotate a token, reset credentials, or revoke a teammate's access · operator role required · no command-line steps needed
My Password
Self-service only — this can only ever set the password for the account you're logged in as right now, never anyone else's. Setting a password also generates a fresh batch of recovery codes — any previous batch stops working.
Invite a new operator
Active & revoked operators
| Username | Role | Status | Created | Revoked |
|---|
Usage
Usage attribution for a selected consumer — for reporting, not billing
| Model | Upstream | Requests | Errors | Prompt tok | Completion tok | Total tok |
|---|
Audit Log
Who changed routing/guardrail policy or issued/revoked a consumer key, and when · read-only
| Time | Actor | Action | Resource |
|---|