netlify-ai-gateway
Use OpenAI, Anthropic, Google Gemini, or OpenRouter models from Netlify Functions or Edge Functions without managing provider API keys or accounts — the gateway injects credentials automatically. Reach for this when you add an AI chatbot or completion endpoint, generate images or text with Gemini/GPT/Claude, summarize form submissions with AI, build an LLM-backed API route, stream a long AI generation, or wire up any server-side AI provider call on Netlify. Covers provider SDK setup, injected en
Security Assessment
About netlify-ai-gateway
This skill teaches an agent how to call AI providers (OpenAI, Anthropic, Google Gemini, OpenRouter) from Netlify Functions and Edge Functions through the Netlify AI Gateway, which injects the provider API keys and base URLs automatically so developers never manage provider accounts or credentials directly. It solves the friction and risk of hand-wiring provider keys into server code: clients are instantiated with no arguments and the SDKs read the gateway-injected environment variables. The skill is explicit that the gateway is server-side only and lists the failure modes that silently break or cost money.
It covers a working Function example with routing config, per-provider SDK setup snippets for Anthropic, OpenAI, Gemini, and OpenRouter (noting OpenRouter needs an explicit base URL and can also be reached through the OpenAI SDK), the full table of injected environment variables, the Gemini/Vertex special case, streaming for generations that would exceed the 60-second synchronous timeout, and local development via netlify dev or the Netlify Vite plugin. It also documents operational constraints: the gateway requires at least one production deploy to activate, is gated to credit-based plans, caps input at 200k tokens, and enforces per-team per-minute rate limits.
Target users are web and full-stack developers building AI chatbots, completion endpoints, form-summarization, image or text generation, or any server-side LLM call on Netlify. The security posture is sound: it documents standard credential injection and environment variables via official tooling, explicitly forbids calling the gateway from browser code, and never exfiltrates secrets.
FAQ
Do I need my own provider API keys?
No. The gateway injects provider API keys and base URLs into Netlify compute contexts, so you instantiate each SDK client with no arguments. It only injects a key if you have not already set your own, and Netlify never overrides keys you set yourself.
Can I call it from the browser?
No. The gateway lives only in Functions and Edge Functions. Calling it from client-side React or browser code will not work; the client should just fetch your own function route.
Why is my generation getting cut off?
Synchronous functions are killed at 60 seconds. For long generations, use SDK streaming with a ReadableStream, or a background function that persists output for the client to fetch.
What are the plan and usage limits?
It requires a credit-based plan (Free, Personal, Pro, or Enterprise), needs at least one production deploy to activate even in local dev, caps input at 200k tokens, and applies per-team per-minute credit-based rate limits.
How do I develop locally?
Use netlify dev via the Netlify CLI, or add the @netlify/vite-plugin to your Vite config and run your normal dev server. Both paths still require an existing production deploy.
Install netlify-ai-gateway
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
netlify/context-and-tools