Guides
Investigating abnormal AI usage.
Practical, metadata-first guides for gateway operators who need to distinguish growth, broken automation, shared access, and possible credential misuse without reading prompts or responses.
- LLM API key abuse detection
Learn how to investigate suspected LLM API-key misuse using request metadata, credential lifecycle records, and customer context. This guide separates high-confidence credential-state evidence from behavioral anomalies, explains what a gateway can observe, and shows why an alert should usually open a verification case—not declare fraud. - AI gateway credential misuse
AI gateways concentrate model access, billing, and downstream identity. This guide explains the investigation problem when a credential may be shared, leaked, or resold, including what gateways preserve, what they replace, and which evidence can distinguish an operational change from misuse. - Investigating unexplained AI usage spikes
An AI-usage spike can be customer growth, a retry loop, an agent failure, a model migration, or credential misuse. This guide provides a practical investigation sequence that starts with the operational question, narrows the time window, and preserves content privacy. - LiteLLM credential exposure response
A gateway credential exposure is not resolved by rotation alone. This guide explains how to contain the exposure, confirm revocation, preserve request evidence, and determine whether the exposed credential was used before the response began. - LLM token resale risk
Token resale turns a provider account, gateway route, or purchased allowance into downstream metered access. This guide explains the observable risk signals, the limits of those signals, and why pricing or shared infrastructure alone cannot establish the source of supply. - AI gateway provenance and delegation
AI-gateway provenance is the ability to connect a billed provider request back to an authorized downstream workload. This guide covers the identity, delegation, and reconciliation records that turn ambiguous metadata into evidence suitable for an investigation. - AI spend anomaly detection
AI spend anomalies are useful for triage but dangerous as verdicts. This guide explains how to compare a credential to its own history across time windows, choose investigation budgets, and avoid treating legitimate launches or batch jobs as abuse. - Authorized versus unauthorized AI usage
Metadata can reveal changed or coordinated AI usage, but it cannot infer permission when authorized and unauthorized activity look identical. This guide explains the boundary between behavioral ranking and an authorization decision. - LLM gateway security logging
Useful LLM gateway logs capture enough metadata to reconstruct an investigation without retaining prompts or responses. This guide defines the minimum event fields, correlation records, retention priorities, and privacy boundaries for a security-ready gateway. - Credential sharing detection for AI platforms
Credential sharing can be approved collaboration, a shared service account, a relay, or misuse. This guide describes how to detect behavior worth reviewing without collapsing those different situations into a misleading fraud label.