← Back to T-Llama
Product Features

The control plane for governed AI usage.

T-Llama combines a local Onramp, private gateway, Entra-backed control plane, budget enforcement, guardrails, and analytics so company AI traffic is usable, governed, and attributable.

Feature groups

Every layer of the mesh, from the endpoint to evidence.

T-Llama Onramp

The Onramp is the local process that tools talk to. It exposes compatible local AI APIs, authenticates local callers, applies endpoint guardrails, and forwards governed traffic to the private gateway.

  • Local OpenAI-compatible /v1 API
  • Anthropic-compatible local API for Claude Code
  • OpenAI Responses local API for Codex
  • Local Session Credential authentication
  • Metadata-only local usage events

Local Session Credentials

Local Session Credentials work like API keys for local tools, but they are not provider keys and they do not authorize direct gateway access.

  • Endpoint-only by design
  • Tool-bound attribution by default
  • Immutable scope — mint a new credential to change project/tool/budget
  • Token values shown once; stored metadata and hashes only
  • OS-protected storage on macOS

Native launch integrations

Launch supported coding tools through T-Llama without hand-copying base URLs or keys.

  • tllama launch claude
  • tllama launch codex
  • Reuse-or-mint local credential flow
  • Project attribution with --project
  • Optional model pinning, centrally validated
  • Restore flow for T-Llama-owned Codex profile

Private gateway

The gateway is the central enforcement plane for identity, model policy, budgets, provider routing, and key custody.

  • tllama-gate fronting Bifrost
  • Entra JWT validation
  • Identity-to-virtual-key mapping
  • Provider keys stay gateway-side
  • Inference-only route surface
  • Gateway reachability diagnostic
  • Fail-closed when the private route is unreachable

Diagnostic echo and contract evidence

T-Llama includes deterministic contract paths so private-gateway behavior can be tested without live provider spend.

  • Gateway-side tllama-echo diagnostic model
  • Phase 1A contract report in CI
  • Phase 2A launch conformance
  • Phase 2C contract report for management, enforcement, and analytics
  • Metadata-only artifacts

Guardrails

The endpoint blocks high-confidence secrets before requests leave the user's machine.

  • Pre-egress deterministic scan
  • Secret fingerprints instead of raw values
  • Guardrail failure class distinct from auth and gateway errors
  • Applies even to diagnostic requests

Management API

Every admin capability is an API first. The portal and future integrations use the same governed endpoints.

  • /control/v1 Management API
  • Entra role-gated admin writes
  • Human delegated tokens and application-token path
  • Projects, members, allow-lists, budgets, personal allowance
  • Me-scoped budget reads for user budget displays

Admin Portal

The Admin Portal gives administrators a visual control plane without creating a portal-only backend.

  • Entra-protected sign-in
  • Project creation and archive
  • Member management by UPN
  • Per-project model allow-lists
  • Project budget update
  • Tenant default personal allowance and user overrides
  • Analytics page

Budget enforcement and snapshots

T-Llama separates authoritative enforcement from user-friendly display. The gateway evaluates live budget state on every request; clients receive display-only snapshots and piggybacked state.

  • Gateway budgets for projects and personal usage
  • Local budgets can be stricter, not looser
  • Smallest applicable budget wins
  • Budget state header for active traffic
  • CLI budget display with spent and remaining amounts

Usage analytics

Metadata-first analytics show who used which project, tool, and model, how many requests ran, what they cost, and where denials happened.

  • Request accounting rows written by the gateway
  • Analytics API endpoints
  • Portal headline tiles
  • Spend over time
  • Group by project, user, model, or tool
  • Cost Confidence badges
  • Budget denial panel

Onramp Dashboard and tray

The endpoint UI track makes T-Llama visible outside the terminal: sign-in, budget visibility, credential minting, usage views, and always-on Onramp readiness.

  • Tokened loopback dashboard shell shipped
  • Browser Entra sign-in flow shipped
  • Budget snapshot foundation shipped
  • Credential mint/revoke/usage pages in flight
  • Tray app with login startup, restart, and status planned

How traffic flows.

Tools talk to the local Onramp. The Onramp authenticates local callers, applies pre-egress checks, and forwards over the private path. The gateway validates identity, rechecks central policy, enforces budgets, routes to providers, and writes metadata-first evidence.

OpenAI APIAnthropic APIResponses APIEntra authPrivate gatewayGateway budgetsProject allow-listsAdmin PortalAnalytics APIDiagnostic contracts

Ready to see it in your environment?