Otoroshi with LLM
-
01
01 Powerful and flexible API management
Otoroshi is a dynamic API gateway that lets you expose, secure, and route all your services. You can manage traffic, authentication, rate limits, and load balancing via a visual interface or REST API. It supports REST, GraphQL, gRPC, and more without requiring changes to your backend code.
0202 Built-in enterprise security and WAF integration
With Coraza WAF built-in, Otoroshi protects your APIs and applications using OWASP security rules. It manages access through API keys or tokens such as Biscuit, developed by Clever Cloud. These tokens allow you to easily enforce custom authorization rules based on your security context and requirements.
0303 Full observability and audit trails
Every interaction is logged in real time* to help you monitor service usage, debug issues, and meet compliance needs. You can export metrics and logs to Elastic, Datadog, or any other monitoring tool to meet your performance and compliance goals.
*Provided an external storage solution is configured (not included by default).0404 Developer-first, open-source foundation
Otoroshi was designed for developers, with a sleek React admin UI and a complete REST API. It supports live updates, plugin extensions, and WebAssembly for advanced customization. The platform is open source, lightweight, and deployable as a JAR or Docker image.
API Gateway, Explained
An API gateway is the single point through which all your service calls pass. It enables routing, authentication, throttling, and logging across services. Otoroshi handles this for APIs by default, and optionally for LLMs when the extension is enabled.
Otoroshi LLM Extension
Extend Otoroshi into an AI service gateway.
The Otoroshi LLM extension, developed by Cloud APIM, turns your API gateway into a secure, centralized access layer for LLM providers like OpenAI, Mistral, and Hugging Face. You can manage API tokens, prompt templates, and request routing from one place, optimizing for cost or performance.
Guardrails can be activated to filter prompts and responses, helping enforce corporate security, privacy, or ethical standards.
Use Cases:
- Secure and expose your internal or external APIs
- Simplify and manage services communication
- Add observability, auditing, and live policy control
- Secure web applications and non-API services
- (For the LLM extension) Centralize access to LLM providers with prompt filtering and request routing
Why Choose Clever Cloud for Otoroshi with LLM?
- One-command deployment: Console; API, or CLI support
- Pre-configured stack: Java runtime and Redis instance included; backups are performed automatically
- Integrated WAF: Enterprise-grade Coraza firewall by default
- Native scaling: Adjustable plan sizes via Clever Console
- Open-source transparency: Fully audit and customize your environment
- Unified billing and lifecycle management
Built by experts, trusted by developers
Created by #OSSbyMAIF and continuously developed by Mathieu ANCELIN, an API Management expert at Cloud APIM, together with MAIF’s teams, Otoroshi is a trusted reference for technical teams seeking serious control over APIs and AI.
Now available in beta with full Clever Cloud integration, it’s ready to scale with your most demanding projects, while you focus on what matters: your product.
Want to learn more about Otoroshi?
Visit the official website to explore all its features and see how it can help you secure your APIs, manage traffic, and streamline your services architecture.
Video
Otoroshi Demonstration
Discover the presentation of Otoroshi by Mathieu Ancelin, creator, and Horacio Gonzalez from Clever Cloud.
Discover our news
UP Program: Clever Cloud announces its fifth startup selection
With this new batch, Clever Cloud welcomes four startups to the UP Program: Sentibee, Pictaderm, Legaia and Cockpit Agriculture.Sōzu 2.0 — turning a reverse proxy into a programmable edge
Sōzu is the reverse proxy that sits in front of every application running on Clever Cloud. After eighteen months of work — first the HTTP/2 multiplexer, built on our existing kawa pivot, then almost every other layer of the proxy, and finally a long run in production on the cleverapps.io load balancers — Sōzu 2.0 is out.K3s vs K8s: What Are the Differences and Which One Should You Choose in 2026?
Kubernetes has become the standard for container orchestration. But depending on your infrastructure constraints (limited resources, edge computing, IoT, or large-scale enterprise clusters), the distribution you choose can radically change the operational experience. K3s and K8s (upstream Kubernetes) address different needs, even though both share the same CNCF-certified foundation.