Guides
Route through OpenRouter
Keep OpenRouter and put governance above it. Requests go out with your attribution and routing preferences, allowlists apply to the vendor and model behind each route, and every call is billed on the cost OpenRouter itself reports.
A team that has standardised on OpenRouter keeps it. Immiscible routes through OpenRouter: your clients call Immiscible’s gateway exactly as before (route model traffic), and Immiscible calls OpenRouter with your OpenRouter key. Nothing about the gate, the evidence or the kill switch changes.
#1. Connect OpenRouter
Under Settings, Connections, choose Connect on OpenRouter and approve at OpenRouter. OpenRouter issues this workspace its own API key through its OAuth PKCE flow; nothing is copied. The key is sealed with AES-256-GCM and used only for this workspace’s traffic, and it shows in your OpenRouter keys, where you can set a limit on it or delete it.
You can still paste a key you already have (sk-or-v1-...) instead. Discovery, which lists every key on the account, needs a management key: OpenRouter offers no OAuth for those, so it is one key made at openrouter.ai/settings/management-keys.
#2. Ask for OpenRouter’s model ids
Clients name models the way OpenRouter does: anthropic/claude-sonnet-4.5, openai/gpt-5, anthropic/claude-opus-4.8, deepseek/deepseek-v4. Each is a route in the catalogue (openrouter/claude-sonnet-4.5 and so on) that records the vendor and model behind it.
curl https://immiscible.fly.dev/v1/chat/completions \
-H "authorization: Bearer ask_..." \
-H "content-type: application/json" \
-d '{ "model": "anthropic/claude-sonnet-4.5", "messages": [{ "role": "user", "content": "Summarise this thread" }] }'Routes such as anthropic/claude-sonnet-4.5 and openai/gpt-5 are on request: the router uses them only when a client asks for one by name, so adding them never changes what it picks for anyone else.
#What goes to OpenRouter
| Sent | Why |
|---|---|
HTTP-Referer | your deployment’s public address, so OpenRouter attributes the traffic to the gateway |
X-Title | your title (default Immiscible), shown on OpenRouter’s dashboard |
provider | your workspace’s routing preferences, replacing anything the client sent |
Set the preferences on the OpenRouter card under Settings, Connections, or with PUT /api/w/:wid/openrouter:
{ "dataCollection": "deny", "allowFallbacks": true, "zdr": false, "order": ["anthropic", "amazon-bedrock"] }dataCollection: "deny" keeps prompts away from hosts that store them. allowFallbacks lets OpenRouter try another host for the same model when one fails.
#Cost is OpenRouter’s number
OpenRouter includes the cost of every response in its usage (usage.cost, in US dollars; on a stream, in the last chunk). Immiscible bills the call on that figure rather than on its catalogue price, because it is the number on OpenRouter’s invoice. The evidence record says so: costSource: "provider_reported" and underlyingModel: "anthropic/claude-sonnet-4.5".
#Allowlists apply to the model behind the route
An agent’s model allowlist and its person’s entitlements (identity and access) are checked against the underlying vendor and model:
| Allowlist | anthropic/claude-sonnet-4.5 through OpenRouter |
|---|---|
anthropic/* | allowed |
anthropic/claude-sonnet-4.5 | allowed |
openai/* | refused, model_not_allowed |
openrouter/* | refused: allowing the aggregator is not allowing the vendor |
openrouter/claude-sonnet-4.5 | allowed: naming the route names its model too |
#Failover is honoured twice
- Inside OpenRouter. With
allowFallbackson, OpenRouter tries another host for the same model when one fails or rate-limits. - Above OpenRouter. When OpenRouter itself fails (a 5xx, a dropped connection, a timeout), the gateway retries once and then fails over to the next eligible route in the catalogue, usually a direct contract with another provider. The failover is on the evidence record and in
immiscible.failoveron the response.
#Before you put confidential data through it
An aggregator is one more company reading every prompt. Under the default policy, task classes whose data class is confidential or above are not routed to aggregator routes; in shadow mode the request still goes where the client asked, and the record says what enforcement would have done.