{"slug": "cloudflare-adds-identity-driven-budgets-to-ai-gateway", "title": "Cloudflare Adds Identity-Driven Budgets to AI Gateway", "summary": "Cloudflare announced on June 5 that its AI Gateway now supports dollar-based spend limits in open beta, while identity-driven budgets and policies using Cloudflare Access are in closed beta. The identity layer attaches verified user, group, or service-token context to model requests, enabling per-user attribution and the ability to block or reroute usage when budgets are exceeded.", "body_md": "# Cloudflare Adds Identity-Driven Budgets to AI Gateway\n\nCloudflare announced on June 5 that AI Gateway now supports dollar-based spend limits, while identity-driven budgets and policies that use Cloudflare Access are in closed beta. The identity layer attaches verified user, group, or service-token context to model requests, giving teams per-user attribution and a way to block or reroute usage when budgets are exceeded.\n\nCloudflare announced on June 5 that its AI Gateway now supports dollar-denominated spend limits, alongside a closed beta for identity-driven budgets and policies that use Cloudflare Access. SiliconANGLE reported on the identity-aware capability on August 5. The earlier first-party announcement is the controlling source for the feature's timing and availability.\n\n### Identity replaces shared-key guesswork\n\nAI Gateway sits between an application and model providers. Cloudflare says its gateway already centralizes request logging, token and cost data, caching, rate limits, and content controls. The new identity integration is intended to answer a question that shared API keys cannot: which employee, team, application, or automated agent generated a request and its associated cost.\n\nWhen a request is authenticated through Cloudflare Access, the gateway validates the token and records identity context such as the user's email, identity-provider group, or service-token name. Organizations can then define different budgets or model-access policies for users and teams. Automated agents and CI/CD systems can receive named identities through Access service tokens, allowing their usage to be measured separately.\n\n### Spend controls are available; identity policies remain a beta\n\nCloudflare says spend limits are available in open beta for AI Gateway users. Administrators can set fixed or rolling dollar limits by model, provider, or custom metadata. When a limit is reached, the default behavior is to block further requests, though Dynamic Routes can send traffic to a lower-cost fallback model instead.\n\nThe identity-driven budgets and policies are less broadly available: Cloudflare described them as a closed beta and directs interested customers to request access. That distinction matters because the August 5 coverage characterized the identity-aware gateway as a launch, while Cloudflare's own June 5 announcement presents the identity layer as a beta paired with generally accessible spend controls.\n\nFor platform and security teams, the practical value is consolidated attribution and policy enforcement at the model-traffic gateway. LDS interpretation: this can improve chargeback and incident investigation, but it also makes the gateway and identity-provider configuration a critical control point that teams should monitor and test.\n\n## Key Points\n\n- 1Cloudflare announced dollar-based AI Gateway spend limits on June 5; the limits are available in open beta.\n- 2Identity-driven budgets and policies use Cloudflare Access to attach verified user, group, or service-token context to requests and remain in closed beta.\n- 3Budget rules can block requests or route them to a lower-cost fallback model, giving teams a single enforcement point for model usage.\n\n## Scoring Rationale\n\nThe capability gives enterprise platform teams practical per-user and per-agent attribution plus enforceable model-spend controls. Its impact is meaningful but bounded because identity-driven budgets and policies remain a closed beta.\n\n## Sources\n\nPrimary source and supporting public references used for this report.\n\nPractice interview problems based on real data\n\n1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.\n\n[Try 250 free problems](/problems)", "url": "https://wpnews.pro/news/cloudflare-adds-identity-driven-budgets-to-ai-gateway", "canonical_source": "https://letsdatascience.com/news/cloudflare-adds-identity-driven-budgets-to-ai-gateway-1933dc01", "published_at": "2026-08-05 13:00:48+00:00", "updated_at": "2026-08-05 14:10:23.465995+00:00", "lang": "en", "topics": ["ai-infrastructure", "ai-tools", "ai-policy"], "entities": ["Cloudflare", "AI Gateway", "Cloudflare Access", "SiliconANGLE"], "alternates": {"html": "https://wpnews.pro/news/cloudflare-adds-identity-driven-budgets-to-ai-gateway", "markdown": "https://wpnews.pro/news/cloudflare-adds-identity-driven-budgets-to-ai-gateway.md", "text": "https://wpnews.pro/news/cloudflare-adds-identity-driven-budgets-to-ai-gateway.txt", "jsonld": "https://wpnews.pro/news/cloudflare-adds-identity-driven-budgets-to-ai-gateway.jsonld"}}