Why compare enforcement rather than feature lists

Most LiteLLM vs. Portkey comparisons line up the same checklist: provider count, caching, guardrails, observability, SSO. On that checklist the two products look close, because both route OpenAI-format requests across many providers with fallbacks and retries. The checklist hides the question a cost owner actually needs answered: when a team runs out of budget, does the next request get stopped, and what does the caller see?

That question has different answers for each product, and the answers depend on deployment details that feature tables skip. The sections below use each vendor's own documentation, read on 2026-10-05.

LiteLLM: free budgets that require a database

LiteLLM documents budgets at four levels: a global proxy budget, plus budgets per virtual key, per internal user, per team, and per end customer. Each can reset on a schedule through budget_duration, written in seconds, minutes, hours, or days such as 30d. If budget_duration is not set, the budget never resets.

The important caveat is in LiteLLM's own docs: every budget is enforced against spend read from the database. On a DB-less deployment the global max_budget fails open. The proxy logs one warning at startup and then keeps serving requests past the limit. Key, team, and user budgets are unavailable there entirely, because virtual keys cannot be resolved without a database. A team that runs LiteLLM in a single container to keep things simple has routing, but no spend ceiling.

When a budget is exceeded on a database-backed proxy, the documented response is an ExceededBudget error. The example in LiteLLM's docs for an end customer over budget returns type auth_error with code 401. Client code that treats every 401 as a credential problem will misreport that event, so handle the message, not only the status.

  • Budget scopes: global proxy, virtual key, internal user, team, end customer.
  • Resets: budget_duration in s, m, h, or d; unset means no reset.
  • Requires Postgres; without it the global budget fails open and per-key budgets do not exist.
  • Customer budgets are global per deployment, shared across every key and team that customer uses.

Portkey: managed control plane, enforcement on the enterprise tier

Portkey's gateway core is open source, and its hosted platform is sold in tiers. Per its pricing page on 2026-10-05, the free Developer tier records 10,000 logs a month with 3-day log retention, and the Production tier costs $49 a month for 100,000 recorded logs, with $9 overages per additional 100,000 and 30-day log retention. Going over the log allowance does not block requests; logs beyond the limit are simply not recorded.

Spend enforcement sits higher. The pricing page lists granular budget and rate limits under Enterprise, and Portkey's usage-limit policy documentation states the feature is available on the Enterprise self-hosting plan only, with gateway version 1.17.0 or later. Those policies cap cost in dollars, tokens, or request count, set at the workspace level and grouped by dimensions such as API key or virtual key. Limits can reset weekly, every Monday at 12:00 AM UTC, monthly, or not at all. When a usage limit is hit, requests are blocked until the reset and the gateway returns 412 Precondition Failed.

A distinct status code is useful. A 412 is easy to route to a budget handler, alert, or fallback path without confusing it for an authentication failure.

The Palo Alto Networks change, and how to choose

Palo Alto Networks completed its acquisition of Portkey and announced general availability of the Prisma AIRS AI Gateway on July 16, 2026, six weeks after closing. Portkey's docs and pricing page now carry the Prisma AIRS name. For buyers this mostly changes the procurement path: the enterprise tier where budget policies live is now sold alongside a security platform, which suits some organizations and slows others.

The practical choice comes down to who runs the control plane and how much you want to pay for enforcement. LiteLLM gives every team hard budgets for the price of operating a proxy and a database. Portkey gives you a hosted UI, logs, and prompt tooling on cheap tiers, and puts cost-based blocking behind an enterprise agreement. Both track spend; neither is built around finance workflows like allocation to cost centers or month-end reconciliation, which is where a FinOps layer such as FrugalAI sits on top of either one.

  • Choose LiteLLM if you need enforced per-team budgets now, can run Postgres, and prefer no vendor contract.
  • Choose Portkey if a managed console matters more than enforcement, or if you are already buying the enterprise tier.
  • On either, test the over-budget path before trusting it: send traffic past a small limit in staging and confirm the request is actually rejected.

Frequently asked questions

Does LiteLLM enforce budgets without a database?

No. LiteLLM's documentation says every budget is enforced against spend stored in the database. Without one, the global max_budget fails open after a single startup warning, and key, team, and user budgets are unavailable.

What does Portkey return when a budget limit is reached?

Portkey's usage-limit policies block further requests until the limit resets and return HTTP 412 Precondition Failed. Its docs list these policies as available on the Enterprise self-hosting plan with gateway 1.17.0 or later.

Is Portkey still an independent product?

Portkey was acquired by Palo Alto Networks, which announced general availability of the Prisma AIRS AI Gateway built on it on July 16, 2026. Portkey's documentation and pricing pages now use the Prisma AIRS AI Gateway name.

Sources and further reading

  1. LiteLLM docs: budgets and rate limits
  2. Portkey pricing
  3. Portkey docs: usage and rate limit policies
  4. Palo Alto Networks: Prisma AIRS AI Gateway general availability

FrugalAI uses primary documentation and published research where possible. Product capabilities and prices can change; verify vendor details before procurement or production changes.