WARDIN VS OPENROUTER

OpenRouter gives every developer 400+ models. Wardin gives the organization the controls — roles, approvals, and a signed receipt for every gateway-routed call.

Once more than a handful of people share an AI budget, the question stops being "can we reach the model?" and becomes "who may spend what, who approved the exception, and can we prove what happened?" OpenRouter is the default answer to the first question: 400+ models behind one OpenAI-compatible API and one credit balance, and — since its 2026 Guardrails launch — real per-key and per-user controls: spend limits that 402 on breach, Zero-Data-Retention routing, model restrictions, prompt-injection defense, DLP. Those controls are shipped and we say so plainly. It has since added Organizations too, with two coarse roles and a member cap. But every one of those guardrails still attaches to a key or a user rather than a role or group: no group-scoped policy, no approval workflow with retained history, no finance-grade ledger, no signed record of each call. Wardin is narrower on models — four provider families, integrated directly — and built for the second question: org-wide RBAC and policy, time-bounded budget approvals that auto-revert and keep their audit history, cost attributed to a team, a key, and a session, and an ED25519-signed, hash-chained receipt for every gateway-routed call. Longer term we see OpenRouter's breadth less as a rival than a plausible upstream for long-tail models behind our routing layer — that integration is built and gated behind a per-tenant opt-in today, pending a verified run against a live OpenRouter key before it's on by default.

FEATURE COMPARISON

Where each product actually stands today.

✓ YES · ~ PARTIAL · ○ ROADMAP · ✕ NO

CAPABILITYWARDINOPENROUTER
Model breadth via one API + one credit balance✕4 provider families, direct integrations (Anthropic, OpenAI, Bedrock, Vertex/Gemini)✓400+ models across every major and long-tail provider, one OpenAI-compatible API, one credit balance
BYOK economics for cross-provider routing✓Yes — bring your own provider keys for the majors, connected and rotated in-product; direct two-party path, no marketplace fee or credit balance✓A plan-dependent monthly BYOK allowance measured in list-price inference cost, then 5%; 5.5% fee on credit top-ups
Per-entity spend & safety guardrails (budget limits + 402s, ZDR routing, model restrictions, prompt-injection defense, DLP)✓Yes, plus org-wide scope — see below✓Yes — shipped as Guardrails in 2026, scoped per individual key/user
Org-level RBAC and group policy rules (not just per-entity limits)✓Yes — roles, group-scoped policies, and model allowlists enforced org-wide~Organizations exist with two coarse roles (Admin/Member) and a documented member cap; guardrails still attach per key/user, not per role or group policy
Finance-grade team/department cost ledger, session-level cost-per-task, time-bounded budget approvals with audit history✓Yes✕Per-key spend limits and dashboards; no approval workflow or session-level attribution
Signed, hash-chained audit receipts✓Yes — ED25519-signed, tamper-evident chain per gateway-routed request✕No
Long-term retention / cold-tier export○In development — built and MinIO-tested, not yet running on a compliance backend✕No documented long-term retention or export product — prompts are not logged by default and no fixed retention period is published
Outcome attribution (accepted work per dollar)✓Yes — quality-gated scoring tied to accepted work✕No
Native Anthropic Messages API for agentic clients (Claude Code, etc.)✓Yes — ANTHROPIC_BASE_URL points straight at us, client unchanged, split cache-token cost accounting✕OpenAI-compatible API only — Anthropic calls pass through a translation layer
Two-party data path to the provider (no extra subprocessor)✓Yes, for the majors — gateway to provider, directly (our own opt-in OpenRouter routing for long-tail models is gated off by default and, when a tenant enables it, adds OpenRouter as a subprocessor for that traffic)✕No — OpenRouter itself sits as an additional subprocessor between you and the model provider
Agentic / MCP tool-call governance (signed receipts for tool invocations)✓Yes — agent registry, tool_allowlist policy, live MCP proxy, signed receipts in the same chain (COMPLY-4)✕No — it publishes an MCP server for coding agents, but no tool-call policy enforcement or signed tool-call record was found
WHERE OPENROUTER IS AHEAD

On breadth, it isn't close: 400+ models across every major and long-tail provider against our four direct families, with BYOK economics (a plan-dependent monthly allowance of list-price inference before a 5% fee; 5.5% on credit top-ups) that no direct-integration product matches. And since Guardrails shipped in 2026, its per-key spend and safety controls are real — it is no longer fair to call OpenRouter ungoverned, and it now has Organizations with Admin/Member roles. What every one of those guardrails has in common is its unit: a key, or a user. The unit Wardin governs is the organization — and the unit it can prove things about is the individual call.

WHERE WARDIN IS AHEAD

Wardin governs at a level OpenRouter's two-tier Organizations don't reach — with role-scoped policy and model allowlists enforced org-wide, time-bounded budget approvals that auto-revert with retained history, and cost attributed to a team, key, and session. Every gateway-routed call emits an ED25519-signed, hash-chained receipt, and agentic clients like Claude Code connect over the native Anthropic Messages API with the cache-token cost split preserved, on a direct two-party path to the majors rather than through an added subprocessor (unless a tenant opts into our own gated OpenRouter routing for long-tail models). OpenRouter's 2026 Guardrails are real but attach to a single key or user rather than a group policy, with no signed record of each call.

WHEN TO CHOOSE EACH

Choose OpenRouter if the job is reach — the widest set of models through one integration and one balance — and per-key guardrails match how your team is structured. Choose Wardin when someone has to answer for the spend: roles and group policy enforced org-wide, budget exceptions approved for a window that auto-revert with their history retained, cost per team, key, and session, and a signed, tamper-evident receipt for every gateway-routed call — including agentic clients like Claude Code on the native Anthropic Messages API, cache-token accounting intact. Breadth gets you to any model. Governance is proving what happened once you got there.

See the enforcement — and the signed receipt — not just the pitch.

Point your SDK at one base URL and get budget hard-stops, policy enforcement, and a signed, hash-chained receipt for every gateway-routed call.

EARLY ACCESS · NO CREDIT CARD REQUIRED