Skip to content

Run any model securely with OpenRouter

You want the freedom to run any model and swap between them without re-plumbing, while every agent run stays isolated from your network and your key. IronClaw's openrouter provider gives you the full OpenRouter model catalog behind a single host-side key, called by an agent that runs inside a per-session gVisor sandbox with network=none.

Where your key lives

The sandbox holds no credential. It reaches OpenRouter only through the host model-proxy unix socket, which stamps each forwarded request with your OPENROUTER_API_KEY on the way out. The key never enters the sandbox image, its environment, or its filesystem. See Security and isolation.

1. See it run with no credentials first

Prove the sandbox loop end to end with the offline demo (one Docker command, no key) via the zero-credential quickstart, then point a group at OpenRouter below.

2. Set your OpenRouter key host-side

Set one key in the control-plane environment, never the sandbox:

export OPENROUTER_API_KEY=sk-or-…

3. Point an agent group at OpenRouter

Opt a group in explicitly (a present key never forces any group to use it):

  • Provider: openrouter
  • Model: any OpenRouter model id (for example anthropic/claude-3.5-sonnet, openai/gpt-4o, or meta-llama/llama-3.1-70b-instruct)

Set it on the group's Provider and Model fields in the web console, or submit the change with ironctl and approve it at the human gateway so the switch lands on the audit log. Because OpenRouter fronts many vendors, you can move a group between models by changing one field.

Why "securely" is the point

OpenRouter gives you model choice. IronClaw makes each of those models safe to hand to an autonomous agent.

  • gVisor per session. Each conversation gets a fresh sandbox with a user-space kernel and network=none. A compromised agent cannot reach your machine or the internet.
  • Least-privilege egress. Only the OpenRouter host is allowlisted on the model-proxy.
  • Credential custody on the host. The key is stamped in the proxy. The agent sees a model reply, never the secret.

See the containment and isolation proof and the full threat model.

See also