Route Claude CLI traffic through AI Gateway and Gemini

Incompatible with
on-prem
Tags
Minimum Version
AI Gateway - 2.0
Previous Versions of this page
TL;DR

Create an AI Model Provider entity to store your Gemini API key, create an AI Model entity with an Anthropic-compatible format that routes to Gemini through that provider, then point Claude CLI’s ANTHROPIC_BASE_URL at your local AI Gateway endpoint so all LLM requests pass through the gateway for monitoring and control.

Prerequisites

This is a Konnect tutorial and requires a Konnect personal access token.

  1. Create a new personal access token by opening the Konnect PAT page and selecting Generate Token.

  2. Export your token to an environment variable:

    export KONNECT_TOKEN='YOUR_KONNECT_PAT'
  3. Run the AI Gateway quickstart script to automatically provision a control plane and data plane in Kong Konnect, and configure your environment:

    curl -Ls https://get.konghq.com/ai | bash -s -- -k $KONNECT_TOKEN 

This sets up a AI Gateway control plane named ai-quickstart, provisions a local data plane, and prints out the following environment variables export:

export AI_GATEWAY_ID=your-gateway-id
export KONNECT_TOKEN=$KONNECT_TOKEN
export KONNECT_CONTROL_PLANE_NAME=ai-quickstart
export KONNECT_CONTROL_PLANE_URL=https://us.api.konghq.com
export KONNECT_PROXY_URL='http://localhost:8000'

Copy and paste these into your terminal to configure your session.

This tutorial uses kongctl to manage Konnect resources programmatically. We recommend keeping kongctl up to date with the latest version (1.13.0).

  1. Install kongctl from developer.konghq.com/kongctl.
  2. Verify the installation:

    kongctl version
  1. Create a Gemini API key in Google AI Studio.
  2. Export the API key as a variable:

    export GEMINI_API_KEY='YOUR_GEMINI_API_KEY'
  1. Install Claude:
     curl -fsSL https://claude.ai/install.sh | bash
  2. Verify the installation:
     claude --version

Create an AI Model Provider entity

Create an AI Model Provider entity to define your connection and store your authentication credentials:

kongctl apply -f - --auto-approve --pat "$KONNECT_TOKEN" << 'EOF'
ai_gateway_model_providers:
  - ref: my-gemini-account
    ai_gateway: !lookup {id: !env AI_GATEWAY_ID}
    name: my-gemini-account
    display_name: "my-gemini-account"
    type: gemini
    config:
      auth:
        type: basic
        headers:
        - name: x-goog-api-key
          value: !secret {source: !env GEMINI_API_KEY}
EOF

ai-quickstart references the AI Gateway created by the quickstart script in the prerequisites above, instead of creating a new one.

The AI Model Provider uses the following settings:

  • type: gemini: Specifies that this provider connects to the Gemini service using Gemini’s standard API format.
  • name: my-gemini-account: A unique identifier that AI Models will reference to route requests through this provider.
  • config.auth: Stores your Gemini API key. value: !secret {source: !env GEMINI_API_KEY} loads the value from your environment at apply time instead of embedding it in the YAML, and kongctl redacts it in plan and diff output. AI Gateway securely manages this credential and injects it into upstream requests automatically, eliminating the need for clients to pass API keys.

Create an AI Policy entity

Create an AI Policy entity using request transformer to remove extra fields that Gemini’s API does not support.

kongctl apply -f - --auto-approve --pat "$KONNECT_TOKEN" << 'EOF'
ai_gateway_policies:
  - ref: strip-claude-beta-info
    ai_gateway: !lookup {id: !env AI_GATEWAY_ID}
    name: strip-claude-beta-info
    display_name: "strip-claude-beta-info"
    type: request-transformer-advanced
    config:
      remove:
        headers:
          - anthropic-beta
          - authorization
          - x-api-key
        querystring:
          - beta
        body:
          - output_config
          - context_management
          - mcp_servers
          - container
          - service_tier
          - reasoning_effort
EOF

Claude Code beta features vary by version and may add other incompatible fields over time. If you still see an error mentioning an unexpected field after applying this Policy, add that field to the appropriate remove list and re-apply.

The AI Policy uses the following settings:

  • type: request-transformer-advanced: Modifies requests before AI Gateway forwards them upstream.
  • config.remove.headers: Removes the anthropic-beta, authorization, and x-api-key headers.
  • config.remove.querystring: Removes the beta query string parameter.
  • config.remove.body: Removes the output_config, context_management, mcp_servers, container, service_tier, and reasoning_effort body fields.

Don’t strip model: AI Gateway uses that field to select the target, and removing it breaks routing.

Create an AI Model entity

Create an AI Model entity to declare which upstream models are available, configure how client requests are routed, and specify which AI Model Provider to use:

kongctl apply -f - --auto-approve --pat "$KONNECT_TOKEN" << 'EOF'
ai_gateway_model_providers:
  - ref: my-gemini-account
    ai_gateway: !lookup {id: !env AI_GATEWAY_ID}
    name: my-gemini-account
    display_name: "my-gemini-account"
    type: gemini
    config:
      auth:
        type: basic
        headers:
        - name: x-goog-api-key
          value: !secret {source: !env GEMINI_API_KEY}
ai_gateway_policies:
  - ref: strip-claude-beta-info
    ai_gateway: !lookup {id: !env AI_GATEWAY_ID}
    name: strip-claude-beta-info
    display_name: "strip-claude-beta-info"
    type: request-transformer-advanced
    config:
      remove:
        headers:
          - anthropic-beta
          - authorization
          - x-api-key
        querystring:
          - beta
        body:
          - output_config
          - context_management
          - mcp_servers
          - container
          - service_tier
          - reasoning_effort
ai_gateway_models:
  - ref: my-claude-gemini
    ai_gateway: !lookup {id: !env AI_GATEWAY_ID}
    name: my-claude-gemini
    display_name: "my-claude-gemini"
    type: model
    formats:
      - type: anthropic
    config:
      route:
        paths:
          - /
        model:
          body_param: model
          values:
            - my-claude-gemini
    targets:
      - name: gemini-2.5-flash
        provider: !ref my-gemini-account#name
        config:
          type: gemini
    policies:
      - !ref strip-claude-beta-info#name
    capabilities:
      - generate
EOF

The AI Model uses the following settings:

  • type: model: Specifies this is a synchronous model for request/response workloads.
  • name: my-claude-gemini: A unique identifier for this model.
  • formats: [type: anthropic]: Declares that this model accepts requests in Anthropic-compatible format, matching what Claude Code sends natively, even though the upstream model is Gemini.
  • config.route.paths: [/]: Configures the custom base path where this model’s routes will be accessible. Setting this to a unique value avoids clashes when you have multiple AI Models.
  • capabilities: [generate]: Enables the text generation capability. For a model using the anthropic format, the generate capability creates a /messages endpoint matching Anthropic’s native Messages API, so combined with your base path, clients send requests to /v1/messages.
  • targets: Specifies which upstream AI Model Provider model to route requests to. Here, provider: !ref my-gemini-account#name references the AI Model Provider we created earlier, and name: gemini-2.5-flash specifies which Gemini model to call upstream.
  • policies: [!ref strip-claude-beta-info#name]: Attaches the AI Policy created earlier so it applies to every request to this AI Model.

Run Claude Code

Claude Code’s experimental beta features send fields that Gemini rejects even with the AI Policy in place. Disable them, then start a session pointed at your local AI Gateway endpoint:

export CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS=1
export ANTHROPIC_BASE_URL=http://localhost:8000/

CLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT=1 \
  claude --allowedTools "WebSearch,Read" --model "my-claude-gemini"

And ask a question to confirm that requests reach AI Gateway.

Tell me about the Madrid Skylitzes manuscript.

Claude Code might prompt you approve its web search for answering the question. When you select Yes, Claude will produce a full-length response to your request:

The Madrid Skylitzes is a remarkable 12th-century illuminated Byzantine
manuscript that represents one of the most important surviving examples
of medieval historical documentation. Here are the key details:

What it is

The Madrid Skylitzes is the only surviving illustrated manuscript of John
Skylitzes' "Synopsis of Histories" (Σύνοψις Ἱστοριῶν), which chronicles
Byzantine history from 811 to 1057 CE - covering the period from the death
of Emperor Nicephorus I to the deposition of Michael VI.

Artistic Significance

- 574 miniature paintings (with about 100 lost over time)
- Lavishly decorated with gold leaf, vibrant pigments, and intricate
detailing
- Depicts everything from imperial coronations and battles to daily life
in Byzantium
- The only surviving Byzantine illuminated chronicle written in Greek

Unique Collaboration

The manuscript is believed to be the work of 7 different artists from
various backgrounds:
- 4 Italian artists
- 1 English or French artist
- 2 Byzantine artists

Help us make these docs great!

Kong Developer docs are open source. If you find these useful and want to make them better, contribute today!