Sign InOpen Brain
VercelEngineering PostOfficial Source

How Tailscale built a customer-facing model router on AI Gateway

Tailscale tied model access and ephemeral agent sandboxes to network identity, without issuing keys to agents. It is a concrete pattern for combining gateways, access control, and isolated execution.

Vercel · Sep 11, 2026
Open Source Open MarkdownOpen JSON
Source Summary

Aperture gives customers one API for **hundreds of models**, with access granted or revoked through tailnet identity. AI Gateway returns usage and cost per request, while Vercel Sandbox provides ephemeral agent execution without issuing a key to the agent.

Practical Implication

Builders should treat routing, identity, retention policy, and execution isolation as one system. The described flow validates identity before work begins, supports global or per-request **zero data retention**, and shuts the sandbox down afterward.

Agent-Ready Context
Aperture gives customers one API for **hundreds of models**, with access granted or revoked through tailnet identity. AI Gateway returns usage and cost per request, while Vercel Sandbox provides ephemeral agent execution without issuing a key to the agent.

Builders should treat routing, identity, retention policy, and execution isolation as one system. The described flow validates identity before work begins, supports global or per-request **zero data retention**, and shuts the sandbox down afterward.

This is a vendor case study rather than an independent security assessment. Tailscale reports moving from prototype to paying customers in **months**, but the material gives no benchmark for isolation, latency, or total cost against competing gateways and sandboxes.
Connected Context · Feed7 Judgment

This makes gateway design a security architecture rather than merely a model-selection convenience: identity, per-request retention, cost reporting, credential handling, and sandbox teardown are joined at one boundary. It strengthens external-control and least-privilege guidance with a deployed customer flow, but the vendor case study still leaves isolation strength, latency, cost, and failure behavior unvalidated.

Security Firewall for Agents — Ryan Dahl, DenoDeno reinforces the principle that credentials and policy must remain outside an untrusted agent; Aperture applies that principle by validating identity and withholding model keys from sandboxed execution.Unlock Agent Autonomy: The Runtime for AI-Native Systems — Tushar Jain, DockerDocker’s task-scoped capability model supplies the broader least-privilege rationale for Aperture’s identity-gated access and ephemeral execution, while Aperture does not claim Docker’s intent-matching layer.Claude Fable 5.1 now available on AI GatewayFable’s mandatory retention shows why Aperture’s global or per-request zero-data-retention policy must constrain route eligibility rather than be treated as a gateway-wide assumption.From fork() to Fleet: Designing an Agent Sandbox Cloud — Abhishek Bhardwaj, OpenAIThe sandbox-cloud design identifies stronger isolation, persistence, and recovery properties that Aperture’s ephemeral sandbox flow does not benchmark or specify.
Context Map
infrasecuritycoding#gateways#sandboxing#agent-reliability
Uncertainty
This is a vendor case study rather than an independent security assessment. Tailscale reports moving from prototype to paying customers in **months**, but the material gives no benchmark for isolation, latency, or total cost against competing gateways and sandboxes.