
Move your team off shared and per-user virtual API keys and onto identity-based access for your AI gateway - no keys to generate, distribute, or rotate for human users.

Virtual API keys solve model routing and budgeting well, but they were never built to be an identity system. Here's where that gap shows up in self-hosted LiteLLM and Bifrost deployments, and what to do instead.
Meet a Pangolin engineer to talk zero trust remote access, open-source, and better access control for your environment.

A general-purpose guide to putting any self-hosted model server - vLLM, Ollama, llama.cpp, LM Studio, LocalAI, or a private downstream gateway - behind Pangolin's identity-aware AI gateway.

Run open-weight models like DeepSeek, Qwen, and Kimi K2 on your own hardware, then reach them securely from anywhere through Pangolin's AI gateway - no API keys, no data leaving your infrastructure.

Give engineers and coding agents access to a self-hosted vLLM or Ollama cluster from one endpoint, authenticated by identity instead of API keys passed around a team.

SSH to private servers through Pangolin with a browser terminal or private CLI over a scoped tunnel. Automatic user provisioning via PAM, without opening port 22 or distributing static keys.
Get a detailed look at how Pangolin provides secure remote access for edge infrastructure, device fleets, and industrial environments.

Learn what MCP tunnels are, how they connect AI agents to private Model Context Protocol servers over outbound-only connections, and why they matter for enterprise security.

Use these remote access policy examples to scope access for admins, contractors, OT systems, internal web apps, and emergency workflows.

Learn how to modernize secure remote access with identity-driven ZTNA, resource-level policy, and reduced public exposure.

Learn what an identity-aware proxy is, how it compares to VPNs and ZTNA, and how Pangolin protects private web apps.

Learn how ZTNA works, why it differs from VPN-based remote access, and how identity, device posture, and policy combine to protect private applications.

Compare Pangolin and Teleport across workforce access, engineering sessions, protocol coverage, and zero trust architecture.

Learn how Pangolin connects sites, resources, identity, and policy to provide zero trust remote access without opening ports.

How a self-hostable open-source access platform and an enterprise cloud security suite differ in architecture, traffic routing, deployment, and fit.

How an open-source, self-hostable remote access platform compares to Cloudflare One (ZTNA, WARP, Access, and Tunnel).

How an identity-based remote access platform and an identity-aware reverse proxy differ in scope, layer, and deployment.
© 2026 Fossorial Inc.
All systems operational