AI API Gateway Check
Check whether an AI API endpoint, model name and key actually work before you write a line of code. Pick a compatibility preset, enter the endpoint and key, type a prompt and press Test API to get the status code, elapsed time and formatted response. Requests that browsers cannot send because of CORS can be routed through a secure server-side proxy, and your key is never saved on our servers.
Use AI API Gateway Check
Read Content
What Is the AI API Gateway Check?
The AI API Gateway Check is a browser tool for testing AI API endpoints in seconds. Instead of installing a client library, writing a script and debugging a confusing error, you pick a compatibility preset, paste an endpoint and an API key, type a prompt, and press one button. You get back the HTTP status code, the elapsed time, and the response body formatted for reading.
It supports the shapes that matter in the AI world. The OpenAI preset targets the standard chat completions endpoint, OpenAI Compatible and OpenAI URL Compatible cover the hundreds of services that reuse that format such as DeepSeek, Groq, Together and local gateways, Anthropic uses the messages endpoint with its own header, Google Gemini uses its generateContent URL with a key in the query string, and Custom sends a simple JSON prompt to any URL you choose.
The tool also works as a small gateway console. You can list the models an endpoint exposes, probe common balance and usage endpoints, add arbitrary request headers, export the whole configuration as a JSON file, import it again later, and keep a history of your last requests in your own browser.
Why Use It — and Who It Is For
Most first attempts at a new AI API fail for boring reasons: a wrong base URL, a trailing slash, an expired key, a model name that was renamed last month, or a browser that silently blocks the call. This tool isolates those problems one at a time.
- Developers verifying a new provider, a proxy gateway or a self-hosted endpoint before integrating it.
- Platform engineers checking whether a key, a model ID or a rate limit is the real cause of a failure.
- QA testers reproducing a reported API error without setting up a local environment.
- Students and hobbyists trying an API key for the first time without writing code.
- Anyone seeing a CORS error in the console who needs a working path to a non browser friendly API.
How This Tool Works
The form runs in your browser. When you press Test API, the page builds a JSON body that matches the selected preset: a messages array for OpenAI style APIs, a max_tokens and messages array for Anthropic, a contents and parts structure for Gemini, or a simple prompt field for Custom. It then adds authentication in the right place: an Authorization bearer header for OpenAI style endpoints, an x-api-key header plus an anthropic-version header for Anthropic, or a key query parameter for Gemini.
There are two ways the request leaves your browser:
- Direct mode (proxy switch off). The page uses a normal fetch to the endpoint. This is fastest and the key never touches our server, but it only works when the provider allows cross origin requests from a browser.
- Secure proxy mode (switch on by default). The request is posted to our server-side proxy, which performs the call and returns the result. This is the route for CORS blocked APIs. The proxy validates the request, forwards it upstream, and returns the status, headers, body, timing breakdown and redirect chain.
The proxy enforces hard rules on the server: only http and https URLs, only ports 80 and 443, only standard HTTP methods, a maximum of 50 headers, 50 query parameters and 50 form fields, a 1 MB request body, a timeout between 1 and 120 seconds, and at most 5 redirects. Hop-by-hop and spoofing headers such as host, cookie, connection and x-forwarded-for are dropped automatically, and response bodies larger than 1 MB are truncated so the browser stays responsive.
Your API key is handled carefully. It is masked by default with a show and hide toggle, it is never written to our database, and with the proxy on it is relayed for that single request and discarded. Key values do stay in your own browser for two features you control: the request history and exported configuration files.
Key Features
- Six compatibility presets - OpenAI, OpenAI Compatible (default), OpenAI URL Compatible, Anthropic, Google Gemini and Custom, each with its own default endpoint, model and authentication scheme.
- Auto format switch - rebuilds the full endpoint URL from a base path so you can edit either one.
- Masked API key field - password style input with show and hide, paste from clipboard, and a live preview line showing the Authorization header that will be sent.
- Secure proxy toggle - route any call through our server when the browser is blocked by CORS.
- Verify SSL toggle - turn certificate verification off for self signed endpoints, with an on screen hint when a certificate error occurs.
- Custom headers - add as many name and value pairs as you need; dangerous headers are filtered out for you.
- Get Models button - issues a GET request to the models path of your endpoint and renders the list, always through the backend proxy so CORS never gets in the way.
- Balance button - tries common usage paths in order (the endpoint itself if it already looks like a usage path, a usage suffix for v1 bases, then origin level usage paths) and shows the first balance-like answer it finds.
- Response panel - status badge, elapsed time, copy button and formatted body.
- Cancel button - aborts a request that is taking too long.
- Local history - the last 50 requests are stored in your browser, click one to reload it, delete individual entries or clear everything.
- Config export, import and sample - save the whole setup as a JSON file named after the upstream host, load it back later, or start from a sample configuration.
How to Use — Step by Step
- Select an API Compatibility preset. OpenAI fills in a default endpoint and the model gpt-4; OpenAI Compatible is the usual starting point for third party gateways.
- Enter the Model ID, for example gpt-4, claude-3-opus or gemini-1.5-flash. Use the clipboard button to paste it if you copied it from a provider dashboard.
- Paste the API Endpoint. Leave the auto format switch on if you prefer editing just the base URL. An inline error appears if the URL is not valid.
- Paste your API Key. It is optional for public endpoints, and required by OpenAI, Anthropic and Gemini. Use the eye icon to check it, then read the Authorization preview line to confirm the header looks right.
- Decide on the two switches. Keep Route through secure proxy on if the provider blocks browser calls, and keep Verify SSL on unless you are testing a self signed certificate.
- Expand Headers and press Add Header if the endpoint needs anything custom.
- Type your prompt in the Prompt box. The default value is ping, which is enough for a connectivity test.
- Press Test API. Watch the status badge and elapsed time, then read the response body. Press Copy to grab it.
- Optional: press Get Models to list available models, or Balance to probe usage endpoints.
- When you are happy with the setup, press Export Config so you can reload the same endpoint, key and headers next time.
Limits and Rules
- The proxy endpoint is rate limited to 30 requests per minute. Direct browser calls are not counted against that limit.
- Allowed methods: GET, POST, PUT, PATCH, DELETE, HEAD and OPTIONS.
- URL length up to 8000 characters, http and https only, ports 80 and 443 only.
- Up to 50 headers (500 characters per name, 5000 per value), 50 query parameters, 50 form fields.
- Request body up to 1 MB; response bodies are truncated at 1 MB. Binary, image, video, audio, PDF and zip responses are returned base64 encoded.
- Timeout is 1 to 120 seconds (30 by default), with at most 5 redirects followed.
- Keys are never stored on our servers. They do live in your browser for history and exported configs, so clear your history and delete exported files if you are sharing a machine.
- Use the tool only with endpoints you are allowed to call. It is a diagnostic instrument, not a way around provider terms, usage caps or access controls.
- There is no captcha and no account requirement.
When to Use It — and When Not To
Use it when you need to know whether an endpoint, model name or key works right now; when a script fails and you want to see the raw status and body; when you are comparing several OpenAI compatible gateways; when you want to list models or check a balance without writing a client; or when a browser fetch fails with a CORS error and you need the proxy path instead.
Do not use it when you need to run a long streaming completion, upload large files, or reproduce an issue that only happens inside your own application code. Streaming responses are returned as a single completed body, so token by token behaviour cannot be observed here. For anything that depends on your exact SDK, retry logic or middleware, reproduce the call in your own stack once this tool has confirmed the endpoint itself is healthy.
Frequently Asked Questions
FAQ
Comments (0)
Describe the issue you encountered so we can investigate and improve the tool.