How Tailscale built a customer-facing model router on AI Gateway
Tailscale tied model access and ephemeral agent sandboxes to network identity, without issuing keys to agents. It is a concrete pattern for combining gateways, access control, and isolated execution.
Aperture gives customers one API for **hundreds of models**, with access granted or revoked through tailnet identity. AI Gateway returns usage and cost per request, while Vercel Sandbox provides ephemeral agent execution without issuing a key to the agent.
Builders should treat routing, identity, retention policy, and execution isolation as one system. The described flow validates identity before work begins, supports global or per-request **zero data retention**, and shuts the sandbox down afterward.
Aperture gives customers one API for **hundreds of models**, with access granted or revoked through tailnet identity. AI Gateway returns usage and cost per request, while Vercel Sandbox provides ephemeral agent execution without issuing a key to the agent. Builders should treat routing, identity, retention policy, and execution isolation as one system. The described flow validates identity before work begins, supports global or per-request **zero data retention**, and shuts the sandbox down afterward. This is a vendor case study rather than an independent security assessment. Tailscale reports moving from prototype to paying customers in **months**, but the material gives no benchmark for isolation, latency, or total cost against competing gateways and sandboxes.
This turns several separate infrastructure controls into one customer-facing operating pattern: identity is checked before routing, retention can be selected globally or per request, credentials stay outside the agent, and execution ends with sandbox shutdown. It reinforces external policy enforcement and isolation, while the vendor case study leaves comparative security, latency, and cost unvalidated.