These pages describe the intended behaviour of the gateway. The open-source release and the enterprise edition are being split out; details will be updated when the first release ships.
Failover
Ordered fallback chains, per-attempt budgets, and what triggers a move to the next target.
A route may declare an ordered chain of targets. Each target is attempted in turn until one returns a successful response.
The chain
A chain is a list of targets attached to a route in the console. A target names a provider and, optionally, a model and a credential.
route POST /v1/messages
├─ 1. anthropic claude-sonnet-5-5
├─ 2. bedrock claude-sonnet-5-5
└─ 3. openai gpt-6-sol
Targets are attempted in listed order. The first target that returns a 2xx response ends
the chain. Reordering the list is a console action and applies to in-flight traffic.
Attempt budgets
Each attempt carries its own timeout. A slow primary cannot consume the whole request deadline, because the deadline is divided across the chain rather than shared by it.
| Budget | Applies to | Where it is set |
|---|---|---|
| Per attempt | One target, including retries against it | On the target |
| Per request | The whole chain, including every attempt | On the route |
When the per-request budget is exhausted, the request ends with 504 and the envelope
describes each attempt that was made.
Retries and rotation
A failed attempt is classified before any decision is taken. The class decides whether the same target is retried, whether the credential is rotated, or whether the chain advances.
- Transient failures retry the same target with exponential backoff and jitter.
- Credential-bound failures rotate to another key in the pool instead of waiting.
- Request-shaped failures do not retry at all; they end the request, because the same failure will occur against every target.
The full table is on the circuit breaking page, which shares the same classification.
When every target fails
The client receives a 503 whose body lists each attempt: the target, the status, and a
truncated copy of the upstream response. The chain is recorded in order, including retries,
so the reason for the final failure is readable without correlating logs.