{"_self":{"principle":"Self-explaining payload — no external context required. This _self block describes what you are reading and where to look next.","widget":"article_topology","feature":"topology","name":"Article topology","what":"Claims, sources, anecdotes, user reports, related embeds, question graph slice — for ask/ROUTER.","contains":"claims, sources, anecdotes, question_graph slice","slug":"cloudflare-unified-billing","urls":{"read":"https://miscsubjects.com/api/articles/cloudflare-unified-billing/topology"},"how_to_use":"Claims, sources, anecdotes, user reports, related embeds, question graph slice — for ask/ROUTER.","write":null,"imessage":null,"router_tag":null,"proof_chain":[{"step":1,"claim":"Articles are voxel graphs of tiered claims, not prose blobs.","verify":"https://miscsubjects.com/api/articles/constitution"},{"step":2,"claim":"Claims link to hash-chained sources via source_ids.","verify":"https://miscsubjects.com/api/articles/cloudflare-unified-billing/sources"},{"step":3,"claim":"Ask reads topology; ingest/claim append to ledger.","verify":"https://miscsubjects.com/api/protocol"},{"step":4,"claim":"Models queue growth: populate → collaborate → repair → reflex.","verify":"https://miscsubjects.com/api/protocol/grow"},{"step":5,"claim":"Graph proves its own shape (reflex) and $/claim (yield).","verify":"https://miscsubjects.com/graph.html?layer=reflex"},{"step":6,"claim":"Full feature index + _explain on every API response.","verify":"https://miscsubjects.com/api/articles/system-map"}],"related_features":[{"id":"ask","name":"Ask protocol","what":"Answer only from topology; creates question_node with gaps and ingest_hint.","urls":{"read":"https://miscsubjects.com/api/articles/cloudflare-unified-billing/prompts","write":"https://miscsubjects.com/api/protocol/ask"}},{"id":"graph_topology","name":"Cross-article graph","what":"Merged claims/sources across condition+stack slugs for one question.","urls":{"read":"https://miscsubjects.com/api/articles/cloudflare-unified-billing/graph-topology?question=..."}},{"id":"question_graph","name":"Question graph","what":"Ask nodes (questions + gaps) and evidence_ingest nodes (pasted model output).","urls":{"read":"https://miscsubjects.com/api/articles/cloudflare-unified-billing/question-graph","write":"https://miscsubjects.com/api/protocol/ask"}},{"id":"voxels","name":"Voxel graph","what":"Claims as atoms, sources as edges (supported_by, posted_by). Per-claim provenance.","urls":{"read":"https://miscsubjects.com/api/articles/cloudflare-unified-billing/voxels","write":"https://miscsubjects.com/api/protocol/claim"}}],"system_map":"https://miscsubjects.com/api/articles/system-map","system_map_markdown":"https://miscsubjects.com/api/articles/system-map?format=markdown","not_medical_advice":true},"_explain":{"feature":"topology","name":"Article topology","what":"Claims, sources, anecdotes, user reports, related embeds, question graph slice — for ask/ROUTER.","why":"Every feature is auditable collective intelligence","how":"Claims, sources, anecdotes, user reports, related embeds, question graph slice — for ask/ROUTER.","model":null,"verifies":null,"urls":{"read":"https://miscsubjects.com/api/articles/cloudflare-unified-billing/topology"},"imessage":null,"router":null,"related":[{"id":"ask","what":"Answer only from topology; creates question_node with gaps and ingest_hint."},{"id":"graph_topology","what":"Merged claims/sources across condition+stack slugs for one question."},{"id":"question_graph","what":"Ask nodes (questions + gaps) and evidence_ingest nodes (pasted model output)."},{"id":"voxels","what":"Claims as atoms, sources as edges (supported_by, posted_by). Per-claim provenance."}],"not_medical_advice":true},"slug":"cloudflare-unified-billing","title":"Cloudflare Unified Billing: the 5% is on the credits, and the 402 is one gateway toggle","register":"essay","tags":["tooling","cloudflare","billing","ai-gateway","unified-billing","llm-routing"],"updated_at":"2026-07-26T05:37:32.278Z","body_excerpt":"Cloudflare Unified Billing is a way of paying for model inference in which Cloudflare, not you, holds the credentials for OpenAI, Anthropic, Google AI Studio, Google Vertex AI, xAI and Groq. You load dollar credits onto your Cloudflare account, send an ordinary HTTPS request to `api.cloudflare.com` carrying one Cloudflare API token, name a model as `provider/model`, and Cloudflare authenticates to the upstream provider, pays them, and deducts the cost from your credit balance. No `OPENAI_API_KEY` or `ANTHROPIC_API_KEY` exists anywhere in the request path. Cloudflare's words: \"Both deduct credits from your account automatically without requiring provider API keys.\"\n\n## Evidence status\n\n**Observed** marks first-party measurements or runtime receipts from the named environment.\n**Derived** marks arithmetic calculated from cited inputs. **Specified** marks vendor or standards\ndocumentation. **Implemented** and **deployed** name code and live-state evidence, respectively.\n**Reproduced** means the stated procedure was rerun. **Externally attested** marks operator reports;\nthose reports show that an experience occurred, not that it is universal.\n\n## Terms this page uses\n\n| Term | Meaning |\n| --- | --- |\n| Unified Billing | Cloudflare authenticates and pays the provider; you pay Cloudflare. Appears as `wholesale: true` in the gateway API and log rows. |\n| BYOK | Bring Your Own Keys — your provider key is stored in Cloudflare Secrets Store and forwarded; the provider bills you. |\n| AI Gateway | The proxy in front of the model call: logging, caching, retries, rate limits, spend limits. Free on all plans. Setup: [/a/cloudflare-ai-gateway-setup](/a/cloudflare-ai-gateway-setup). |\n| Authenticated gateway | A gateway with its `authentication` setting on, which then demands a Cloudflare API token on every request. |\n| Credits | Prepaid dollars on the Cloudflare account. Bought at a 5% surcharge; spent at the provider's own per-token rate. |\n| Neurons | The unit Workers AI bills in, $0.011 per 1,000. A separate ledger from credits. |\n\n## The 5% lands on the money, not on the traffic\n\nCloudflare states it in one sentence: \"A 5% fee is applied to all credits purchased through Unified Billing. For example, a $100 credit purchase will result in a $105 charge. Inference pricing from providers is passed through with no markup — you pay the same per-token rates as you would directly with the provider.\"\n\nThat is a surcharge at top-up, not a per-request markup. Nothing you change inside a request moves it, because every dollar you eventually spend on tokens cost $1.05 to acquire.\n\nTwo public statements about that number disagree; both are printed here rather than reconciled away. On Hacker News, **yencabulator** corrected a commenter who had called Cloudflare's gateway the free option: \"Free? They take the same 5% fee as OpenRouter does.\" Right about Cloudflare, imprecise about OpenRouter. OpenRouter's FAQ uses the same shape — it \"charges a fee when you purchase credits\" and passes provider pricing through \"without any markup\" — but the rate rendered on that page is **5.5% with a $0.80 minimum** for cards, 5% for crypto. On $100 that is $105.00 against $105.50; on $20, $21.00 against $21.10. Same mechanism, different price, and \"the same 5%\" is close rather than exact.\n\nThe number was hard to find at all, which is why it was disputed. **bm-rf**, reading the launch docs: \"Not seeing any pricing info on the models[1] page. Wonder how much of a lift this is over paying providers directly. Perhaps Cloudflare is doing this at cost? Also interesting that zero data retention is not on by default\". **6thbit**, same thread: \"i wonder about their princing and potential markup on top of token usage?i presume they wont let you \\\"manage all your AI spend in one place\\\" for free.\" Both were guessing. The 5% is on the Unified Billing feature page, not on the model catalogue they were reading.\n\n## The arithmetic for 100 million input and 20 million output tokens a m","ranking":"safety-first (interaction_risk/limitations), then quote-gated effective_weight","claims":[{"id":"c17","text":"The report that /ai/v1/responses returns 402 on an authenticated gateway is open and uncommented on cloudflare/ai, and did not reproduce on this account with openai/gpt-4.1-mini on 2026-07-26.","tier":"mechanistic","section":"The 402 comes from one setting","interaction_risk":false,"status":"active","source_ids":["s11","s24"],"why_material":"A reader hitting the same wall needs to know the report exists, is unresolved, and is not universally reproducible.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.3,"quote_gated":false},{"id":"c19","text":"Cloudflare's launch documentation carried no pricing on the model catalogue page, which is why operators publicly assumed a per-token markup that does not exist.","tier":"anecdotal","section":"The 5% lands on the money, not on the traffic","interaction_risk":false,"status":"active","source_ids":["s15","s16"],"why_material":"It explains why the number is disputed at all and where a reader should look for it.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.3,"quote_gated":false},{"id":"c20","text":"Teams have merged changes that delete provider API keys from their code in favour of a single Cloudflare API token with AI Gateway Run permission.","tier":"anecdotal","section":"Five routes, ranked","interaction_risk":false,"status":"active","source_ids":["s17","s18"],"why_material":"It is the evidence that the auth collapse, not the price, is what people adopt this for.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.3,"quote_gated":false},{"id":"c1","text":"Unified Billing means Cloudflare authenticates and pays the upstream provider, so a client holds one Cloudflare API token and no provider keys.","tier":"system","section":"What Unified Billing is","interaction_risk":false,"status":"active","source_ids":["s1","s17","s18"],"why_material":"Without this the reader cannot tell the feature apart from a proxy that forwards their own key.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c2","text":"The only Cloudflare charge is a 5% surcharge on credits purchased; AI Gateway itself is free on all plans and inference is passed through at the provider's per-token rate.","tier":"system","section":"The 5% lands on the money, not on the traffic","interaction_risk":false,"status":"active","source_ids":["s1","s4"],"why_material":"This is the entire price of the arrangement and the number the whole decision turns on.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c3","text":"Models named @cf/vendor/model are billed as Workers AI Neurons at $0.011 per 1,000 and are explicitly not charged through Unified Billing.","tier":"system","section":"Model ids and endpoints decide the billing lane","interaction_risk":false,"status":"active","source_ids":["s1","s25","s7"],"why_material":"A mixed setup produces two separate line items, which a reader should expect rather than debug.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c4","text":"Unified Billing requires both loaded credits and a gateway with authentication turned on, created through Settings then Create authentication token then the Authenticated Gateway toggle.","tier":"system","section":"Five things that must be true before a single request bills","interaction_risk":false,"status":"active","source_ids":["s1","s2"],"why_material":"These are the two prerequisites, and the second one is the cause of the most common failure.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c5","text":"A provider/model request routed at a gateway with authentication off returns HTTP 402 with code 2021 and the message 'Gateway authentication is required to use unified billing'.","tier":"system","section":"The 402 comes from one setting","interaction_risk":false,"status":"active","source_ids":["s11","s2","s21"],"why_material":"It is the single most common failure and it presents as a model problem rather than a settings problem.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c6","text":"Four REST endpoints accept Unified Billing traffic — /ai/run, /ai/v1/chat/completions, /ai/v1/responses and /ai/v1/messages — and only /ai/v1/messages refuses Workers AI @cf/ ids outright.","tier":"system","section":"Model ids and endpoints decide the billing lane","interaction_risk":false,"status":"active","source_ids":["s19","s3"],"why_material":"Choosing the wrong endpoint for the model family is the second most common failure.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c7","text":"With Unified Billing an anthropic/* model id is validated by Anthropic's schema, so an OpenAI-shaped body carrying role 'system' in messages[0] fails with 'Invalid value at messages[0].role: Invalid option: expected one of \"user\"|\"assistant\"'.","tier":"system","section":"anthropic/* gets Anthropic's validation rules","interaction_risk":false,"status":"active","source_ids":["s12","s13","s22","s3"],"why_material":"This is the exact point where the OpenAI-compatible veneer leaks, and the error names a field the client author never set.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c8","text":"A Unified Billing model id is written provider/model while a Workers AI id is written @cf/vendor/model, and the Workers AI form additionally requires the cf-aig-gateway-id header.","tier":"system","section":"Model ids and endpoints decide the billing lane","interaction_risk":false,"status":"active","source_ids":["s3"],"why_material":"Without the id convention a reader cannot predict which ledger a call lands in.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c9","text":"The HTTP API covers OpenAI, Anthropic, Google AI Studio, Google Vertex AI, xAI and Groq.","tier":"system","section":"What is covered, and the four places the documentation stops","interaction_risk":false,"status":"active","source_ids":["s1"],"why_material":"Coverage is the reason to adopt the arrangement, so the list has to be stated rather than implied.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c10","text":"Logged per-request cost equals token counts multiplied by the provider's published per-million rate exactly, on both openai/gpt-4.1-mini and anthropic/claude-sonnet-5.","tier":"system","section":"What one billed request actually leaves behind","interaction_risk":false,"status":"active","source_ids":["s10","s23","s8"],"why_material":"It is the only test of the no-markup claim, and it is testable from data the account already holds.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c11","text":"Zero data retention applies only to Unified Billing requests on Cloudflare-managed credentials, is off by default, is supported for OpenAI and Anthropic only, and falls back to the non-ZDR configuration silently for other providers.","tier":"system","section":"What is covered, and the four places the documentation stops","interaction_risk":false,"status":"active","source_ids":["s1","s15"],"why_material":"A reader with a data-handling constraint would otherwise assume the default is safe.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c12","text":"Spend limits cover Unified Billing and BYOK, block with HTTP 429, and are eventually consistent, so concurrent bursts can exceed the limit before enforcement catches up.","tier":"system","section":"What is covered, and the four places the documentation stops","interaction_risk":false,"status":"active","source_ids":["s5"],"why_material":"It is the only cost control available and its failure mode is a 429 that looks like rate limiting.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c13","text":"Workers AI @cf/ models keep returning 200 on the same gateway that returns 402 for provider/model, so a working @cf/ call is not evidence the gateway is configured correctly.","tier":"system","section":"The 402 comes from one setting","interaction_risk":false,"status":"active","source_ids":["s2","s21","s25"],"why_material":"It is the false signal that sends people to debug the model id instead of the gateway setting.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c14","text":"BYOK requires an authenticated gateway too, so switching off Unified Billing does not remove the setting that caused the 402.","tier":"system","section":"Five routes, ranked","interaction_risk":false,"status":"active","source_ids":["s6"],"why_material":"A reader treating BYOK as the escape hatch from the 402 would make the same request fail a second way.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c15","text":"On 100,000,000 input and 20,000,000 output tokens a month of openai/gpt-4.1-mini the inference is $72.00 and the Unified Billing fee is $3.60, against $72.00 and no fee for BYOK.","tier":"system","section":"The arithmetic","interaction_risk":false,"status":"active","source_ids":["s10","s16","s20","s23","s8"],"why_material":"The fee is meaningless without a denominator, and this is the arithmetic that decides which route a reader takes.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c16","text":"Cloudflare charges a flat 5% on credit purchases while OpenRouter's published card fee is 5.5% with a $0.80 minimum, so the widely repeated claim that they charge the same 5% is close but not exact.","tier":"system","section":"The 5% lands on the money, not on the traffic","interaction_risk":false,"status":"active","source_ids":["s1","s14","s9"],"why_material":"Two public statements disagree and the page has to publish both rather than pick one.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c18","text":"Removing the system message makes the OpenAI-shaped request succeed, and moving it to a top-level system field on /ai/v1/messages keeps the system prompt and succeeds.","tier":"system","section":"anthropic/* gets Anthropic's validation rules","interaction_risk":false,"status":"active","source_ids":["s12","s13","s22"],"why_material":"Naming the failure without giving both working bodies leaves the reader exactly where they started.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c21","text":"A successful anthropic/* call on /ai/v1/chat/completions returns no content field and reports usage as input_tokens and output_tokens rather than OpenAI's prompt_tokens and completion_tokens.","tier":"system","section":"anthropic/* gets Anthropic's validation rules","interaction_risk":false,"status":"active","source_ids":["s22"],"why_material":"A client that parses the OpenAI envelope will read an empty answer and a missing key without any error to explain it.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c22","text":"Every Unified Billing log row carries wholesale true and byok null, which is how a request's billing lane is confirmed after the fact.","tier":"system","section":"What one billed request actually leaves behind","interaction_risk":false,"status":"active","source_ids":["s23"],"why_material":"It is the only after-the-fact way to prove which credential paid for a given call.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false}],"sources":[{"id":"s1","type":"publisher_documentation","url":"https://developers.cloudflare.com/ai-gateway/features/unified-billing/","title":"Cloudflare AI Gateway — Unified Billing","quote":"A 5% fee is applied to all credits purchased through Unified Billing. For example, a $100 credit purchase will result in a $105 charge. Inference pricing from providers is passed through with no markup — you pay the same per-token rates as you would directly with the provider.","summary":"The fee, the no-markup pass-through, the two prerequisites (credits loaded, gateway authenticated), the supported provider list, the exclusion of Workers AI @cf/ models, the negative-balance caution, and the ZDR section. Positive on clarity of the fee, silent on the 402.","claim_ids":["c1","c11","c16","c2","c3","c4","c9"]},{"id":"s2","type":"publisher_documentation","url":"https://developers.cloudflare.com/ai-gateway/configuration/authentication/","title":"Cloudflare AI Gateway — Authenticated Gateway","quote":"The `AI Gateway Read`, `Run`, and `Edit` permissions cannot be restricted to a single gateway — unlike R2, which supports per-bucket scoping. Any token with `AI Gateway Run` can send requests through every gateway in the account, including any configured with stored provider keys through Bring Your Own Keys (BYOK), consuming those credentials.","summary":"The exact dashboard click path for turning authentication on, and the warning that AI Gateway token permissions are account-scoped. Also carries the behaviour table whose 'Off / No header → Request succeeds' row is contradicted by the measured 402 for Unified Billing. Negative on that row.","claim_ids":["c13","c4","c5"]},{"id":"s3","type":"specification","url":"https://developers.cloudflare.com/ai-gateway/usage/rest-api/","title":"Cloudflare AI Gateway — REST API","quote":"The `/ai/v1/messages` endpoint strictly uses Anthropic's API schema and supports routing to Anthropic and other third-party models. Workers AI models (`@cf/`) do not support this schema.","summary":"The reference the endpoint and model-id behaviour comes from: four endpoints with a per-endpoint support matrix, the author/model vs @cf/author/model naming rule, the cf-aig-gateway-id requirement, and the per-request cf-aig-* header table.","claim_ids":["c6","c7","c8"]},{"id":"s4","type":"publisher_documentation","url":"https://developers.cloudflare.com/ai-gateway/reference/pricing/","title":"Cloudflare AI Gateway — Pricing","quote":"AI Gateway's core features available today are offered for free, and all it takes is a Cloudflare account and one line of code to get started. Core features include: dashboard analytics, caching, and rate limiting.","summary":"Establishes the zero in the BYOK column of the money table: the gateway itself costs nothing, so the only Cloudflare charge in the Unified Billing route is the 5% credit surcharge.","claim_ids":["c2"]},{"id":"s5","type":"publisher_documentation","url":"https://developers.cloudflare.com/ai-gateway/features/spend-limits/","title":"Cloudflare AI Gateway — Spend limits","quote":"Spend limits are eventually consistent. The current request's cost is recorded after completion, so a burst of concurrent requests can briefly exceed the limit before enforcement catches up.","summary":"Confirms spend limits cover both Unified Billing and BYOK, that they block with 429, and that they are computed from the same per-request cost field the log rows carry. The eventual-consistency admission is why a 429 can arrive under budget.","claim_ids":["c12"]},{"id":"s6","type":"publisher_documentation","url":"https://developers.cloudflare.com/ai-gateway/configuration/bring-your-own-keys/","title":"Cloudflare AI Gateway — BYOK (Store Keys)","quote":"Ensure your gateway is authenticated.","summary":"The alternative route. Keys live in Secrets Store and the provider bills you directly — and the prerequisite list shows BYOK requires the same authenticated gateway Unified Billing does, so switching lanes does not remove that step.","claim_ids":["c14"]},{"id":"s7","type":"publisher_documentation","url":"https://developers.cloudflare.com/workers-ai/platform/pricing/","title":"Cloudflare Workers AI — Pricing","quote":"Workers AI is included in both the Free and Paid Workers plans and is priced at **$0.011 per 1,000 Neurons**.","summary":"The other ledger. Gives the unit and rate that a measured @cf/ call's neurons field converts into, which is how the Workers AI row of the money table is priced.","claim_ids":["c3"]},{"id":"s8","type":"publisher_documentation","url":"https://developers.openai.com/api/docs/pricing","title":"OpenAI — API pricing","quote":"gpt-4.1-mini 0.4 0.1 1.6","summary":"OpenAI's own per-million rates for gpt-4.1-mini: $0.40 input, $0.10 cached input, $1.60 output. Used to test Cloudflare's no-markup claim against a real logged cost field, and to price the worked example.","claim_ids":["c10","c15"]},{"id":"s9","type":"publisher_documentation","url":"https://openrouter.ai/docs/faq","title":"OpenRouter — FAQ, what are the fees for using OpenRouter","quote":"OpenRouter charges a fee when you purchase credits. We pass through the pricing of the underlying model providers without any markup, so you pay the same rate as you would directly with the provider.","summary":"The other side of the disagreement over 'the same 5%'. Identical mechanism to Cloudflare's, but the rate rendered on the page is 5.5% with a $0.80 minimum for card payments and 5% for crypto — so the mechanism matches and the number does not.","claim_ids":["c16"]},{"id":"s10","type":"publisher_documentation","url":"https://platform.claude.com/docs/en/about-claude/models/overview","title":"Anthropic — Model overview and pricing","quote":"Introductory pricing of $2 / $10 per MTok applies to Claude Sonnet 5 through August 31, 2026.","summary":"The published rate the measured Cloudflare cost field is reconciled against for anthropic/claude-sonnet-5, plus the standard $3 / $15 that replaces it after 2026-08-31 — which is what makes the last row of the money table move.","claim_ids":["c10","c15"]},{"id":"s11","type":"github","url":"https://github.com/cloudflare/ai/issues/548","title":"AI Gateway REST: /ai/v1/responses rejects Unified Billing on an authenticated gateway","quote":"POST to `/ai/v1/responses` with Unified Billing auth (`Authorization: Bearer {CF_API_TOKEN}` plus `cf-aig-gateway-id: {authenticated_gateway_id}`) returns HTTP 402 even though the gateway has `authentication: true`.","summary":"The canonical 402 report, filed on Cloudflare's own repository with a full curl reproduction: identical headers and model return 402 on /ai/v1/responses and 200 on /ai/v1/chat/completions, across openai/gpt-5.4, gpt-5.4-mini and gpt-5.5. Negative. Open with zero comments; did not reproduce on this account today, and both outcomes are published.","claim_ids":["c17","c5"]},{"id":"s12","type":"github","url":"https://github.com/anomalyco/opencode/issues/32951","title":"Cloudflare AI Gateway (Unified Billing) rejects `role: \"system\"` in messages array when proxying Anthropic models","quote":"Cloudflare AI Gateway Unified Billing routes requests to Anthropic's backend. When the model is `anthropic/*`, the gateway applies Anthropic's validation rules, which **do not accept `role: \"system\"` inside the `messages` array**.","summary":"The shape trap named precisely. opencode 1.17.8 against anthropic/claude-sonnet-4.6 failed on every request because the OpenAI-compatible client puts the system prompt in messages[0]. Negative — the OpenAI-compatible veneer leaks Anthropic's schema.","claim_ids":["c18","c7"]},{"id":"s13","type":"github","url":"https://github.com/withastro/flue/issues/327","title":"Support anthropic models via cloudflare's unified billing","quote":"have been leaning into cloudflare's AI gateway unified billing so that I don't have to provision keys for openai/anthropic directly. Ran into a bit of an issue where using anthropic's models in this way doesn't quite work.","summary":"States the motive plainly — no per-provider keys — then hits the same mismatch from the adapter side: the Cloudflare binding formats every cloudflare/... request as OpenAI chat-completions, which works for cloudflare/@cf/... ids and not for cloudflare/anthropic/claude-sonnet-4.6. Mixed, leaning negative; patched locally and verified from a bare setup.","claim_ids":["c18","c7"]},{"id":"s14","type":"hn","url":"https://news.ycombinator.com/item?id=48346648","title":"Comment on \"OpenRouter raises $113M Series B\" — the Cloudflare gateway is not free","quote":"Free? They take the same 5% fee as OpenRouter does.","summary":"Direct correction of a commenter who called Cloudflare's gateway the free option, citing the unified-billing docs page. Negative on the pricing-surprise axis, and the claim this page reconciles against OpenRouter's own published 5.5% + $0.80 card fee.","claim_ids":["c16"]},{"id":"s15","type":"hn","url":"https://news.ycombinator.com/item?id=47793121","title":"Comment on \"Cloudflare's AI Platform\" — no pricing on the models page","quote":"Not seeing any pricing info on the models[1] page. Wonder how much of a lift this is over paying providers directly. Perhaps Cloudflare is doing this at cost? Also interesting that zero data retention is not on by default","summary":"Read the launch docs and could not find pricing at all, and separately noticed zero data retention is off by default. Negative — the pricing-opacity complaint that precedes the later 5% discovery, and the earliest public note that ZDR is opt-in.","claim_ids":["c11","c19"]},{"id":"s16","type":"hn","url":"https://news.ycombinator.com/item?id=47793207","title":"Comment on \"Cloudflare's AI Platform\" — markup on token usage","quote":"i wonder about their princing and potential markup on top of token usage?i presume they wont let you \"manage all your AI spend in one place\" for free.","summary":"Grants Cloudflare is well positioned network-wise but assumes a markup on token usage. Negative — the suspicion that turns out to be half right: there is a fee, but it sits on the credit purchase and not on the tokens, which the measured cost rows confirm.","claim_ids":["c15","c19"]},{"id":"s17","type":"github","url":"https://github.com/jeremyhart/claworc/pull/6","title":"Simplify Cloudflare AI Gateway to Unified Billing; fix migration guard","quote":"Cloudflare authenticates and bills the upstream provider, so no per-provider keys are needed.","summary":"Merged pull request rewriting a connector to drop the confusing \"Provider API Key\" plus separate \"Gateway Token\" pair in favour of a single Cloudflare API token with AI Gateway Run permission. Positive — the auth collapse is the payoff people are actually after.","claim_ids":["c1","c20"]},{"id":"s18","type":"github","url":"https://github.com/kyleboas/blob/pull/124","title":"Allow Cloudflare Unified Billing without upstream provider keys","quote":"Cloudflare Unified Billing lets the gateway handle upstream authentication and billing, so provider API keys should be optional when routing through the AI Gateway.","summary":"Merged pull request fixing a callLLM that attached an upstream Authorization header on every gateway request and injected ANTHROPIC_API_KEY/OPENAI_API_KEY into agent inputs, blocking pure Unified Billing flows. Now requires only aiGatewayToken, with provider keys as an explicit BYOK fallback. Positive.","claim_ids":["c1","c20"]},{"id":"s19","type":"repository","url":"https://github.com/massoumicyrus/claude-code-cloudflare-gateway","title":"claude-code-cloudflare-gateway — a Worker that speaks Anthropic Messages and forwards to this surface","quote":"tools/contract-test.mjs","summary":"MIT-licensed reference implementation of the routing described here, including the anthropic/* lane and cf-aig-gateway-id handling, with a 21-check wire contract test and a capture tool that logs exactly what a client sends. Where a reader can read the code rather than trust the prose.","claim_ids":["c6"]},{"id":"s20","type":"independent_measurement","url":"https://miscsubjects.com/a/claude-code-on-cloudflare-ai-gateway","title":"Measured per-turn cost of coding traffic through the same gateway","quote":"MCP attached GLM-5.2 149,443 in / $0.20922644 / 10.9s; Kimi 149,187 in / $0.02852109","summary":"Independent of this page's own probes: per-turn token and cost figures captured with tools/capture-gateway.mjs and read back from gateway logs, for a real coding agent on the same account. Gives the 5% a denominator in monthly terms rather than per-request cents.","claim_ids":["c15"]},{"id":"s21","type":"runtime_receipt","url":"https://miscsubjects.com/a/cloudflare-unified-billing","title":"First-party: the 402 reproduced against two gateways, 2026-07-26","quote":"{\"errors\":[{\"message\":\"Gateway authentication is required to use unified billing. Enable authentication on your gateway or provide your own API key (BYOK).\",\"code\":2021}],\"success\":false,\"result\":{},\"messages\":[]}","summary":"Two POSTs to /ai/v1/chat/completions with model openai/gpt-4.1-mini, the same token and the same body, differing only in cf-aig-gateway-id: the gateway with authentication:false returned 402 code 2021, the gateway with authentication:true returned 200 with content 'ok' and usage 14/1. Method published in the article so it can be rerun.","claim_ids":["c13","c5"]},{"id":"s22","type":"runtime_receipt","url":"https://miscsubjects.com/a/cloudflare-unified-billing","title":"First-party: the anthropic/* shape trap and both working bodies, 2026-07-26","quote":"{\"errors\":[{\"message\":\"Model execution failed (User Input Error): Invalid value at messages[0].role: Invalid option: expected one of \\\"user\\\"|\\\"assistant\\\"\",\"code\":7003}],\"success\":false,\"result\":{},\"messages\":[]}","summary":"anthropic/claude-sonnet-5 on an authenticated gateway: an OpenAI-shaped body with role 'system' at messages[0] returned HTTP 400 with this error; the same body without the system message returned 200 but with no content field; /ai/v1/messages with a top-level system returned 200 with the text and gatewayMetadata keySource 'Unified'.","claim_ids":["c18","c21","c7"]},{"id":"s23","type":"runtime_receipt","url":"https://miscsubjects.com/a/cloudflare-unified-billing","title":"First-party: gateway log rows with the cost field, reconciled against published rates","quote":"\"tokens_in\":22,\"tokens_out\":4,\"cost\":0.00008400000000000001,\"authentication\":true,\"wholesale\":true,\"byok\":null","summary":"Three rows read back from GET /ai-gateway/gateways/default/logs for the calls made in this article. Each cost value equals tokens times the provider's published per-million rate to the digit, on two providers — the no-markup claim tested rather than repeated. wholesale:true is the Unified Billing marker; byok:null confirms no stored key.","claim_ids":["c10","c15","c22"]},{"id":"s24","type":"runtime_receipt","url":"https://miscsubjects.com/a/cloudflare-unified-billing","title":"First-party: /ai/v1/responses returned 200, so issue 548 did not reproduce here","quote":"\"object\":\"response\",\"model\":\"openai/gpt-4.1-mini\",\"status\":\"completed\",\"usage\":{\"input_tokens\":14,\"output_tokens\":2","summary":"POST /ai/v1/responses with openai/gpt-4.1-mini and cf-aig-gateway-id pointed at the authenticated gateway returned HTTP 200 with a full Responses envelope. Negative result for the endpoint-specific 402 in cloudflare/ai issue 548 on this account and model; the issue remains open and uncommented, so both are published rather than one being chosen.","claim_ids":["c17"]},{"id":"s25","type":"runtime_receipt","url":"https://miscsubjects.com/a/cloudflare-unified-billing","title":"First-party: a Workers AI model on the unauthenticated gateway, billed in Neurons","quote":"\"usage\":{\"prompt_tokens\":42,\"completion_tokens\":2,\"total_tokens\":44,\"prompt_tokens_details\":{\"cached_tokens\":0},\"neurons\":1.529652714729309}","summary":"@cf/meta/llama-3.3-70b-instruct-fp8-fast through the same gateway that 402s on provider/model returned HTTP 200 and reported neurons rather than a dollar cost. Direct evidence that the authentication requirement belongs to Unified Billing and not to the gateway, and that a working @cf/ call proves nothing about the configuration.","claim_ids":["c13","c3"]}],"anecdotal_sources":[],"scientific_sources":[],"user_reports":[],"related_articles":[],"question_graph":{"slug":"cloudflare-unified-billing","questions":[],"evidence":[],"edges":[],"counts":{"questions":0,"evidence":0,"edges":0}},"honesty":{"active_claims":22,"retracted_claims":0,"cut_claims":0,"challenges":0,"scrub_events":0,"note":"Retracted/cut claims stay on ledger but are excluded from ask unless ?include_inactive=1"},"counts":{"claims":22,"claims_total":22,"sources":25,"anecdotal":0,"scientific":0,"user_reports":0,"questions":0,"evidence_ingests":0}}