Preloop vs LiteLLM: Full control plane vs LLM proxy

Preloop is the open-source AI agent control plane — an MCP firewall, AI model gateway, human approvals, runtime observability, and audit trail in one self-hostable platform. LiteLLM is a widely used open-source LLM proxy with broad provider support, commonly used as a lightweight, drop-in gateway. The honest one-liner: if all you need is a fast, minimal LLM proxy to route traffic across providers, LiteLLM is excellent; if you also need MCP tool governance, human approvals, runtime session observability, and an audit trail in one product, Preloop is the full control plane.

At a glance

Feature Preloop LiteLLM
License Apache 2.0 (open source core) MIT (open source)
Self-hosted option Yes, on any infrastructure Yes
MCP-native tool governance Yes — MCP Firewall with policy-as-code Out of scope
Model gateway with budgets Yes — OpenAI/Anthropic-compatible, per-agent attribution Yes — budgets, rate limits, provider routing
Human approvals Yes — mobile, watch, Slack, Mattermost, email, webhook Out of scope
Runtime agent observability Yes — session timelines, tool + model calls, decisions Call-level logs, spend tracking
Policy-as-code Yes — YAML + CEL for tool calls Config-based routing rules
Console UI Yes — console, mobile app, dashboards Basic admin UI
Works with any agent runtime Yes — Claude Code, Codex CLI, Cursor, Gemini CLI, OpenClaw, OpenCode, any MCP client Any LLM-using app
Pricing model Open-source + optional SaaS Open-source + commercial Enterprise tier
Vendor lock-in Minimal Minimal
Onboards existing local agents Yes — preloop agents discover No direct equivalent
Codebase Polyglot (Python backend, Lit/TypeScript frontend, Go CLI) Primarily Python

What LiteLLM does well

LiteLLM is a strong open-source proxy that many teams already love:

  • Very broad provider support. Route to OpenAI, Anthropic, Google, Mistral, Bedrock, Azure, Vertex, local models, and many more with consistent request/response shapes.
  • Minimal, lightweight. Deploy as a single Python proxy and start routing LLM traffic.
  • Sensible gateway features. Rate limits, fallbacks, retries, budgets, and spend tracking.
  • Strong community and ecosystem. Widely adopted, documented, and integrated across the LLM-ops landscape.
  • MIT-licensed core. Permissive, easy to embed and extend.

If your job description is "put a proxy in front of LLM calls so I can switch providers, enforce budgets, and log spend," LiteLLM is an excellent fit.

Where Preloop is different

Preloop and LiteLLM overlap on the model gateway layer, but Preloop is a full control plane rather than a proxy.

  • MCP tool governance is native. The Preloop MCP Firewall inspects every tool call and decides allow / deny / require approval / require justification based on policy-as-code in YAML with CEL conditions. A gateway-only product does not sit on the tool path.
  • Human approvals are first-class. When a rule needs a human, reviewers get paged on mobile, watch, Slack, Mattermost, email, or a custom webhook with full context. Async-safe mode supports long-running reviews without breaking the agent's transport.
  • Runtime session view across tools and models. One timeline per agent session shows every tool call, every model call, matched policy, approver, spend, and outcome. That is operational evidence, not just per-call logs.
  • Audit trail across the whole agent fleet. Durable, searchable evidence of what agents attempted, which policy matched, who approved, and what happened.
  • Console and mobile app. Preloop ships a full web console and mobile/watch experience for approvals and visibility — not just a proxy URL.
  • preloop agents discover. One CLI command enrolls Claude Code, Codex CLI, Cursor, Gemini CLI, OpenClaw, and OpenCode on a developer's machine by rewriting local configurations to route through Preloop.
  • Polyglot codebase. The CLI, backend services, and frontend are built in complementary languages optimized for each surface (Python backend, TypeScript/Lit frontend, a Go CLI) — which matters when you're running Preloop at scale alongside other tooling.

When to choose LiteLLM

  • Your only requirement is an LLM proxy with broad provider support, budgets, and logging.
  • You do not need MCP tool governance, human approvals, or runtime session timelines in the same product.
  • You want the smallest possible surface to route model traffic and nothing more.

When to choose Preloop

  • Platform and DevEx teams rolling out Claude Code, Codex CLI, Cursor, Gemini CLI, OpenClaw, and OpenCode who need to control what those agents can do, not only which model they call.
  • Security teams in regulated SaaS that need self-hostable MCP governance, approvals, and searchable audit evidence next to the model gateway.
  • Engineering teams standardizing on one control plane for MCP tool calls, model traffic, approvals, runtime observability, and audit — instead of stitching a proxy, an approvals tool, and an observability product.
  • Open-source-first organizations that want a complete Apache 2.0 control plane they can read, fork, and extend.
  • Teams building EU AI Act readiness evidence that need durable logs of matched policies, approvers, and outcomes mapped to runtime sessions.
  • Teams that want zero-touch agent onboarding via preloop agents discover.

Adoption notes

Preloop and LiteLLM can coexist. A common pattern is to keep LiteLLM as the upstream model router (for its broad provider support) and point the Preloop model gateway at LiteLLM as an upstream provider. That way, you keep the provider flexibility LiteLLM is famous for, while layering Preloop's MCP firewall, approvals, runtime sessions, and audit trail on top.

If your deployment is LiteLLM-only today, introducing Preloop usually looks like:

  1. Run preloop agents discover on a developer's machine to enroll one coding agent into Preloop.
  2. Configure that agent's model gateway URL to point at Preloop, and configure Preloop to forward to LiteLLM.
  3. Start with observability and approvals; introduce deny rules and budgets incrementally.

FAQ

Is Preloop an alternative to LiteLLM?
Preloop includes an LLM gateway that serves many of the same jobs as LiteLLM, but Preloop is a broader control plane with MCP tool governance, human approvals, runtime session observability, and audit. For teams that only need a proxy, LiteLLM remains a great choice. For teams that need governance end-to-end, Preloop is the fit.

Can I use LiteLLM and Preloop together?
Yes. A common setup is Preloop's model gateway in front of LiteLLM as an upstream provider — Preloop applies tool policies, approvals, and audit, while LiteLLM handles broad provider routing.

Does Preloop have budgets and rate limits like LiteLLM?
Yes. Preloop supports per-agent, per-flow, per-key budgets and attribution through its model gateway.

Is Preloop open source?
Yes. The Preloop core is Apache 2.0 licensed and self-hostable. An optional enterprise tier adds features like RBAC, team-based approvals with quorum, and audit impersonation tracking.

How does Preloop govern MCP tool calls?
Via YAML policies with ordered rules and CEL expressions. Rules can inspect tool name, server, parameter values, agent identity, or other context, and decide allow, deny, require approval, or require justification.

What is preloop agents discover?
A CLI command that scans a developer's machine, finds local Claude Code, Codex CLI, Cursor, Gemini CLI, OpenClaw, and OpenCode configurations, backs them up, and rewrites them to route through Preloop. No SDK changes.