One gateway controls models, callers, and spending
Experiential puts hosted, customer-key, and local model routes behind an OpenAI-compatible API. The local setup creates model aliases, identities, grants, budgets, and virtual keys, then serves Chat Completions, Responses, and Anthropic Messages on loopback. This suits a platform team that wants each coding agent or user to see an approved model list instead of receiving raw provider credentials. The README's first-run example starts with a $50 command-budget warning threshold.
The scope goes beyond request forwarding. Experiential can import OpenTelemetry traces, mine evaluation scenarios, compare models, fit a router, and prepare a managed fine-tuning run. Those steps call models and may cost money, so the CLI estimates spend and asks for confirmation when it crosses configured thresholds. We did not measure routing quality, model accuracy, gateway latency, or cost reduction. Those outcomes depend on the traces, providers, models, and policies a team supplies.
What happened when we ran it
Our sandbox installed commit 5a88cae in 253 seconds. The 22.7 MB checkout expanded to 5,941 MB after 148 packages were installed. The repository contained 1,434 files and about 486,236 lines of source. Our scan found 3 CI workflow files, no Dockerfile, and no tests directory at the repository root. Pip-audit reported 2 known vulnerabilities, but the supplied result did not identify their packages or severity.
The build succeeded in 5 seconds. Pytest then ran for 900 seconds and timed out after reaching 22%, with the final log showing continued passing progress dots rather than a failure traceback. That does not prove the remaining suite would pass, and it does not supply a completed test count. It does show that a full fresh-container check needs more than the 15-minute window we allowed.
Python 3.12 starts the gateway, while capture needs 3.13
The package requires Python 3.12 or newer. Running exp opens setup for a provider connection, model and reasoning selection, public alias, identity, budget, and one-time virtual key. The gateway then binds only to 127.0.0.1 by default and exposes its OpenAI-compatible endpoint on port 8000. Provider credentials can come from environment variables or the user data store, while Bedrock follows the AWS credential chain.
A working local route still needs more configuration than a single pip install. Each caller needs a grant and virtual key, and each alias needs an exact model and provider. Usage accounting is content-free, but local traffic content capture is enabled separately unless the operator uses --ghost. Anonymous aggregate PostHog product telemetry is also on by default; exp config telemetry disable records the opt-out in .exp/settings.toml.
macOS capture installs a network extension and certificate authority
The experimental capture command requires macOS and Python 3.13 or newer. On first use it installs the signed Mitmproxy Redirector app, asks the user to approve its network extension, and creates a constrained local certificate authority for selected provider hosts. Capture targets supported Codex and Claude Code traffic over HTTPS, while certificate-pinned apps and unsupported protocols pass through without collection. UDP, QUIC, and HTTP/3 are not inspected.
Captured traces include prompts, responses, and tool content, then upload to the Experiential platform. Credential headers are excluded, according to the usage guide. A 15-second watchdog disables interception if the foreground process stops responding, and Ctrl+C ends the session, though the installed extension approval and local CA remain. Security reviewers should assess that design separately from the ordinary loopback gateway because it changes trust on the workstation.
Two October issues can block provider setup
Issue 1199 demonstrates a model-list response taking about 7 seconds despite a 0.5-second configured timeout, because repeated small reads each finish before HTTPX's per-read limit. The report says this can leave exp login or provider setup waiting on a slow operator-supplied endpoint. Issue 1197 shows that one malformed model entry can abort discovery and hide valid models returned beside it. Both were open on October 4, 2026, with proposed fixes already represented by open pull requests.
A third open report, issue 1175, says Vertex token-refresh failures can escape as raw Google authentication exceptions, preventing the gateway from classifying some failures for retry or failover. These are specific edge cases rather than evidence that every provider route is unreliable. They matter because provider discovery and normalized failure handling sit on the adoption path: if those fail, the richer routing policy never gets a chance to run.
Version 0.7.151 arrived during same-day issue work
GitHub showed 8,804 stars and 112 open issues and pull requests on October 4, 2026. The repository was pushed that day, and v0.7.151 was released within minutes of the recorded push. Pull requests and issue updates continued through the same date. That is active maintenance, though the 0.7.x release line and rapid revisions mean operators should pin versions and read upgrade notes before changing a gateway that carries production model traffic.
Experiential makes the most sense when identities, budgets, trace capture, evaluations, and routing policy belong in one owned system. The 5,941 MB environment and unfinished 900-second suite are costs a platform team can plan around; they are excessive for a developer who only wants to swap provider URLs. Start with a noncritical traffic slice, disable any collection you do not need, and keep provider SDK retries from multiplying the gateway's own attempt limits.

