Teams, Keys & Budgets
Flit empowers platform engineering and FinOps teams to delegate model access responsibly, enforce strict financial budgets, and eliminate runaway LLM bills.
1. Team Governance & Native LiteLLM Delegation
Platform administrators manage organizational access under Access → Teams (/admin?section=teams). Flit delegates team persistence, budget enforcement, and key quotas directly to LiteLLM's battle-tested engine:
- Native Storage: LiteLLM owns the underlying team, membership, and virtual key tables. Flit maintains zero redundant team tables.
- Curated Bridge: The browser calls Flit's authenticated administrative API (
/api/admin/team/*and/api/teams/*), which validates the admin session and CSRF token before communicating with the private gateway. - Membership Lifecycle: Team members must be active, pre-provisioned Flit accounts. Member removal safely revokes associated team credentials without deleting the user's platform identity.
2. Scoped Virtual Keys & Multi-Resource Grants
Virtual keys are provisioned for human developers or automated service accounts and enforce granular boundaries across multiple resource types:
| Constraint Type | Enforcement Semantics | Configuration Values |
|---|---|---|
| Model Tiers | Restricts which models or tiers the key can invoke | aquila, aquila-fast, aquila-smart, aquila-power, or exact deployment IDs |
| MCP Tool Grants | Restricts which registered MCP server tools the key can access | Selected server-level tools (default: all tools denied) |
| A2A Agent Grants | Restricts which external Agent-to-Agent entities the key can invoke | Explicit agent grant allowlist |
| Rate Limits | Throttles request and token velocity to prevent runaway loops | Positive integer RPM (requests/min) and TPM (tokens/min) |
| Reset Durations | Defines budget renewal intervals | Native duration strings: 1h, 1d, 30d |
3. Hard Budget Caps & Circuit Breaking
Teams can be assigned a finite, non-negative USD budget cap with configurable renewal durations (such as monthly or weekly):
- Real-Time Spend Tracking: Spend is tracked continuously in LiteLLM for all completions, embeddings, and responses.
- Hard Cap Circuit Breaker: Once a team's recorded spend meets its limit, further inference requests using its keys are immediately rejected with an HTTP 403
budget_exceedederror, completely eliminating unexpected runaway provider bills. - Instant Team Blocking: Administrators can manually toggle a team's active status to block all incoming inference traffic immediately.
4. Usage Analytics & Cost Attribution
The Flit Admin Analytics dashboard (/admin?section=analytics) provides verified 7-day overviews and up to 90-day custom reports:
- Token Accounting: Full breakdown of prompt tokens, completion tokens, cache read tokens, and cache creation tokens.
- Tier Attribution: Real-time breakdown across Fast, Smart, and Power tiers (via
aquila:v1:tier:*tags). - Identity & Credential Attribution: Precise usage breakdown by user account, key alias, and client access channel.