Two-tier role model
Organization Owners and Members pair with Project Admins and Project Members, so access maps to how your teams actually work.
Control exactly who can use which models, how much they can spend, and for how long-with organization roles, project roles, and permission-aware API keys built into FastRouter.
No credit card required · Free to start
Organization
FastRouter AI
Production
8 keys · $2k budget
Sandbox
3 keys · $200 budget
sk-fr••••4f2a
Production · scoped user key
Set access once at the organization level, delegate to project admins, and let builders move fast inside safe, scoped boundaries.
Organization Owners and Members pair with Project Admins and Project Members, so access maps to how your teams actually work.
Every key is tied to a user and inherits their project permissions-self-service for builders, fully governed for admins.
Set budgets, TPM, and RPM at the project level, then add tighter caps, expiry, and logging rules on each key.
FastRouter separates company-wide ownership, project-level collaboration, and runtime key controls so every permission has a clear, predictable boundary.
Organization
Project
User API key
Organization-level roles draw the outer boundary of access. Owners run the control plane; members are limited to the projects they're invited to.
Full administrative control over billing, members, projects, API keys, settings, and integrations.
Scoped strictly to assigned projects-no access to organization settings, billing, or user management.
Add more than one owner for redundancy and shared administration as your team grows.
Organization members
+ InviteJordan Claude
Priya Nair
Sam Cole
Each project is independently configurable-its own models, rate limits, budget, members, and keys-so workloads stay cleanly separated.
Manage project settings, invite members, and administer every API key inside the project.
Create and manage personal API keys based on the permissions they've been granted.
Set accessible models, tokens-per-minute, requests-per-minute, and an optional budget cap per project.
Production
API keys are user-linked and permission-aware. Builders self-serve while admins keep budgets, model access, limits, and logging aligned to risk.
Cap maximum spend per key with daily, weekly, or monthly resets-or leave it unlimited.
Restrict accessible models and set per-key TPM and RPM that always stay within the project caps.
Schedule automatic key expiration and disable content logging for keys that handle sensitive data.
New user API key
A clear breakdown of permissions across projects, API keys, and organization-level controls-so there's never any ambiguity about who can do what.
| Permission | Org Owner | Project Admin+ Org member | Project Member+ Org member | Org MemberNo project |
|---|---|---|---|---|
| Projects | ||||
| Create projects | Included | Not included | Not included | Not included |
| View project | Included | IncludedOwn only | IncludedOwn only | Not included |
| Edit project settings | Included | Included | Not included | Not included |
| Delete project | Included | Not included | Not included | Not included |
| Project members | ||||
| View project members | Included | Included | Not included | Not included |
| Add project members | Included | Included | Not included | Not included |
| Edit member roles | Included | Included | Not included | Not included |
| API keys | ||||
| Create & manage own keys | Included | Included | Included | Not included |
| Manage all keys in a project | Included | Included | Not included | Not included |
| Manage keys across all projects | Included | Not included | Not included | Not included |
| Organization controls | ||||
| Billing & credits | Included | Not included | Not included | Not included |
| Manage organization members | Included | Not included | Not included | Not included |
| External keys (BYOK) | Included | Not included | Not included | Not included |
| Virtual models | Included | Not included | Not included | Not included |
| MCP servers | Included | Not included | Not included | Not included |
| Prompt management | Included | Not included | Not included | Not included |
Organization Owners are automatically Project Admins on every project. “Own only” = projects the member has been added to.
RBAC works best when it removes friction. FastRouter combines org ownership, project membership, and key-level controls so teams ship without loose shared credentials.
Isolate production, staging, and experimental traffic into distinct projects-no shared credentials across workloads.
Give finance project-level budgets and per-key caps while engineering keeps day-to-day velocity.
Invite temporary teammates with project-only access and API keys that expire automatically.
Keep agent, MCP, and application workflows inside approved project permissions and model scopes.
FastRouter has two organization-level roles-Owner and Member-and two project-level roles-Project Admin and Project Member. Organization Members get their effective permissions from the project roles they're assigned, which keeps access granular without complex policy configuration.
Owners have full administrative control: managing billing and subscriptions, adding or removing members, accessing and administering every project, creating keys across the organization, and configuring global settings and integrations. Members are limited to the projects they're invited to and cannot change organization-wide settings, billing, or user access.
A Project Admin manages the project's settings, members, and all of its API keys. A Project Member can create and manage their own personal API keys based on the permissions they've been granted, but cannot edit project settings or manage other members. Organization Owners are automatically Project Admins on every project.
No. Organization Members operate strictly within the projects they're explicitly invited to and only inherit their assigned project permissions. A member with no access to a given project cannot view it, its members, or its keys.
Projects set the outer boundary with accessible models, tokens-per-minute, requests-per-minute, and an optional budget cap. Individual user keys can then add their own tighter limits-maximum spend with daily, weekly, or monthly resets, plus TPM and RPM-that always stay within the parent project's caps.
Organization-wide setup stays with Owners: billing and credits, managing organization members, external provider keys (BYOK), virtual models, MCP servers, and prompt management. Project Admins and Project Members work inside their projects-managing project settings, members, and API keys-but can't change these organization-level controls.
Spin up projects, invite your team with scoped roles, and issue governed keys with budgets, limits, and expiry in minutes.