Get started

Concepts

The ideas every LatentStack product shares: organizations, roles, API keys, models, tiers, teams, guardrails and usage.

The gateway

Every model request from LatentCode, LatentWork, the Agents API and your own code goes to one place: the LatentStack gateway, running on your server. Clients never talk to a model provider directly. For each request, the gateway:

  • identifies you from your API key and works out which organization and team the request belongs to;
  • runs the organization's guardrails over the request;
  • checks that your tier allows the model, and applies rate limits, budgets and credits;
  • sends the request to the provider that serves the model, using credentials your administrator configured;
  • records the tokens and cost against you, your organization and your team.

Because every request passes through the gateway, the policies below apply the same way to every product.

Organizations

An organization is a tenant: a company, department or group with its own members, tiers, teams, guardrails, model and provider settings, and usage. Nothing is shared between organizations.

  • One account, many organizations. Your account belongs to you, and you can be a member of several organizations, with a different role and tier in each.
  • The active organization. The console shows one organization at a time; switch with the organization switcher. A request is counted against the organization that's active for it.
  • Your default organization is used when a client doesn't say which one it means. It's set to the first organization you join.
  • Creating one. On the Organizations page, choose New organization. You become its owner, and it gets its own default tier. Your deployment may turn organization creation off.

Joining an organization

Way inHow it works
InvitationAn owner or admin invites you by email from the Members page. Open the link and sign in (or create an account) with the invited email address to accept. Invitations expire after 14 days, and a new invitation to the same address replaces the old one.
Public organizationOrganizations can be Public — discoverable. Find them under Discover public organizations and request to join. Depending on the organization's setting, you join straight away or an admin approves the request.
Added by an adminAn admin creates your account, or adds your existing account, from the Users page. You may get a welcome email with a temporary password and your API key.
AutomaticYour organization may add new accounts automatically.

Roles

Inside an organization, each member has one of three roles:

RoleCan do
memberUse the models their tier allows, see their own usage, join teams they are added to.
adminEverything a member can, plus: invite, approve, remove and change the role of members; manage users, tiers, teams, guardrails, prompts and organization settings; see the organization's usage.
ownerEverything an admin can, plus delete the organization and transfer ownership. Each organization has one owner.
  • Admins and owners see the Administration section of the console sidebar. Members see only Organization and My account.
  • You can only change members whose role is below yours, never the owner and never yourself. Invitations can grant admin or member; ownership moves only by transfer.
  • An owner can't leave an organization without first transferring ownership.

API keys

An API key identifies you to the gateway. Keys start with ls-. Send yours as a bearer token; the gateway also accepts it in an x-api-key header, which Anthropic clients use:

Authorization: Bearer ls-…
  • One personal key per account. It's created with your account. Copy it from Account settings → API Key in the console (open it).
  • Rotating. Select Regenerate on the same card. The old key stops working immediately, so update LatentCode and LatentWork with the new one. Administrators can't regenerate another user's key.
  • Not tied to an organization. Your personal key works in every organization you belong to. Clients choose the organization with the X-Org-Id header; without it, the gateway uses your default organization.
  • Keys end with membership. If you're removed from an organization, requests to it fail even though the key is still valid. If your account is deleted, the key stops working.

Models

Each organization chooses which models it offers; admins manage them in the console.

IdeaWhat it means
Model idHow you name a model in a request, for example anthropic/claude-haiku-4-5: usually <vendor>/<model>. Use ids exactly as GET /v1/models returns them. LatentCode may show a longer id that includes the provider.
ProviderThe service that actually runs the model, such as Anthropic, OpenAI, Gemini, Amazon Bedrock, Azure or OpenRouter.
Context windowThe most tokens a request and its reply can use together. LatentCode uses it to decide when to compact a long conversation.
Max output tokensThe longest reply the model can produce.

The model pickers in LatentCode and LatentWork list only the models your tier allows.

Tiers

A tier is a bundle of allowed models and limits. Admins create tiers on the Tiers page and assign them to users and teams. Every organization has a default tier that new members start on.

SettingEffect
Allowed modelsWhich models members on the tier can use. A request for any other model is refused with model_not_allowed.
Default modelThe model clients preselect when they first connect, and fall back to on errors. It must be one of the allowed models.
Rate limitsRequests per minute, hour, 6 hours and day, per model, with a default for models not listed. 0 means unlimited. Limits count requests, not tokens.
Budget limitsUS-dollar spend caps per minute, hour, 6 hours and day, plus optional per-model daily caps. 0 means unlimited.
Background modelsThe models LatentCode uses behind the scenes, such as for subagents and session titles.

Which tier applies

When you work in a team, the team's tier applies. Otherwise you get the tier an admin gave you in the organization, or the organization's default tier.

If none applies, the request is refused with no_tier_assigned. Rate limits and budgets are counted separately for each organization, and for each team within it.

Teams

A team (a project in the API) is a group of members inside an organization with its own tier and, optionally, its own instructions that are added to every request made for the team. Admins manage teams on the Teams page; you see yours under My Teams.

  • You choose a team in LatentCode or LatentWork. API clients send the team's id in the X-Project-Id header.
  • Requests for a team use the team's tier and count against the team's limits, separately from your personal usage.
  • Admins can give individual members a different tier or rate limits within a team.

Guardrails

Guardrails screen every request before it reaches a model. Each organization sets its own on the Guardrails page:

  • AI policy check. A model you choose reviews each request against policies you write in plain language, and blocks requests that break them.
  • Sensitive data (PII). Detects data such as card numbers, email addresses, phone numbers and national ID numbers. Block refuses the request; Sanitize redacts or masks the data and sends the rest.

A blocked request fails with a 400 error that says why. See Admin Console to configure guardrails and Troubleshooting for the errors.

Usage and cost

The gateway records every request: the model, input, output, cached and reasoning tokens, and the cost in US dollars.

WhereWhoWhat you see
My UsageEveryoneYour tier, allowed models, rate-limit and budget usage, credits, and spend by model and day, for you personally or for a team.
Budget AlertsEveryoneAn email when your daily spend crosses a percentage of your budget.
OverviewAdminsSpend over time, top models and top users.
Usage AnalyticsAdminsDetailed usage and cost across the organization.

Three kinds of spending limit

LimitSet onBehaviour
Rate limitsTier, team memberRequests per window. Requests may slow down near a limit and fail with 429 past it.
BudgetsTierDollar spend per window. Requests fail with 402 until the window resets.
CreditsOrganization, memberA balance that goes down with use and doesn't reset by itself. The organization has a pool, and each member can have a cap within it. When either runs out, requests fail with 402. Members can ask for more with Request Credits on My Usage; admins answer on Credit Requests.

Signing in to the console

The console uses email and password. Anyone can create an account on the sign-up page; an account on its own belongs to no organization until you create or join one. If you forget your password, the sign-in page emails you a 6-digit code to reset it. The code is valid for 10 minutes.