Simple, transparent pricing.
0% markup — you pay exactly what providers charge. Revenue comes from the platform fee, not a tax on your tokens.
Free
$0
Free
- Up to 2M tokens/day, best-effort
- Full guardrails on every call
- $3 credit + premium-model trial
- Local & open-source models
- No credit card, free forever
Popular models
Budget Pass
Rp 10rb/hari
or Rp 60k/week
- 3M tokens/day, guaranteed
- Budget-tier models
- Full guardrails
- Pay per day or week — no subscription
Popular models
Plus Pass
Rp 25rb/hari
or Rp 150k/week
- 5M tokens/day, guaranteed
- Budget + Mid-tier models
- Full guardrails
- Pay per day or week — no subscription
Popular models
Pro
$27/mo
Rp 499rb
≈ Rp 16rb/hari ☕
- All models — Budget, Mid, Premium & frontier
- Monthly allowance: ~250M tokens (lean) → ~1M (frontier: Opus, GPT-Astra)
- Batch routing (50% off)
- Response cache
- 5 API keys · team & org
Enterprise
$499+/mo
Rp 8,5jt+
- All tiers incl. Ultra
- SSO/SAML
- Audit log export
- SLA guarantee
- Net-30 invoicing
Free tier
Guardrails on every call — even the free ones
Every signup gets up to 2M tokens/day of guarded calls on low-cost models — best-effort by design, free forever. Plus a $3 prepaid credit and a premium-model trial to start. No credit card, billed in Rupiah.
Guarded, not raw
Every free call runs through the full guardrail stack — prompt-injection detection, PII handling and content moderation — the same defense your paid traffic gets.
Best-effort, honest
The free bucket is best-effort and resets daily. When you need reliable throughput that is never throttled, that is what the paid plans are for.
Pay in Rupiah when you grow
Upgrade with local payment — QRIS, GoPay and Rupiah, no international credit card required.
See the guardrails catch an attack in real time: Try the injection comparison →
Platform fee
How the top-up fee works
Tokens bill at raw provider cost (0% markup) on every plan. When you top up your prepaid balance (minimum Rp 50rb), Anoman's only charge is a small platform fee: your payment method's processing cost, plus a flat 5% service fee, grossed up and shown itemised.
Models by region
Pick where your data is processed
Every model declares the region where the request is processed. Filter the catalog by region to align your model choice with your compliance posture. Many models process abroad, so check the region before you choose.
Indonesia
Framework: UU PDP
Models: Frontier + curated chat
Best for: All Indonesian-resident workloads
Singapore
Framework: PDPA
Models: Planned — no models yet
Best for: PDPA workloads (planned, not yet available)
China
Framework: PIPL
Models: 9 OSS text + 3 OSS vision
Best for: Cost-optimized OSS, ~50–75% cheaper
United States
Framework: —
Models: Most frontier flagship
Best for: Latency-insensitive global
Europe
Framework: GDPR
Models: EU-resident frontier
Best for: GDPR workloads
Global
Framework: Multi-region
Models: Routed for best latency
Best for: Default residency-agnostic
Pricing across regions is pass-through — Anoman applies 0% markup. The platform fee covers the gateway, guardrails, and observability.
Compare plans
Everything you get
Full feature breakdown across all tiers.
| Feature | Free | Budget Pass | Plus Pass | Pro | Enterprise |
|---|---|---|---|---|---|
| Monthly token allowance | — | Pass-based | Pass-based | Up to ~250M/mo | Custom |
| Overage | Hard cap | Hard cap | Hard cap | Overflow to balance | Negotiated |
| Daily token allowance | 2M/day | 3M/day | 5M/day | — | No cap |
| Requests / min (rate) | 20 | 30 | 60 | 120 | 30,000 |
| Tokens / min (rate) | 40K | 60K | 120K | 500K | 100M |
| Max concurrent requests | 25 | 30 | 60 | 150 | 500 |
| Budget models | |||||
| Mid models | |||||
| Premium models | Trial | ||||
| Ultra models | |||||
| Community models (opt-in) | |||||
| API keys | 1 | 1 | 1 | 5 | Unlimited |
| Prompt injection detection | |||||
| PII masking (4 modes) | |||||
| Content moderation | |||||
| Conversational guardrails | |||||
| Agent policy control | |||||
| MCP governance | |||||
| Batch routing (50% savings) | |||||
| Response cache | |||||
| Team management + RBAC | |||||
| Organization workspaces | |||||
| Member groups + entitlements | |||||
| SSO/SAML | |||||
| Audit log export | |||||
| Custom rate limits | |||||
| SLA guarantee | |||||
| Net-30 invoicing | |||||
| IDR billing | |||||
| Support | Community | Community | Community | Dedicated |
Featured models
Curious how we stack up against other providers? Compare Anoman vs OpenRouter, OpenAI & more →
Frequently Asked Questions
Everything you need to know about Anoman AI and LLM gateway security.
What is an LLM gateway?
An LLM gateway is a proxy between your application and the upstream model providers. It routes requests, enforces security policies, meters usage, and gives you observability — through one OpenAI-compatible endpoint. Anoman is the guarded LLM gateway: prompt-injection defense, PII masking, and policy control run on every call.
Is Anoman a drop-in replacement for OpenAI?
Yes. Anoman exposes a fully OpenAI-compatible API — point your base_url at Anoman and nothing else changes. Any SDK that works with OpenAI (Python, TypeScript, Go, and others) works with Anoman out of the box.
How does Anoman stop prompt-injection attacks?
Every request passes an ML classifier trained for prompt-injection detection (configurable threshold) plus heuristic and content-moderation checks, blocking malicious prompts before they ever reach a model. Injection detection is mandatory — only the sensitivity is adjustable, never the check itself.
What latency does the gateway add?
Under ~30ms at p50 and ~80ms at p95, including the full guardrail pipeline (injection detection, PII masking, content moderation, policy). A typical model call takes 500ms–3s, so the overhead is negligible.
Is my data safe from Anoman itself?
Anoman never trains on your data, and guarded models' providers never train on it either; the may-train community lane is opt-in. Cache is partitioned per customer so no one sees another customer's data, API keys are bcrypt-hashed, and PII is detected and masked on every request before it reaches any model.
Where does my data actually go?
Your account data and logs are stored in Jakarta (subprocessors listed on the privacy page), where the gateway runs. A request leaves Indonesia only when the model you choose is processed elsewhere, and each model's detail page shows its processing region. No silent cross-border transfers.
Is there any lock-in?
No. Anoman is OpenAI-compatible — you changed two lines of config to come in, and you can change them back to leave. There's no proprietary SDK to rip out. Start free, cancel anytime.
Why trust a newer, Indonesia-based vendor?
Because trust here is instrumented, not asserted: every response returns a verifiable receipt of exactly what we did (region, guardrail results, routing, cost), we run a public status page and the Founding 50 program, and Anoman is built by security experts with more than 15 years in enterprise cybersecurity.
Do you have SOC 2 or ISO 27001?
Formal certification is planned. In the meantime we handle enterprise security reviews and vendor questionnaires directly, and every call already returns machine-readable evidence of the controls applied — contact us for provider documentation and a Data Processing Agreement.
What's your uptime and SLA?
We target 99.9% monthly on the gateway and publish live status at anoman.io/status. A contractual SLA is available on the Enterprise plan.
Why not just use LiteLLM or build this myself?
You could — and then you'd own building and maintaining guardrails, PII masking, data residency, batch routing, observability, and audit logging yourself, forever. Anoman ships all of them on every call, maintained, behind one OpenAI-compatible endpoint.
Ready to secure every AI call?
Start for free. No credit card required. Upgrade when you need more.