Skip to main content
If you run Claude or OpenAI models on Microsoft Foundry (formerly Azure AI Foundry), you can send those requests through the Mnemom gateway instead of calling your Foundry resource directly. The gateway forwards each request to your Foundry endpoint with your Foundry credential, and applies the same Safe House screening, integrity checkpoints, policy enforcement and tracing it applies to every other request. Nothing about your Foundry setup changes. You keep your resource, your deployments, your Azure billing and your credential. Mnemom never stores the credential. It is forwarded to your endpoint on each request and nowhere else.
Same door, same path, same body as a request to the provider’s own API. Four things to get right:
  • Send your Foundry key in the provider’s native auth header (x-api-key on /anthropic, Authorization: Bearer on /openai).
  • Add x-mnemom-foundry-endpoint with your resource endpoint.
  • Add x-mnemom-api-key with a Mnemom API key.
  • Put the deployment name in model, and keep Foundry’s default deployment name, which is the model id.
There is no separate Foundry door and no Foundry-specific request shape.

How it differs from the provider doors

On the provider doors the gateway forwards your request to the provider’s own API, whether Anthropic, OpenAI or Google, using the provider key you send. With Microsoft Foundry the gateway forwards to a Foundry endpoint you own instead. Two things follow from that:
  • A Mnemom API key is required. On the provider doors x-mnemom-api-key is optional, because the gateway can identify your agent from the provider key you send. With Foundry the credential you send belongs to your Azure resource, so the Mnemom API key is required to tell the gateway whose request it is.
  • Your deployment name is the model. Foundry serves models as named deployments. Put the deployment name in the request body’s model field, exactly as you would when calling Foundry directly.

Before you start

You need:
  • A Foundry resource with a deployment of a supported model, using the default deployment name (the model id, for example claude-sonnet-5 or gpt-5). See Request body for why the name matters.
  • The resource’s endpoint. It has one of two shapes: https://<resource>.services.ai.azure.com or https://<resource>.openai.azure.com. Claude deployments use the services.ai.azure.com form.
  • A credential for that resource: the resource’s API key. On the /openai door a Microsoft Entra bearer token also works.
  • A Mnemom API key with the gateway capability, from an organization with billing set up. See API Keys and Pricing. The organization that owns the key is charged for the governance work on each request.
The endpoint must be an https URL whose host ends in .services.ai.azure.com or .openai.azure.com. Any other host is rejected with 400. Only the scheme and host are used: the gateway appends the path you called, so a path in the header has no effect.

Endpoints

Use the /anthropic door for Claude deployments and the /openai door for OpenAI deployments. These three paths are the only paths the gateway forwards to Foundry. Any other path returns 400.

Headers

Microsoft’s own api-key header is not read by the gateway. Send the Foundry key in the provider’s native header as shown above. Only the headers Foundry needs are forwarded: the content and credential headers, plus anthropic-version and anthropic-beta on the /anthropic door. Every x-mnemom-* header is removed before the request leaves the gateway.
x-mnemom-api-key and your Foundry credential are two different credentials with two different jobs. The Mnemom key authorizes the request and never leaves the gateway. The Foundry credential is used only to call your endpoint. Do not swap them, and do not send either in the request body.

Request body

Send the provider’s standard request body. The model field carries your Foundry deployment name. Do not add an api-version query parameter. The gateway forwards the path you call unchanged.
Keep the default deployment name. Foundry names a deployment after the model id by default. The gateway reads the model value to recognize which model it is talking to and to request a reasoning trace in the form that model accepts. A deployment with a custom name is not recognized as any supported model, and current Claude models reject the resulting request with 400. If you have renamed a deployment, create one with the default name and use that.

Supported models

Microsoft Foundry support covers Anthropic and OpenAI models only. The deployment you name must serve one of these models. Anthropic (/anthropic door)
  • Claude Fable 5.1
  • Claude Fable 5
  • Claude Opus 5.5
  • Claude Opus 5
  • Claude Sonnet 5.5
  • Claude Sonnet 5
  • Claude Opus 4.8
  • Claude Opus 4.7
  • Claude Sonnet 4.6
  • Claude Haiku 5.5
  • Claude Haiku 4.5
OpenAI (/openai door)
  • GPT-6.1 Sol
  • GPT-6 Astra
  • GPT-5.6 Sol
  • GPT-5.6 Terra
  • GPT-5.6 Luna
  • GPT-5
The model ids to use as deployment names are listed under Canonical model IDs on the Provider Support page. Gemini is not offered through Microsoft Foundry. Other models that Foundry can host, including other OpenAI models not listed above, are not supported through the gateway today. Safe House, integrity checkpoints and policy enforcement apply per door exactly as described in Provider Support: thinking-trace analysis is available on the /anthropic door and not on the /openai door.

Examples

Set your deployment name as the model value. The examples below assume a Claude deployment named claude-sonnet-5 and an OpenAI deployment named gpt-5, the default names for those models. Compared with the provider-door examples, only the key and the endpoint header change.
The SDKs send the Foundry key in the provider’s native auth header, exactly as the curl examples do.

Response

The response body is the provider’s native response, as returned by your Foundry deployment. The gateway relays it and adds its own response headers. Two things to plan for:
  • Governance can stop a request. Under a blocking enforcement mode, a request that fails a checkpoint is answered by the gateway and never reaches Foundry. Read X-Mnemom-Verdict to tell the two apart.
  • Claude responses include a thinking block. As on the provider doors, the gateway enables extended thinking so it can analyze the agent’s reasoning. The content array carries a thinking block alongside the text block, so read blocks by type rather than by position. See the Gateway Quickstart note on thinking elements.
See the Headers reference for the full set and how to parse X-Mnemom-Verdict.

Errors

Errors raised by the gateway use the standard gateway envelope:

Billing

Microsoft bills your Foundry resource for the model inference. Mnemom charges only for the governance work it does on the request, as described in What is not charged.