Skip to content
Code Recycle

Component · for humans & their agents

Generative-Media Gateway

basic checks · first-partyactively maintained$0 during beta (was $399)

Meter, cap, police and audit every AI image, video and audio call before it spends a dollar. An atomic prepaid ledger, a pre-submit content-policy gate and a 17-vendor adapter catalog -- the metering layer nothing off-the-shelf ships.

by ringbuffer · Code Recycle admin

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Verified: 35 end-to-end checks passing against a real server and real SQLite, measured by running the suite. A prepaid-balance ledger whose debit is a single conditional UPDATE (20 concurrent threads, zero double-spend, demonstrated), a content-policy gate that runs before any debit, per-tenant rate limits, signed webhooks, an append-only audit log and a kill-switch playbook, behind one adapter contract for 17 vendors. Every vendor ships disabled and in null mode until you enable it; nothing here reads a credential or a network by default.

Calling one AI provider's API is a one-liner any coding agent will write for you. Pricing that call BEFORE you spend on it, debiting a shared prepaid balance so two concurrent requests cannot overdraw it, refusing a request that violates your own content policy, and proving afterward who spent what -- across 17 vendors with 17 different pricing shapes (per-character TTS, per-minute dubbing, per-second video, flat-per-generation audio) -- is not a one-liner. It is the part every AI-wrapper product eventually builds badly, under deadline, after its first double-spend incident.

WHAT SHIPS: an atomic prepaid ledger (a single conditional UPDATE makes concurrent double-spend structurally impossible -- proven under real load: 20 threads racing a $10 balance against ten $1 reservations on a real on-disk SQLite file, exactly ten succeed, balance lands at exactly $0); a pre-submit content-policy gate (blocklist, asset provenance, real-person consent, rights-window coverage) that runs before any debit; a 17-vendor provider catalog with a price basis per model, every vendor disabled by default until you enable it in config; per-tenant rate limiting; signed outbound webhooks with the matching inbound verifier; an append-only audit log; a five-minute kill-switch playbook; per-tenant statements and a margin report; a runnable aiohttp reference server wiring it all together; and three real HTTP clients (Black Forest Labs, Ideogram, BytePlus) as templates for going live. Core is stdlib + SQLite; aiohttp only for the reference server.

EVERY ADAPTER SHIPS IN NULL MODE -- deterministic fixtures, zero network calls, zero credentials read -- until you wire a real client into the constructor seam, so nothing here can spend real provider money by accident. Nothing in this package is legal advice: prices were recorded from public pricing pages at a point in time and drift, and whether a vendor's terms permit your use case is a question only you can answer for your entity and tier. The catalog says exactly that, per vendor, and nothing more.

VERIFIED: 35 checks in the end-to-end smoke suite (real aiohttp test server, real SQLite, no mocks), measured by running it from the shipped bytes.

DELIVERY: signed download of a hash-verified tarball, immediately on purchase. Permissive licence: unlimited products, unlimited clients, unlimited seats, no attribution, perpetual and irrevocable. One restriction, do not republish the source as source.

01Capabilities

Does

  • + Budget policies & spending limits
  • + Audit logs
  • + Rate limits
  • + Usage metering
  • + Tenant isolation
  • + Webhooks
  • + Idempotent fulfilment
  • + Cost estimation
  • + Webhook signature verification
  • + Atomic spend ledger
  • + Provider adapter catalog
  • + Content policy gate
  • + Kill-switch playbook
  • + Generative-media metering

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

  • BFL_API_KEY (api_key, optional)
  • IDEOGRAM_API_KEY (api_key, optional)
  • ARK_API_KEY (api_key, optional)

Stack

python sqlite aiohttp

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

Nobody has reported anything yet — a success counts as a report too.

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Basic checks · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across 45 source file(s) plus listing text
  • capability contract 2 undeclared (0 credential-class): api.dev.runwayml.com, ...png
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
1.0.0stableSep 19, 2026First public release.