فارسی Docs For teams and organizations

Enterprise usage guide

How organizations can make DaLAi available to their teams and applications: suitable tools, deployment patterns, and managing keys, costs and security.

For an organization, DaLAi means one account and one balance that different teams and applications use, each with its own separate key. All models are available under stable names, and each key's usage is shown separately.

This guide answers three questions: which tool suits each of the organization's tasks, which pattern to use to connect these tools to DaLAi, and how to manage keys, costs and security.

What DaLAi provides for an organization

The right tool for each job

Organization's needSuggested tool and why
Staff chatOpen WebUI or LibreChat. An internal portal with single sign-on; staff do not see the key
Questions over documentsAnythingLLM or Open WebUI. A separate workspace for each team and uploading of the organization's documents
Software developmentClaude Code, Cline, Kilo Code or Continue. A separate key for each developer or team, with a credit limit
Automationn8n or Dify. First replies to emails, sorting requests and summarizing reports, on the organization's own server
Customer supportDify or n8n. Ticket triage and draft replies, reviewed by a specialist before sending
Custom productOpenAI Agents SDK, LangGraph or Claude Agent SDK. Your own agent or product, with full control in code
Internal gatewayLiteLLM Proxy. A single entry point for all applications, with virtual keys and a spending cap for each team, behind one DaLAi key

Where to configure each tool is covered in Tools overview.

Chatting with documents requires an embedding model, which DaLAi does not currently offer. AnythingLLM and Open WebUI have their own local embedding model that runs on your server.

Four deployment patterns

1. A separate key for each team or application

The simplest pattern, suited to an organization with a few applications or a few small teams. For each team, each application and each environment (test and production), create a separate key with a clear name, such as support-bot-prod or dev-team-backend. Each key's usage is shown separately in Usage Logs, and if a key leaks, you delete only that one and the rest keep working.

2. Internal chat portal

Install Open WebUI or LibreChat on the organization's server and give a DaLAi key to it alone. Staff sign in with their organizational account (OIDC or LDAP), never see the key, and an administrator decides which models each group can access. Conversations stay on the organization's own server.

LibreChat keeps a separate balance for each user. In Open WebUI, the models of a new connection are visible only to the administrator until the administrator makes them public or assigns them to a group.

3. Internal gateway with team budgets

When you have dozens of applications and teams, put LiteLLM Proxy between them and DaLAi. Each team gets its own virtual key from this gateway, with a budget cap and a list of allowed models, and behind them all there is only one DaLAi key, on your server.

model_list:
  - model_name: claude-sonnet-4-5
    litellm_params:
      model: openai/claude-sonnet-4-5
      api_base: https://dalai.ir/v1
      api_key: os.environ/DALAI_API_KEY

Virtual keys and per-team budgets are included in the open-source version of LiteLLM. Some features, such as single sign-on to its admin panel for more than five users, require LiteLLM's own commercial license.

4. Process automation

Install n8n or Dify on the organization's server and give each workflow its own key, with access only to the models it needs and a credit limit. That way, a workflow stuck in a loop spends only its own credit. The two settings these two tools need are covered in Tools overview.

Managing keys and costs

Keys are created in the Console, under API Keys. Set these fields for each key:

A request that arrives from an address outside the IP Whitelist is returned with a 403 error and this message: “Your IP address is not on this token's allowlist” (in Persian for an account whose language is Persian). The meaning of other messages is explained in Errors and limits.

For a team's usage report, set the Token Name filter in Usage Logs to that team's key name. The Dashboard shows an overview of usage and balance. The organization's balance is prepaid and displayed in toman; full details are in Wallet, top-ups and billing.

Security and data

Setup, step by step

  1. For an organizational account, email support@dalai.ir. During the pilot launch period, access is by invitation only.
  2. Arrange your initial balance. For now, top-ups are made manually, after coordination.
  3. List your teams, applications and environments, and create a separate key for each, with a credit limit and a list of allowed models.
  4. Choose a deployment pattern and configure the tools as described in Tools overview.
  5. Start with a small team, watch usage in Usage Logs for a week, and then adjust the limits and models. For choosing a model, see Models overview.

For an organizational account, top-ups and any billing question, email support@dalai.ir.