Gemini CLI ↗︎ supports a custom Google Gemini API base URL. Point it at an AI Gateway custom domain protected by Cloudflare Access. Use cloudflared to generate a short-lived Access token before you start Gemini CLI.
Gemini CLI does not support an API key helper. You must refresh the token when the Access session expires.
Before you start, you need:
- An AI Gateway with a custom domain.
- Cloudflare Access enabled on the custom domain with a policy that allows your identity.
- Credentials for Google AI Studio. Use Unified Billing credits or store a Google AI Studio key in AI Gateway with BYOK (Store Keys).
cloudflaredinstalled.- Gemini CLI ↗︎ installed and updated to the latest version.
-
Set the Google Gemini base URL to your AI Gateway custom domain. Replace
ai.example.comwith your custom domain.export GOOGLE_GEMINI_BASE_URL="https://ai.example.com/google-ai-studio" -
Authenticate to Access and store the resulting token in
GEMINI_API_KEY.export GEMINI_API_KEY="$(cloudflared access login -app https://ai.example.com)" -
Start Gemini CLI and send a prompt. Requests now route through AI Gateway.
gemini
Run the authentication command again when the Access token expires. You can also add these commands to a bootstrap script that starts Gemini CLI.
For more information about these environment variables, refer to Gemini CLI configuration ↗︎.
To confirm traffic reaches AI Gateway, refer to Verify it works.