BYOK Provider Configuration
With BYOK (Bring Your Own Key), you add and configure each provider using your own API keys. This page describes how to set up and manage BYOK providers in Settings → Providers. Supported connections include OpenAI, Azure, Anthropic, Vertex, OpenAI-compatible endpoints, and a customer-owned Vercel AI Gateway key.
Adding a provider
- Open Settings → Providers.
- Find the provider you want to use (e.g. OpenAI, Azure OpenAI, OpenAI Compatible, Anthropic, Google Generative AI, Google Vertex AI, Mistral AI) in the BYOK list. See BYOK Providers for the full list and descriptions.
- Enable the provider (e.g. toggle “Enabled”).
- Enter your API key when the provider requires one. Some providers also let you set a base URL (e.g. for proxies or custom endpoints). For Google Vertex AI, you must also set Project ID and Location in Provider Options, and use a service account key (JSON) as the API key.
- Save. You can use Test connection (if available) to confirm the configuration works.
Your requests to that provider will use your key (when applicable); you are billed by the provider according to their terms.
API key and base URL
- API key: Obtain it from the provider’s dashboard or developer site. Store it securely; the app masks it after saving. For Google Vertex AI, paste the full service account key (JSON) from Google Cloud.
- Base URL: For OpenAI, OpenAI-compatible, and Azure OpenAI connections, enter the provider origin (for example
https://api.openai.com). You can include or omit/v1; both work. Leave blank to use the catalog default when we know one (OpenAI defaults tohttps://api.openai.com). Use a custom origin for proxies or self-hosted APIs. - Google Vertex AI only: In Provider Options, set Project ID and Location (e.g.
us-central1). See Google Cloud Vertex AI for enabling the API and creating a service account.
Test connection
After saving, use Test connection to verify that the key and optional base URL work. If the test fails, check the key, base URL, and provider status.
If chat fails because the provider API key is out of credits (or rejected), the chat UI shows a toast explaining that. This is distinct from optional Steinkauz AI Budget errors. Add credits in the provider’s billing settings, or switch provider or model.
Execution environment
For each provider you can set an execution environment (E0–E5). That class describes how much you trust this integration for sensitive workloads.
In chat, you separately choose Auto or Manual sensitivity policy for each thread. The server computes effective data sensitivity and checks your routing matrix against the provider’s environment before each send. See the full Data routing policy guide.
Disabling a provider
Turn the provider off in settings to stop using it. Your saved key and settings remain, but no new requests will be sent to that provider until you enable it again.
Provider create, update, and delete appear in Settings → Configuration Audit (and as five recent events on the Providers page). Your provider API key is never stored in that log. See Configuration Audit.
For an overview of BYOK and supported providers, see BYOK.