Skip to content

Model accounts and API keys

Connect your own API keys or cloud model accounts. Work you ask for uses your accounts first, then the organization's, then the platform's.

What you can connectLink to What you can connect

  • API keys: Anthropic, OpenAI, Google Gemini and OpenRouter.
  • Amazon Bedrock with an IAM access key (Claude models only).
  • Google Vertex AI with a service account key.
  • Azure OpenAI with a key and the resource endpoint.

You can have one account of each kind for yourself, and the organization can have one of each kind.

What never connectsLink to What never connects

A Claude or ChatGPT sign-in, its tokens or its login files. Agent refuses them, and admin keys and temporary keys too. To use a Claude or ChatGPT plan, see Subscriptions and vendor terms.

Connect an accountLink to Connect an account

  1. Open Model accounts and select Connect.
  2. Choose the provider and paste the credential.
  3. Optional: choose the tiers it serves, and a daily and monthly budget.
  4. Select Check and connect. Agent makes one free, read-only call. When the check fails, nothing is stored.

Only owners and admins can connect organization accounts. Any member can connect their own.

The orderLink to The order

For a call, Agent tries your own accounts first (as the person who asked for the work), then the organization's, then the platform's. An assignee's key never pays for work someone else asked for. When an account fails or its budget is spent, the call goes to the next one.

Fall back to the platform (on by default) lets the platform's models answer when your accounts cannot. When it is off, the call fails instead. A tier that no account serves always runs on the platform.

StatusesLink to Statuses

Works (ready), Refused (invalid) and Unreachable: the check could not reach the provider. Select Test to check again. A key that the provider refuses during work stops being used until it is tested again.

How keys are storedLink to How keys are stored

Encrypted in the vault. The page shows only the last four characters, or the service account's email. Disconnect deletes the credential and keeps its past spend.

Checked against the product on 2026-10-05.

Was this helpful?