DocsAPI Reference
Bring your own key

Bring your own key

Route your organization's Anthropic and OpenAI traffic through your own provider accounts. Tokamak still meters every request at a price you set, and charges nothing for what your keys serve.


Your organization may already have its own Anthropic or OpenAI account, with a committed-spend contract, higher rate limits, or a data agreement. Bring your own key (BYOK) lets requests to those providers run on your account instead of on Tokamak's capacity.

Everything else keeps working:

  • Your tools keep using Tokamak model ids and Tokamak API keys.
  • Analytics, Insights and budgets still see every request.
  • Tokamak meters the requests your keys serve at an internal price that you set, for example your contract rate. It charges nothing for them. Your provider bills you directly, as it always has.
A request when your organization has its own key
Your toolSends a Tokamak model id, such as anthropic/claude-sonnet-5
Your keyServes it when an active key maps that model, at your internal price
Tokamak capacityServes every other model, and a request your key failed, at list price
With Your key only, a failed request is not retried on Tokamak: a rejected or disabled key answers 503 byok_key_unavailable, and other provider errors reach your tool as sent.
Model ids stay Tokamak ids. The key serves only models its template mapping enabled; everything else is served by Tokamak as before.

How the money works

Who served the requestUsage cost in reportsCharged to your Tokamak credit
Your keyYour internal price for that model$0
Fallback: your key failed, and Tokamak served the retryTokamak's list priceList price
Tokamak: a model your keys do not serveTokamak's list priceList price
Metered everywhere, charged only for Tokamak capacity
Your key served itUsage cost at your internal priceCharged $0. Your provider bills you.
FallbackYour key failed; Tokamak served itCharged at list price.
Tokamak served itA model your keys do not serveCharged at list price.
Your internal price never changes what Tokamak charges.
Usage cost is what analytics, Insights and budgets count. Only the charged amount reaches your Tokamak credit, and only when billing is enforced on your deployment.

These rules follow from the table:

  • An internal price never changes what Tokamak charges. It applies only to requests your own keys served. Setting it to $0 makes those requests free in reports; it does not make Tokamak's requests cheaper.
  • Budgets count key-served requests at the internal price. A team cannot get around its budget by routing through a provider key.
  • Your key serves requests even when your Tokamak credit is empty. Tokamak still takes the usage-limit reservation, so budgets keep blocking.
  • A failed key falls back to Tokamak once, charged at list price, unless you choose Your key only. See When a key fails.

Who does what

You areYou doRead
A platform administratorSwitch BYOK on for the organization, and decide on fallback and the allowed providersBring your own key (platform)
An organization owner or adminAdd keys, choose models and routing, and set internal pricesSet up your keys, Prices and reports
A billing viewerSee what your keys served and what reached your creditPrices and reports
A memberNothing. Your tools use the same models and commands; the Setup guide shows which models your organization's key servesSet up your keys

Good to know

  • Supported providers. Anthropic (Messages API) and OpenAI (Chat Completions and Responses). Google is listed as coming soon.
  • Keys are write-only. Tokamak encrypts a key when you save it and only ever shows its first and last characters. Only the provider's official API receives the key.
  • Inference API keys cannot touch provider keys. Only an owner or admin signed in to the app can add, change or read provider-key settings. A Tokamak API key (sk_live_…) can use the models, never the keys.
  • Responses you store live in your account. A Responses API object your key created stays in your OpenAI account. Tokamak remembers which key created it, so retrieving, deleting or cancelling it (/v1/responses/{id}, and its input_items) goes to that key, and a new response that continues it with previous_response_id prefers that key. While the key is disabled, those calls answer 503 byok_key_unavailable, since the response cannot be read on other capacity. Once the key is deleted, they answer 404.

On this page