Bring your own key
Route your organization's Anthropic and OpenAI traffic through your own provider accounts. Tokamak still meters every request at a price you set, and charges nothing for what your keys serve.
Your organization may already have its own Anthropic or OpenAI account, with a committed-spend contract, higher rate limits, or a data agreement. Bring your own key (BYOK) lets requests to those providers run on your account instead of on Tokamak's capacity.
Everything else keeps working:
- Your tools keep using Tokamak model ids and Tokamak API keys.
- Analytics, Insights and budgets still see every request.
- Tokamak meters the requests your keys serve at an internal price that you set, for example your contract rate. It charges nothing for them. Your provider bills you directly, as it always has.
How the money works
| Who served the request | Usage cost in reports | Charged to your Tokamak credit |
|---|---|---|
| Your key | Your internal price for that model | $0 |
| Fallback: your key failed, and Tokamak served the retry | Tokamak's list price | List price |
| Tokamak: a model your keys do not serve | Tokamak's list price | List price |
These rules follow from the table:
- An internal price never changes what Tokamak charges. It applies only to requests your own keys served. Setting it to $0 makes those requests free in reports; it does not make Tokamak's requests cheaper.
- Budgets count key-served requests at the internal price. A team cannot get around its budget by routing through a provider key.
- Your key serves requests even when your Tokamak credit is empty. Tokamak still takes the usage-limit reservation, so budgets keep blocking.
- A failed key falls back to Tokamak once, charged at list price, unless you choose Your key only. See When a key fails.
Who does what
| You are | You do | Read |
|---|---|---|
| A platform administrator | Switch BYOK on for the organization, and decide on fallback and the allowed providers | Bring your own key (platform) |
| An organization owner or admin | Add keys, choose models and routing, and set internal prices | Set up your keys, Prices and reports |
| A billing viewer | See what your keys served and what reached your credit | Prices and reports |
| A member | Nothing. Your tools use the same models and commands; the Setup guide shows which models your organization's key serves | Set up your keys |
Good to know
- Supported providers. Anthropic (Messages API) and OpenAI (Chat Completions and Responses). Google is listed as coming soon.
- Keys are write-only. Tokamak encrypts a key when you save it and only ever shows its first and last characters. Only the provider's official API receives the key.
- Inference API keys cannot touch provider keys. Only an owner or admin signed in to the app can add, change or read provider-key settings. A Tokamak API key (
sk_live_…) can use the models, never the keys. - Responses you store live in your account. A Responses API object your key created stays in your OpenAI account. Tokamak remembers which key created it, so retrieving, deleting or cancelling it (
/v1/responses/{id}, and itsinput_items) goes to that key, and a new response that continues it withprevious_response_idprefers that key. While the key is disabled, those calls answer503 byok_key_unavailable, since the response cannot be read on other capacity. Once the key is deleted, they answer404.
Under the hood
The classifier behind tokamak/auto, the exact questions it is asked, the evaluations behind the defaults, what it costs, what leaves your deployment, and why the router works the way it does.
Set up your keys
From zero to one. Your platform administrator switches BYOK on; you add a provider key, keep the template's models, choose routing and a starting price, and your members' requests start running on your account.