Bring your own keys

Use your existing OpenAI, Anthropic, Google, or Azure account inside Cocobox — your keys, your billing.

Last updated

Cocobox can route AI requests through your own provider keys. No credit is consumed; the provider bills you directly.

Add a key

Settings → AI → Provider keys → Add.

Supported providers:

  • OpenAI — sk-… keys.
  • Anthropic — sk-ant-… keys.
  • Google AI Studio — keys for Gemini API.
  • Azure OpenAI — endpoint + deployment id + key.
  • AWS Bedrock — access key + secret + region (cross-account roles supported on Enterprise).

Keys are encrypted at rest with the same scheme as DB credentials. They’re decrypted only at request time, in memory, and never logged.

Restrict which models a key can access

Click a key → Allowed models → check or uncheck. Useful when:

  • You have a separate provider account for production vs. development.
  • You want analysts to use cheap models only.
  • You want to disable a model that’s deprecated.

Per-user vs. workspace keys

By default, a key is workspace-scoped — every member uses it.

Toggle Personal key to keep it to yourself. Personal keys are only used when you trigger an AI action; teammates fall back to workspace keys (or credits).

Order of resolution

When the editor or API picks a provider, it tries in order:

  1. Per-API-key override — if the calling API key has allowed_models set to a single provider, that wins.
  2. Personal key for the requesting user.
  3. Workspace key for the provider.
  4. CocoboxAI credits for the model alias.

If none of those resolve, the request 402s with no_provider_available.

Removing a key

Removing a key:

  • Severs new requests immediately.
  • Does not revoke the upstream key — go to your provider’s console to actually disable it. Cocobox just stops using it.