Bring Your Own Key (BYOK)
Route every AI call for your workspace through your own Anthropic API key. Included in every paid plan. Beta.
What BYOK is
BYOK is included in every paid OrgBolt plan — it swaps OrgBolt's house Anthropic key for one you provide yourself. It's a security and compliance feature for the Anthropic leg of your stack, not a premium upsell: the price is the same whether or not you turn it on. From the moment your workspace owner saves a key in /settings → AI Provider, every AI call OrgBolt makes for that workspace — chat (Sonnet/Opus), title summarization (Haiku), metadata pre-injection (Haiku) — runs through your Anthropic account.
OrgBolt's credit ledger is bypassed entirely for those calls. You pay Anthropic directly at their wholesale rates; your subscription pays for the platform — auth, workspace storage, Salesforce integration, the deploy pipeline — not the AI inference itself.
Who BYOK is for
Two customer cohorts hit a wall with OrgBolt's credit pricing and BYOK solves their problem:
- Heavy daily users — credit usage adds up at scale. BYOK lets you pay Anthropic directly at their list price for the AI calls that matter, rather than drawing down your workspace credits.
- Compliance / enterprise buyers — your data-handling rules require LLM traffic to flow under your own Anthropic contract for audit, regional, or BAA reasons. BYOK gives you a clean boundary you can show your security review team.
What flows where with BYOK on
This is the disclosure for the compliance use case. BYOK affects only the Anthropic leg of OrgBolt's data flow — every other vendor remains under OrgBolt's contracts.
| Flows through YOUR Anthropic contract | Stays under OrgBolt's vendor contracts |
|---|---|
| Chat messages (user input and prompts you paste) | Conversation history at rest (Supabase Postgres) |
| System prompts and per-task instructions | Salesforce metadata cache (Supabase Postgres) |
| Conversation history sent on each turn | Audit logs and billing events (Supabase, Lemon Squeezy) |
| Image / file attachments sent to the model | Email sends (Resend) |
| Tool inputs/outputs (describe_object, deploy results) | Edge / DNS / tunneling (Cloudflare) |
| Token usage + cache telemetry from Anthropic | Salesforce OAuth tokens (encrypted in Supabase Vault) |
How to set up BYOK
- Make sure your workspace is on a paid plan. (BYOK is included in every paid plan; the free trial doesn't get it.)
- Generate an Anthropic API key at console.anthropic.com → Settings → API Keys. The key needs access to Haiku, Sonnet, and Opus — most personal keys have all three by default.
- In OrgBolt, go to /settings → AI Provider. (Workspace owner only — billing contacts and members don't see the panel.)
- Paste the key and click Save & validate. We send a 1-token Haiku ping with your key to confirm it works (~$0.00005 to your Anthropic account). If validation fails, the panel surfaces Anthropic's error verbatim so you can fix it.
- On success, the key is encrypted into Supabase Vault and your next chat message routes through your Anthropic account. The masked display (sk-ant-…XXXX) confirms which key is configured.
Rotating or removing your key
Replace key: paste a new one, click Save & validate. We swap the stored secret atomically and delete the old one from Vault. No downtime — the next chat message picks up the new key.
Remove key: click Remove and type your workspace name to confirm. The Vault secret is deleted immediately (not waiting for the weekly orphan sweeper) and your workspace reverts to OrgBolt's credit-debited path for all subsequent AI calls.
What happens if your subscription lapses
BYOK is honored only while your workspace is on a paid plan (active or cancelled-pending-expiry). If you cancel and your paid period ends — or your subscription expires — your stored key is preserved by default but becomes inactive: AI calls revert to OrgBolt's credit-debited path silently. Re-subscribing reactivates BYOK with the same key, no re-paste needed.
If you'd rather have the key gone, remove it any time from /settings → AI Provider. The Vault secret is deleted immediately and your workspace reverts to OrgBolt's credit-debited path.
When something goes wrong
BYOK calls hard-fail rather than fall back to OrgBolt's contract. This is intentional — the Anthropic-leg boundary that compliance customers chose BYOK for would be violated by a silent fallback.
- Your key is invalid / revoked: chat shows the verbatim Anthropic error and points you at /settings. Fix the key and the next message works.
- Your Anthropic account is out of credit: same error path, classification 'quota'. Top up at console.anthropic.com.
- Anthropic is rate-limiting you: we retry once with backoff. If it still fails, the error surfaces — you can pace your traffic or raise limits in the Anthropic console.
- Anthropic is down: 5xx surfaces after one retry. Try again in a few minutes; Anthropic publishes status at status.anthropic.com.
Seeing what your BYOK calls cost
/billing shows an AI Costs card with a date range picker (this month, last month, last 3 months, etc.). When the selected range contains BYOK messages, the card switches to a two-column layout: OrgBolt billed and Your Anthropic spend. Both columns aggregate to per-task spend in a drill-down table so you can see where the AI money is going.
The Your Anthropic spend column reflects Anthropic's list prices for the actual tokens consumed (input + output + cache). It's not what Anthropic invoices you for — they charge per-account, not per-OrgBolt-workspace — but it's a faithful per-message estimate at Anthropic's published rates.
About Anthropic's prompt cache
Anthropic's prompt cache is per-API-key. When you flip on BYOK, your first few messages don't benefit from the warm cache OrgBolt shares across non-BYOK customers. You'll pay full input cost on the cache-creation call (~1.1× normal), then 25% on cache reads thereafter — exactly how the cache works for everyone, just with your own copy.
Over a session, the cost difference is negligible; over a single first message, you might see slightly higher token cost than the equivalent non-BYOK message. This is expected and not a bug.