Every model is served on your own provider credential. This is not a tier or an option — it is enforced by a database constraint, and there is no platform capacity to fall back to.
What happens to your key
- Encrypted with AES-256-GCM under a data key generated for that credential.
- That data key is itself wrapped by a master key held in Google Cloud KMS, which never leaves the key service. A copy of our database decrypts nothing.
- No endpoint returns a stored credential. Not to you, not to staff, not to support. Listing gives a four-character hint.
- Decrypted in memory only at dispatch, only for a request your organisation made.
Adding one
POST/v1/byok
curl
curl -X POST https://autonomousrelay.com/v1/byok \
-H "Authorization: Bearer $AGENTROUTER_MANAGEMENT_KEY" \
-H 'content-type: application/json' \
-d '{
"provider": "anthropic",
"api_key": "sk-ant-...",
"name": "prod",
"fallback_policy": "none_for_provider"
}'Management key only. An inference key is refused here, deliberately — see Authentication.
Fallback policy
platform— if your key fails, serve on platform capacity. Currently unreachable: nothing is resold.none_for_models— a failure returns an error rather than quietly spending elsewhere.none_for_provider— strictest. Every request to this provider must use your credential.
Managing credentials
GET/v1/byok
PATCH/v1/byok/:id
DELETE/v1/byok/:id
PATCH accepts only disabled. To change a key, replace the credential — there is no update path that could return the old value.
Your provider’s usage policies bind you directly, because you are their customer. Their restrictions are frequently stricter than ours and change without telling us.