API keys and model providers
My API Keys stores user-authorised model-provider configuration for supported AI features. These keys are different from Gamut bearer API tokens and from Gateway-managed runtime credentials.
| Credential | Purpose | Custody |
|---|---|---|
| Model-provider key | Run permitted AI Assist, Consultant or generation features. | Stored and used server-side for the authorised user context. |
| Gamut bearer token | Integrate with supported Gamut API resources. | Created by the user and stored by the external integration. |
| Gateway connection credential | Invoke an approved external tool or provider at runtime. | Held by the governed Gateway connection, never the agent. |
Configure safely
Section titled “Configure safely”- Obtain a dedicated organisational provider key where possible.
- Restrict provider-side project, spend and capability.
- Add it through My API Keys; do not paste it into assessment notes or chat.
- Run a low-risk test and confirm the selected provider.
- Monitor usage and rotate according to policy.
- Remove the key promptly when no longer required or suspected exposed.
The browser does not receive the stored provider secret during ordinary AI use. Entitlement, permission and usage quotas still apply even when the user supplies the provider key.
Privacy decisions
Section titled “Privacy decisions”Configuring a key does not itself authorise sending every workspace record. Use scores-only privacy mode for framework AI Assist when detailed context is unnecessary. The AI Consultant uses the permitted workspace context shown on its screen and should not be used where that context is not appropriate for the configured provider.