Skip to content

API keys and model providers

My API Keys stores user-authorised model-provider configuration for supported AI features. These keys are different from Gamut bearer API tokens and from Gateway-managed runtime credentials.

CredentialPurposeCustody
Model-provider keyRun permitted AI Assist, Consultant or generation features.Stored and used server-side for the authorised user context.
Gamut bearer tokenIntegrate with supported Gamut API resources.Created by the user and stored by the external integration.
Gateway connection credentialInvoke an approved external tool or provider at runtime.Held by the governed Gateway connection, never the agent.
  1. Obtain a dedicated organisational provider key where possible.
  2. Restrict provider-side project, spend and capability.
  3. Add it through My API Keys; do not paste it into assessment notes or chat.
  4. Run a low-risk test and confirm the selected provider.
  5. Monitor usage and rotate according to policy.
  6. Remove the key promptly when no longer required or suspected exposed.

The browser does not receive the stored provider secret during ordinary AI use. Entitlement, permission and usage quotas still apply even when the user supplies the provider key.

Configuring a key does not itself authorise sending every workspace record. Use scores-only privacy mode for framework AI Assist when detailed context is unnecessary. The AI Consultant uses the permitted workspace context shown on its screen and should not be used where that context is not appropriate for the configured provider.