Setting up BYOK
Bring your own keys (BYOK) means the LLM proxy forwards requests with your organization's own OpenAI, Anthropic, or Google API key. Your provider bills you directly, and Harriet adds no per-token charge.
Add an organization key
- Open Settings. Scroll to the LLM API keys (BYOK) card. It lists each provider with its status: Key configured, No key, or Managed billing only.
- Choose the provider. In Add or replace a key, pick OpenAI, Anthropic, or Google from the Provider select.
- Paste the key. Enter it in the API key field and select Save key. The status row changes to Key configured.
- Repeat per provider. Keys are per provider: one for OpenAI, one for Anthropic, one for Google. Use Remove on a row to delete that provider's key.
BYOK only matters when Use Harriet as LLM proxy is on (same Settings screen): that is the switch that routes Harriet Desktop and managed Claude Desktop model calls through Harriet in the first place. See the LLM proxy for how routing works.
How the billing source is decided
The proxy decides per provider, per request. If your organization has a BYOK key for the provider, the call is forwarded with that key and recorded as BYOK usage: no credit debit, no markup, billed to you by the provider. If there is no BYOK key, the call falls back to a Harriet-managed key and is billed to your prepaid balance as managed usage. BYOK keys take precedence over Harriet-managed credits.
Because the decision is per provider, mixing is normal: you can BYOK Anthropic while OpenAI runs on credits. The Billing tab's LLM providers card shows the current mode for each provider, and the This month card splits spend into BYOK spend and Managed spend.
A provider with neither a BYOK key nor a managed key rejects requests with a clear error rather than silently switching providers. If people report failing model calls, check the provider's status row first — see connection errors.
Key security
Keys are stored server-side against your organization and used only when Harriet proxies LLM calls on your behalf; devices never receive them. The console treats them as write-only: as the card itself says, "Keys are never shown after save." To rotate a key, save a new value over the old one.
Anthropic (EU) has no BYOK
The Anthropic (EU) models are resale-only: they run on a Harriet-managed platform key and are always billed through managed credits. There is nothing to configure on the BYOK card — when your plan includes them, the Anthropic (EU) row shows Managed billing only. They require Endpoint AI Business or higher; see Plans & pricing.