Overview
BYOK lets you use your own provider API keys (OpenAI, Anthropic, etc.) while still benefiting from OpenModex’s routing, monitoring, fallbacks, and unified billing. This is ideal when:- You have volume discounts or enterprise agreements with providers
- You need to use a specific provider account for compliance
- You want direct billing with the provider for certain models
Setup
1
Go to Provider Keys
Open the Dashboard → Settings → Provider Keys.
2
Add a Provider Key
Click Add Key, select the provider, and paste your API key.
3
Verify
OpenModex will validate the key with a test request. Once verified, requests for that provider will use your key.
Security
All provider keys are encrypted at rest using AWS KMS envelope encryption (AES-256). OpenModex never logs or exposes your provider keys.
- Keys are encrypted immediately on submission
- Only the key prefix is stored for identification (e.g.,
sk-...abc) - Decryption happens in-memory only at request time
- Keys are never included in logs, analytics, or API responses
How Routing Works with BYOK
When you have a BYOK key configured for a provider:- Requests targeting that provider use your key instead of OpenModex’s shared pool
- You’re billed directly by the provider — OpenModex does not charge for model tokens
- You still pay the OpenModex subscription fee for platform features
- Routing, caching, fallbacks, and monitoring still work normally
Mixed Configuration
You can configure BYOK for some providers and use OpenModex-managed keys for others:- GPT-4o requests use your OpenAI key (billed by OpenAI)
- Claude requests use OpenModex’s key (billed by OpenModex)
- Fallbacks between BYOK and managed providers work seamlessly