Skip to content

Using your own AI API keys

The AI area controls which provider powers your organisation's AI features. Only administrators can manage it.

The simpler route is usually a curated AI package: a combination of provider, models and jurisdiction classification vetted by the operator. The own credentials on this page apply when your organisation has not chosen a package (the "Own configuration" tile).

Storing credentials

  1. Open AI → Access.
  2. Click the Own configuration tile. It opens that section in place of the package catalogue.
  3. Follow its Set up credentials link.
  4. Pick the provider. Which fields appear next depends on it:
    • OpenAI — key, and optionally the organisation ID.
    • Anthropic — the key only.
    • Google (Vertex) — the service account JSON. A plain API key is not enough here: it would silently use the global endpoint and void processing within the EU.
    • OpenAI-compatible endpoint — key, endpoint URL and model name. All three are required; without them the organisation counts as "AI not configured" afterwards.
  5. Save with Save and check. The connection check runs right after the save, so it tests exactly what you entered.
Stored securely

Keys are stored encrypted and never shown in plain text. Leave the key field empty when editing to keep the existing key. What the form does not show for the selected provider does not apply to it and is cleared on save.

Changing the provider or the endpoint

If you change the provider or the endpoint URL, you have to enter the key again. That is deliberate rather than a form quirk: the stored key is never shown to you in clear, and without this step it could be sent to a new address by someone who does not know it. Typing the same key again is enough. Changing only the model or the organisation ID does not ask.

The endpoint URL must start with https:// and point at a publicly reachable address.

Checking the connection

The connection check asks the provider for its model list. It costs nothing, transfers no content, and works while AI is still switched off for the organisation: set up first, switch on afterwards is the normal order.

The result is kept. The page then states when it was last checked and whether the connection worked; the "Access" row in the AI overview shows a red dot when the last check failed.

What the check cannot see: it answers "is the key valid", not "can I work with it". An account without credit, or a model your key is not cleared for, passes the check and still fails on every request. When the provider refuses a request, the chat answer says so and points back to this page. The provider's own wording reaches only the operator's server log, because a chat answer is read by everyone in the project.

Removing the access

Remove access deletes the key, endpoint and model name. The selected provider stays, and the operator's access applies again afterwards, as far as one is stored for that provider.

This is the only way a key disappears. Saving with an empty field keeps it.

What's next

Credentials alone do not switch AI on — it also has to be enabled for the organisation, see Enabling or disabling AI. After that, features such as the AI assistant use the configured provider.