# Using your own AI API keys

The AI area controls which provider powers your organisation's AI features. Only
administrators can manage it.

The simpler route is usually a curated [AI package](https://lalabase.com/docs/en/guides/ai/packages): a combination of
provider, models and jurisdiction classification vetted by the operator. The own
credentials on this page apply when your organisation has not chosen a package (the
"Own configuration" tile).

## Storing credentials

1. Open **AI → Access**.
2. Click the **Own configuration** tile. It opens that section in place of the package
   catalogue.
3. Follow its **Set up credentials** link.
4. Pick the **provider**. Which fields appear next depends on it:
   - **OpenAI** — key, and optionally the organisation ID.
   - **Anthropic** — the key only.
   - **Google (Vertex)** — the **service account JSON**. A plain API key is not enough
     here: it would silently use the global endpoint and void processing within the EU.
   - **OpenAI-compatible endpoint** — key, **endpoint URL** and **model name**. All
     three are required; without them the organisation counts as "AI not configured"
     afterwards.
5. Save with **Save and check**. The connection check runs right after the save, so it
   tests exactly what you entered.

<div class="docs-callout docs-callout--info">
  <div class="docs-callout__title">Stored securely</div>
  <p><strong>Keys are stored encrypted and never shown in plain text.</strong> Leave the key field empty when editing to keep the existing key. What the form does not show for the selected provider does not apply to it and is cleared on save.</p>
</div>

## Changing the provider or the endpoint

If you change the **provider** or the **endpoint URL**, you have to enter the key again.
That is deliberate rather than a form quirk: the stored key is never shown to you in
clear, and without this step it could be sent to a new address by someone who does not
know it. Typing the same key again is enough. Changing only the model or the
organisation ID does not ask.

The endpoint URL must start with `https://` and point at a publicly reachable address.

## Checking the connection

The connection check asks the provider for its model list. It costs nothing, transfers
no content, and works while AI is still switched off for the organisation: set up first,
switch on afterwards is the normal order.

The result is kept. The page then states when it was last checked and whether the
connection worked; the "Access" row in the AI overview shows a red dot when the last
check failed.

What the check cannot see: it answers "is the key valid", not "can I work with it". An
account without credit, or a model your key is not cleared for, passes the check and
still fails on every request. When the provider refuses a request, the chat answer says
so and points back to this page. The provider's own wording reaches only the operator's
server log, because a chat answer is read by everyone in the project.

## Removing the access

**Remove access** deletes the key, endpoint and model name. The selected provider stays,
and the operator's access applies again afterwards, as far as one is stored for that
provider.

This is the only way a key disappears. Saving with an empty field keeps it.

## What's next

Credentials alone do not switch AI on — it also has to be enabled for the
organisation, see [Enabling or disabling AI](https://lalabase.com/docs/en/guides/ai/enable-disable). After that, features
such as the [AI assistant](https://lalabase.com/docs/en/guides/ai/assistant) use the configured provider.
