Skip to main content

Bring your own key

Bring your own key, or BYOK, lets a Qodex project use your OpenAI API key for LLM calls. A project can also connect a ChatGPT subscription you already pay for. This is useful when your team wants provider billing to go directly to your own account, wants separate usage visibility, or has internal controls around model spend.
This page covers cloud BYOK, which you configure in Settings > LLM keys in the Qodex app. On a self-hosted deployment you set the provider key with an environment variable such as OPENAI_API_KEY instead; see self-hosted environment variables. Cloud projects do not use environment variables for BYOK.

What changes with BYOK

Qodex takes zero margin on BYOK usage.

1. Open LLM keys

Open the account menu at the bottom of the left navigation, choose Settings, then open LLM keys. The OpenAI key section is at the top. If the project is waiting for activation, click Add OpenAI key. If it already uses Qodex platform credits, click Add my own key.

2. Save your key

Paste an OpenAI API key that starts with sk-, then click Save key. Qodex validates the key before saving it. If OpenAI rejects the key, Qodex shows the upstream error so you can fix it before running tests. The saved key is encrypted at rest. The UI only shows the last four characters after save.

3. Run Qodex normally

After the key is saved, the next LLM call for that project uses your key. Open Usage from the project account menu to review usage behavior. BYOK traffic is billed through your provider account rather than the platform-funded key.

4. Rotate or remove the key

Go to Settings > LLM keys, then choose Remove for the OpenAI key and confirm Remove. To rotate a key, click Replace, paste the new key, and click Save key. Removing the key returns the project to the platform-funded key only when the project is admin-approved. Otherwise, the project returns to pending and Qodex stops working until a valid key is added or access is approved.

Connect a ChatGPT subscription

Instead of an API key, a project admin can connect a ChatGPT account the team already pays for. Reviews and runs on the project then use that account.
  1. Go to Settings > LLM keys and find ChatGPT subscription.
  2. Click Connect ChatGPT.
  3. Open the sign-in URL Qodex shows in a new tab and sign in to ChatGPT.
  4. After ChatGPT redirects, copy the code from the address bar, paste it into Paste the OAuth code, and click Connect account.
The connected account shows one of these states: To stop using the account, click Disconnect and confirm. Reviews and runs go back to your plan’s credentials. Usage on a connected ChatGPT subscription does not count against Qodex-funded caps. If a project has both an OpenAI key and a ChatGPT subscription, the OpenAI key is used first.

Security testing and code scans

Security testing and code scans never run on a connected ChatGPT subscription or on Qodex’s shared OpenAI capacity. They use the project’s own OpenAI key when one is saved. Otherwise, they run on a separate Qodex-managed model.

Limits

  • OpenAI keys and a connected ChatGPT subscription are self-serve in Settings > LLM keys.
  • Bringing your own Anthropic or Google key is planned. The Qodex team can route a project’s Qodex-funded calls through Anthropic or Google on request; that usage is billed by Qodex, not to your provider account.
  • Keys are project-scoped. Each project stores its own key.
  • Qodex validates the key at save time. If the provider later revokes it, the failure appears in run logs.
  • Qodex plan caps do not limit BYOK provider spend. Use your provider account controls for that.

Next steps

Usage and cost caps

Understand how BYOK affects project caps.

Self-hosted environment variables

Configure platform fallback keys when self-hosting.

How Qodex works

See where LLM calls fit into the agent loop.

Integrations

Return to all integrations.