Bring your own key
Bring your own key, or BYOK, lets a Qodex project use your OpenAI API key for LLM calls. A project can also connect a ChatGPT subscription you already pay for. This is useful when your team wants provider billing to go directly to your own account, wants separate usage visibility, or has internal controls around model spend.This page covers cloud BYOK, which you configure in Settings > LLM keys in the Qodex app. On a self-hosted deployment you set the provider key with an environment variable such as
OPENAI_API_KEY instead; see self-hosted environment variables. Cloud projects do not use environment variables for BYOK.What changes with BYOK
Qodex takes zero margin on BYOK usage.
1. Open LLM keys
Open the account menu at the bottom of the left navigation, choose Settings, then open LLM keys. The OpenAI key section is at the top. If the project is waiting for activation, click Add OpenAI key. If it already uses Qodex platform credits, click Add my own key.2. Save your key
Paste an OpenAI API key that starts withsk-, then click Save key.
Qodex validates the key before saving it. If OpenAI rejects the key, Qodex shows the upstream error so you can fix it before running tests.
The saved key is encrypted at rest. The UI only shows the last four characters after save.
3. Run Qodex normally
After the key is saved, the next LLM call for that project uses your key. Open Usage from the project account menu to review usage behavior. BYOK traffic is billed through your provider account rather than the platform-funded key.4. Rotate or remove the key
Go to Settings > LLM keys, then choose Remove for the OpenAI key and confirm Remove. To rotate a key, click Replace, paste the new key, and click Save key. Removing the key returns the project to the platform-funded key only when the project is admin-approved. Otherwise, the project returns to pending and Qodex stops working until a valid key is added or access is approved.Connect a ChatGPT subscription
Instead of an API key, a project admin can connect a ChatGPT account the team already pays for. Reviews and runs on the project then use that account.- Go to Settings > LLM keys and find ChatGPT subscription.
- Click Connect ChatGPT.
- Open the sign-in URL Qodex shows in a new tab and sign in to ChatGPT.
- After ChatGPT redirects, copy the code from the address bar, paste it into Paste the OAuth code, and click Connect account.
To stop using the account, click Disconnect and confirm. Reviews and runs go back to your plan’s credentials.
Usage on a connected ChatGPT subscription does not count against Qodex-funded caps. If a project has both an OpenAI key and a ChatGPT subscription, the OpenAI key is used first.
Security testing and code scans
Security testing and code scans never run on a connected ChatGPT subscription or on Qodex’s shared OpenAI capacity. They use the project’s own OpenAI key when one is saved. Otherwise, they run on a separate Qodex-managed model.Limits
- OpenAI keys and a connected ChatGPT subscription are self-serve in Settings > LLM keys.
- Bringing your own Anthropic or Google key is planned. The Qodex team can route a project’s Qodex-funded calls through Anthropic or Google on request; that usage is billed by Qodex, not to your provider account.
- Keys are project-scoped. Each project stores its own key.
- Qodex validates the key at save time. If the provider later revokes it, the failure appears in run logs.
- Qodex plan caps do not limit BYOK provider spend. Use your provider account controls for that.
Next steps
Usage and cost caps
Understand how BYOK affects project caps.
Self-hosted environment variables
Configure platform fallback keys when self-hosting.
How Qodex works
See where LLM calls fit into the agent loop.
Integrations
Return to all integrations.