Appearance
Provider API Keys: Where Each Kind Lives
VeriPrompt calls OpenAI, Anthropic, Google, Mistral and other AI providers on your behalf. It needs a credential for each one, and there are three places such a key can be entered, depending on who owns it. This guide tells you which page to use for which key, and how the gateway decides which one to send.
Not the key you were looking for?
- To let your own application call the VeriPrompt gateway, you need a gateway API key: Settings → API Keys (see the Quickstart).
- The keys that protect stored data at rest are encryption keys, managed under Admin → Security, not here.
The three levels at a glance
| Level | Who sets it | Where | Applies to |
|---|---|---|---|
| Platform | Super Admin | Admin → System Settings → Platform API Keys | Every company on the platform, as the shared fallback |
| Company | Company admin (Account Owner / Admin) | Admin → AI Models (Models tab) | Everyone in your company |
| Personal / BYOK | Any user (if the policy allows) | Settings → API Credentials | Only the user who added it |
When a request runs, the gateway picks the most specific credential that exists: personal → company → platform. A company key therefore overrides the platform key for that company, and a personal BYOK key overrides both for that user.
Platform keys (Super Admin)
Platform keys are the credentials VeriPrompt itself pays for. They power internal services such as Guru, Architect and MCP execution, and they serve as the fallback when a company has no key of its own and its access policy permits Platform Keys.
- Go to Admin → System Settings (
/admin/system-settings). - Scroll to Platform API Keys and click Add Platform API Key.
- Choose the Provider, pick the Model the key should serve, paste the API key and select a Quality Tier.
- Save. The key is encrypted before it is stored; the list shows only when it was set or rotated.
To rotate a key, edit the entry and enter the new value. Leaving the key field empty on an edit keeps the existing secret.
Permissions
Only Super Admins see the Platform API Keys section.
Company keys (Admin → AI Providers / AI Models)
Admin → AI Providers (/admin/ai-providers) and Admin → AI Models (/admin/ai-models) are the same page, opened on different tabs (Providers / Models / Provider Groups) — switch tabs without losing your place.
- Company API keys are set once per provider, not per model: open the Models tab, click the key pill in a provider's header (it reads Set API key, Key verified, Key set (untested) or Key test failed), and enter the key and optional endpoint. That one key covers every model configured under that provider.
- The Providers tab's edit form no longer has a credential field — it links to the Models tab instead. If you're looking for a per-row key field from an older version of this page, that's why it's gone.
- Adding a model to your company from the catalog (the Models tab's catalog-only rows, labelled Not configured) auto-activates it immediately if its provider already has a validated key — no separate enable step needed. Models added before the key was set are not retroactively activated; toggle them on from the Providers tab.
- Test All (Providers tab) validates every configured model against its provider so a wrong or expired key is caught before users hit it. Per-model Test (Models tab) checks just one.
Model catalogue vs. credentials
A catalog-only model carries no key of its own — it inherits its provider's key once you add it and the provider has one set. A model that is active but has no credential at any level fails with an authentication error at request time, and the routing engine skips it once health checks record the failure.
Personal keys (BYOK)
Users add their own provider keys under Settings → API Credentials. Whether they may do so, and whether personal keys are required, is a company access policy — see BYOK for the policy table, compliance tags and location options.
Which key did a request actually use?
- The Ranger gateway logs record the credential source for each call (
USER,COMPANYorPLATFORM). - If a provider returns 401 Unauthorized, the key that was selected is wrong or revoked — not missing. Check the most specific level first (a personal key, then the company row) before replacing the platform key.
