Appearance
BYOK (Bring Your Own Key)
BYOK lets you use your own AI provider credentials while still getting Veriprompt's intelligent routing, safety features, and analytics.
Why Teams Use BYOK
- Keep billing with your provider - Use your existing enterprise agreements and volume discounts
- Control which models are available - Define exactly which models your team can access
- Separate dev and production credentials - Use different keys for different environments
- Compliance requirements - Meet data residency requirements by specifying provider locations
- Cost transparency - Track usage per credential with detailed analytics
Getting Started
Adding a New API Key
- Navigate to Settings > API Credentials in the dashboard
- Click Add API Key
- Select the provider and model from the catalog
- Enter your API key
- Optionally add a nickname (e.g., "Production Key", "Testing Key")
- Choose ownership: Company Key (shared) or Personal Key
Location & Compliance Options
When adding or editing a credential, you can expand the Location & Compliance Options section to specify:
Country
Select the country where your AI provider processes data. This is used for:
- Geofencing rules to ensure data stays within specific regions
- Routing decisions based on data residency requirements
- Compliance with regulations like GDPR, LGPD, etc.
Common locations:
- US - United States (most major providers)
- DE - Germany (EU-compliant options)
- GB - United Kingdom
- JP - Japan
- SG - Singapore (APAC region)
Region/Datacenter
Specify the exact datacenter or region, such as:
us-east-1- AWS US Easteu-west-1- AWS EU Westasia-southeast1- GCP Singapore
Expected IP Ranges
For advanced security, specify the IP ranges (in CIDR notation) that the provider should connect from:
104.18.0.0/16- Example range- Multiple ranges can be comma-separated
This helps with:
- Validating that responses come from expected infrastructure
- Detecting potential man-in-the-middle scenarios
- Audit and compliance logging
Compliance Tags
Mark credentials with relevant compliance frameworks:
- GDPR - EU General Data Protection Regulation
- HIPAA - Healthcare (US)
- SOC2 - Service Organization Control 2
- ISO27001 - Information Security Management
- PCI-DSS - Payment Card Industry
- CCPA - California Consumer Privacy Act
- LGPD - Brazil's Data Protection Law
These tags are used by routing policies to ensure prompts are only sent to compliant providers.
Credential Management
Validating Credentials
Click the Validate button to test that your API key is working. The system will make a minimal test call to verify:
- The key is valid and active
- The provider endpoint is reachable
- Response latency is measured
Active/Inactive Status
Toggle credentials between Active and Inactive states:
- Active - Available for routing and execution
- Inactive - Excluded from routing (preserved for future use)
Bulk Import
Import multiple credentials at once using CSV or Excel files:
- Click Import in the credentials section
- Download the template file
- Fill in your credentials with columns:
provider- Provider name (openai, anthropic, google)model- Model ID (gpt-4, claude-3-opus)api_key- Your API keynickname- Optional friendly nameowner_type- COMPANY or USER
- Upload and import
Access Policies
Your organization's access policy determines what you can do with credentials:
| Policy | Description |
|---|---|
| Platform Keys | Use Veriprompt-provided shared credentials |
| Company Keys | Use credentials shared across your organization |
| Personal Keys | Use your own individual credentials |
| Require BYOK | Must use your own keys (platform keys disabled) |
Contact your administrator to adjust these policies.
Security Best Practices
- Use separate keys for environments - Don't share production keys with development
- Rotate keys regularly - Replace credentials periodically
- Set expiration dates - Configure keys to expire when projects end
- Specify locations - Always set country/region for compliance tracking
- Enable compliance tags - Mark credentials with relevant frameworks
- Monitor usage - Review analytics for unusual patterns
Integration with Routing
BYOK credentials integrate with Veriprompt's intelligent routing:
- Geofencing - Routes are filtered based on credential location
- Compliance filtering - Only compliant credentials are considered
- Cost optimization - BYOK costs are tracked separately
- Fallback handling - Platform keys can serve as fallback when BYOK fails
Hybrid Provider Assignment (Pooled + BYOK)
Every chat category (and the routing policy behind it) has a provider sourcing mode that decides where requests in that category get their provider credentials from. There are three modes:
| Mode | Where requests run | Typical use |
|---|---|---|
| POOLED | Veriprompt's shared platform provider pool | Everyday, lower-sensitivity traffic where cost and convenience matter most |
| PASS_THROUGH | Your company's own BYOK credentials only — the prompt is sent using your provider keys | Sensitive traffic, or when a classification sets requiresPassThrough / your access policy sets Require BYOK |
| HYBRID | A blend of both — pooled providers and your company's BYOK keys in one policy | When you want BYOK where it's available but a pool fallback so requests never get stuck |
Why this matters
A common setup uses different modes per category:
- A "General" category stays POOLED so routine questions use the shared pool and stay cheap.
- A "Confidential" category is set to PASS_THROUGH (or HYBRID) so sensitive prompts only ever travel over your own provider keys — keeping the data inside your provider contract and data-residency boundary.
If a classification is marked as requiring pass-through (requiresPassThrough), Veriprompt enforces it server-side: a category that isn't PASS_THROUGH will be rejected for that classification. Likewise, if your access policy sets Require BYOK, platform pool keys are disabled and requests must use your own credentials.
Walk-through: assigning providers in each mode
You configure modes under Admin → Chat Settings → Chat Categories. Your BYOK keys come from Settings → Credentials.
POOLED example
- Open Admin → Chat Settings → Chat Categories and create or edit a category, e.g. General.
- Set Mode to POOLED.
- Save. Requests in this category are routed across the shared platform pool by the routing policy — no BYOK key is attached.
PASS_THROUGH example
- First add your provider key under Settings → Credentials (e.g. a Company OpenAI key).
- Open Admin → Chat Settings → Chat Categories, create or edit a category, e.g. Confidential.
- Set Mode to PASS_THROUGH.
- Select the pass-through credential to use (this is required for PASS_THROUGH). All prompts in this category are sent using that key only.
- Save. Sensitive prompts now run exclusively on your own credentials.
HYBRID example
- Add one or more provider keys under Settings → Credentials.
- Open Admin → Chat Settings → Chat Categories, create or edit a category, e.g. Confidential (resilient).
- Set Mode to HYBRID.
- Attach at least one BYOK credential (required for HYBRID), and choose whether to prefer BYOK first.
- Save. Requests now try your BYOK key and the pool together — using BYOK where available and falling back to (or mixing with) the pool so a single key outage never blocks the category.
Per-User Provider & Quality Profiles
Beyond company-wide categories, each user can set their own default provider and default quality tier for chat and Guru. These are stored as a per-user preference:
defaultProvider— your preferred provider (e.g.anthropic). Set it toautoto let Veriprompt's routing decide for you.defaultQuality— your preferred quality tier, one of:cheap— lowest costfast— quickest responses (the default)quality— highest-capability modelssecure— privacy/compliance-oriented models
These per-user defaults act as a fallback for Guru chat, Guru explain/refine, and the chat terminal whenever no more specific choice applies.
How precedence works
Veriprompt picks a provider in this order — the first one that applies wins:
- Explicit selection in the request — a provider or model you pick directly for that message.
- Category / policy routing — the routing rules of the chat category you're using (including POOLED / PASS_THROUGH / HYBRID above).
- Your own default profile — your
defaultProvideranddefaultQuality. - Company default — the organization-wide fallback.
Example: You set defaultProvider: "anthropic" and defaultQuality: "quality". When you open a chat in a category that has no specific provider routing and don't pick a provider for the message, Guru uses Anthropic at the quality tier. If you instead set defaultProvider: "auto", Veriprompt's router chooses the best provider for you at the quality tier. If the category itself is set to PASS_THROUGH, that category routing takes priority over your personal default.
