AI glossary · Tokens and cost
What is BYOK (bring your own key)?
Also called: bring your own key, bring your own API key
Definition
BYOK (bring your own key) is a model where an AI app or tool runs on your own API key from a provider such as OpenAI, Anthropic or Google, so usage is billed to your account instead of the app’s.
Explained
How it works
Without BYOK, an app calls the model with its own key and recovers the cost through a subscription or credits. With BYOK, you create an API key with the provider and paste it into the app; the provider then bills you per token at its normal price, under its own terms and rate limits.
Where the key goes is what matters. In a server-proxy design, the key travels to the app’s server, which calls the provider for you, so you are trusting that server not to log or misuse it. In a browser-direct design, the page calls the provider straight from your browser and the key never reaches the app’s server. That only works where the provider allows browser requests; Anthropic’s TypeScript SDK, for example, refuses to run in a browser until you set dangerouslyAllowBrowser.
The catch with browser-direct is that a key in a page is reachable by any script on that page, so it is only as safe as the site.
Example
How BYOK works on this site
The Gemini playground and the API key checker here are browser-direct. Your key is held in the page’s memory and sent only to the provider’s own API address; it never goes to our server and is never put in a URL, analytics or logs. Tools that offer “Remember on this device” save it in your browser’s local storage only if you tick it, and the site’s Content Security Policy limits which addresses a page can send data to: this site, the approved provider APIs and our analytics endpoint, which never receives your key.
The key checker sends one request that lists models, which costs nothing. Playground chats count against your own Gemini API account and its limits. The full details are in our privacy policy.
| App’s own key | BYOK, server proxy | BYOK, browser-direct | |
|---|---|---|---|
| Who pays the provider | The app (you pay the app) | You | You |
| Where your key goes | No key needed | App’s server, then provider | Straight to the provider |
| Who sees your prompts | App and provider | App and provider | Provider (not the app’s server) |
| Main risk | Markup and the app’s limits | Server logs or leaks the key | A malicious script on the page |
Cost and quality
Why it matters
BYOK lets a free or cheap tool give you full model access without a subscription markup, and you see the real per-token cost on your own provider dashboard. For the tool maker, it takes the cost of model calls off their bill.
The risk sits with the key. Create a separate key for each tool, set a spending limit where the provider offers one, prefer tools that call the provider browser-direct, and revoke the key if anything looks wrong.
Don’t mix up
Common confusions
- BYOK in AI apps vs BYOK in cloud security
- In cloud security, BYOK means supplying your own encryption key to protect stored data. It is a different idea with the same acronym; in AI tools, BYOK means your own model API key.
- BYOK vs an OpenAI-compatible API
- An OpenAI-compatible API is a request format other providers copy, so one client can talk to many models. BYOK tools often rely on it so you can bring a key from any compatible provider, but the ideas are separate.
Go deeper
Try it and read more
- Free toolGemini API PlaygroundTry the Gemini API free with your own key.
- Free toolAPI Key CheckerCheck whether an API key works, without storing it.
- Free toolGet an AI API key: free tiers comparedWhich AI APIs you can use for free, which need a card, and step-by-step guides for Gemini, Groq, OpenRouter, Mistral, OpenAI and Claude keys.
Related
Related terms
- API keyAn API key is a secret string that identifies your account to a service such as the OpenAI, Claude or Gemini API, so every request made with it is authorised, rate-limited and billed to you.
- Rate limitA rate limit is a cap on how many requests or tokens an account may send to an API per minute or per day, and going over it makes the API reject requests with HTTP 429 until the allowance refills.
- OpenAI-compatible APIAn OpenAI-compatible API is a model API that accepts OpenAI’s Chat Completions request format, so you can call it with the official OpenAI SDK by changing only the base URL, the API key and the model name.