AI Providers and Bring Your Own Keys (BYOK)
Bring Your Own Key (BYOK) means Dawn uses your team's own provider API key for agent runs instead of charging those runs to Dawn-managed credentials. Use this page if you want to control provider spend, choose exactly which models your workspace can use, or mix multiple AI vendors in one workspace.
Why teams use BYOK
- You want provider usage billed to your own OpenAI, Anthropic, or OpenRouter account instead of Dawn credits.
- You want tighter control over which models agents in a workspace are allowed to use.
- You want one workspace to use more than one AI vendor instead of standardizing on a single provider.
- You want to use a model ID that is valid for your provider account even if Dawn has not added it to its suggested catalog yet.
What Dawn supports today
- OpenAI, Anthropic, OpenRouter, and xAI can be added with workspace API keys.
- You can allow a different set of models for each provider.
- Custom model IDs are supported for those providers when you need something outside Dawn’s built-in list.
- Azure OpenAI can still appear as a provider in Dawn, but it is not part of the current workspace BYOK flow.
- Linked OpenAI ChatGPT access is separate. It uses the workspace owner’s existing OpenAI ChatGPT account rather than a workspace API key. See Link Existing OpenAI ChatGPT Account.
- The AI Providers tab only appears when the current billing plan allows workspace provider management, and this setup is currently managed by the workspace owner.
How to turn it on
- Open Workspace settings as the workspace owner.
- Open the AI Providers tab.
- Click Add provider and choose OpenAI, Anthropic, OpenRouter, or xAI.
- Paste the API key for that provider.
- Choose the models you want agents in this workspace to be allowed to use.
- If you rely on a model that is not listed but the provider supports custom model IDs, add it there and include it in the allowed models.
- Click Save. Dawn stores the key encrypted and validates the provider configuration.
- Repeat that process for any other providers you want available in the same workspace.
- After that, update your agent profiles so they use one of the provider and model combinations you just allowed.
What model allowlists actually do
The model list on each provider is not just informational. It is the workspace policy for what agents are allowed to pick from that provider.
- If a model is not allowed here, agents in that workspace should not be able to use it.
- You can allow a conservative set of models for production work and keep experimental ones out.
- You can allow different models on different providers in the same workspace.
- If you add a custom model ID, Dawn can preserve it for that workspace even when it is not part of the built-in suggested catalog.
When BYOK changes billing
BYOK matters financially because it changes who pays for the model run.
- Runs that use a workspace API key do not consume Dawn credits.
- Those runs are billed by your provider account instead, so the provider dashboard is the source of truth for cost and usage.
- Workspace API keys stay attached to the workspace until they are removed.
Linked OpenAI ChatGPT access is separate from BYOK
This OpenAI ChatGPT-linked path does not use a workspace API key in Dawn. If you want to use OpenAI models through an existing ChatGPT account, the workspace owner links that account and enables ChatGPT for the workspace.
- This is why this setup lives in a separate ChatGPT section instead of the provider API-key list.
- Availability is tied to the current workspace owner’s linked ChatGPT account.
- If workspace ownership changes, the new owner may need to link ChatGPT again before this path becomes available.
Use Link Existing OpenAI ChatGPT Account for that flow.
xAI and Grok models
xAI is configured through the same AI Providers flow as other API-key providers. Add the xAI provider, allow the Grok models your workspace should use, then select a Grok model on an agent profile.
Use xAI Grok Models for the dedicated setup and rollout guide.
Troubleshooting
- AI Providers tab is missing: the current billing plan does not expose workspace Bring Your Own Key (BYOK) or provider management.
- Stored credential is inactive: the workspace may still have a saved key, but the current plan no longer allows Bring Your Own Key (BYOK) use.
- Provider row saved but models are missing from agent settings: confirm that the intended models are checked in that provider entry and that the provider validated successfully.
- Custom model does not appear: only providers that allow custom model IDs can accept models outside the built-in list.
- Codex is enabled but still missing: confirm the current workspace owner completed the ChatGPT linking flow and the ChatGPT section is enabled for the workspace.
- Unexpected billing behavior: confirm whether the run used Dawn-managed credentials, a workspace API key, or the workspace owner ChatGPT link.
Completion Checklist
- AI Providers tab is visible for the current plan.
- Expected Bring Your Own Key provider rows are present.
- Allowed models match workspace policy.
- ChatGPT section reflects current link state.