Skip to content
AI you can check

Bring your own AI key: what it means and when it makes sense

What an AI API key is, who you pay, where your requests go, and how to keep a key safe, plus how to add, test or remove one in PlexiDesk.

If an app with AI features has asked you to "bring your own API key", you may have wondered what you are signing up for. It sounds technical, but the idea is simple: the app uses your own account with an AI provider, instead of an account it runs for you. That changes three things you will care about: who you pay, where your requests go, and what you have to look after.

This guide explains each of those in plain terms, gives you a short routine for keeping a key safe, and then shows how it works in PlexiDesk, where Plexii, the assistant, can run on your own key or on AI credits from your PlexiDesk account. For the rest of how the assistant works, see how Plexii shows its sources and asks before it acts.

What an API key actually is

An API key is a long code that an AI provider issues from your account with them. When an app sends a request with your key attached, the provider knows the request is yours. It answers the request and counts the usage against your account.

That makes a key closer to a card number than to a password. Anthropic's own guidance puts it this way: "Much like a credit card number, if someone obtains and uses your API key, they incur charges on your behalf." (Anthropic's guidance on keeping API keys safe (opens in a new tab)) Anyone who holds your key can spend from your account, so it deserves the same care as your card.

You create a key on the provider's website, in what is usually called the console. With Anthropic, for example, you can use separate keys for separate purposes and delete any one of them from the API keys page of the console without touching the others.

Your key or managed AI: what changes

Apps that use AI tend to offer one or both of two set-ups.

Your own key. You sign up with the AI provider, create a key and paste it into the app. The provider bills you directly for what you use, at its own rates, and you see that usage in the provider's console. You set the key up once on each computer.

Managed AI. The app runs the AI for you. There is no key to create: you sign in and it works. The app counts what you use, usually against a balance or allowance that comes with your account.

Neither suits everyone. Managed AI is the quicker start, with nothing to set up or look after. Your own key suits people who already have an account with the provider, who want the bill to come from the provider, or who want to set the provider's spending limits themselves.

Where your requests go

This is the part worth checking for any app you use, because the answer differs from app to app.

With your own key, some apps send each request straight from your computer to the provider, and others pass it through their own service first. The app's help pages or privacy policy should say which. When a request goes straight to the provider, what happens to it after that is governed by your account with the provider, so the provider's terms are the ones to read.

With managed AI, requests usually pass through the app's own service on their way to the provider, so the app can count what you use. Two sets of terms then apply: the app's and the provider's.

Either way, a request carries whatever the AI needs to answer you: your question, plus the parts of your documents or notes it is working from. A key changes the route, not the contents. Decide what you ask about the way you would with any outside service.

Keeping a key safe

A few habits go a long way:

  • Keep it to yourself. Don't paste a key into a chat, an email or a support ticket. Anthropic's guidance says: "Don't include your API key in public discussions, emails, or support tickets, even between you and Anthropic."
  • Give it to apps you trust. The same guidance points out that when you upload your key to a third-party tool, you are giving that tool's developer access to your account. Before you paste a key into any app, check how it stores the key and where it sends requests.
  • Set a spending limit. See whether your provider lets you cap what an account can spend. Anthropic's documentation says "You can also set your own spend limit below your tier's cap to control costs", under Settings, Billing in its console (Anthropic's documentation on spend limits (opens in a new tab)).
  • Test it, then watch it. After you add a key, run a test so you know it works, and look at your usage every so often. A sudden jump is worth a look.
  • Remove what you don't use. If you stop using an app, or think a key may have been exposed, delete the key in the provider's console. For a key you suspect is compromised, Anthropic recommends "revoking the key immediately".

Setting one up in PlexiDesk

In PlexiDesk, keys live on the AI tab of Settings, which you open with the gear at the right-hand end of the header. Scroll to AI · API keys. The guide to adding your own API keys has every step; in short:

  1. Find the Anthropic API key row. If you don't have a key yet, the link under the row opens Anthropic's console in your browser.
  2. Paste the key and click Save key. Before you paste, the field shows in grey how a key from that service usually starts, which helps you spot a key pasted into the wrong row.
  3. Click Test. It sends a one-word request with your key, which uses a tiny amount of your Anthropic usage, and shows Key works with the name of the model that answered.
  4. Later, use Replace to swap in a new key, or Remove to take it out. PlexiDesk asks you to confirm, and says what stops working without the key.

You can also add a key during the welcome the first time you open PlexiDesk, or skip that step and set up AI later, as the getting started guide describes.

A few things worth knowing:

  • Keys stay on your computer, encrypted. Each key is encrypted with your computer's secure storage. Once saved, PlexiDesk shows just its last four characters. Keys are not part of your PlexiDesk account, your backups or your exports, so you add them again on each computer you use.
  • Your key goes straight to Anthropic. With your own Anthropic key, requests go straight from your computer to Anthropic. The guide to what leaves your computer sets this out next to every other feature.
  • Or skip the key. While you are signed in, Plexii can run on PlexiDesk AI credits instead, with no key to set up. On credits, requests go through PlexiDesk to Anthropic so that their use can be counted against your balance. How credits work with each plan is on the pricing page.
  • You choose, computer by computer. Under AI · source, Automatic uses your credits first and then your own key, PlexiDesk credits always uses your balance while you are signed in, and Your own key always goes direct to Anthropic. New installs start on Automatic. See AI settings.
  • You can see what you use. After the first AI request, a box headed AI usage on this device shows how many AI calls this computer has made, the tokens sent and received, and an estimated cost marked est.

A handful of features always use your own Anthropic key, even when everything else runs on credits. Two examples are the Summary, Cleaned and Speakers views of a voice note, and AI Expand in a mind map. The API keys guide lists them all.

Which should you choose?

Run through these questions:

  • Do you already have an account with Anthropic? Then your own key is a natural fit. Set a spending limit in Anthropic's console, add the key, and click Test.
  • Do you want to start in a minute, with nothing to manage? Sign in and let Plexii run on credits. There is no key to create, store or replace.
  • Do you work on more than one computer? A key is added on each computer separately. Credits follow your sign-in, though the AI · source choice is still set per computer.
  • Is the route what matters most? With your own key and Your own key selected, requests never pass through PlexiDesk on their way to Anthropic. On credits, they do, so they can be counted.
  • Do you use the features that always need a key? If you rely on voice note summaries or AI Expand, add a key even if everything else runs on credits.

You can change your mind at any time. A new choice under AI · source takes effect straight away, with no restart.

Whichever you pick, the assistant works the same way: it answers from your own desks and documents, shows the sources it used, and at the default setting asks before it changes anything. Show your sources, ask before you act explains those two rules, the Plexii assistant on the product page shows them in the app, and Local-first, explained covers where the rest of your work lives.

All postsMore in AI you can check