← All guides

Locus product guide · Updated

API Key Management and BYOK for AI Agents

Locus Pro managed tools use supported provider access through your Locus account. Enterprise BYOK, or bring your own key, connects your own provider credential to custom API actions. Use managed access to reduce separate provider setup; use BYOK when you need your own supported service, provider account, or contract.

Managed access and BYOK have different account ownership

For managed catalog operations, you do not need a separate provider account or API key for each supported service. Your Locus credential controls access and the applicable Locus balance pays for use. Confirm the exact endpoint and model coverage in the catalog.

With a Custom API, the upstream account and credential are yours. The provider’s usage and data-handling terms still apply. BYOK does not erase a provider subscription or make upstream calls free. You also own the responsibility to keep that credential valid and adequately funded.

Import only operations the integration supports

Custom APIs must be enabled for the enterprise workspace. A workspace owner with recent MFA or passkey verification and the required scopes creates or updates the provider. Configure a public HTTPS base URL, an authentication method, and suitable rate, concurrency, and timeout limits.

Import supported OpenAPI 3.0 or 3.1 JSON or YAML, or define actions manually. Review each action’s method, path, inputs, example, provider cost, and customer markup. Unsupported operations are reported, and newly imported actions start disabled. Test and enable the actions your agents actually need.

Understand the BYOK billing distinction

A Custom API call paid from the workspace pool does not consume Locus credits for provider usage; the upstream provider bills your saved credential directly. A customer-funded call charges the configured provider cost plus markup to the end-user balance, and that charge is workspace-owned revenue. Both paths produce receipts and activity records.

The configured provider cost is your pricing input, not a guarantee that Locus has measured the upstream provider’s eventual invoice. Keep it aligned with your provider contract and validate the economics on representative requests.

Keep upstream secrets out of agent prompts

Store the provider credential through the supported Custom API flow. Give the agent an appropriate Locus connection and tool access rather than the upstream secret. Do not embed tenant secret keys in browser code or prompts; use short-lived end-user tokens for supported customer-facing browser features.

Disable an action when it should stop being discoverable or callable. After a state-changing action times out, inspect upstream state before starting a new logical operation: the provider may have completed the change even if the client did not receive the response.

Frequently asked questions

Can I import any API without changes?

No. Imports must meet the supported OpenAPI, authentication, HTTPS, operation, and schema requirements. Review unsupported operations and validate enabled actions before rollout.

Do agents see my saved provider key?

Saved upstream credentials stay private in the supported Custom API flow. Agents use their authorized Locus connection to access enabled actions.

Implementation references

Use these first-party references for current request contracts and account requirements. Tool availability, prices, and negotiated terms can change.

Related guides