# Model keys (BYOK)

> The Engine on your own keys: which key runs what.

## What the Engine is

The Engine (BYOK, bring your own key) opens everything the CoPilot opens, but its AI runs on model keys you own. Your provider bills you for what you use; Cariara bills only the plan. It includes no Cariara Live AI minutes. Buy a 60-minute top-up if you also want AI on Cariara’s keys. Keys are used only while your account holds a live Engine plan, including its free trial. On any other plan, saved keys sit unused and AI runs on Cariara’s keys and minutes.

## Providers

Keys are added only on the Engine. Without it, Account → Model keys lists the providers read-only with Get the Engine . Provider Group What you enter The core three run the features in the next table. A key from any provider lists the models it can run under Models , and Use for picks which one runs Coding, Answers and Helpers first.

## Which key runs what

An OpenAI key and a Gemini key together run every feature. OpenAI alone runs everything except Gemini's document and web search, which fall back to keyword search; Live interview audio needs OpenAI. An Anthropic key gives the best coding answers. Feature Runs on, in order Without that key When a feature can run on more than one provider, it tries them in the order shown and skips any you have no key for.

## Add, test and remove keys

Create a key with your provider: Anthropic Console, Google AI Studio, the OpenAI platform, or the console of any provider above. For Azure OpenAI and AWS Bedrock, use credentials limited to model calls. Open Account → Model keys , paste it and press Save. For More models and Your cloud, press Add on the provider first. Cariara checks the key with the provider before storing it; a rejected key is not saved. Test checks a saved key again. Save a new key over a saved one to replace it. Remove deletes it; AI that needs it stops until you add one again. Set a spending limit with your provider. Cariara never caps or pauses AI on your own keys.

## Never on Cariara’s keys

On the Engine, an AI request runs on your key for that provider or not at all. It never falls back to Cariara’s keys, including for work that runs after the page answers: diagrams, document indexing and job-alert emails all use your keys. Turned off on the Engine: streaming transcription and Cohere result reranking run only on Cariara’s keys, so the Engine uses Whisper on your OpenAI key and standard ranking instead. Paid by your top-ups: voice dictation in Ask runs on Cariara’s speech service and draws top-up minutes, if you have any.

## Usage and billing

Subscription & usage lists this month’s requests and tokens on your keys, by provider, to match against your provider’s bill. Requests on your keys draw no Cariara minutes. The header shows Own keys instead of minutes left. Top-up minutes you buy stay usable on Cariara’s keys and never expire. See Top-ups & AI time .

## How keys are stored

Encrypted with AES-256-GCM, bound to your account and the provider, so a stored key cannot be read for anyone else. Only the last four characters are ever shown back. The full key is decrypted only for your own AI requests. Removing a key, or deleting your account, deletes it.

## Troubleshooting

Add your … key in Account → Model keys : the feature needs a provider you have no key for. Add that key, or one from the table above. The provider rejected this key : the key is wrong, revoked, or the project has no billing set up. Provider unreachable : the provider did not answer the check. Try again in a minute. Answers stop mid-session : your provider’s quota or spending limit was reached. Raise it with the provider.

Source: https://docs.cariara.com/model-keys
