Skip to content
GuidesJuly 12, 2026

BYOK: bring your own keys to every provider

Attach the OpenAI, Anthropic, Google, and 60+ other provider keys you already pay for, route them through one OpenAI-compatible URL at $0 markup, cap spend per key, and — if you donate idle quota to the shared pool — earn up to 8% back and unlock Go for free while a donated key stays active.

What is BYOK on AnyRouter?

Bring Your Own Key (BYOK) lets you attach your own upstream provider keys to your AnyRouter account. When a request matches a model one of your keys can serve, AnyRouter forwards the call on your key and you pay the provider directly at their list price. You keep every AnyRouter feature — one unified API, logs, analytics, presets, routing, app attribution — on top of accounts you already have.

AnyRouter exposes BYOK for more than 60 providers: OpenAI, Anthropic, Google AI Studio, Groq, NVIDIA NIM, Z.ai, Ollama Cloud, and enterprise endpoints like Azure OpenAI, Bedrock, and Vertex AI. The full provider-by-provider setup guide lives at /docs/features/byok-providers.

Does AnyRouter charge markup on BYOK?

No. AnyRouter charges nothing for BYOK traffic — no per-request fee, no surcharge, no minimum. Requests served through your own provider keys never deduct AnyRouter credits, on any plan. You only ever pay your provider. If every BYOK key for a provider is exhausted, requests can optionally fall through to pay-as-you-go credits so work keeps flowing.

  • $0 markup on your own keys — you pay the provider, nothing to AnyRouter.
  • Keep your own rate limits — you route on your account's quota, not a shared pool.
  • Automatic failover — add more than one key per provider and a burned key (401/429) is quarantined while the next takes over.
  • Load-balancing strategies — Fallback, Round Robin, Weighted, or Random per provider.
  • Per-key budgets — cap monthly spend on any key so a runaway loop can't drain a provider account.

Route across your whole key pool

Once you've added keys, three built-in ids route across all of them without naming a specific model — and because they only ever use your own keys, they never spend AnyRouter credits:

Model idRoutes to
anyrouter/byokEvery model your configured keys can reach
anyrouter/codingThe coding-capable subset
anyrouter/agentThe tool / function-calling subset, built for agents
curl https://anyrouter.dev/api/v1/chat/completions \
-H "Authorization: Bearer $ANYROUTER_API_KEY" \
-H "Content-Type: application/json" \
-d '{
  "model": "anyrouter/coding",
  "messages": [{ "role": "user", "content": "Refactor this function" }]
}'

How are my keys protected?

BYOK keys are sensitive credentials and AnyRouter treats them that way. They're encrypted at rest with a per-row salt, so a leak of one key's ciphertext never weakens another. They're write-only in the UI — after save only an alias and a masked identifier are shown. They're stripped from request and response logs, validated live on save (then the validation response is discarded), and only ever sent to the upstream provider they're scoped to.

Route the provider keys you already pay for through one API at $0 markup.

Connect a key

Route your first request in 2 minutes

Start free with your own keys, or top up and pay per token. Get $4/mo in credits and free models on Go — $2/mo, or free when you donate a provider key.

Start free