Skip to content

Organizations & Workspaces

Invite teammates, set roles, switch between workspaces, and isolate billing per organization.

Working solo, a personal account is all you need. But the moment a second person — or a second service — needs to share your keys, credits, presets, or logs, passing a single secret around stops scaling. Organizations give a team one shared workspace: shared API keys, one credit pool, common presets, a single usage history, and one billing surface, all gated by roles.

Overview

Every account has a private personal workspace and can belong to any number of shared organization workspaces. The workspace picker in the dashboard sidebar switches between them, and the active workspace decides which keys, credits, presets, and logs you see.

WorkspaceHow manyShared?Created
PersonalExactly one per accountNeverAutomatically on first sign-in
OrganizationAs many as you likeWith every member (subject to role)On demand

You can belong to many organizations at once and hold a different role in each.

If you are the only person who will ever use AnyRouter, stay in your personal workspace. A one-person organization adds management overhead with no benefit.

How it works

When to create an organization

Create one when any of these is true:

  • Shared billing. You want a single invoice and one credit pool instead of expensing individual top-ups.
  • Shared keys. Multiple people or services issue and rotate keys under one umbrella, with one set of usage limits.
  • Shared logs. Engineering, ops, and finance all inspect request history, spend, and errors against the same dataset.
  • Shared presets. A curated set of model presets (system prompts, defaults, routing rules) should stay consistent across teammates.
  • Onboarding and offboarding. People join and leave; you grant or revoke access without rotating credentials.

Roles

Every member has exactly one role per organization. Each organization must have at least one owner at all times.

CapabilityOwnerAdminMember
View organization keysYesYesYes
Create and revoke organization API keysYesYesNo
View shared credits balanceYesYesYes
Top up credits or change billingYesNoNo
View shared logs and usageYesYesYes
Create and edit shared presetsYesYesNo
Store and rotate BYOK credentialsYesYesNo
Invite new membersYesYesNo
Change member rolesYesYesNo
Remove membersYesYesNo
Promote another member to ownerYesNoNo
Transfer ownershipYesNoNo
Delete the organizationYesNoNo
  • Owner — the most authority. Only owners can change billing, transfer ownership, or delete the organization.
  • Admin — everything an owner can do except billing, ownership transfer, and deletion. Right for senior engineers and team leads who manage day-to-day access.
  • Member — the default for new invitees. Members use the organization (make requests, browse presets, view logs and credits) but cannot manage members, mint keys, or change configuration.

What is workspace-scoped vs. account-scoped

Switching workspaces reloads the dashboard against that workspace's data. Some things travel with the switch; others are properties of your account.

Workspace-scoped (changes with the switch)Account-scoped (never changes)
API keys (sk-ar-…) — personal and org keys stay invisible to each otherYour profile (name, email, avatar, sign-in methods)
BYOK credentials — stored per workspaceAuthentication (session, MFA, recovery)
Presets, including @preset/<slug> references — same slug can resolve differently per workspaceNotification preferences
Credits — personal and org pools are separate
Usage and logs — scoped to the active workspace's keys

API requests are authenticated by the key, not by the workspace picker. A personal sk-ar-… key always charges your personal credits; an organization key always charges that organization — regardless of what the dashboard is showing. The picker only affects what you see.

Billing

Credits live at the workspace level. Each organization has its own balance, separate from every member's personal balance and every other organization's.

  • Top-ups. Only an owner can top up an organization's credits or change billing details. Admins and members see the balance but cannot purchase.
  • Spend. Any request made with an organization key draws from the organization's pool — members don't need their own credits to use org keys.
  • Seats. AnyRouter does not currently charge per seat; invite as many teammates as you need at no additional fixed cost. You pay for what you consume. Seat-based pricing is expected on Enterprise plans in the future but does not apply to standard organizations today.
  • Low-balance alerts. Owners and admins can opt in to low-balance email alerts. Members do not receive billing alerts by default.
  • Invoices and receipts. Receipts for org top-ups are emailed to the owner who performed the top-up and are visible to all owners and admins in the dashboard.

Configure

Invite teammates

Invitations are by email. As an owner or admin:

  1. Open the organization on the Organizations page in your dashboard.
  2. Click Invite member.
  3. Enter the teammate's email and pick a role (Admin or Member).
  4. Send the invitation.

The invitee receives a sign-in link. If they already have an AnyRouter account on that address, accepting the invite adds the organization to their workspace picker immediately. If not, they create an account first, then the organization appears.

  • Expiry. Invitations expire after 7 days. Re-send from the same screen if a teammate misses the window.
  • Resending. If the email didn't arrive, resend from the same screen — resending refreshes the 7-day expiry.
  • Revoking. A pending invitation can be revoked any time before acceptance. After acceptance, remove the person as a member instead.

Switch workspaces

The workspace picker in the dashboard sidebar lists your personal workspace first, then every organization you belong to. Selecting a different workspace reloads the dashboard against that workspace's data.

Leave an organization

Open the Organizations page, find the organization, and choose Leave organization. Access is removed immediately. Keys you created inside the organization stay with the organization and keep working — the keys belong to the org, not to you.

Last-owner protection. AnyRouter refuses to let the last remaining owner leave or downgrade their own role. Before an owner can leave, they must transfer ownership to another member (or promote an admin to owner first). If you are the last owner and want out, either promote another member to owner, or delete the organization — which permanently removes every key, preset, log, and credit balance attached to it. Deletion has no recovery; export anything you need first.

SSO and enterprise

Enterprise organizations can enable SAML SSO so members sign in through your identity provider (Okta, Azure AD, Google Workspace, etc.) instead of a password or social login. SSO is configured by an owner from organization settings and applies to every member. Once enforced, members can no longer use email or social providers for that organization.

  • Domain verification. Before SSO can be enabled, the organization must verify ownership of one or more email domains via a DNS TXT record. Once verified, AnyRouter routes invitees on those domains into the organization's SSO flow.
  • SCIM provisioning. Enterprise organizations can also enable SCIM so your IdP creates, updates, and deprovisions members automatically. Removing a user from your IdP removes them from the AnyRouter organization on the next sync.

SSO and SCIM are available on the Enterprise plan. Contact us through the dashboard support link to start.

Frequently asked questions

Can I move a key from my personal workspace into an organization?

No. Keys belong to the workspace they were issued in. Mint a new organization key and update your clients.

Will my teammates see the requests I make with my personal key?

No. Personal-workspace traffic is private and never appears in any organization's logs.

Can a member see other members' personal information?

Members see the display name, avatar, and role of every other member. They cannot see other members' personal keys, credits, or usage.

What happens to my organizations if I delete my account?

If you are the only owner of an organization, account deletion is blocked until you transfer ownership or delete the organization. Members and admins can delete their accounts normally; the organizations are unaffected.

Can I rename an organization?

Yes. Owners and admins can rename it any time from the Organizations page. The change appears for every member on their next page load.

Related