Enterprise guide
Bring Your Own LLM Key
Route your organization’s AI requests through your own model-provider credentials.
What It Is
By default, Shortcut serves AI requests using Shortcut-owned provider accounts. With LLM BYOK, your organization supplies its own provider credentials instead, so your users’ AI requests run under your provider relationship, your data agreements, and your provider billing.
Supported credentials: Anthropic API keys, OpenAI API keys, Google Gemini API keys, and OpenAI-compatible endpoints (an HTTPS base URL of your choice with an OpenAI-style API key).
How Your Keys Are Handled
- Keys are stored encrypted and are never returned to the browser after saving.
- Status views show enabled/configured state and masked metadata only.
- BYOK routing fails closed: if your configured credentials cannot be used, requests fail rather than silently falling back to Shortcut-owned keys.
- Calls made with your credentials are billed by your provider directly and do not consume Shortcut credits.
BYOK vs. Private LLM Gateway
These two enterprise options solve different problems and can be evaluated independently:
- BYOK: AI requests are served through Shortcut with your provider credentials. You control the provider account and billing.
- Private LLM Gateway: AI requests are sent directly from the Shortcut client to a gateway endpoint your organization operates. You control the network path.
Getting Started
LLM BYOK is available on enterprise plans and is enabled for your organization by Shortcut. Once enabled, organization administrators configure and manage provider keys from the organization settings surface.
Contact your Shortcut account team or support to enable BYOK and plan the rollout for your organization.