文档首页

Governance

LLM API keys (bring your own key)

Add OpenAI, Anthropic, Google Gemini, and other provider keys at the organization level: security, billing, rotation, and how keys affect chat vs document vision and transcription.

byokopenai api keyanthropicgeminillm keys

Bring your own key (BYOK) means FlexyAgents calls model providers with credentials you store in the dashboard (Settings → LLM API Keys, path may include your locale prefix such as /en/). Usage on those calls is billed by your provider under your agreement; hosted plans may still enforce FlexyAgents-side quotas where the platform supplies the model.

A Google Gemini key is especially important if you use image description (vision) or audio/video transcription during knowledge uploads or website crawls: when an organization Gemini key is active, those features use your key and do not consume hosted “image recognition” or “media transcription” quotas on your FlexyAgents plan.

Where to add keys

Navigate to Dashboard → Settings → LLM API Keys (exact labels may vary slightly by locale). Add one key per provider you need. Keys are stored encrypted; only authorized org members can view or replace them.

After saving, allow a minute for configuration to propagate before re-testing agents that failed with missing-key errors.

  • Supported providers include major chat model vendors (OpenAI-compatible where applicable, Anthropic, Google Gemini, and others listed in the UI).
  • If your plan is BYOK-only for a given provider, chat will not fall back to FlexyAgents-hosted keys—you must supply a valid key.

Gemini and knowledge ingestion

Image uploads and crawls can run OCR (text extraction from pixels) without Gemini. Optional Gemini vision generates richer natural-language descriptions of images for search and answers—that is what plan limits call “image recognition” when billed on hosted infrastructure.

Similarly, audio and video files can be transcribed with Gemini when enabled; hosted plans may count successful transcriptions toward monthly “media transcription” limits unless your org supplies a Gemini key.

  • Upload UI shows monthly hosted usage for image recognition and media transcription so operators know before hitting limits.
  • If you see a quota error on upload, add a Gemini key or ask an admin to raise plan limits; OCR-only paths may still produce some text without vision.

Rotation and incident response

Treat LLM keys like database passwords: calendar rotation, immediate rotation if a key leaks, and documentation of which teams own which provider accounts.

When a key expires, affected agents return provider errors—check dashboard logs and test chat with a single message before announcing all-clear.

  • Prefer separate keys or projects per environment (staging vs production) so a staging leak does not compromise production spend caps.
  • Use provider-side usage alerts and budgets; FlexyAgents does not replace your cloud billing guardrails.

Compliance and data flow

Your DPA with each model vendor governs subprocessors, regions, and retention. FlexyAgents passes prompts and retrieved context to the provider you select for the agent.

For strict data residency, confirm both FlexyAgents deployment options and the provider region for the key you configure.

在你的技术栈上构建

准备上线有依据的助手了吗?

开始试用,或与我们沟通上线、治理和企业级要求。