Skip to main content
Bring Your Own Key (BYOK) runs the AI-model calls behind agent responses on your own AWS Bedrock or Anthropic credentials instead of platform credits. The organization Owner sets it up once under Admin Settings → BYOK, and every workspace in the organization uses it.

Why BYOK

  • Your own spend. Model calls on your key bill to your AWS or Anthropic account, not to CloudThinker credits.
  • Your own quotas. Your provider limits apply, not platform credit limits.
  • Your choice of model. Pick the model for each mode and module, or keep the defaults.
  • Data residency on Bedrock. Pick an AWS region to keep inference inside the US, the EU, or Asia Pacific.

Prerequisites

  • A Scale, Scale+, or Enterprise plan. See Pricing & Plans.
  • The Owner role in the organization. Admins and other members see the key status but not the credentials.
  • One of these credentials:
    • An AWS IAM access key with Bedrock invoke permissions. See Prepare AWS Bedrock.
    • An Anthropic Console API key. It starts with sk-ant.

Supported models

Your key runs these models. CloudThinker picks a default for each row, and you can change it. A dash means the provider does not offer the model on BYOK. On Bedrock, Claude Opus 4.6, 4.7, 4.8, and 5.5 and Claude Sonnet 4.6 run with the Global (recommended) region or with a US, Canada, or EU region. They are not available with an Asia Pacific region. GPT models run on the Bedrock OpenAI-compatible endpoint and do not follow the Region you pick. GPT-6 Sol and Luna always use their Global profile. GPT-5.6 runs in us-east-1, us-east-2, or us-west-2, and a key with any other region sends GPT-5.6 calls to us-east-1.
If your data must stay in the EU or Asia Pacific, do not pick a GPT model. Its requests can leave that geography.
You pick a model for six rows: the Light, Pro, and Ultra chat modes, and the Review, Cyber, and Resolve modules. Review conventions follow the Review row, and Cyber chat follows the Cyber row. A row you set to CloudThinker credits runs on the platform instead of your key.

Prepare AWS Bedrock

Skip this section if you use an Anthropic API key.
1

Enable the models in Bedrock

Open Amazon Bedrock in the AWS Console. If Bedrock asks for the Anthropic use case form, submit it once for your AWS account. See the AWS model access documentation. For GPT models, see OpenAI models in Amazon Bedrock.
2

Create the IAM user and policy

Create a user and attach a policy that allows Bedrock to invoke the models. Drop the openai ARNs and the bedrock-mantle statement if you pick no GPT model.
These commands need an AWS profile with iam:CreateUser and iam:PutUserPolicy.
3

Create an access key

Save the AccessKeyId and the SecretAccessKey from the output. You enter them in CloudThinker.
The anthropic.claude-* wildcard covers the models CloudThinker adds later. For a tighter policy, list each model ID from Supported models. Add each inference profile too, such as us.anthropic.claude-opus-5.

Connect your key

1

Open BYOK settings

Go to Admin Settings → BYOK.
2

Choose the provider

Under Step 1 Provider, select AWS Bedrock or Anthropic.
3

Enter the credentials

Fill in Step 2 Credentials.
  • Access key ID: an AKIA key for a permanent key, or an ASIA key for a temporary one.
  • Secret access key: the secret for that key.
  • Session token: required only for a temporary ASIA key.
  • Region: keep Global (recommended), or pick one AWS region. See Choose a Bedrock region.
4

Review the models

Step 3 Models on your key shows the model for each row. Click Customize models to change a row, or to set a row to CloudThinker credits. At least one row must run on your key.
5

Verify and activate

Click Verify and activate. CloudThinker sends a short test call to each model you picked, then saves the key.Success state: the key card shows Active, the key hint, the region, and the model for each row.
CloudThinker encrypts the credentials at rest. The browser never gets the saved secret back.

Choose a Bedrock region

The Region you pick sets the Bedrock inference profile. Bedrock can serve a request from any AWS region inside that profile. Pick a regional option when your data must stay in one geography. Sao Paulo has no geographic profile, so it uses the Global profile. GPT models do not follow the region. See Supported models.

Manage the key

The key card shows the provider, the state, the key hint, the region, and the last verification time. The card shows one of four states: Active, Saved, paused, Key expired, or Disabled after error. One provider is active at a time. To switch provider, remove the key and connect the other provider.

How it works

  • One key for the organization. Every workspace and member uses the Owner’s key.
  • The “Your key” badge. In chat, a Your key badge marks a turn that runs on your key and spends no credits.
  • Session tokens. For a permanent AKIA key, CloudThinker renews the session token itself. A temporary ASIA key can’t be renewed, so rotate it before it expires.
  • Fallback. When a call on your key still fails after retries, CloudThinker runs it on a platform model with platform credentials. Fallback calls spend platform credits.
  • What each call sends. A call sends the agent’s system prompt, tool definitions, conversation history, and retrieved context. CloudThinker replaces known secrets and detected personal identifiers with placeholders first. See Data Protection.

Automatic disable on credential errors

When the provider rejects the credentials, CloudThinker turns BYOK off. Examples are an expired session token, a revoked access key, or an access-denied error. Agent work continues on platform credits until you restore the key. You get one high-severity notification named BYOK Credentials Error — AWS Bedrock Auto-Disabled or BYOK Credentials Error — Anthropic Auto-Disabled. It names the provider error code. The key card shows Disabled after error and the same code. To restore BYOK, click Rotate key, enter valid credentials, and click Verify and save.

Troubleshooting

  • Read the error under the button. It shows the provider’s own message and the model that failed.
  • For Bedrock, confirm the Anthropic use case form is approved for your AWS account.
  • Confirm the IAM policy covers the model and the inference profile of your region.
  • For a GPT model, confirm the policy allows bedrock-mantle:CreateInference.
  • Set a row you can’t serve to CloudThinker credits, then verify again.
  • A regional option uses the us., eu., or apac. inference profile.
  • Confirm the IAM policy allows inference-profile/*.anthropic.claude-*, or that profile by name.
  • Confirm that Bedrock serves the model in that geography, or switch the Region to Global (recommended).
  • Bedrock has no apac. profile for current Claude models. With an Asia Pacific region, pick Global (recommended) instead.
  • CloudThinker no longer serves that model on your key.
  • Click Edit models, pick another model for the row, and click Verify and save.
  • The provider rejected the credentials. See Automatic disable on credential errors.
  • Read the error code on the key card or in the notification.
  • Click Rotate key and enter valid credentials.
  • A temporary ASIA key expires. Switch to a permanent AKIA key to stop repeats.
  • Confirm the key card shows Active, not Saved, paused.
  • Confirm the organization is on Scale, Scale+, or Enterprise.
  • Check that the mode or module row runs on your key, not on CloudThinker credits.

Pricing & Plans

Which plans include BYOK

Usage

Track credit and model usage across your workspace

Notifications

Get alerted when a BYOK key stops working