Bring Your Own Anthropic Key (BYOK)
Eligible accounts can supply their own Anthropic API key for StackJack's AI automation features. With your key on file, automation runs and the builder's AI help bill your Anthropic account directly…
Written By Christopher Scaminaci
Last updated About 22 hours ago
Eligible accounts can supply their own Anthropic API key for StackJack's AI automation features. With your key on file, automation runs and the builder's AI help bill your Anthropic account directly instead of consuming StackJack credits — useful when you already have an Anthropic relationship, negotiated rates, or spend-governance requirements. Your automation's agents, environments, vaults, run sessions and transcript fetches, and enabled memory stores then use your own Anthropic workspace and key, which is what makes removing or replacing the key later a decision worth reading about below.
Requirements
- An eligible account. Either at least one connector subscription on the Enterprise tier, or an active Agent Runner plan — the flat-fee plan includes key enrollment whatever your connector plans are. Either one alone qualifies you. Your effective connector plan is the highest tier across your active connector subscriptions. Eligibility is enforced server-side when you upload the key, not just hidden in the UI — and, for a key admitted by an Agent Runner plan rather than an Enterprise connector plan, re-checked on every run. That is the difference between the two routes: an Enterprise-tier key keeps working for as long as you hold the key, while a key enrolled on the Agent Runner route stops being used if that plan ends — see When an Agent Runner plan ends below.
- Owner access. Only the primary owner and co-owners can set, replace, or remove the key.
- An Anthropic API key from your own Anthropic account (keys start with
sk-ant-).
Seeing which credentials you are on is separate from being allowed to change them. Everyone who can open Automations → Credits sees the Anthropic credentials card and the mode it states, whether or not the account qualifies. What changes with eligibility and role is the controls:
That last row is deliberate: a key already on file can always be withdrawn by an owner, even after the account stops qualifying, so you are never left with your own key billing runs and no way to take it back.
What changes when BYOK is active
- Your workspace, your key. Agents, execution environments, vaults, run sessions and transcript fetches, and enabled memory stores use your Anthropic workspace and key rather than StackJack's, which matters when a key is later removed or replaced.
- Zero credits. BYOK runs skip the pre-flight credit check and reservation entirely — a low or zero credit balance does not block a run.
- Audit trail preserved after settlement. Once final settlement completes, your credit transaction history records a zero-amount "BYOK run" entry with StackJack's approximate usage calculation. A missing entry while the run is active or just terminalized is not evidence that no Anthropic usage occurred; Anthropic's bill remains authoritative for charges on your key.
- Most guardrails still apply. Runtime caps, tool policy, dry-run mode, consent, connector allowances and concurrency limits are unchanged, and the guided builder's live tool tests still draw on the connector's monthly allowance. The Max credits per run cap does not apply to BYOK runs — credit metering is skipped entirely, so there is no mid-run credit check or credit-cap stop. Use Max runtime to bound BYOK run length (and cost on your Anthropic bill).
- Recovery is a fresh execution. BYOK removes StackJack's credit reservation; it does not make provider execution idempotent. If StackJack must replace a stranded run after first confirming the old session stopped, it may start one fresh replacement attempt under the same run record, and both Anthropic attempts can appear on your Anthropic bill. The replacement can repeat connector changes the first attempt already completed, so write workflows that must happen only once need vendor-side idempotency or deduplication.
- Models and tools are unchanged. Model selection, allow-list or deny-list tool policy, and plan-based connector-tool gating are identical with or without BYOK. Native Anthropic capabilities (web search, web fetch, code execution) are configured per automation and are never plan-gated for anyone.
- Staff runs. Staff-initiated diagnostic runs never charge your credits regardless of BYOK. Run execution for your organization uses your workspace configuration.
The Credits tab always shows which mode you are in:
- Managed Anthropic credentials — the default; every run is metered against credits.
- Your Anthropic key (BYOK) with a green tenant-supplied badge — your key is active; runs are not metered against credits.
- Your Anthropic key (BYOK) with an amber runs paused badge — your key is still stored, but it is not being used and runs are refused, because the Agent Runner plan that let you enrol it has ended. See When an Agent Runner plan ends.
Setting your key
- Open Automations → Credits and find the Anthropic credentials card — it reads Managed Anthropic credentials until a key is on file, and Your Anthropic key (BYOK) after.
- Click Set key.
- Paste your Anthropic API key (it must start with
sk-ant-) and click Save.
Your key is stored in Azure Key Vault. StackJack never logs it, never displays it again — not even masked — and the portal has no way to read it back. If you lose track of which key you supplied, rotate it on the Anthropic side and set the new one here.
Automations created before you added your key. An automation provisioned before your key was saved lives in StackJack's platform workspace, and its runs would not line up with your workspace. If you add, replace or remove a key after automations already exist and execution reports a workspace mismatch, contact StackJack support rather than retrying the run: StackJack has a repair operation that re-provisions existing automations into your Anthropic workspace, individually or all at once. When memory is enabled, that migration copies/imports it into the new workspace and then archives the old memory store. You can also move an automation's memory yourself, without waiting for support: while the store is still in StackJack's shared workspace, its Memory card offers a one-way move into your workspace. That moves the notes only — it does not re-provision the automation itself. See Automation memory.
Replacing or removing the key
- Replace key — opens the same dialog; the new key overwrites the old one. It is shown only while your account still qualifies to enroll a key.
- Remove key — after confirmation, your account reverts to StackJack-managed credentials. Automation runs, builder turns, and AI Assist suggestions are all metered against your credit balance again from the next one onward (reservation and reconciliation), so check that your balance can cover your automation activity before removing the key. You can set a new key again at any time, if your account still qualifies.

What removing the key does not undo
Removing the key changes how your automations run from then on. It does not move anything that already ran. Contact support before you remove a key permanently, so your automations' workspace placement, and any memory that needs migrating, can be reviewed.
- Work already created under your key stays in your Anthropic workspace. Sessions, transcripts, environments, and automation memory were created there, and StackJack does not migrate them. Automations provisioned into your workspace stay there until they are re-provisioned, and execution can then report a workspace mismatch — contact support for re-provisioning rather than retrying such a run.
- A past run's transcript may stop opening. StackJack fetches a transcript with whichever key is on file at the moment you ask, so a session that lives in your workspace cannot be read once the key is gone. Restoring an eligible key to that same workspace is what brings it back; otherwise contact support, who can investigate with you.
- A run created under your key can stop being resumable. Removing the key returns future runs to credits; it is not a guarantee that a specific paused session resumes where it left off.
- Automation memory follows the same rule. Memory stores created under your key live in your workspace. See Automation memory.
When an Agent Runner plan ends
Scope. This applies only to a key that a flat-fee Agent Runner plan admitted. A key admitted by an Enterprise connector plan is never evaluated, and neither is a key that was already on file before this behaviour shipped — those are grandfathered. Enterprise wins: if your account is on an Enterprise connector tier today, that route admits your key on its own and nothing below applies, whatever happened to an Agent Runner plan you also once held.
What counts as ended. A canceled Agent Runner plan, or one StackJack has deactivated. These do not count, and runs keep working normally through all of them:
- a failed payment that is still being retried (a plan in dunning, past due with your payment provider),
- a paused subscription,
- a cancellation that is scheduled but has not taken effect yet.
What happens to runs. They are refused — never quietly moved back onto StackJack credits. Each new run a trigger starts is recorded as a Failed run carrying this message, with no credits consumed and no reservation taken, and it gets the usual failure notification (see Failure Notifications):
Your Agent Runner plan has ended, so your own Anthropic key is no longer used for runs. Re-subscribe to Agent Runner to resume using it, or remove the key to run on StackJack credits.
A run that was already paused waiting for your approval is the exception: it is not failed. Resuming it is refused with the same sentence, and the run stays Awaiting input. Restoring the Agent Runner plan is the route that resumes it on the key it started with. Removing the key is not the same remedy — it changes what later runs use, and it does not move an already-started session out of your Anthropic workspace, so a paused run may not be resumable afterwards. The approval deadline keeps running either way.
Other things that need the key while it is paused. Saving or repairing an automation is refused the same way: creating, updating, restoring a version, resyncing or repairing an automation needs your key too, so those actions return the same sentence until you resolve the plan or remove the key. So are fetching a run's Anthropic transcript, the run's tool-call sequence and its backfill, and listing, reviewing, redacting, clearing, and migrating agent memory — the message is the sentence above, not a transient error, so retrying will not help. Erasure and cleanup still work: hard-deleting a memory store, deleting an automation, and archiving or deleting the Anthropic resources StackJack created in your account (sessions, environments, memory stores) all complete normally, so an ended plan never strands resources you cannot remove.
Nothing is deleted. The refusal happens before StackJack ever reads the stored key, so the key stays in Azure Key Vault exactly as you left it, and StackJack's reference to it survives too. Restoring the plan restores the key without you re-entering it.
What the Credits tab shows. The key card keeps its Your Anthropic key (BYOK) title but its description changes to "Your organization's own Anthropic API key is stored but not in use: your Agent Runner plan has ended, so runs are paused", the green tenant-supplied badge becomes an amber runs paused badge, and a paragraph below names both ways out. Remove key stays available, because Remove is never gated on eligibility; Replace key disappears while the plan is lapsed and comes back with the subscription.
Your two ways out, and they are not equivalent.
- Restore the Agent Runner plan — runs resume on your own key immediately, including for the sessions already in your workspace. Contact StackJack to arrange it. This is the only route that resumes a run already paused in your Anthropic workspace.
- Remove the key — click Remove key and confirm. New runs go back to StackJack credits, which means they draw on your credit balance again. That does not move an existing session out of your workspace: automations provisioned into your Anthropic workspace can report a workspace mismatch afterwards, and a session created under your key can stop being fetchable. Contact StackJack support for re-provisioning rather than retrying such a run.
Enrollment did not change. An inactive Agent Runner plan still cannot enrol a new key — which means a lapsed flat-fee account has strictly fewer options than an account whose Enterprise connector plan lapsed with a key already on file.
For what else an Agent Runner plan governs, see Agent Runner plans and concurrency slots.
Builder assistance runs on your key too
An organization with its own key pays for its own builder help the same way it pays for its own runs.
For an organization with its own key:
- Wizard chat turns and AI Assist suggestions run on your key and are billed to your Anthropic account, in your Anthropic workspace. They cost 0 StackJack credits, and the zero is the ordinary consequence of using your key rather than a separate accounting rule.
- Your key is resolved once per turn, and there is no fall-back. If it cannot be read, or if it is on file under an entitlement that has lapsed, the turn is refused rather than quietly served on StackJack's account. The builder says the key was refused and what to do about it — for a key it cannot read, that is to re-enter it.
- A key Anthropic itself rejects — revoked, rotated, or pointed at a workspace it has no rights in — is reported as a key problem, not a StackJack outage. Storing a key proves only that StackJack can read it; nothing asks Anthropic whether it still works until a call is made.
- A lapsed Agent Runner plan reaches builder assistance too, when that plan is what admitted your key in the first place. Runs pause and builder turns are refused together. Removing the key returns both to credits.
- A wizard message you have sent runs to its answer on your key. Closing the tab or losing the connection does not stop it, so the wizard can deliver a long answer after the connection drops, or after you reload the page. Anthropic bills your account for that answer either way; StackJack charges nothing for it.
- Server-side token counting still runs on StackJack's account and still costs nothing. It is a measurement, not a generated answer. Local character counters call no model at all.
- A test launched with Test agent is an actual automation run, so it uses your key and your Anthropic workspace and is billed by Anthropic.
For a managed-key organization nothing changed: the same wizard and suggestion calls use StackJack's account and reserve and settle StackJack credits — see Credits.
Your Anthropic key does not cover fast decisions
Decision steps and smart filters call TypeSafe AI, a different vendor from the one that runs your automations. Your Anthropic key — BYOK or not — has nothing to do with them.
- Having an Anthropic key on file neither pays for a decision call nor stops one.
- A decision call is never folded into a run's credit total, so a BYOK run that used a decision step still settles at zero StackJack credits for the run itself.
- If you want decision calls to run on your own vendor account, that is a separate key, stored separately. See Fast Decisions and Your Own TypeSafe Key.
- A TypeSafe key StackJack cannot read is a refusal, never a quiet fall-back to StackJack's own key. The decision step then fails under the author's on failure choice and the smart filter applies its outage choice, exactly as if the vendor were unreachable.
Notes
- Your key is also used by StackJack's support AI when it researches your support tickets — with BYOK active, that activity bills your Anthropic account too (it never consumes credits either way).
- If your Anthropic key is revoked or out of quota on Anthropic's side, runs will fail with Anthropic's error — StackJack does not fall back to managed billing automatically while a key is on file. Remove the key to return to managed credits. That is a different failure from an ended Agent Runner plan — in that case StackJack refuses the run itself with the message above rather than passing on an Anthropic error.
More in Billing, Plans & Credits
How Billing WorksThe Billing PageUpgrading a Connector PlanCanceling, Downgrades, and Payment IssuesStill need help? Ask the team