Skip to main content
Automations

BYOK — Using Your Own Anthropic Key

Written By Christopher Scaminaci

Last updated 7 days ago

BYOK — Using Your Own Anthropic Key

BYOK (Bring Your Own Key) lets your tenant supply its own Anthropic API key. With BYOK, managed agents, environments, vaults, run sessions and transcript fetches, and enabled memory stores use your Anthropic workspace and key — Anthropic bills you directly, and no StackJack credits are deducted for those runs. Builder AI features follow the same boundary: wizard chat and AI-assist suggestions use the same key your runs use. StackJack charges managed-key organizations credits for billable wizard and suggestion calls, and records zero credits when you have your own key on file — those calls are billed to your Anthropic account instead. A key that cannot be read refuses the request rather than falling back to StackJack's key. Server-side token counting calls no model and is free either way.

Who can use BYOK

Two kinds of account qualify, and either one alone is enough: an Enterprise connector plan, or a flat-fee Agent Runner plan on any connector plan. Eligibility is enforced server-side when you upload the key, not just hidden in the UI — and, for a key admitted by an Agent Runner plan rather than an Enterprise connector plan, re-checked on every run (see below). Your effective connector plan is the highest tier across your active connector subscriptions.

Setting up your key

Only the tenant owner can set, replace, or remove the key.

  1. Go to the Credits tab of the Automations area in the portal and find the key-mode card — titled Managed Anthropic credentials until a key is active, and Your Anthropic key (BYOK) once one is (its key-management controls appear for eligible accounts).
  2. Paste your Anthropic API key. It must start with sk-ant-.
  3. Save. The key is stored in Azure Key Vault and is never displayed again in the portal — you can replace or remove it, but not view it.

The Credits tab showing tenant-supplied BYOK active, credit packs, and an empty StackJack credit ledger.
The Credits tab after a tenant-supplied key is active; the secret itself is never shown.

Removing the key reverts your tenant to managed (credit-metered) billing for all subsequent runs. It changes execution going forward; it does not move an automation or a session that already lives in your Anthropic workspace. A run created under your key can therefore stop being resumable, and its transcript can stop being fetchable, once the key is gone — transcript fetches use whichever key is on file at the moment you ask. Contact StackJack support for re-provisioning rather than retrying such a run. Removing the key is also one of the two remedies when an Agent Runner plan that admitted the key ends — see If your Agent Runner plan ends.

What changes for runs

With a BYOK key in place:

  • Your workspace, your key. Agents, execution environments, vaults, run sessions and transcript fetches, and enabled memory stores use your Anthropic workspace and key.
  • Zero credits. BYOK runs skip the pre-flight credit check and reservation entirely. There's no balance requirement to start a run.
  • Audit trail preserved after settlement. Once final settlement completes, your credit transaction history records a zero-amount "BYOK run" entry with approximate usage. A missing entry while the run is active or just terminalized is not evidence that no Anthropic usage occurred; Anthropic's bill remains authoritative for tenant-key charges.
  • Most guardrails still apply. Runtime caps, tool policy, dry-run mode, and consent are unchanged. The max credits per run cap does not apply to BYOK runs — credit metering is skipped entirely, so there is no mid-run credit check or credit-cap stop. Use the runtime cap to bound BYOK run length (and cost on your Anthropic bill).

Crash recovery has a separate cost and side-effect boundary. After StackJack proves a stranded session stopped, it may start one fresh replacement attempt under the same run record. Both Anthropic attempts can create direct charges in your workspace, and connector changes completed by the first attempt can repeat. Use vendor-side idempotency or deduplication for write workflows that must happen only once.

If your Agent Runner plan ends

Scope. This applies only to a key that a flat-fee Agent Runner plan admitted. A key admitted by an Enterprise connector plan is never evaluated, and neither is a key that was already on file before this behaviour shipped — those are grandfathered. The Enterprise plan also wins outright: if your account is on the Enterprise connector plan today, your key keeps working whatever happened to an Agent Runner plan you also once held.

What counts as ended. A cancelled or deactivated Agent Runner plan. A failed payment still in retry, a paused subscription, and a cancellation that is scheduled but not yet effective all keep working normally.

What happens. Runs are refused. Each attempt is written Failed carrying this message, and it never falls back to StackJack credits:

Your Agent Runner plan has ended, so your own Anthropic key is no longer used for runs. Re-subscribe to Agent Runner to resume using it, or remove the key to run on StackJack credits.

Nothing is deleted. The refusal happens before StackJack reads the stored key, so the key and its reference both survive. Restoring the plan restores the key with nothing to re-enter.

What still works. Erasure is deliberately unaffected: hard-deleting a memory store and deleting an automation complete normally. What is refused is use — fetching a run's transcript or tool-call sequence, and listing, clearing, redacting, or migrating agent memory.

Builder assistance runs on your key too

This changed on 19 September 2026. Builder assistance used to run in StackJack's own Anthropic account for every tenant, BYOK or not, and StackJack paid for it. It no longer does. StackJack does not absorb a customer's AI spend, so an organization with its own key pays for its own builder help the same way it pays for its own runs.

For a BYOK tenant:

  • Wizard chat turns and AI-assist suggestions run on your key and are billed to your Anthropic account, in your Anthropic workspace. They cost 0 StackJack credits, and the zero is now the ordinary consequence of using your key rather than a separate accounting rule.
  • Your key is resolved once per turn, and there is no fall-back. If it cannot be read, or if it is on file under an entitlement that has lapsed, the turn is refused rather than quietly served on StackJack's account. The builder says the key was refused and what to do about it.
  • A key Anthropic itself rejects — revoked, rotated, or pointed at a workspace it has no rights in — is reported as a key problem, not a StackJack outage. Storing a key proves only that StackJack can read it; nothing asks Anthropic whether it still works until a call is made.
  • A lapsed Agent Runner plan now reaches builder assistance too, when that plan is what admitted your key in the first place. Runs pause and builder turns are refused together. This is the part most people assume is unaffected, and since 19 September 2026 it is not. Removing the key returns both to credits.
  • A wizard message you have sent runs to its answer on your key. Since 26 September 2026 closing the tab or losing the connection no longer stops it, so the wizard can deliver a long answer after the connection drops, or after you reload the page. Anthropic bills your account for that answer either way; StackJack charges nothing for it.
  • Server-side token counting still runs on StackJack's account and still costs nothing. It is a measurement, not a generated answer.
  • Local character counters remain ordinary builder helpers. They call no model at all.
  • A test launched with Test agent is an actual automation run, so it uses your key and your Anthropic workspace and is billed by Anthropic, exactly as it always did.

For a managed-key tenant nothing changed: the same wizard and suggestion calls use StackJack's account and reserve and settle StackJack credits.

Your Anthropic key does not cover fast decisions

Decision steps and smart filters call TypeSafe AI, a different vendor from the one that runs your automations. Your Anthropic key — BYOK or not — has nothing to do with them.

  • Having an Anthropic key on file neither pays for a decision call nor stops one.
  • A decision call is never folded into a run's credit total, so a BYOK run that used a decision step still settles at zero StackJack credits for the run itself.
  • If you want decision calls to run on your own vendor account, that is a separate key, stored separately. See Fast Decisions and Your Own TypeSafe Key.
  • A TypeSafe key StackJack cannot read is a refusal, never a quiet fall-back to StackJack's own key. The decision step then fails under the author's on failure choice and the smart filter applies its outage choice, exactly as if the vendor were unreachable.

Automations created before you added your key

An automation provisioned before your BYOK key was saved lives in StackJack's platform workspace, and its runs would not line up with your workspace. If you added a BYOK key after creating automations, contact StackJack support to migrate them—StackJack has a repair operation that re-provisions existing automations into your Anthropic workspace, individually or all at once. When memory is enabled, migration copies/imports it into the new workspace and then archives the old memory store.

You can also move an automation's memory yourself, without waiting for support: while the store is still in StackJack's shared workspace, its Memory card offers a one-way move into your workspace. That moves the notes only — it does not re-provision the automation itself. See Automation memory.

Frequently asked

Does BYOK change which models or tools my automations can use? No. Model selection, allow-list or deny-list tool policy, and plan-based connector-tool gating are identical. Native Anthropic capabilities (web search, web fetch, code execution) are configured per automation and are never plan-gated for anyone.

Do StackJack staff runs use my key? Staff-initiated diagnostic runs never charge your credits regardless of BYOK. Run execution for your tenant uses your workspace configuration.

What happens if I remove my key while automations exist? Subsequent runs revert to managed credit billing (reservation + reconciliation). Automations already provisioned into your Anthropic workspace stay there until they are re-provisioned, and execution can then report a workspace mismatch. Sessions and memory stores are workspace-bound the same way, so an existing run's transcript or memory can become unreachable. Contact support before you remove a key permanently so your automations' workspace placement, and any memory that needs migrating, can be reviewed.

What happens if my Agent Runner plan ends but my key is still on file? Runs are refused with the worded message above rather than being silently billed to credits. The key stays stored; restore the plan, or remove the key so new runs go on credits again. Those two are not equivalent for work already in flight: only restoring the plan resumes a run paused in your Anthropic workspace. Note the asymmetry: enrollment admission did not change, so an inactive Agent Runner plan still cannot enrol a new key — which means a lapsed flat-fee account has strictly fewer options than an account whose Enterprise connector plan lapsed with a key already on file.