> For the complete documentation index, see [llms.txt](https://notara-1.gitbook.io/notara-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://notara-1.gitbook.io/notara-docs/byok.md).

# BYOK (Bring Your Own Key)

Notara requires you to provide your own LLM API key. This means you pay your AI provider directly for the tokens your team uses, giving you full cost transparency and control.

## Why BYOK?

There are a few reasons Notara takes this approach rather than bundling an LLM key:

1. **Cost transparency**: you see exactly what you're spending on AI in your provider's dashboard. There's no markup hidden inside a Notara line item.
2. **Provider choice**: different teams have different needs. Some prefer Anthropic Claude's reasoning, others need OpenAI's tool use, others have compliance requirements that favor a specific provider.
3. **Rate limits**: your provider's rate limits are yours — Notara doesn't share capacity across customers.
4. **No key custody risk**: Notara never holds a key that could expose your AI usage if Notara were breached.

## Supported Providers

| Provider          | Models                                 | Notes                                    |
| ----------------- | -------------------------------------- | ---------------------------------------- |
| **Anthropic**     | Claude 3.5 Sonnet, Claude 3 Opus, etc. | Recommended — best reasoning performance |
| **OpenAI**        | GPT-4o, GPT-4-turbo, etc.              | Fully supported                          |
| **Google Gemini** | Gemini 1.5 Pro, Gemini Flash           | Fully supported                          |
| **Kimi**          | Moonshot models                        | Fully supported                          |
| **GLM**           | ChatGLM models                         | Fully supported                          |
| **DeepSeek**      | DeepSeek-V2, DeepSeek-Coder            | Fully supported                          |

New providers are added regularly. Contact <support@notara.ai> if your preferred provider isn't listed.

## How to Add Your Key

1. In the Notara dashboard, go to **Settings → BYOK**.
2. Select your provider from the dropdown.
3. Paste your API key into the input field.
4. Click **Verify** — Notara makes a small test call to confirm the key is valid and has the right permissions.
5. Click **Save**.

You can update or rotate your key at any time by repeating these steps. The old key is replaced immediately.

## Key Security

Your API key is encrypted at rest using **AES-256-GCM** with a workspace-specific encryption key. It is:

* Never logged in plain text
* Never included in error messages or audit logs
* Never transmitted to any third party other than your chosen provider
* Decrypted only at agent runtime when a call needs to be made, then discarded from memory

## When you need a key

| Surface                                                 | Model comes from                            |
| ------------------------------------------------------- | ------------------------------------------- |
| MCP clients (Claude Code, Cursor, others), Free or paid | The client itself. No key needed in Notara. |
| Slack bot, Notara chat, scheduled workflows (paid)      | Your model API key saved in Notara          |

## Usage and cost

Notara does not meter tokens against a credit allowance and does not mark up model usage. Your provider bills every call made with your key directly, and your provider's dashboard shows the spend. Notara records token counts for usage reporting, never prompt or response content.

To keep costs down, keep always-loaded (spine) documents short, start new Slack threads instead of letting one grow very long, and review how often scheduled workflows run.

## Provider-Specific Guides

* [Anthropic (Claude)](/notara-docs/byok/anthropic.md) — detailed setup for the recommended provider
