Skip to content

AI agents. Provider API keys ​

This article is a continuation of AI agents quick start. The quick start describes how to add the first shared key; here you will find which provider keys there are, which one a workspace uses, and what happens to the keys when a key, a workspace, a provider, or the module is deleted. The workspaces themselves are covered in the article AI agents. Workspaces and access.

You'll need a server with BeAdmin — our partners ship a ready‑to‑use VPS the moment you order.

Proven over 15 years in hosting. Your VPS with BeAdmin is ready to go out of the box.

  • Germany
  • Netherlands
  • Sweden
  • Switzerland
  • Spain
  • USA
Select server

European reliability made simple. Launch BeAdmin with your VPS in just one click.

  • Germany
  • Netherlands
  • Sweden
  • Estonia
  • Romania
  • Switzerland
  • Spain
  • United Kingdom
  • USA
Sign up

Where to get a key ​

The agent works on your behalf, so it needs your own API key: the module does not issue keys. You issue a key in your provider account. For Claude Code that is an Anthropic key, which you can issue in your account at platform.claude.com. For other providers, you issue the key in the provider's own account.

Tokens are billed by the provider. The panel does not see the spend and does not limit it, so you need to monitor spend and set limits in the provider account.

Once saved, a key cannot be viewed: it is stored on the server encrypted. If you lose a key, issue a new one with the provider and replace the old one with it. The panel also does not check that the key works: a typo or a revoked key shows up only when the agent fails to reach the provider.

Shared key and workspace key ​

You can set two types of key for each provider:

TypeWhere it is setWhere it applies
Shared keyIn the module settings, on the provider's cardIn all workspaces that have no key of their own
Workspace keyOn the workspace page, in the Provider API keys sectionOnly in this workspace; overrides the shared key

Keys are set per provider: each provider has its own shared key, and a workspace has its own key for each provider. One provider's key will not work for another. Without a licence you get one provider, so you will have one shared key; to connect more providers, buy slots in your licence — see How to get a licence for details.

The shared key is convenient when all workspaces run on one account: you set the key once. A workspace key is needed when you want to split spend: for example, so that a colleague's or a client's tokens are billed to their account rather than yours.

In a workspace, the agent uses whichever key exists:

  • if the workspace has a key of its own, it is used and the shared key is ignored;
  • if there is no key of its own but there is a shared one, the shared key is used;
  • if there is neither, the agent cannot work in this workspace until you set a key.

Shared key ​

How to add the shared key for the first time is described in the quick start. Later you can replace it, for example if the key was revoked or you moved to another account, or delete it. The old key cannot be viewed, so you need to get the new one from the provider.

After the shared key is deleted, workspaces without a key of their own stop working. Workspaces with their own key keep working as before.

module settings, AI providers tab — the provider card with the shared key setmodule settings, AI providers tab — the provider card with the shared key set

Workspace key ​

Open the page of the workspace you need and, in the Provider API keys section, set a key for the provider with the Set a separate key for this workspace button. The section is available once the provider is installed: until then there is nowhere to set keys.

workspace page — the Provider API keys section with a provider row where the shared key applies and the Set a separate key for this workspace buttonworkspace page — the Provider API keys section with a provider row where the shared key applies and the Set a separate key for this workspace buttonworkspace key dialog with an empty Key field and a note that the key will replace the shared oneworkspace key dialog with an empty Key field and a note that the key will replace the shared one

A workspace key overrides the shared one only in this workspace; the other workspaces keep using the shared key. To change a workspace key, replace it. To return a workspace to the shared key, delete the workspace key. If there is no shared key, the agent stops working in the workspace after its key is deleted, so set the shared key first.

What happens to keys on deletion ​

The shared key belongs to an installed provider, and a workspace key belongs to the workspace itself. That is why the shared key does not survive deleting a provider or the module, while a workspace key lives as long as the workspace exists.

What you doShared keyWorkspace key
You delete the shared keyDeletedStays; workspaces with their own key keep working
You delete a workspace keyStaysDeleted; the workspace falls back to the shared key, and if there is none, the agent in it stops working
You delete a workspaceStaysDeleted along with the workspace
You delete a providerDeletedStays and applies again after the provider is installed again
You delete the module without Delete workspace filesThe shared keys of all providers are deletedStay with their workspaces and return after the module is installed again
You delete the module with Delete workspace filesThe shared keys of all providers are deletedDeleted along with the workspaces
You reinstall the moduleNot affectedNot affected

⚠️ After installing again, set the shared key again

Deleting a provider or the module erases the shared key, and it does not come back after installing again. Until you set it again, workspaces without a key of their own cannot start the agent.

If the agent does not work ​

If the agent in a workspace does not start or cannot reach the provider, check the following in order:

  1. Is there a key. A workspace key is needed or, if there is none, the provider's shared key. After a provider or the module is installed again, you need to set the shared key again.
  2. Is the key valid. The panel does not check it, so make sure in the provider account that the key has not been revoked and that the account still has an available limit.
  3. Is the workspace running. You cannot connect to a stopped workspace or to one blocked by the licence limit — see workspace states.
  4. Is the provider blocked. A provider that exceeded the licence limit does not start in any workspace, and the key has nothing to do with it; see the article AI agents. Module management for details.

What's next ​

  • AI agents. Module management — module settings, installing and removing a provider, blocking by limit, updating, reinstalling, and removing the module.

BeAdmin © 2025. All rights reserved.