BRING YOUR OWN KEYS
Your credentials.
Your provider account.
Use your ZRouter account API key to authenticate to the gateway, then route a request with a provider key saved in your own account.
1. Save a supported provider key
Open Bring your own keys in the dashboard. Select an available provider connection, enter your provider API key, and save it.
The current BYOK implementation supports configured connections for OpenAI, Anthropic, Gemini AI Studio, Groq, OpenRouter, DeepSeek, xAI, Cerebras, Hugging Face, Alibaba Bailian, Chutes, Cohere, Fireworks AI, Kilo AI, Kimi Code, Meta, MiniMax, OpenCode Go, Xiaomi, and Z.ai. Only enabled connections and models available to your account appear. Adding a key does not add new models to the workspace.
2. Make a BYOK request
Add X-ZRouter-BYOK: true and use either a provider-qualified model from a connection where you saved a key, or one of your virtual models:
curl 'https://zrouter.si/v1/chat/completions' \
-H "Authorization: Bearer YOUR_ZROUTER_KEY" \
-H "X-ZRouter-BYOK: true" \
-H "Content-Type: application/json" \
-d '{
"model": "PROVIDER_INSTANCE/MODEL_ID",
"messages": [{"role": "user", "content": "Hello"}],
"max_tokens": 256
}'You can also turn on BYOK in the playground. Requests without the BYOK header use the gateway-funded prepaid flow.
Use your keys with virtual models
Send a virtual model selector, such as accounts/<account-id>/auto, with X-ZRouter-BYOK: true. Routing, failover, and the Super Intelligence Router work as usual, but only across targets on providers where you saved a key. Switch or add providers in the virtual model; your app keeps the same model name and endpoint.
If none of a virtual model's targets is on a provider you saved a key for, the request fails instead of using platform credit.
How credentials are handled
Saved provider credentials are encrypted at rest with AES-256-GCM and bound to the account and provider. Saved secrets are not returned by the API. BYOK uses isolated provider clients built from your own keys and never uses the shared response cache. A BYOK request is never served with platform keys.
You can replace or remove your own saved provider key. Removing it from ZRouter does not revoke it at the provider; revoke exposed credentials with the provider as well.
Billing and usage
Your provider bills your provider account directly. ZRouter’s current routing fees are $0 per million input tokens and $0 per million output tokens. These fees are separate from provider charges.
BYOK token usage is still metered and appears in your account. Enabled budgets and rate limits still apply. Any ZRouter routing fee requires sufficient prepaid credit; a negative credit balance also blocks requests.
Current boundaries
BYOK uses official endpoints for supported connections. Custom base URLs, Azure credentials, and Vertex service accounts are not supported by customer BYOK. Your provider key must have access to the selected model.