Skip to content

BYOK

BYOK stands for bring your own key. The gateway forwards inference requests to upstream providers using customer-supplied provider API keys, rather than a single shared key managed by the gateway operator.

Storage

Provider keys are stored in the gateway database, encrypted at rest with AES-256-CBC plus HMAC-SHA256 for integrity. The encryption passphrase is held outside the database, configured by Myra for your deployment. A gateway never returns a stored key value to the SPA; only the alias and metadata are exposed in admin responses.

Scope

A BYOK key is bound to one of two scopes:

  • Gateway-level — the key is used for inference requests routed through one specific gateway.
  • Tenant-level — a key held at the tenant level, used by administrative and usage-synchronisation tasks.

On the inference path the gateway reads only the gateway-level key for the requested provider. If a required manual key is absent, the request fails with 424 provider_key_missing — there is no fall-through to a tenant-level key. Tenant-level keys are not consulted when routing inference; they serve the admin and usage-sync paths.

Exception — Myra managed (keyless) models. When the tenant has enabled a Myra-provided managed model on the default alias and no per-gateway key is present, the gateway injects Myra's rotating pool key instead of failing, metered to the tenant's budget. See Managed (keyless) Claude. Keyless first-party providers (the Myra EU fleet) never need a stored key.

Exception — self-serve subscriptions. A tenant on a self-serve plan never stores an Anthropic key: its Anthropic credential is the managed pool key, injected on every request without any per-gateway enablement. The models it may route are the ones its plan includes. Before that key is used the gateway verifies, fail-closed, that the workspace has a dollar cap, that the model carries a billable price, and that the workspace is within its allowance — an unverifiable balance is refused 503 spend_unverified, and an exhausted one 429 quota_exceeded on a paid plan or 402 trial_budget_exhausted on the free trial (whose credit is per user, not per workspace), never an unmetered request on Myra's account. These checks run on delegated sub-agent turns too, which bypass the ordinary access-phase quota gate.

Rotation

A key is rotated by adding the new key as a new alias and removing the old alias. The gateway picks up the change on the next request without restart. Decrypted keys are held in a short-lived (≤60s) in-memory cache; deleting a key evicts that cache immediately, so a revoked key cannot be presented on a subsequent request.

See also