Added user-managed API keys for enterprise-configured providers (#919)
Build and Release / Determine run mode (push) Waiting to run
Build and Release / Read metadata (push) Blocked by required conditions
Build and Release / Sync Flatpak repo (push) Blocked by required conditions
Build and Release / Collect Flatpak artifacts (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-aarch64-apple-darwin, osx-arm64, macos-latest, aarch64-apple-darwin, dmg,app,updater, dmg) (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-aarch64-pc-windows-msvc.exe, win-arm64, windows-latest, aarch64-pc-windows-msvc, nsis,updater, nsis) (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-aarch64-unknown-linux-gnu, linux-arm64, ubuntu-22.04-arm, aarch64-unknown-linux-gnu, appimage,updater, appimage) (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-x86_64-apple-darwin, osx-x64, macos-latest, x86_64-apple-darwin, dmg,app,updater, dmg) (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-x86_64-pc-windows-msvc.exe, win-x64, windows-latest, x86_64-pc-windows-msvc, nsis,updater, nsis) (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-x86_64-unknown-linux-gnu, linux-x64, ubuntu-22.04, x86_64-unknown-linux-gnu, appimage,updater, appimage) (push) Blocked by required conditions
Build and Release / Prepare & create release (push) Blocked by required conditions
Build and Release / Publish release (push) Blocked by required conditions

Co-authored-by: Thorsten Sommer <SommerEngineering@users.noreply.github.com>
This commit is contained in:
Dominic NeuburgandThorsten Sommer authored and GitHub committed 2026-08-15 11:20:36 +02:00
1 parent a9a37b6bf5
commit 592c9c76e2
23 files changed
+479 -50

No files matched your search

+74
View File
@@ -535,3 +535,77 @@ CONFIG["LLM_PROVIDERS"][#CONFIG["LLM_PROVIDERS"]+1] = {
```
The API key will be automatically decrypted when the configuration is loaded and stored securely in the operating system's credential store (Windows Credential Manager / macOS Keychain).
## Letting users provide their own API key
Sometimes you want to hand out a preconfigured provider -- a fixed host, model, and instance name
-- without embedding a shared API key for it. Each user then brings their own key, for example
their personal OpenAI or Anthropic account, while everything else about the provider stays exactly
as your organization configured it.
Set `AllowUserProvidedAPIKey` on the provider:
```lua
CONFIG["LLM_PROVIDERS"][#CONFIG["LLM_PROVIDERS"]+1] = {
["Id"] = "9072b77d-ca81-40da-be6a-861da525ef7b",
["InstanceName"] = "Corporate OpenAI GPT-4",
["UsedLLMProvider"] = "OPEN_AI",
["Host"] = "NONE",
["Hostname"] = "",
["AllowUserProvidedAPIKey"] = true,
["AdditionalJsonApiParameters"] = "",
["Model"] = {
["Id"] = "gpt-4",
["DisplayName"] = "GPT-4",
}
}
```
With `AllowUserProvidedAPIKey` set, the provider still shows up as managed by your organization,
and users still cannot change the host, model, instance name, or any other field. The settings
page shows a key icon instead of the usual lock icon for this provider; opening it only offers the
API key field, with everything else disabled.
The flag works the same way for embedding and transcription providers:
```lua
CONFIG["EMBEDDING_PROVIDERS"][#CONFIG["EMBEDDING_PROVIDERS"]+1] = {
["Id"] = "3f0a4e8c-1d6b-4a91-8f2e-7c5d9b0a4e13",
["Name"] = "Corporate Embeddings",
["UsedLLMProvider"] = "OPEN_AI",
["Host"] = "NONE",
["Hostname"] = "",
["AllowUserProvidedAPIKey"] = true,
["Model"] = {
["Id"] = "text-embedding-3-large",
["DisplayName"] = "Text Embedding 3 Large",
}
}
CONFIG["TRANSCRIPTION_PROVIDERS"][#CONFIG["TRANSCRIPTION_PROVIDERS"]+1] = {
["Id"] = "b1c7d24f-5e83-4a06-9d1b-2f8e6a3c7d50",
["Name"] = "Corporate Transcription",
["UsedLLMProvider"] = "OPEN_AI",
["Host"] = "NONE",
["Hostname"] = "",
["AllowUserProvidedAPIKey"] = true,
["Model"] = {
["Id"] = "whisper-1",
["DisplayName"] = "Whisper",
}
}
```
For embedding providers, the settings page keeps the test button available next to the key icon, so
users can verify their own key right after entering it.
This is mutually exclusive with an embedded `APIKey` on the same provider: if both are present,
AI Studio ignores the embedded key and logs a warning, because the whole point of the flag is that
each user manages their own key. Combine the two across different providers if you need it -- one
provider with a shared, embedded key and another with `AllowUserProvidedAPIKey` -- but not on the
same provider.
The user's key follows the same "withdrawing a configuration" philosophy as everything else in this
document: if your configuration stops offering this provider, AI Studio removes the provider from
the settings but leaves the user's key in the OS keyring rather than deleting it, in case the same
provider comes back later. See [Withdrawing a configuration](#withdrawing-a-configuration).