If you’ve used AI at all, it has probably always looked the same: a website, a text box, an answer. Somewhere behind it there’s an account, possibly a monthly charge, and at no point has anyone asked you for anything called a key.
Then you try a tool that has AI inside it — a writing app, a notes app, something for organising what you’re learning — and instead of simply working, it opens a settings panel and asks for an API key.
And there it is. The phrase sounds like the edge of the map. Here be programmers. A lot of people close the panel at that point and quietly file the whole feature under “not for me”.
It was for them. But nobody explained it, and the phrase really does sound like a locked door. So here is the explanation — the whole shape of the thing, not just which button to press — because once you can see the shape, the key turns out to be one of the more sensible ideas in consumer software right now.
Every “bring your own” is the same story
Start with the phrase, because it’s older than AI and it tells you most of what you need.
Bring your own bottle. A restaurant that doesn’t sell wine. Odd at first — surely wine is where restaurants make their money — until you see what it means. The restaurant has decided it is in the food business and not the wine business. You choose the wine, you pay the shop’s price instead of the restaurant’s markup, and in return you carry the bottle. A small responsibility, in exchange for choice and a lower bill.
Bring your own device. Your employer stops issuing phones. You use the one you already own and like, you’re not stuck with whatever the IT department bought in bulk, and in return you’re the one who looks after it.
Same shape every time. Something that used to be bundled comes unbundled. The customer gains a choice and a better price, and takes on a small job the vendor used to do. Whether that’s a good trade depends entirely on whether you wanted the choice.
Bring-your-own-key is exactly that shape, applied to the AI inside an app. Once you see it that way, the rest is details. Useful details, though, so let’s have them.
What the key actually is
Every company that makes an AI model — OpenAI, Google, Anthropic — has two front doors.
One is the chat window you know: ChatGPT, the Gemini app, claude.ai. Theirs, branded, with an account and usually a monthly plan. You log in, you type, it answers.
The other door is for software rather than people. It’s called an API, and it reaches the same models — same GPT, same Gemini, same Claude — with no chat window and no login page. Any program can knock on it: a writing app, a notes app, a script someone wrote on a Tuesday. It sends a request, it gets an answer.
A login page is no use to a program, because there’s no one to type into it. So the API uses a key instead. A key is a long string of letters and numbers that a program sends along with every request. The model company reads it and knows two things: which account this belongs to, and whom to bill.
An API key is a password for programs instead of people. That’s the whole definition. It is not an account by itself, not a subscription, not a file to install. It’s text — a line you copy from the model company’s website and paste into an app.
How it’s actually paid for
That’s the plumbing. What people actually want to know is what it costs, so here is how each door is paid for.
The chat plans first. Claude Pro and Max come with an allowance — a five-hour window and a weekly ceiling, both sized by the vendor — and when you run out, you can wait for the clock or switch on extra usage, which buys more at the same rate the API charges. ChatGPT Plus and Pro work the same way: a cap on messages per window, and credits you can buy for use beyond it. The same vendors sell API-style tools — Claude Code, Codex — on those same subscriptions, drawing from the same allowance. A subscription is an allowance with a meter behind it.
Now the API. The cheapest way in costs nothing: Google’s Gemini API has a free tier that needs no card and no commitment — rate-limited, but enough to find out whether you want an assistant at all — and you add billing only if you outgrow it. OpenAI, Anthropic and OpenRouter ask you to load a balance first, a few dollars up front, which your requests then draw down. Once you’re on a paid tier anywhere, you can set a ceiling, and on all four the ceiling is a hard stop, not a warning. Credits on most of them expire after a year. An API account is a prepaid block with a cap on it.
Underneath, both doors meter the same thing: tokens, the units of text a model reads and writes. The plan hides that number behind an allowance and a reset clock. The key shows it to you.
So the difference isn’t a subscription versus paying per use — both doors do both. It’s who sets the allowance. On a plan, the vendor decides how much you get, on what clock, at what tier, and you pay the same whether you use it or not. With a key, you decide how much to load and where to cap it, and you pay for what you use. Which comes out cheaper depends on how you use it, and the numbers on both sides change often enough that any figure written here would be stale before you read it. Who’s in control doesn’t change.
Four kinds of AI app
Now the apps. Once you’re clear on who holds the key, most of them fall into one of four kinds, and it’s worth knowing which one you’re looking at.
The first kind is the model company’s own product. ChatGPT, the Gemini app, claude.ai. One company makes the model and the window you talk to it through. There’s no key because there’s nobody in between — you have an account with the company that owns the model, and that account does everything a key would.
The second kind is a third-party app with AI built in, where the app company holds the key. Perplexity is one: a search engine that is AI all the way through, running on models it licenses. Microsoft’s Copilot is another: AI added to software that was already there. Your text goes to the app company’s server, their server calls the model with their key, and the answer comes back through them. You pay them a subscription. It feels like the chat window because, structurally, it is one, with an extra company in the loop. Whether the app is any use without the AI varies — Perplexity is nothing without it; Word was Word for decades before Copilot arrived.
The third kind asks for your key, and can’t really do anything without it. These are apps whose whole reason to exist is a different way of working with a model: alternative chat clients like TypingMind, with a layout or a memory the vendor’s own window doesn’t offer; coding assistants like Cline, which sit inside your editor and write with whatever model you point them at. There’s no bundled AI because the app company has decided it’s in the interface business and not the AI business. Bring your own bottle, and the restaurant doesn’t serve food either. That’s not a flaw; it’s what the app is.
The fourth kind is a complete piece of software on its own, which offers AI as one more thing it can do if you bring a key. This is Knogra. Building graphs, moving between scenes, notes, equations, layouts, saving, loading, importing, exporting — everything the tool exists for runs with no key, no account, and no AI anywhere in the picture. Plenty of people use it that way, and there’s a respectable argument that working out a subject’s structure yourself is where the learning actually happens. If you want an assistant on top of that — one that knows which node you’re on, can propose what ought to connect there, talk a topic through, draft an equation or a pictogram — then it needs a key.
There’s a quieter advantage to the two kinds that ask for a key, and it’s one people feel before they can name it. A new app asking for your card is a real ask: you don’t know who they are, how they store it, or whether they’ll exist next year. With a key, the app never sees a payment detail. The only company that does is the one you bought the key from — Google, OpenAI, Anthropic, or an aggregator you chose yourself — and what the app gets instead is a credential you can revoke in ten seconds. Trying an unknown tool becomes a much smaller decision.
The line between the third kind and the fourth matters more than it looks, and it’s worth checking before you assume. If an app asks for a key, the honest question is whether it’s a restaurant that doesn’t serve wine, or a wine bar. Both are fine. They’re just different places to walk into.
One key from the model maker, or one from an aggregator
This is the part that confuses people most, and it decides where you go to sign up.
A direct key comes from the company that makes the model. Google issues keys for Gemini, OpenAI for GPT, Anthropic for Claude. One account with each, one bill from each, and each key works only on that company’s models.
An aggregator is a different kind of company. OpenRouter, the best-known, makes no models of its own. It holds accounts with many model companies and resells access to all of them. One signup, one key, one balance you top up — and then, request by request, you choose whose model answers. Your request goes to OpenRouter, and OpenRouter passes it on to the vendor you picked.
Why you’d want an aggregator: one signup instead of five. One balance instead of five bills. Trying a different model is a dropdown, not another account and another card form. And it often reaches models whose own signup is awkward, waitlisted, or unavailable where you live.
Why you’d want a direct key: one fewer company in the chain, so your text goes to the model maker and nobody else. Usually a slightly better price — OpenRouter, for instance, adds a small fee to every top-up, which is the reseller’s margin made visible. And a vendor’s newest capabilities tend to appear on its own API first.
That comparison contains the honest privacy point, so here it is in plain words: through an aggregator, two companies see your request instead of one. That isn’t an accusation. It’s what a reseller is, and it’s the same trade you make with a reseller of anything. It’s worth knowing you’re making it.
Knogra supports both — Gemini, OpenAI and Anthropic directly, and OpenRouter — because which of those two lists sounds more like you is a real question with a real answer, and it isn’t ours to make for you.
One request, start to finish
Since Knogra is the example, here is a single request the whole way through, so the arrangement stops being abstract.
You’re on a node — say the Chain Rule, in a calculus graph you’re building — and you ask the assistant what else ought to connect here. Knogra gathers what it knows about where you are: the node itself — its title, its tags, any comment or equation you wrote on it — the scene around it, its direct connections, and the conversation you’ve had with the assistant so far. Not your notes; those stay on your machine and are never part of a request. It puts that together with your question, attaches your key, and sends it from your browser to the company you chose. Straight to Google, if you set up Gemini. To OpenRouter, if you went that way, which then passes it on to whichever model you selected.
The model answers. The reply comes back to your browser — the same one that sent it — and Knogra takes it apart: some prose, which goes in the chat panel, and a handful of proposed nodes and connections, which appear as suggestions you accept or dismiss one at a time. Nothing lands in your graph until you say so.
That’s the whole transaction. Count the parties: you, your browser, the model company. No server of ours anywhere in it, because there isn’t one. The key travelled from your browser to the vendor and nowhere else. The cost of that one request came off your account with them, and not off any bill from us — there is no bill from us.
Do it a hundred times and it’s a hundred of those. Nothing accumulates anywhere except in your graph, on your machine, and on your account with the vendor.
What’s yours now
Every bring-your-own comes with a small job. Here is this one, and it’s smaller than the vocabulary suggests.
The credential is on your machine — in your browser’s local storage, which is why no one else’s server has it, and also why anyone who can sit down at your browser can read it. On a shared computer, that matters. It’s the same rule as a saved password, and no stricter.
The account is prepaid by default. A new API account starts as a balance you loaded — or, on Google, as a free tier with no card on file. Requests draw it down; when it’s empty, they stop. It cannot spend more than you put in unless you switch on automatic reloading — and if you do, each provider has a hard cap you can set alongside it. Load what you’ll use in a year, since credits on most of them expire after that.
Keys are disposable. Make one per app — most consoles let you name them — and if one ever leaks, delete that one. Ten seconds, and it’s dead, and nothing else you use is affected. A leaked password means changing it everywhere; a leaked key means deleting a key. This is the one place the key is plainly better than the password it replaces.
And the app maker can’t do any of that for you, because they’ve never seen it. Which is the point.
What a decent app does with your key
If you’re handing a credential to a piece of software, you’re entitled to know what it does with it. Here are the questions worth asking of any app, with Knogra’s answers, since it’s the one we can answer for.
Does the key go anywhere except the model company? No. Every request — chat, equations, images — goes from your browser straight to the provider. The key is never sent to us.
Does it stay out of the things you share? A workspace file — the thing you’d send a friend or post online — has the keys stripped out before it’s written. That’s enforced in code, not in a policy document. A graph that quietly carried your key to everyone you shared it with would be a serious bug, and it’s the one we made sure can’t happen.
Does the app choose the privacy-friendly option when the vendor’s default isn’t? One concrete case: OpenAI’s API keeps requests and replies on its servers by default, for a conversation feature we don’t use. We switch that off on every request. The default wouldn’t have broken any promise we made, but a privacy choice should be a choice, not something inherited from a vendor.
And one thing you may run into if you go looking. Calling Anthropic from a browser requires a setting whose name includes the word “dangerous”. It refers to the key being visible to code running in your browser — which is what bring-your-own-key is, on every provider, everywhere. It isn’t a warning about Anthropic or about Knogra. It’s a description of the arrangement you chose.
Where this is heading
A guess, offered as a guess.
Bring-your-own-key is spreading because the thing being unbundled has become a commodity. There are several capable models, from several companies, roughly interchangeable for most everyday tasks, with prices falling every few months. When the ingredient is interchangeable, the thing you’re actually choosing is the app — and it starts to look strange for the app to insist on picking your ingredient for you and charging a markup on it.
Three things are pushing the same way. Many people already have an account with a model company, so plugging an app into the account you have is more natural than opening yet another subscription. Apps that bundle AI are exposed to the vendors’ pricing and have to pass it on, marked up, which is a hard place to compete from. And the model companies have noticed: getting a key from Google is a couple of clicks, and OpenRouter is very nearly a consumer product with a developer’s name.
It won’t be for everything. Software that does heavy processing on its own servers can’t hand you the bill for the AI part alone. People who want nothing to manage, ever, are better served by a bundle and should take one. And few employers will ask staff to bring their own keys. Bring-your-own-key belongs to a particular corner: local-first tools, privacy-minded tools, tools for people who like to know where their text goes. That corner is growing. It’s still a corner.
Which leaves one practical thing worth knowing about it. Once you hold a key, you hold it for every app that accepts one, and the number of those is climbing — editors, note-takers, terminals, browser extensions, tools you haven’t heard of yet. The first key is the only one that costs any effort. After that it’s a setting you already know how to fill in.
The five minutes
If you’ve decided you want one, this is all of it.
Pick where to get it. New to this: OpenRouter if you want one key that reaches most models, Gemini if you want the shortest path from nothing to a working assistant — its free tier needs no card, and if paying anything up front is what’s been stopping you, this is where to start. Already have an OpenAI or Anthropic account: use it.
Go to their website and generate a key. The wording varies — “API keys”, “credentials”, “create secret key” — but it’s always a short page with an obvious button. If it’s Anthropic, scope the key to a workspace when you make it; the option is on that screen, and a key without it fails every request with an error that doesn’t say why. Copy the key before you close the page; most vendors show it exactly once.
Load a small balance and set the cap. Same website, billing section. On Google’s free tier there’s nothing to load and nothing to cap, so skip this until you add billing. Once you’re paying anywhere, there’s a hard cap — OpenAI and Anthropic call it a spend limit, Google a spend cap, OpenRouter a credit limit on the key — and it stops requests rather than emailing you about them. Leave automatic reloading off until you’ve seen a month of your own usage.
Paste it into the app. In Knogra: Settings, your provider’s section, the key field. Leave the model at its default.
Ask it something. If it answers, you’re done. If OpenAI in particular won’t answer and everything looks right, re-paste the key first — OpenAI’s rejection message is one the browser won’t show to the page, so a wrong key looks like a dead connection.
And about cost, since it’s the question everyone actually has: this post deliberately names no prices. AI pricing moves too fast for any figure to survive a month — prices drop, free allowances come and go, vendors run promotions, new models land weekly. Nearly all of that movement is in your favour, and because you’re choosing the model yourself, you collect the improvements by changing a dropdown. Look at what your provider offers when you sign up. Look again in a few months. Treat it as a market that’s moving your way, not as homework.
The door
Back to the settings panel that started this — the one that asked for a key and looked like the edge of the map.
It’s telling you which of the four kinds of app you’re in. It isn’t going to stand between you and the model company, take a cut, and keep a copy. It’s offering you the choice of vendor and the vendor’s own price, and asking you to carry the bottle.
If it’s the fourth kind, you can decline, and the tool is still the tool. If it’s the third, the key is the point, and now you know what you’re being asked for. Either way, five minutes and a spending cap, and every app that takes a key answers to one account that’s yours.
It was never a locked door.