Documentation Menu
Managing Keys
View, update, rotate, or remove your AI provider keys from the dashboard.
On this page
Managed access needs no customer-visible secret. Keys you add yourself are managed from the dashboard’s advanced Settings area.
Viewing your keys
Settings lists only provider keys you added yourself. The server-managed credential is deliberately hidden; view its remaining prepaid balance on Billing.
Updating or rotating a key
To replace a key — for example, after rotating it at the provider:
Open advanced Settings
Open the provider-key section for your helper.
Edit the provider entry
Use the edit control next to the provider you want to update.
Paste the new key and save
The old key is replaced. Your helper restarts briefly to pick up the change.
Good rotation practice: create the new key at the provider first, save it in BrainRoad, confirm your helper is working, then revoke the old key in the provider’s dashboard.
Removing a provider
Each provider entry has a remove control. Removing your own key returns the helper to BrainRoad-managed access when managed balance and entitlement are available. At zero managed balance, new model work waits; nothing is deleted.
Where keys are stored
Your own keys are written into your helper’s private, isolated runtime configuration. BrainRoad’s account-managed credential arrives through a Kubernetes Secret or mounted file, never through the browser, Helm arguments, process arguments, or another account. BrainRoad can rotate its managed credential without touching keys you added yourself.
Related docs
- How API Keys Work — managed access and optional BYOK
- Choosing a Provider — supported providers and how to pick