Skip to main content
Two kinds of keys live under Settings, and they do different jobs:

Save a provider key

You need the admin role.
  1. Open Settings, then BYOK. The page is titled Providers; messages from Orca call it “Settings, Providers”.
  2. On the provider’s card, choose Set key (or Replace if one is saved).
  3. Paste the key into API key and choose Save key. The provider checks the key before it is saved. It is stored encrypted and never shown again.
Supported providers are OpenAI, Anthropic, OpenRouter, Vercel, and cheaperinference. Once a key is saved, you can choose that provider in an agent’s Provider field, and its models run on your key, billed by your provider. Without a key, the provider is greyed out there. Orca charges nothing for their tokens. A model name says who pays. orca/openrouter/anthropic/claude-sonnet-4.5 runs on Orca credit; anthropic/claude-sonnet-4-5 runs on your Anthropic key. Nothing moves between them on its own. See models and provider keys.

Remove a provider key

Choose Remove on the card. From then on, the next turn of any session on that provider is refused until a key is set again. Sessions never move to Orca credit on their own; to keep one going, switch who pays for it.

Create an API key

  1. Open Settings, then API keys, and choose Create key.
  2. Give it a Name, such as “CI deploys”, and choose Create key.
  3. Copy the key. This is the only time it is shown, so store it in your secret manager.
Keys start with orca_sk_. Use one as the bearer token with the OpenAI SDKs and the CLI:
A key acts for this organization with your role. It keeps working until it is revoked, even after you leave the organization. See organizations and roles.

Revoke an API key

In the key’s row menu, choose Revoke key, then Revoke. Every request with that key fails from then on with HTTP 401, and it cannot be undone. Members see and revoke the keys they created. Admins see and revoke every key in the organization.