Skip to main content
Use your own supported AI-provider credentials with eligible P2HS AI workflows.

When to use BYOK

  • your organization already has provider access;
  • you need a specific supported provider or model;
  • you want provider usage billed directly to your account;
  • organizational policy requires customer-controlled credentials.

How it works

BYOK is separate from P2HS-managed AI. Eligible projects can connect a supported provider through a customer-configured integration and use that connection for the actions it admits.

Connect a provider

  1. Open the P2HS dashboard.
  2. Select the eligible workspace or project.
  3. Open AI or Integrations settings and choose BYOK.
  4. Select a supported provider and enter the requested credentials.
  5. Save and verify the connection, then choose it in an eligible AI workflow.

Billing and security

  • credentials are scoped to the project or workspace scope exposed by the product;
  • secrets are stored as managed references and are not returned to browser clients;
  • provider-specific setup is shown only when that provider is intentionally connected;
  • rotate or revoke credentials through the connection settings;
  • upstream provider charges are billed by that provider;
  • P2HS orchestration, build, or credit charges may still apply according to the workspace’s current configuration;
  • credentials are managed as secrets and should be rotated or revoked through settings.
BYOK provider names and model controls describe the provider you intentionally connect. They do not reveal which upstream providers or models P2HS-managed AI uses.
Check the dashboard for the current eligibility, connection fields, and billing treatment of BYOK for your workspace.
If the connection fails, see BYOK troubleshooting.