> For the complete documentation index, see [llms.txt](https://docs.warp.dev/llms.txt).
> Markdown versions of each page are available by appending .md to any URL.

# Team-managed LLM API keys and endpoints

Configure shared LLM provider API keys and custom endpoints for your team from the Admin Panel, including cloud agents.

Business and Enterprise admins can configure shared provider API keys and OpenAI-compatible endpoints for local and [cloud Warp Agent runs](https://docs.warp.dev/platform/). Team members select the configured models without handling the credentials themselves.

Unlike [personal BYOK](https://docs.warp.dev/agents/inference/bring-your-own-api-key/) and [personal endpoints](https://docs.warp.dev/agents/inference/custom-inference-endpoint/), team-managed configuration is stored securely by Warp and is available to cloud agents.

![Team-managed API keys and endpoints demo](https://i.ytimg.com/vi/Ko1rFyL1jfo/sddefault.jpg)

Note

Team-managed API keys and endpoints are available on Warp’s Business and Enterprise plans. See [Warp pricing](https://www.warp.dev/pricing) for plan details.

## Key features

-   **Admin-configured, shared across the team** - An admin sets provider keys and custom endpoints once in the Admin Panel, and they appear automatically in every member’s model picker.
-   **Local and cloud runs** - Use your team’s providers with the Warp Agent in either location.
-   **First-party keys and custom endpoints** - Configure API keys for OpenAI, Anthropic, and Google, and add one or more OpenAI-compatible custom endpoints (for example, OpenRouter or LiteLLM).
-   **Optional personal configuration** - Admins choose whether members may also add their own [API keys](https://docs.warp.dev/agents/inference/bring-your-own-api-key/) and [endpoints](https://docs.warp.dev/agents/inference/custom-inference-endpoint/). See [member key precedence](#member-key-precedence) for how Warp chooses a key.

## How team-managed providers differ from self-serve BYOK and BYOLLM

Warp offers several ways to bring your own AI infrastructure. Use this table to pick the right one, and follow the links for full details.

| Name | Configured by | Stored | Works with cloud agents | Plans |
| --- | --- | --- | --- | --- |
| **Team-managed API keys and endpoints** | Team admin (Admin Panel) | Server-side by Warp | Yes | Business and Enterprise |
| **[Personal BYOK](https://docs.warp.dev/agents/inference/bring-your-own-api-key/)** | Each member | Locally on the member’s device | No | Free and all eligible paid plans |
| **[Personal custom inference endpoint](https://docs.warp.dev/agents/inference/custom-inference-endpoint/)** | Each member | Locally on the member’s device | No | Free and all eligible paid plans |
| **[BYOLLM — AWS Bedrock](https://docs.warp.dev/enterprise/enterprise-features/byollm-aws-bedrock/)** | Team admin (Admin Panel) | Cloud-native IAM (no stored keys) | Yes | Enterprise only |
| **[BYOLLM — Gemini Enterprise](https://docs.warp.dev/enterprise/enterprise-features/byollm-gemini-enterprise/)** | Team admin (Admin Panel) | Cloud-native IAM (no stored keys) | No (interactive sessions only) | Enterprise only |

Team-managed API keys and endpoints are an admin-configured option on Business and Enterprise. BYOLLM requires Enterprise. Choose team-managed keys and endpoints to route through provider APIs (OpenAI, Anthropic, Google) or any OpenAI-compatible endpoint using stored keys. Choose [AWS Bedrock BYOLLM](https://docs.warp.dev/enterprise/enterprise-features/byollm-aws-bedrock/) for cloud-native IAM routing through your AWS account, including cloud agent support. Choose [Gemini Enterprise BYOLLM](https://docs.warp.dev/enterprise/enterprise-features/byollm-gemini-enterprise/) for cloud-native IAM routing through your Google Cloud project; in this iteration, Gemini Enterprise BYOLLM supports interactive sessions only, with cloud agent support planned.

## How it works

### First-party keys and custom endpoints

-   **First-party keys (BYOK)** - The admin adds an API key for a provider Warp supports (OpenAI, Anthropic, or Google). Members select the normal Warp model for that provider, and the server routes the request through the team key when the member has no key of their own.
-   **Custom endpoints (BYOE)** - The admin adds one or more OpenAI-compatible Chat Completions endpoints. Each endpoint has a name, a base URL, an API key, and one or more models, where each model has a model name (sent to the endpoint) and an optional alias (shown to members). Team endpoint models appear in every member’s model picker as their own entries, labeled with the endpoint name.

### Member key precedence

When the admin allows member-managed keys and endpoints, a member’s own key for a provider takes precedence over the team’s. Custom endpoints don’t require precedence, because a member’s endpoint and a team endpoint are always distinct:

-   **First-party keys** - If a member has their own key for a provider, requests route through the member’s key; otherwise the team key is used; otherwise Warp-managed inference is used (if allowed).
-   **Custom endpoints** - A member’s own endpoint and a team endpoint never collide, even if they share a name. The member’s endpoint is used when they select it; team endpoints resolve to the team’s stored credential.

### Cloud agents

[Cloud Warp Agent runs](https://docs.warp.dev/platform/) can use your team’s keys and endpoints when you select a configured provider model or endpoint. **Auto** uses Warp-provided inference; see [billing behavior](#billing-behavior). Personal keys and endpoints stored on a member’s device aren’t copied to cloud runs.

## Configuring team-managed keys and endpoints

### Prerequisites

-   You have admin access to your team’s [Admin Panel](https://docs.warp.dev/enterprise/team-management/admin-panel/).
-   Your organization is on the Business or Enterprise plan.

### Configure keys and endpoints

Configure team providers from the [Admin Panel](https://docs.warp.dev/enterprise/team-management/admin-panel/) **Models** page, where a **First-party API keys** card and a **Custom endpoints** card sit alongside the Direct API and AWS Bedrock cards.

1.  In the [Admin Panel](https://docs.warp.dev/enterprise/team-management/admin-panel/), go to the **Models** page.
2.  To add a team API key, use the **First-party API keys** card: enter the key for a provider (OpenAI, Anthropic, or Google) and save it. Each provider row shows whether a key is configured without revealing the stored value.
3.  To add a team custom endpoint, use the **Custom endpoints** card: enter a name, a base URL, an API key, and at least one model (a model name plus an optional alias), then save. An endpoint can’t be saved without a name, a valid base URL, an API key, and at least one model.
4.  Choose whether members may add their own keys and endpoints. When this is off, Warp won’t use any key or endpoint a member adds, even if they’ve saved one — their saved keys are preserved for when it’s turned back on.

The team’s enabled models appear in members’ model pickers when their team settings refresh.

Note

A team endpoint’s base URL must be reachable from Warp’s hosted services. Use a public HTTPS URL by default, or [connect a private LLM gateway through private networking](https://docs.warp.dev/enterprise/enterprise-features/private-networking/).

### Keep inference on your team’s providers

By default, members can still choose Warp-managed models even when team providers are configured. To require that inference goes to your providers, turn off **Direct API** access on the **Models** page so Warp-managed models are no longer selectable.

## Member experience

Members select a model from the picker without configuring team credentials:

-   **Custom endpoints** - Each enabled team endpoint model appears in the model picker as its own entry, showing the model’s name (or alias) and the endpoint name. Members select it like any other model.
-   **First-party keys** - Members select the standard model for a provider (for example, a Claude, GPT, or Gemini model), and requests route through the team key automatically. If a member has added their own key for that provider, their own key takes precedence.

If the admin allows members to add their own keys and endpoints, members can still do so through the standard self-serve [BYOK](https://docs.warp.dev/agents/inference/bring-your-own-api-key/) and [custom inference endpoint](https://docs.warp.dev/agents/inference/custom-inference-endpoint/) settings.

## Billing behavior

-   **Provider-billed inference** - Your provider or endpoint bills team-routed inference directly rather than consuming Warp-provided inference usage.
-   **Auto uses Warp-provided inference** - **Auto** consumes Warp usage. Select a specific model or endpoint to use your team’s provider. [Custom routers](https://docs.warp.dev/agents/inference/custom-routers/) apply provider keys after choosing a model, preferring a member’s own key over the team key. Routers cannot target endpoint models.
-   **Other Warp charges remain** - Customer-supplied inference incurs [platform charges](https://docs.warp.dev/support-and-community/plans-and-billing/platform-credits/) for local Business and Enterprise runs and all cloud runs. Cloud runs on Warp-hosted compute also incur [compute charges](https://docs.warp.dev/support-and-community/plans-and-billing/credits/#compute-usage).

External inference bills are not fully represented in Warp’s totals. See [usage and billing](https://docs.warp.dev/support-and-community/plans-and-billing/credits/#charges-and-estimates) for cost-reporting limitations.

## Security and data handling

Warp encrypts team API keys and endpoint URLs at rest. Members receive model names, endpoint names, aliases, and whether a provider key is configured, not the stored keys or endpoint URLs.

Warp uses the stored credentials to call your provider without delivering them to member devices or cloud agent environments.

### Zero Data Retention (ZDR)

Warp is **SOC 2 compliant** and has **Zero Data Retention (ZDR)** agreements with its contracted LLM providers. When you route through your own keys or endpoints:

-   Data retention on the **provider side** is determined by your provider’s account settings.
-   Warp **cannot enforce ZDR** for requests sent through your keys or endpoints.
-   If your provider account doesn’t have ZDR enabled, your requests may be retained according to their terms.

## Related pages

-   [Bring Your Own API Key](https://docs.warp.dev/agents/inference/bring-your-own-api-key/) — Self-serve, user-level API keys for OpenAI, Anthropic, and Google.
-   [Custom inference endpoint](https://docs.warp.dev/agents/inference/custom-inference-endpoint/) — Self-serve, user-level OpenAI-compatible endpoints.
-   [Bring Your Own LLM](https://docs.warp.dev/enterprise/enterprise-features/bring-your-own-llm/) — BYOLLM overview: route inference through [AWS Bedrock](https://docs.warp.dev/enterprise/enterprise-features/byollm-aws-bedrock/) or [Gemini Enterprise (Vertex AI)](https://docs.warp.dev/enterprise/enterprise-features/byollm-gemini-enterprise/).
-   [Private networking](https://docs.warp.dev/enterprise/enterprise-features/private-networking/) — Connect a private team-managed LLM gateway without a public endpoint.
-   [Admin Panel](https://docs.warp.dev/enterprise/team-management/admin-panel/) — Configure team settings and model routing.
-   [Model Choice](https://docs.warp.dev/agents/inference/model-choice/) — Full list of supported models.
-   [Contact sales](https://www.warp.dev/contact-sales) — Get help with Enterprise setup.
