Skip to content

Enterprise > Enterprise features

Team-managed LLM API keys and endpoints

Open in ChatGPT ↗
Ask ChatGPT about this page
Open in Claude ↗
Ask Claude about this page
Copied!

Configure shared LLM provider API keys and custom endpoints for your team from the Admin Panel, including cloud agents.

Business and Enterprise admins can configure shared provider API keys and OpenAI-compatible endpoints for local and cloud Warp Agent runs. Team members select the configured models without handling the credentials themselves.

Unlike personal BYOK and personal endpoints, team-managed configuration is stored securely by Warp and is available to cloud agents.

  • Admin-configured, shared across the team - An admin sets provider keys and custom endpoints once in the Admin Panel, and they appear automatically in every member’s model picker.
  • Local and cloud runs - Use your team’s providers with the Warp Agent in either location.
  • First-party keys and custom endpoints - Configure API keys for OpenAI, Anthropic, and Google, and add one or more OpenAI-compatible custom endpoints (for example, OpenRouter or LiteLLM).
  • Optional personal configuration - Admins choose whether members may also add their own API keys and endpoints. See member key precedence for how Warp chooses a key.

How team-managed providers differ from self-serve BYOK and BYOLLM

Section titled “How team-managed providers differ from self-serve BYOK and BYOLLM”

Warp offers several ways to bring your own AI infrastructure. Use this table to pick the right one, and follow the links for full details.

NameConfigured byStoredWorks with cloud agentsPlans
Team-managed API keys and endpointsTeam admin (Admin Panel)Server-side by WarpYesBusiness and Enterprise
Personal BYOKEach memberLocally on the member’s deviceNoFree and all eligible paid plans
Personal custom inference endpointEach memberLocally on the member’s deviceNoFree and all eligible paid plans
BYOLLM — AWS BedrockTeam admin (Admin Panel)Cloud-native IAM (no stored keys)YesEnterprise only
BYOLLM — Gemini EnterpriseTeam admin (Admin Panel)Cloud-native IAM (no stored keys)No (interactive sessions only)Enterprise only

Team-managed API keys and endpoints are an admin-configured option on Business and Enterprise. BYOLLM requires Enterprise. Choose team-managed keys and endpoints to route through provider APIs (OpenAI, Anthropic, Google) or any OpenAI-compatible endpoint using stored keys. Choose AWS Bedrock BYOLLM for cloud-native IAM routing through your AWS account, including cloud agent support. Choose Gemini Enterprise BYOLLM for cloud-native IAM routing through your Google Cloud project; in this iteration, Gemini Enterprise BYOLLM supports interactive sessions only, with cloud agent support planned.

  • First-party keys (BYOK) - The admin adds an API key for a provider Warp supports (OpenAI, Anthropic, or Google). Members select the normal Warp model for that provider, and the server routes the request through the team key when the member has no key of their own.
  • Custom endpoints (BYOE) - The admin adds one or more OpenAI-compatible Chat Completions endpoints. Each endpoint has a name, a base URL, an API key, and one or more models, where each model has a model name (sent to the endpoint) and an optional alias (shown to members). Team endpoint models appear in every member’s model picker as their own entries, labeled with the endpoint name.

When the admin allows member-managed keys and endpoints, a member’s own key for a provider takes precedence over the team’s. Custom endpoints don’t require precedence, because a member’s endpoint and a team endpoint are always distinct:

  • First-party keys - If a member has their own key for a provider, requests route through the member’s key; otherwise the team key is used; otherwise Warp-managed inference is used (if allowed).
  • Custom endpoints - A member’s own endpoint and a team endpoint never collide, even if they share a name. The member’s endpoint is used when they select it; team endpoints resolve to the team’s stored credential.

Cloud Warp Agent runs can use your team’s keys and endpoints when you select a configured provider model or endpoint. Auto uses Warp-provided inference; see billing behavior. Personal keys and endpoints stored on a member’s device aren’t copied to cloud runs.

Configuring team-managed keys and endpoints

Section titled “Configuring team-managed keys and endpoints”
  • You have admin access to your team’s Admin Panel.
  • Your organization is on the Business or Enterprise plan.

Configure team providers from the Admin Panel Models page, where a First-party API keys card and a Custom endpoints card sit alongside the Direct API and AWS Bedrock cards.

  1. In the Admin Panel, go to the Models page.
  2. To add a team API key, use the First-party API keys card: enter the key for a provider (OpenAI, Anthropic, or Google) and save it. Each provider row shows whether a key is configured without revealing the stored value.
  3. To add a team custom endpoint, use the Custom endpoints card: enter a name, a base URL, an API key, and at least one model (a model name plus an optional alias), then save. An endpoint can’t be saved without a name, a valid base URL, an API key, and at least one model.
  4. Choose whether members may add their own keys and endpoints. When this is off, Warp won’t use any key or endpoint a member adds, even if they’ve saved one — their saved keys are preserved for when it’s turned back on.

The team’s enabled models appear in members’ model pickers when their team settings refresh.

By default, members can still choose Warp-managed models even when team providers are configured. To require that inference goes to your providers, turn off Direct API access on the Models page so Warp-managed models are no longer selectable.

Members select a model from the picker without configuring team credentials:

  • Custom endpoints - Each enabled team endpoint model appears in the model picker as its own entry, showing the model’s name (or alias) and the endpoint name. Members select it like any other model.
  • First-party keys - Members select the standard model for a provider (for example, a Claude, GPT, or Gemini model), and requests route through the team key automatically. If a member has added their own key for that provider, their own key takes precedence.

If the admin allows members to add their own keys and endpoints, members can still do so through the standard self-serve BYOK and custom inference endpoint settings.

  • Provider-billed inference - Your provider or endpoint bills team-routed inference directly rather than consuming Warp-provided inference usage.
  • Auto uses Warp-provided inference - Auto consumes Warp usage. Select a specific model or endpoint to use your team’s provider. Custom routers apply provider keys after choosing a model, preferring a member’s own key over the team key. Routers cannot target endpoint models.
  • Other Warp charges remain - Customer-supplied inference incurs platform charges for local Business and Enterprise runs and all cloud runs. Cloud runs on Warp-hosted compute also incur compute charges.

External inference bills are not fully represented in Warp’s totals. See usage and billing for cost-reporting limitations.

Warp encrypts team API keys and endpoint URLs at rest. Members receive model names, endpoint names, aliases, and whether a provider key is configured, not the stored keys or endpoint URLs.

Warp uses the stored credentials to call your provider without delivering them to member devices or cloud agent environments.

Warp is SOC 2 compliant and has Zero Data Retention (ZDR) agreements with its contracted LLM providers. When you route through your own keys or endpoints:

  • Data retention on the provider side is determined by your provider’s account settings.
  • Warp cannot enforce ZDR for requests sent through your keys or endpoints.
  • If your provider account doesn’t have ZDR enabled, your requests may be retained according to their terms.