Drafting keys

Bringing your own Anthropic key for AI-assisted drafting — where it is stored, what "remember on this browser" means, and how to remove it.

Available Updated 2026-09-24

The BYO path for Intent drafting uses your Anthropic key. Insights uses the server-configured provider instead. A separate funded drafting path can use Orneos credit when enabled.

Adding a key

Settings → Profile → Drafting key. Paste an Anthropic API key and save.

Two things follow from it being yours:

  • You are billed by the provider, directly, under your own account and their terms. Orneos adds nothing.
  • The key is personal, not the team’s. Nobody else’s session can use it, and it is not shared by being in the same team.

Without a key, BYO drafting is unavailable. Manual Intent authoring still works; the funded option depends on configuration and allowance.

”Remember on this browser”

When saving, you choose whether the key persists.

ChoiceLifetime
Not rememberedHeld in memory for the session. Gone on reload.
RememberedKept in this browser’s storage. Survives reloads and restarts.

Remembered means this browser, on this machine. It does not follow you to another device.

Changing this setting for a saved key means re-entering it

The settings form does not read a saved secret back into its input. To change whether the key is remembered, change the checkbox, paste the key again and save. This UI rule does not make a raw remembered key unreadable from browser storage.

What you can see afterwards

The settings UI shows only a masked hint and whether a key is configured; it does not reveal the saved key. If you choose Remember, the raw credential is stored in this browser’s local storage. It is not an encrypted secret vault: code with this site’s storage access or someone controlling the browser profile can read it. Session-only storage is the default. Revoke an exposed key with the provider.

The status you see is re-derived from durable state rather than remembered by the page you are looking at. That matters in a small but real way: remove the key in another tab, and this tab will not keep telling you a key is saved.

Removing a key

Remove, in the same card.

Removal is reported honestly. A failed erase is not shown as a removal, and if a partial failure leaves bytes on disk the Remove control stays available — even if this tab’s memory is already empty — so you are never left with a stored secret and no control to clear it.

If you suspect a key was exposed, revoke it at the provider. That is the only action that is guaranteed regardless of what any browser is holding.

What happens on sign-out

Signing out ends the credential owner/session and starts key cleanup. A failed erase remains actionable through Remove.

A company change is a workspace-data boundary, not necessarily the end of the same personal credential owner/session. Do not infer key erasure from a replica reset; explicitly Remove it when you want to clear it. See Privacy and your data.

Server-funded AI

Work in progress; access is deployment-dependent

The funded implementation can support drafting without a personal key when configured and granted an allowance. This documentation does not establish that production has enabled it or issued credit. Insights has a separate server-provider path. See AI funding and usage.

Something here wrong, missing or out of date? Tell us at support@orneos.com — corrections to these pages are welcome and we would rather hear it than have you work around it.