# Drafting keys Bringing your own Anthropic key for AI-assisted drafting — where it is stored, what "remember on this browser" means, and how to remove it. Status: Available Documentation updated: 2026-09-24 Source: https://docs.orneos.com/docs/ai-keys The BYO path for [Intent drafting](https://docs.orneos.com/docs/intent) uses **your** Anthropic key. [Insights](https://docs.orneos.com/docs/insights) uses the server-configured provider instead. A separate [funded drafting path](https://docs.orneos.com/docs/ai-funding) can use Orneos credit when enabled. ## Adding a key **Settings → Profile → Drafting key.** Paste an Anthropic API key and save. Two things follow from it being yours: - **You are billed by the provider**, directly, under your own account and their terms. Orneos adds nothing. - **The key is personal, not the team's.** Nobody else's session can use it, and it is not shared by being in the same team. Without a key, BYO drafting is unavailable. Manual Intent authoring still works; the funded option depends on configuration and allowance. ## "Remember on this browser" When saving, you choose whether the key persists. | Choice | Lifetime | |---|---| | Not remembered | Held in memory for the session. Gone on reload. | | Remembered | Kept in this browser's storage. Survives reloads and restarts. | Remembered means *this browser*, on *this machine*. It does not follow you to another device. **Changing this setting for a saved key means re-entering it** The settings form does not read a saved secret back into its input. To change whether the key is remembered, change the checkbox, paste the key again and save. This UI rule does not make a raw remembered key unreadable from browser storage. ## What you can see afterwards The settings UI shows only a masked hint and whether a key is configured; it does not reveal the saved key. If you choose **Remember**, the raw credential is stored in this browser's local storage. It is not an encrypted secret vault: code with this site's storage access or someone controlling the browser profile can read it. Session-only storage is the default. Revoke an exposed key with the provider. The status you see is re-derived from durable state rather than remembered by the page you are looking at. That matters in a small but real way: remove the key in another tab, and this tab will not keep telling you a key is saved. ## Removing a key **Remove**, in the same card. Removal is reported honestly. A failed erase is not shown as a removal, and if a partial failure leaves bytes on disk the Remove control stays available — even if this tab's memory is already empty — so you are never left with a stored secret and no control to clear it. If you suspect a key was exposed, revoke it at the provider. That is the only action that is guaranteed regardless of what any browser is holding. ## What happens on sign-out Signing out ends the credential owner/session and starts key cleanup. A failed erase remains actionable through Remove. A company change is a workspace-data boundary, not necessarily the end of the same personal credential owner/session. Do not infer key erasure from a replica reset; explicitly Remove it when you want to clear it. See [Privacy and your data](https://docs.orneos.com/docs/privacy-and-data). ## Server-funded AI **Work in progress; access is deployment-dependent** The funded implementation can support drafting without a personal key when configured and granted an allowance. This documentation does not establish that production has enabled it or issued credit. Insights has a separate server-provider path. See [AI funding and usage](https://docs.orneos.com/docs/ai-funding). ## Related - [AI in Orneos](https://docs.orneos.com/docs/ai-overview) — the rules that govern every model call. - [Personal access tokens](https://docs.orneos.com/docs/personal-tokens) — a different credential, for agents reading your data. - [Settings](https://docs.orneos.com/docs/settings)