Why BYOK
- Your own spend. Model calls on your key bill to your AWS or Anthropic account, not to CloudThinker credits.
- Your own quotas. Your provider limits apply, not platform credit limits.
- Your choice of model. Pick the model for each mode and module, or keep the defaults.
- Data residency on Bedrock. Pick an AWS region to keep inference inside the US, the EU, or Asia Pacific.
Prerequisites
- A Scale, Scale+, or Enterprise plan. See Pricing & Plans.
- The Owner role in the organization. Admins and other members see the key status but not the credentials.
- One of these credentials:
- An AWS IAM access key with Bedrock invoke permissions. See Prepare AWS Bedrock.
- An Anthropic Console API key. It starts with
sk-ant.
Supported models
Your key runs these models. CloudThinker picks a default for each row, and you can change it. A dash means the provider does not offer the model on BYOK.
On Bedrock, Claude Opus 4.6, 4.7, 4.8, and 5.5 and Claude Sonnet 4.6 run with the Global (recommended) region or with a US, Canada, or EU region. They are not available with an Asia Pacific region.
GPT models run on the Bedrock OpenAI-compatible endpoint and do not follow the Region you pick. GPT-6 Sol and Luna always use their Global profile. GPT-5.6 runs in
us-east-1, us-east-2, or us-west-2, and a key with any other region sends GPT-5.6 calls to us-east-1.
You pick a model for six rows: the Light, Pro, and Ultra chat modes, and the Review, Cyber, and Resolve modules. Review conventions follow the Review row, and Cyber chat follows the Cyber row. A row you set to CloudThinker credits runs on the platform instead of your key.
Prepare AWS Bedrock
Skip this section if you use an Anthropic API key.1
Enable the models in Bedrock
Open Amazon Bedrock in the AWS Console. If Bedrock asks for the Anthropic use case form, submit it once for your AWS account. See the AWS model access documentation. For GPT models, see OpenAI models in Amazon Bedrock.
2
Create the IAM user and policy
Create a user and attach a policy that allows Bedrock to invoke the models. Drop the These commands need an AWS profile with
openai ARNs and the bedrock-mantle statement if you pick no GPT model.iam:CreateUser and iam:PutUserPolicy.3
Create an access key
AccessKeyId and the SecretAccessKey from the output. You enter them in CloudThinker.Connect your key
1
Open BYOK settings
Go to Admin Settings → BYOK.
2
Choose the provider
Under Step 1 Provider, select AWS Bedrock or Anthropic.
3
Enter the credentials
Fill in Step 2 Credentials.
- AWS Bedrock
- Anthropic
- Access key ID: an
AKIAkey for a permanent key, or anASIAkey for a temporary one. - Secret access key: the secret for that key.
- Session token: required only for a temporary
ASIAkey. - Region: keep Global (recommended), or pick one AWS region. See Choose a Bedrock region.
4
Review the models
Step 3 Models on your key shows the model for each row. Click Customize models to change a row, or to set a row to CloudThinker credits. At least one row must run on your key.
5
Verify and activate
Click Verify and activate. CloudThinker sends a short test call to each model you picked, then saves the key.Success state: the key card shows Active, the key hint, the region, and the model for each row.
Choose a Bedrock region
The Region you pick sets the Bedrock inference profile. Bedrock can serve a request from any AWS region inside that profile.
Pick a regional option when your data must stay in one geography. Sao Paulo has no geographic profile, so it uses the Global profile. GPT models do not follow the region. See Supported models.
Manage the key
The key card shows the provider, the state, the key hint, the region, and the last verification time.
The card shows one of four states: Active, Saved, paused, Key expired, or Disabled after error. One provider is active at a time. To switch provider, remove the key and connect the other provider.
How it works
- One key for the organization. Every workspace and member uses the Owner’s key.
- The “Your key” badge. In chat, a Your key badge marks a turn that runs on your key and spends no credits.
- Session tokens. For a permanent
AKIAkey, CloudThinker renews the session token itself. A temporaryASIAkey can’t be renewed, so rotate it before it expires. - Fallback. When a call on your key still fails after retries, CloudThinker runs it on a platform model with platform credentials. Fallback calls spend platform credits.
- What each call sends. A call sends the agent’s system prompt, tool definitions, conversation history, and retrieved context. CloudThinker replaces known secrets and detected personal identifiers with placeholders first. See Data Protection.
Automatic disable on credential errors
When the provider rejects the credentials, CloudThinker turns BYOK off. Examples are an expired session token, a revoked access key, or an access-denied error. Agent work continues on platform credits until you restore the key. You get one high-severity notification named BYOK Credentials Error — AWS Bedrock Auto-Disabled or BYOK Credentials Error — Anthropic Auto-Disabled. It names the provider error code. The key card shows Disabled after error and the same code. To restore BYOK, click Rotate key, enter valid credentials, and click Verify and save.Troubleshooting
Verification failed
Verification failed
- Read the error under the button. It shows the provider’s own message and the model that failed.
- For Bedrock, confirm the Anthropic use case form is approved for your AWS account.
- Confirm the IAM policy covers the model and the inference profile of your region.
- For a GPT model, confirm the policy allows
bedrock-mantle:CreateInference. - Set a row you can’t serve to CloudThinker credits, then verify again.
Access denied on one region
Access denied on one region
- A regional option uses the
us.,eu., orapac.inference profile. - Confirm the IAM policy allows
inference-profile/*.anthropic.claude-*, or that profile by name. - Confirm that Bedrock serves the model in that geography, or switch the Region to Global (recommended).
- Bedrock has no
apac.profile for current Claude models. With an Asia Pacific region, pick Global (recommended) instead.
A row shows Model retired, pick another
A row shows Model retired, pick another
- CloudThinker no longer serves that model on your key.
- Click Edit models, pick another model for the row, and click Verify and save.
BYOK turned itself off
BYOK turned itself off
- The provider rejected the credentials. See Automatic disable on credential errors.
- Read the error code on the key card or in the notification.
- Click Rotate key and enter valid credentials.
- A temporary
ASIAkey expires. Switch to a permanentAKIAkey to stop repeats.
Turns don't show the Your key badge
Turns don't show the Your key badge
- Confirm the key card shows Active, not Saved, paused.
- Confirm the organization is on Scale, Scale+, or Enterprise.
- Check that the mode or module row runs on your key, not on CloudThinker credits.
Related
Pricing & Plans
Which plans include BYOK
Usage
Track credit and model usage across your workspace
Notifications
Get alerted when a BYOK key stops working