Console features

Bring your own AI key

Run OKIAS AI verifications on your own Google Gemini API key. Google bills the model usage to your Google account; OKIAS charges only a platform fee.

With bring-your-own-key (BYOK) the same OKIAS verification flow and decision engine run, but the AI calls are made with your key. Google Gemini is the only supported provider.

What it costs

WhoWhat you pay
OKIASA platform fee of 5 credits ($0.05) per verification — charged only when it is APPROVED, from your normal KYC credits.
GoogleModel usage, billed by Google to the Google Cloud project that owns the key. OKIAS never sees or pays that bill.

If a verification fails because Google refused a call on your key, it ends with an error and is not charged. See Pricing for the current fee.

Set it up

1
Create a Gemini key
Create a key in Google AI Studio, enable billing on its project and restrict it to the Generative Language API. The console has a step-by-step guide at Dashboard → Your own Gemini key → Help.
2
Save it in OKIAS
On Your own Gemini key paste the key and choose Check and save. OKIAS confirms it with Google's free list-models call (no tokens used) before storing it. A key Google rejects is never stored.
3
Switch a project
Under Projects choose Use my key on an AI project, optionally pick a model from the list OKIAS offers, then run one live verification to test it.
Which projects can use BYOK
BYOK is available on AI projects decided by OKIAS. Projects using manual review or merchant-decision mode cannot switch to it.

How your key is protected

  • The key is encrypted with AES-256-GCM under a per-key data key, wrapped by a master key held only on the server and bound to your account.
  • It is never shown again — the console displays only its last 4 characters and a fingerprint.
  • Only the verification worker decrypts it, at the moment it calls Google. Key material is scrubbed from error messages and logs.
  • One active key per account. Replace key rotates it; Revoke key erases it immediately.

No silent fallback

A BYOK project never runs on OKIAS-paid AI. If your key is revoked, rejected by Google or missing, new verifications on that project are refused (BYOK_KEY_NOT_VALID) until you save a new key or switch the project back to OKIAS AI. Problems are shown on the key card in the console.

CodeMeaning
BYOK_KEY_INVALIDGoogle rejected the key when you saved it. Nothing was stored.
BYOK_VALIDATION_UNAVAILABLEOKIAS could not confirm the key with Google (timeout, quota). Nothing was stored — try again.
BYOK_KEY_NOT_VALIDThe project uses BYOK but the account has no valid key — the verification is refused.
BYOK_REQUIRES_AI_MODEBYOK only works on an AI project decided by OKIAS.
BYOK_NOT_AVAILABLEThe BYOK fee is not on sale right now; the verification is refused, never re-priced.

Next steps