AI
Bring your own AI provider key, choose between a personal key and the team's, and what Steerd does and does not store.
Connect an AI provider so Steerd can draft replies for you.
Steerd does not resell AI. You bring a key from a provider you already have an account with, and the usage is billed to you by them at their prices. Nothing on this screen is required: with no key set up, the drafting features are simply off and the rest of Steerd is unchanged.
Before you hand over a key: AI provider keys sets out exactly what Steerd sends where, and the smallest key that still works at each provider.
That is the page to read if your company has a policy about third-party API keys, or if you are the person who has to approve one.
Two keys, and which one wins
There are at most two keys in play, and only ever two.
Your key is yours alone. Nobody else on the team can see it or change it, and that includes admins. Set one and it takes priority over the team's for everything you do.
The team key is set up by an admin and everyone on the team can draft with it. If you have no key of your own, this is the one Steerd uses. Members can see that it exists, along with the provider, the model and the endpoint. They cannot change it.
Your key first, then the team's, then the feature is off.
That order is what lets a team hand everyone one working key without stopping anyone from using their own account instead.
Choosing a provider
OpenAI, Anthropic, Google Gemini and Mistral are named, and picking one fills in the endpoint for you. You only need the key and, if you want something other than the default, a model name.
OpenAI-compatible endpoint is the fifth option and it covers everything else: OpenRouter, Groq, Together, DeepSeek, Azure OpenAI, or a proxy your company runs. It is the one option where the endpoint is required, because there is no default to fall back on.
The endpoint has to be reachable from the internet
Steerd calls your provider from its own servers, not from your browser. So the endpoint must
be a public https address.
An address that only resolves on your own machine or inside your office network will not work.
This is also why http is refused outright: your key travels in a request header, and a plaintext
hop would put it on the wire.
What happens when you save
Steerd makes one cheap call to the provider before storing anything. That is deliberate: a typo in a key should fail here, on a settings screen, and not later while you are halfway through answering a client.
If the check passes, the key is encrypted and stored, and the card shows when it last answered. If it fails, nothing is stored and the message says which part went wrong: a rejected key, an address we could not reach, or a provider that refused the request.
The key is never shown again
Once saved, there is no screen, no export and no API response that returns it. Steerd encrypts it and the only thing that ever reads it back is the drafting feature itself.
That means the field is always blank when you come back to this screen. To change a key, type the new one. You are not editing the old value, you are replacing it.
Leaving the team, or being disabled by an admin, removes your personal key.
That is one-way. If you rejoin later, you set the key up again; a re-invite never brings an old credential back to life.
Rate limits
Saving a key makes Steerd call your provider, so those checks are limited to a handful per minute for the whole team. If you hit it, wait a minute and save again. It is not a limit on drafting.