BYOK is safe when the answer to one question is "architecturally no": can anyone but you read your API key? This checklist tells you how to verify it for any tool in five minutes — and what the failure modes actually look like.
Scope, one line: this audits credential safety in AI tools — not the cloud-security BYOK model (bring-your-own-encryption-key in KMS systems), which shares the acronym but not the threat model.
The four places an API key can live
| Storage | What it means | Risk profile |
|---|---|---|
| Client-side, encrypted (browser localStorage/IndexedDB, ciphertext via AES-256-GCM) | Key is unreadable at rest; only your device can decrypt it | Best — a server breach yields nothing usable |
| Client-side, plaintext | Key sits readable in browser storage | Weak — any XSS on the page can read it |
| Server-side, encrypted at rest | The operator holds the keys, encrypted with a key they also hold | Trust-dependent — insiders and breaches can expose keys |
| Server-side, plaintext | A database table with your keys in it | Unacceptable — single breach leaks every customer's provider access |
Ask the vendor which row applies, or better — verify it yourself with the test below.
How the key should travel
Storing the key safely is half the question. The other half is what happens per request:
- TLS-only transport ("your key is sent over HTTPS"): the server sees the key in plaintext on every call. This is a proxy model — better than a shared key, worse than client-side encryption.
- Single-use encrypted envelope: the client encrypts the key against an ephemeral server public key (ECIES-style), the server decrypts it in memory for that one request and never persists it. This is the SynthHires model — the strongest claim available: the server can process your key but cannot store it.
- Local-only execution: tools that call providers directly from your device never transit anything. Strongest of all, limited to desktop apps.
The 5-minute audit checklist
Run this against any BYOK tool before trusting it:
- Storage probe: open DevTools → Application → Local Storage/IndexedDB. Search for your key's prefix (
sk-,sk-ant-,AIza…). If the plaintext key appears anywhere, it's not encrypted client-side. (If you see base64 blobs instead, that's consistent with encrypted storage — expected.) - Network probe: DevTools → Network → send one message. Look at the request payload. Does your key appear in plaintext in a JSON field? If yes, the server receives readable credentials on every call.
- Rotation story: check the settings for a "remove key" action. A real implementation deletes the local ciphertext; there's nothing server-side to purge.
- Sync behavior: if the tool syncs keys across devices, the sync must be opt-in per item and end-to-end encrypted — keys the server could decrypt are keys the server could leak.
- Breach behavior: read the security page for the actual claim. "We never store your keys" (architectural) beats "we encrypt your keys" (operational — encrypted by whom, with whose key?).
What key leakage actually looks like
- The failure mode is silent spend. A leaked key bills your provider account until revoked — 10/$50 per MTok) burning tokens unattended is an expensive week.
- Your best tripwire is a spend cap. Set a hard monthly budget in each provider console the day you create the key. Every provider with billing supports one.
- Rotation is the recovery. Revoke in the provider console (takes seconds), generate a new key, re-paste in the tool. A real BYOK app makes this a two-minute operation because there's nothing server-side to untangle.
FAQ
Is BYOK safe to use with my OpenAI or Anthropic key?
Yes, when implemented with client-side encryption and single-use transport — the failure modes that matter (server breach, insider access, operator error) yield no usable credentials. The residual risks are on your side: key hygiene (don't paste keys into unknown tools) and provider-account security (enable spend caps).
Where does SynthHires store my API key?
In your browser, encrypted with AES-256-GCM before anything else happens; the plaintext key never reaches SynthHires servers — requests carry single-use encrypted handoff envelopes instead. There is no server-side keys table. The Security & BYOK doc details the cryptography and the BYOK architecture explainer shows the envelope design.
How do I know if my API key was leaked?
Watch for usage you didn't generate (provider consoles show per-key usage) or bill spikes. Set spend caps as tripwires, rotate immediately on suspicion — revocation kills a leaked key's value instantly.
Is browser storage or a desktop keychain safer?
A desktop keychain (OS-level credential store) is marginally stronger against local malware; encrypted browser storage is the standard for web apps and, with AES-256-GCM, robust against the realistic threat model (server-side breaches, network interception). What both share: the secret never lands on a server.
Audit this platform with the checklist — start at the Security & BYOK doc, get your keys in the Get API keys guide, or read what BYOK means first.