<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/ai-gateway-attach-provider-keys-to-ai-gateway-keys-lgfeyxorw" -->

---
title: AI Gateway: attach provider keys to AI Gateway keys
description: Ngrok&#x27;s AI Gateway now lets developers attach their own OpenAI, Anthropic, or other provider API keys directly to an AI Gateway key, instead of pasting raw...
canonical: https://daily.dev/posts/ai-gateway-attach-provider-keys-to-ai-gateway-keys-lgfeyxorw
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: AI Gateway: attach provider keys to AI Gateway keys | daily.dev
og:description: Ngrok&#x27;s AI Gateway now lets developers attach their own OpenAI, Anthropic, or other provider API keys directly to an AI Gateway key, instead of pasting raw...
og:url: https://daily.dev/posts/ai-gateway-attach-provider-keys-to-ai-gateway-keys-lgfeyxorw
og:image: https://api.daily.dev/og/posts/lGfEYxOrw.png
og:image:alt: AI Gateway: attach provider keys to AI Gateway keys
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# AI Gateway: attach provider keys to AI Gateway keys

**[ngrok Blog](https://daily.dev/sources/ngrok)** · 4 min read · 0 upvotes · 0 comments

## Summary

Ngrok's AI Gateway now lets developers attach their own OpenAI, Anthropic, or other provider API keys directly to an AI Gateway key, instead of pasting raw provider credentials into Traffic Policy config. Apps authenticate with the AI Gateway key, and the gateway forwards requests upstream using the attached provider credential, keeping keys out of application code and Traffic Policy. Provider keys are AES-256 encrypted, up to 15 keys per provider can be attached for failover, and existing Traffic Policy BYOK setups still work but can no longer add or rotate keys, requiring migration via a provided guide. Self-hosted providers (Ollama, vLLM) still configure keys in Traffic Policy. Billing is unchanged and BYOK remains free.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://ngrok.com/blog/ai-gateway-provider-keys>

## Questions this post answers

### How do I set up bring-your-own-key BYOK with ngrok AI Gateway now?

Attach your OpenAI, Anthropic, or other provider key directly to an AI Gateway key instead of pasting it into Traffic Policy config. Your app authenticates to AI Gateway using the AI Gateway key, and AI Gateway uses the attached provider credential when sending the request upstream, so provider secrets stay out of application code and Traffic Policy.

_daily.dev surfaces gateway and API key management changes like this as they roll out._

### Will my existing ngrok AI Gateway Traffic Policy BYOK config still work after the provider keys change?

Existing Traffic Policy configuration using providers[].api_keys and api_key_selection continues to function, but new keys can no longer be added and existing ones can no longer be rotated through Traffic Policy. Migration to the new attached-key system is required for ongoing key management, and a step-by-step migration guide covers the process.

_developers planning a BYOK migration can track breaking changes like this on daily.dev._

### How many provider API keys can I attach to a single ngrok AI Gateway key for failover?

Up to fifteen keys per provider can be attached to a single AI Gateway key, enabling failover and staged rollouts. Provider keys are encrypted with AES-256, and plaintext is only held in memory for the upstream request, never written to disk or logs.

_daily.dev helps engineers evaluating gateway failover and key rotation setups stay current._

## Similar posts on daily.dev

- [Why use BYOK through Kilo Gateway instead of going directly to the provider?](https://daily.dev/posts/why-use-byok-through-kilo-gateway-instead-of-going-directly-to-the-provider--dq6wsutd8) · Kilo Blog · 0 upvotes · 0 comments
- [BYOK: Use Your Own AI Models in ABP Studio AI Agent](https://daily.dev/posts/byok-use-your-own-ai-models-in-abp-studio-ai-agent-ijlgawowo) · We Are .NET · 0 upvotes · 0 comments
- [Kilo Gateway now supports BYOK across 20 providers \(DeepSeek, xAI, and more\)](https://daily.dev/posts/kilo-gateway-now-supports-byok-across-20-providers-deepseek-xai-and-more--ezwsuxwpw) · Kilo Blog · 0 upvotes · 0 comments
- [The End of the 'Wrapper' Era? Anthropic's New API Terms Explained](https://daily.dev/posts/the-end-of-the-wrapper-era-anthropic-s-new-api-terms-explained-cyiso2k2c) · SitePoint · 0 upvotes · 0 comments
- [n8n Best Practices](https://daily.dev/posts/n8n-best-practices-c6aelp7wv) · portkey · 0 upvotes · 0 comments

---

Tags: [#devtools](https://daily.dev/tags/devtools), [#authentication](https://daily.dev/tags/authentication), [#api-gateway](https://daily.dev/tags/api-gateway)

[View this post on daily.dev](https://daily.dev/posts/ai-gateway-attach-provider-keys-to-ai-gateway-keys-lgfeyxorw)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"AI Gateway: attach provider keys to AI Gateway keys","url":"https://daily.dev/posts/ai-gateway-attach-provider-keys-to-ai-gateway-keys-lgfeyxorw","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/ai-gateway-attach-provider-keys-to-ai-gateway-keys-lgfeyxorw"},"datePublished":"2026-08-23T07:21:07.926Z","dateModified":"2026-08-23T07:25:27.339Z","description":"Ngrok's AI Gateway now lets developers attach their own OpenAI, Anthropic, or other provider API keys directly to an AI Gateway key, instead of pasting raw...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e0eccc83b63bf123bf678cbf33e4c21b?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e0eccc83b63bf123bf678cbf33e4c21b?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"ngrok Blog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"ngrok Blog","logo":"https://media.daily.dev/image/upload/s--718XXxvE--/f_auto,q_auto/v1787469610/logos/ngrok?_a=BAMAMicg0","url":"https://daily.dev/sources/ngrok"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/ai-gateway-attach-provider-keys-to-ai-gateway-keys-lgfeyxorw","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"devtools,authentication,api-gateway","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"ngrok Blog","item":"https://daily.dev/sources/ngrok"},{"@type":"ListItem","position":3,"name":"AI Gateway: attach provider keys to AI Gateway keys"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/ai-gateway-attach-provider-keys-to-ai-gateway-keys-lgfeyxorw#faq","mainEntity":[{"@type":"Question","name":"How do I set up bring-your-own-key BYOK with ngrok AI Gateway now?","acceptedAnswer":{"@type":"Answer","text":"Attach your OpenAI, Anthropic, or other provider key directly to an AI Gateway key instead of pasting it into Traffic Policy config. Your app authenticates to AI Gateway using the AI Gateway key, and AI Gateway uses the attached provider credential when sending the request upstream, so provider secrets stay out of application code and Traffic Policy. daily.dev surfaces gateway and API key management changes like this as they roll out."}},{"@type":"Question","name":"Will my existing ngrok AI Gateway Traffic Policy BYOK config still work after the provider keys change?","acceptedAnswer":{"@type":"Answer","text":"Existing Traffic Policy configuration using providers[].api_keys and api_key_selection continues to function, but new keys can no longer be added and existing ones can no longer be rotated through Traffic Policy. Migration to the new attached-key system is required for ongoing key management, and a step-by-step migration guide covers the process. developers planning a BYOK migration can track breaking changes like this on daily.dev."}},{"@type":"Question","name":"How many provider API keys can I attach to a single ngrok AI Gateway key for failover?","acceptedAnswer":{"@type":"Answer","text":"Up to fifteen keys per provider can be attached to a single AI Gateway key, enabling failover and staged rollouts. Provider keys are encrypted with AES-256, and plaintext is only held in memory for the upstream request, never written to disk or logs. daily.dev helps engineers evaluating gateway failover and key rotation setups stay current."}}]}
```

