Connect your own OpenAI, Anthropic, or Mistral API keys for direct extraction
Dynamite Docs, 2026-08-12
What bringing your own provider key changes
Bring Your Own Key, or BYOK, separates the document review workspace from the model account. Dynamite Docs prepares the extraction request, keeps the source beside the proposed result, and exports the data you accept. The connected provider authenticates the model request and bills its own usage.
The provider controls model availability, rate limits, regional handling, retention terms, and API charges. Dynamite Docs controls its own plan rules, review workflow, and exports. Check both sides before estimating a production batch.
Free and Starter own-key pages use the monthly PE allowance. Pro and Scale own-key runs cost 0 PE. Provider charges, file-size limits, and provider limits still apply on every plan.
A provider key does not make extraction correct by default. Test a representative PDF, scan, or photo, confirm that the selected model supports the source, and compare identifiers, dates, money, tax, and table rows with the original before scaling the route.
- Provider billing: The connected provider account pays for its own API usage
- Model discovery: Dynamite Docs lists models returned for the verified account
- Plan accounting: Free and Starter use PE; Pro and Scale own-key runs cost 0 PE
- Source review: Check proposed fields and rows beside the document before export
Security architecture: how provider credentials and documents stay protected
Connecting an external API key requires strict credential hygiene. In Dynamite Docs, provider API keys never touch client-side browser storage after initial input. The server encrypts every key at rest using AES-256-GCM with server-side encryption keys managed via BYOK_ENCRYPTION_KEY.
The server decrypts a stored key only when it needs to authenticate a request to that provider. The raw secret is not returned to the browser after setup. Rotate or remove the key from the provider and Dynamite Docs if you suspect it was exposed.
Provider handling depends on the provider, API product, account, region, and current terms. Read those terms for the exact account you connect. The Dynamite Docs policy engine can exclude routes that do not meet an active training or residency rule, but it cannot rewrite a provider contract.
When a document must not be sent to an external model API, use the signed local Ollama companion on an eligible plan. Pair the local route with browser-only file storage and verify the complete workflow against your organization's policy.
- AES-256-GCM encryption: Provider keys are encrypted at rest with server-side keys and never sent back to browser clients
- Provider terms: Check retention, training, region, and subprocessor terms for the connected account
- Dedicated credentials: Use a separate key where the provider supports scoped access and rotation
- Policy controls: Exclude routes that do not meet the active document-handling rule
Google Gemini: connect a key and inspect available models
Google AI Studio provides developer access to Gemini models. Model names, limits, regions, and prices can change, so use the list returned for your connected account instead of copying a model ID from an old guide.
Choose a vision-capable model for scanned PDFs and images. A model that only accepts text cannot inspect an image-only page, even when the API key verifies successfully.
Check the Google account dashboard for current request and token limits before a batch. Run one representative multi-page file first, then review page joins, line items, totals, and the values that affect downstream work.
Follow these steps to generate your Google AI Studio API key:
- Step 1: Open the Google AI Studio API Key Console in your browser
- Step 2: Sign in with your Google account or Google Workspace administrator profile
- Step 3: Click the blue Create API key button in the top left corner
- Step 4: Select Create API key in new project (or link to an existing Google Cloud project with billing enabled)
- Step 5: Copy the generated string starting with
AIzaSy...and store it in your password manager - Step 6: In Dynamite Docs, open Settings > AI & Processing, select Google Gemini, paste the key, click Verify & Save, and choose a discovered model
Groq Cloud: connect a key and check vision support
Groq exposes a provider API and account-specific model list. Verify the key, then choose from the models currently returned for that account.
Do not assume every listed model can read document images. Check vision support before using a scan, receipt photo, or image-only PDF.
Use the provider dashboard for current request, token, and billing limits. A fast response is not evidence of correct extraction, so compare the result with the source before using the route in a batch.
Follow these steps to generate your Groq API key:
- Step 1: Navigate to the Groq Cloud Console
- Step 2: Create a free account or log in with GitHub, Google, or email
- Step 3: Click API Keys in the left navigation sidebar
- Step 4: Click the Create API Key button and enter a label such as
dynamitedocs-vision - Step 5: Copy the secret key starting with
gsk_.... Groq displays this secret key only once upon creation - Step 6: In Dynamite Docs, open Settings > AI & Processing, select Groq, paste the key, and choose a vision-capable model returned for the account
Mistral AI: connect a key and review regional terms
Mistral provides text, vision, and document-processing options through its developer platform. Verify which models and endpoints are available to the connected account.
For multilingual invoices, test the printed languages, decimal separators, dates, tax identifiers, and table headers that appear in your real files. Model support does not remove the need for a source check.
If regional processing matters, verify the selected product, endpoint, account configuration, and current Mistral terms. A provider headquarters address alone does not establish the route used by a request.
Follow these steps to generate your Mistral API key:
- Step 1: Open the Mistral La Plateforme Console
- Step 2: Sign up for a developer account or sign in to your existing workspace
- Step 3: Select API Keys from the Workspace menu in the left navigation panel
- Step 4: Click Create new key, assign workspace permissions, and name the credential
dynamitedocs-pixtral - Step 5: Copy the secret token and store it securely in your password manager
- Step 6: In Dynamite Docs, open Settings > AI & Processing, select Mistral, paste the key, and choose a compatible model returned for the account
OpenAI and Anthropic: connect keys and test dense documents
OpenAI and Anthropic expose models with different vision capabilities, context limits, prices, and account requirements. Verify the key and select from the models currently available to your account.
Dense agreements, audit schedules, and degraded scans should be tested with representative pages. Check footnotes, crossed-out values, decimal places, continued tables, and any value that can change a financial conclusion.
A requested JSON shape helps constrain a response, but your application must still validate required fields, types, null states, and column names before an import.
Generate your credentials using these official console workflows:
- OpenAI setup: Go to the OpenAI Platform API Keys dashboard, click Create new secret key, select model permissions, and copy the
sk-proj-...token - Anthropic setup: Go to the Anthropic Console Settings, click Create Key, name it
dynamitedocs-claude, and copy thesk-ant-...key - Model choice: Select a vision-capable model for scanned or image-only sources
- Pilot check: Compare the same representative documents before changing the active model for a production workflow
Local Ollama companion: run model inference on your computer
Use the local companion when model inference should run through an Ollama instance on your computer instead of an external model API. The companion is available on Starter, Pro, and Scale plans.
The companion listens on loopback port 8756, connects to local Ollama, and requires a signed local token for every route. Pair it with browser-only file storage when the complete document workflow must stay off external model providers.
Local speed and model quality depend on the model, document, memory, and hardware. Install a vision-capable model for scans and images, then test the smallest text and most difficult table in your real documents before committing to a batch.
Follow these steps to configure private on-device extraction:
- Step 1: Download and install the Ollama runtime from Ollama Official Download
- Step 2: Install a model that supports the input you plan to process; images and scans require vision support
- Step 3: Confirm that the model runs successfully in Ollama before connecting the companion
- Step 4: Download the Dynamite Docs Windows companion or verify Ollama is serving on port 11434
- Step 5: In Dynamite Docs, navigate to Settings > AI & Processing, click the Local Ollama tab, and confirm the connection status indicator is green
How to connect and verify a provider key in Dynamite Docs
Open Dynamite Docs Settings, choose AI & Processing, select a provider, paste the secret key, and choose Verify & Save Key. The exact provider setup time depends on the provider account and permissions.
Verification checks the credential and discovers models available to the account. A successful key check does not prove that the chosen model accepts images or that an extraction will be accurate.
Always test your setup with a representative sample file before launching a large batch. Upload an invoice with multiple line items, check that the columns extract cleanly into the table grid, and verify that confidence scores highlight any low-contrast values.
- Open settings: Navigate to Settings > AI & Processing in your Dynamite Docs workspace
- Select provider: Choose from Google Gemini, Groq, Mistral, OpenAI, Anthropic, OpenRouter, or Custom Endpoint
- Verify connection: Click Verify & Save Key to perform a live permission and quota health check
- Configure fallbacks: Choose only routes that support the document and satisfy the same provider policy
Troubleshooting rate limits, token limits, and multi-page batch runs
Provider rate limits and context limits are account-specific. An HTTP 429 usually means the provider rejected the current request volume. Check its response headers and dashboard, reduce concurrency, or wait for the limit to clear.
A configured fallback must accept the source format (vision vs. text) and pass the active provider policy. If no eligible route is available, let the extraction fail visibly instead of silently sending the document somewhere unintended.
Very large scans increase upload time and model input size. Use a readable original, keep all text and page edges visible, and avoid resampling that makes small characters harder to inspect.
A different model can produce different headers, null states, or values. Keep required columns explicit and validate the first output from a new model before a spreadsheet formula or downstream import depends on it.
- HTTP 429 management: Enable automatic retry backoff and size batch queues to fit provider rate limits
- Image preparation: Preserve legibility, orientation, contrast, and complete page edges
- Cost planning: Use the current provider dashboard and a measured pilot batch
- Output validation: Check required columns and types after a model or provider change
Frequently asked questions about BYOK document extraction
Common questions from finance, operations, and IT teams implementing BYOK document extraction workflows.
- Are AI provider API keys free? Provider pricing and free allowances change. Check the provider account you plan to connect and use its current dashboard for limits and billing.
- Does Dynamite Docs charge Processing Entitlements (PE) when I use my own key? Free and Starter own-key pages use the monthly PE allowance. Pro and Scale own-key runs cost 0 PE. Provider charges and limits still apply.
- Will the provider train on my documents? Handling depends on the provider, API product, account, region, and current terms. Check those terms. Dynamite Docs can block routes that do not meet an active no-training rule, and eligible plans can use the local Ollama companion.
- Do I need to write code or prompts to use my API key in Dynamite Docs? No code or prompt engineering is required. Dynamite Docs handles document parsing, prompt construction, coordinate extraction, JSON validation, and export formatting. You simply paste your API key once in settings and use the visual workspace.
- Can vision models extract handwritten receipts and blurry photos? They can attempt them, but handwriting, blur, glare, skew, fading, and cropping increase error risk. Compare merchant, date, tax, total, and line items with the source.
- What happens when a provider encounters downtime or rate limits? An eligible configured fallback may be used. If no compatible route is available, the run can fail and should be retried after the provider recovers.
Start with a pilot test on your most difficult document layout
An own-key route gives you control over the provider account and model selection. It does not control the provider's terms or make the extracted values correct without review.
Before rolling out batch extraction, connect the provider in Dynamite Docs Settings and process a small set of difficult, representative documents. Compare every required field and line item with the source, record the corrections, and measure provider errors, retries, review time, and charges before expanding the volume.
Sources checked for this note
- Google AI Studio API Key Management
- Groq Cloud Developer Console
- Mistral AI La Plateforme Console
- OpenAI Developer Platform API Keys
- Anthropic Developer Console Settings
- Ollama Official Runtime Download
- OpenRouter API Key Management
- NIST SP 800-38D: Recommendation for Block Cipher Modes of Operation (Galois/Counter Mode)
Related workflow: Automate invoice, receipt, and statement intake for accounting teams.
Keep reading
Try it yourself. Upload a PDF, scan, or image and let Dynamite Docs infer the schema.