# OpenAI's "bring your own key" policy

**URL:** <https://community.openai.com/t/openais-bring-your-own-key-policy/14538>\
**Category:** API\
**Created:** [January 13, 2022, 8:04pm UTC](https://community.openai.com/t/openais-bring-your-own-key-policy/14538 "2022-01-13T20:04:46Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Fusseldieb](https://sea2.discourse-cdn.com/openai1/user_avatar/community.openai.com/fusseldieb/32/11896_2.png) [@Fusseldieb](https://community.openai.com/u/Fusseldieb)\
**Post date:** [September 15, 2022, 2:30am UTC](https://community.openai.com/t/openais-bring-your-own-key-policy/14538/6 "2022-09-15T02:30:16Z")

</div>

> [@Xerxes](#):
>
> will be stored in environment variables on the servers

As per Documentation:

> - The application **may not store** end-users’ API keys **server-side** or otherwise access end-users’ API keys in an ongoing fashion.

You will probably need to use your own key and charge users based on their usage. If you’re not sure if they’ll pay, have them “charge up” the account via credit card, etc in the first place and then deduct the usage.

What this also means is that since they’re using your key, if some of your customers produce harmful content in a repeated manner, your key may be revoked and your entire business falls apart. Always pass the content through the OpenAI content filter API first and evaluate if it’s considered ‘safe’. If not, you can set up your own flag/ban system. Better safe _(banning a single customer)_ than sorry _(getting your key revoked)_.

---

_[View the full topic](https://community.openai.com/t/openais-bring-your-own-key-policy/14538)._
