Status: Planned and unavailable. Do not paste a provider credential into
the developer portal or send one to /v1/execute; no public BYO enrollment,
storage, routing, rotation, revocation, usage, or fee contract is active.
The live personal partner preview uses Praxa’s bundled inference supply. The
public request cannot choose a provider, model, credential, or funding mode.
Intended use cases
A future BYO option may help customers that have provider committed spend, provider-specific procurement terms, a DPA, regional requirements, or a fine-tuned deployment under their own account. Those motivations do not make the capability available today.Required security properties
Before BYO can activate, its implementation must prove:- application-layer envelope encryption at rest;
- runtime-only decryption and strict tenant binding;
- no plaintext in logs, errors, gateway state, analytics, or API responses;
- one-time write-only enrollment and safe metadata-only readback;
- rotation that activates the replacement before revoking the predecessor;
- immediate authoritative revocation and bounded cache propagation;
- provider/model failover constrained to the tenant’s funded lanes;
- billing and usage separation between bundled and tenant-funded calls;
- cross-tenant negative tests and operational key-loss/recovery procedures.
praxa_sk_ API keys.