AI Model Keys
AI Model Keys is where you add your own AI provider keys and choose which models Nexus uses. On the page itself it is titled AI Credentials & Model Defaults.
What "bring your own key" means
Nexus does not provide an AI key. You add your own for each provider you want to use, and your requests are billed to it. The page says: "Bring your own API keys. APEX uses your personal key first, then any team key — there is no platform-wide fallback. If no key is configured for a provider, requests to it are blocked."
- Keys are stored encrypted and shown only as their last four characters.
- If you have no key for a provider, requests to it are blocked, not billed to a shared account.
- Your keys are used only for your requests.
Open the page
Click Settings → AI Model Keys in the Nexus sidebar. You need the AI credentials permission to see the menu item. The same page is also reached from the avatar menu ("AI credentials") and from Open AI Credentials → when Nexus has no model set up.
The page header
- A counter row: "N configured", "N verified" and "X / 1 required defaults set". The last is green once your Chat / General default is set, and amber until then.
- An amber banner when you have no defaults at all: "No model defaults are configured. AI features like Nexus Chat and Doc Intelligence will not work until you set at least the Chat / General default in the Model Defaults tab."
There are six tabs: API Keys (the default), Model Defaults, Private LLMs, Model Keys, Agent limits and Usage.
API Keys tab
Add a key
Find the provider
The page lists a card for each provider your administrator has enabled. If none are enabled you see "No AI providers are available yet." and are asked to contact your administrator.
Screenshot placeholderScreenshot to add: Provider cards showing Verified or Not verified badges and key suffixes. Open the card
Click the card to expand it. A green border shows a key is already saved.
Fill in the details
- Label (optional): a name for your own reference, up to 128 characters.
- API key: paste it. A stored key shows "(stored — enter new key to replace)".
- Base URL: only for providers that need one, such as a local Ollama.
- Extra fields: for providers that need more, such as an Azure API version.
Save
Click Save Key (or Update Key). A toast says "(provider) credential saved." Saving always resets the key to Not verified.
Verify
Click Verify. Nexus fetches the provider's model list with your key. Toasts: "Credential verified — found N models.", "Credential rejected — (provider) returned an authentication error." or "Could not verify the (provider) credential — the provider returned no models. Check the key and try again."
Remove (red) deletes the key at once, with no confirmation. A toast says "Credential removed." Its spend limit goes with it.
A red badge Key rejected by provider means the provider refused your key when Nexus last listed its models. The models shown for it are then fallbacks, not live results.
Platform AI Providers summary
If providers are enabled, a table above the cards lists each with a status: "Built-in · no key needed", "Verified (date) ••••1234", "Key saved · not verified" or "Not configured", and an Add key → or Edit link that opens the card.
GitHub Copilot
Copilot connects with a sign-in code instead of a key.
- Click Connect with GitHub.
- Open the address shown and enter the large code.
- Wait for "Waiting for authorization…". A toast says "GitHub Copilot connected as @user."
Errors include "This GitHub account has no active Copilot subscription.", "The device code expired before authorization completed. Try again." and "Authorization was denied." Disconnect removes the connection.
Spend limit
Once a key exists, set a limit on what it may spend.
- Amount: a number, blank for "Unlimited".
- Period: Daily, Weekly or Monthly (default).
- Click Save. A toast says "Spend limit saved."
- A meter shows "$X of $Y this month". It turns amber at 90% and red at 100%.
- At 100% calls are blocked: "Your '(provider)' key has used $X of its $Y (period) limit. Raise the limit in Settings -> AI Model Keys to continue."
- Show usage by session lists the sessions that spent: Session, Last used, Calls, Cost.
Models and testing
Expand Models & testing to see the models your key can use ("N available"). Use Filter models… when there are many.
Click Test on a model to send one tiny real request with your own key. It spends a little of your own quota, and it is the only reliable way to know a model works on your plan. Results read, for example, "✓ Served in 412 ms — this model works on your plan with your own key." or "Not available · HTTP 403". There is no "test all".
Model Defaults tab
"Choose which model APEX uses for each type of AI task." Models come from the keys you saved.
| Group | Use cases |
|---|---|
| Primary | Chat / General (required), Code Generation, Reasoning, Embeddings, Reranking, Image Generation |
| Sub-agent task models | Explore, Audit, Plan, Review. Unset ones use your Code Generation default |
| Context summarization | Context Compaction |
| Cortex task models | Conversation Titles, Memory Classification, Causal Chain Assembly, Rationale Synthesis, Benchmark Judge |
Set a default
Click Set default on a row. Choose a Provider ("-- Provider --") and a Model ("-- Model --", searchable).
Save
Click Save. A toast says "Model default saved."
A set default shows as provider/model, with Change and a red X that clears it at once ("Model default cleared.").
Context Compaction has extra fields: Compaction trigger (a percentage, default 80), Also compact above (a token count, blank for off), and Keep recent context verbatim (Default, Small 15%, Medium 25%, Large 40%, or Custom).
If you start a chat without choosing a model, Nexus picks the cheapest allowed model you have a key for. If none exists you see the Set your AI model default dialog, whose button Open AI Credentials → brings you here.
Private LLMs tab
For your own Ollama, LM Studio or any OpenAI-compatible endpoint: "Models become available in the model selector with prefix user_private::."
- Click Add Provider.
- Fill in Display Name (e.g. "My Local Ollama"), Base URL (e.g.
http://localhost:11434), an optional API Key and an optional Default Model (e.g.llama3.2:latest). - Click Save & Connect.
Each row shows Reachable or Unreachable, the base URL, "N models detected" and the last verified time, with Verify, Edit and a trash button (confirm "Remove (name)?"). Empty: "No private LLM providers yet."
Model Keys tab
These are the reverse of the rest of the page: keys issued to you so your own applications can call models hosted by Nexus. "Each key is tied to a specific model and shown only once."
- Click New Key. It is disabled until an administrator has a hosted model ready.
- Choose a Model, enter a Label and an optional Description, then click Generate Key.
- Copy the key from the panel "Copy this key now. It will not be shown again." Copy shows "Copied!".
Revoke asks "Revoke key "(label)"?" and warns that any application using it stops working immediately.
Agent limits tab
Controls when long runs pause. "Agents have no step cap. A long run pauses and asks you to continue when it stops making progress, or when it passes a spend, token or time budget. A pause never loses work."
- Turn Pause long runs on spend/time on (the default) or off. When off, "Loop checks (repeats, errors, no new results) still pause a stuck run."
- Optional budgets: Spend budget per run (USD), Token budget per run (tokens) and Time budget per run (minutes). Leave blank for the platform default. Each shows its default and the administrator's maximum.
- Click Save. A toast says "Agent limits saved." Reset discards unsaved changes.
- A value must be above zero. Above the maximum you see "Above the maximum of (value)."
These limits cover your own chats and coding runs. Agent Force teams have their own budgets. See Guardrails.
Usage tab
"Your own LLM spend and token usage, across every provider you've configured a key for." Choose 7d, 30d (default) or 90d. You see a card per provider with spend and any limit meter, a daily chart, and a My Models breakdown. Empty: "No LLM usage in this window."
When a key is missing or rejected
Nexus tells you where something went wrong:
- A toast with the reason and an action link: "Open Settings, Credentials" brings you to this page.
- In the New Chat dialog, an inline message with the same link.
- Set your AI model default: "No model has been configured for your account. Open AI Credentials to add a provider key and choose your default model."
See Chat for where these appear.
Agent Force and your AI key
Each member of an AI team bills one person's key, by default the team owner's. A teammate hiring a member can choose My AI key under Runs on. The owner controls this with the switch Teammates may hire on my AI key, which is off by default. See Knowledge: Resources.