Bring your own key
Any provider that takes an API key can run on your account instead of ours. Connect the key once at Your provider keys. From then on, every run on that provider uses your credential, the provider bills you at your negotiated rate, and Cracked charges only the platform fee.
Why you would
- You already have a paid Apify, OpenAI, Apollo or Semrush plan with volume pricing.
- You need the provider's audit log to show your own account, for compliance.
- The provider is marked needs key here and you do not want to wait for us to enable it.
- The provider is your key only (Resend, Twilio): sending mail or SMS is always done from your own identity.
How it is stored
Credentials are encrypted with AES-256-GCM using a server-side key that is not in the database. The dashboard shows only the first and last four characters. Disconnecting deletes the ciphertext.
Precedence
Your key wins. If a workspace has a connected credential for a provider, runs use it even when the master account is live. billing.byok is true on those runs and billing.providerUsd is 0.