Concepts
Provider credentials
You bring your own model provider keys. Clovie stores them securely and uses them to forward your agents' requests.
Your agents' requests are sent to model providers with your own provider keys. You keep your existing accounts, contracts and data agreements with each provider, and the provider bills you directly.
Why agents never see provider keys
Agents call the gateway with a Clovie agent key. The gateway then calls the provider with your provider key. So:
- A leaked agent key cannot be used against your provider account directly, and you can revoke it in Clovie without rotating anything at the provider.
- You rotate a provider key in one place, and every agent picks up the change immediately.
- Each agent's usage is still tracked separately, even though they share one provider account.
Add a provider credential
Organization administrators manage credentials in AI Governance → Models → Provider credentials.
Select Add credential.
Choose the Provider, then choose How Clovie gets the key:
- Stored encrypted: paste the key into API key. Clovie encrypts it with a key unique to your organization, and it is never shown again.
- Your secret store (self-hosted installations): enter the Secret name where the key already lives in your own secret store. Clovie reads it when it's needed and never stores it.
- No secret (cloud identity) (self-hosted installations): for Azure OpenAI, Amazon Bedrock and Google Vertex AI, Clovie uses your cloud's own identity instead of a key.
Optionally add a Name such as "Production", then save. Select Test to check the credential with the provider.
Clovie never uses its own keys for your traffic. If an agent calls a provider you haven't added a credential for, the request is refused with a message that names the provider.
Credential status
| Status | What it means |
|---|---|
| Verified | The last test or request with this credential succeeded. |
| Failing | The provider rejected the credential. The reason is shown next to it. |
| Not tested yet | The credential hasn't been used or tested since it was added. |
Replace and delete
- Replace swaps in a new key. The old key stops being used immediately.
- Delete removes the credential. Requests that need it are refused until you add another.
Adding, replacing, deleting and testing credentials is recorded in your audit log.
Models you host yourself
If you run your own models, or use a cloud provider's hosted model service, an administrator can register them in AI Governance → Models → More → Custom models so agents can call them through the gateway like any other model.