Cursor API Key Management
Overview
Manage any Cursor BYOK/provider credentials as individual, least-privilege secrets with approved routing, ownership, rotation, spending limits, and exposure response.
Prerequisites
- An approved provider/model route, named key owner, secrets-manager integration, and budget policy.
- Confirmation that BYOK is permitted for the intended data classification and tenant configuration.
Instructions
- Issue one scoped key per owner or approved service through the provider/secrets manager.
- Configure it through the approved UI/injection path; never commit it, paste it into rules, or share it between users.
- Set provider spending/rate controls, review usage, and rotate on schedule or suspected exposure.
- Revoke first, then investigate, when a key is lost, leaked, or no longer required.
Output
- An attributable, scoped credential with rotation, budget, and revocation evidence.
Examples
Create a personal provider key in the approved secret manager, configure it only in the local secure setting, verify a low-cost non-sensitive request, and confirm usage attribution. If it appears in logs, chat, or git, revoke it immediately and replace it; do not attempt to redact history before revocation.
Configure Bring Your Own Key (BYOK) for AI model providers in Cursor. BYOK lets you use your own API keys to bypass Cursor's monthly quota, pay per token directly, and access models not included in Cursor's subscription.
Supported Providers
| Provider |
Key Format |
Models Available |
| OpenAI |
sk-proj-... or sk-... |
GPT-4o, GPT-4o-mini, o1, o3, GPT-5 |
| Anthropic |
sk-ant-api03-... |
Claude Sonnet, Claude Opus, Claude Haiku |
| Google |
AIzaSy... |
Gemini 2.5 Pro, Gemini Flash |
| Azure OpenAI |
Azure portal key |
Any deployed Azure OpenAI model |
| AWS Bedrock |
IAM credentials |
Claude, Titan, Llama models |
| OpenAI-compatible |
Varies |
Ollama, LM Studio, Together AI, etc. |
Configuration Steps
OpenAI
- Go to platform.openai.com/api-keys
- Create a new API key (project-scoped recommended)
- In Cursor:
Cursor Settings > Models > check Use own API key
- Paste key in the OpenAI API Key field
- Select model from dropdown (e.g.,
gpt-4o)
Anthropic
- Go to console.anthropic.com/settings/keys
- Create a new API key
- In Cursor:
Cursor Settings > Models > check Use own API key
- Paste key in the Anthropic API Key field
- Select Claude model from dropdown
Google (Gemini)
- Go to aistudio.google.com/apikey
- Create API key
- In Cursor:
Cursor Settings > Models > check Use own API key
- Paste key in the Google API Key field
Azure OpenAI
Azure requires additional configuration beyond a simple API key:
- In Azure Portal: create an Azure OpenAI resource
- Deploy your desired model (e.g.,
gpt-4o)
- Note the Endpoint URL and API Key from the resource
- In Cursor:
Cursor Settings > Models:
Azure Configuration:
API Key: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Endpoint: https://your-instance.openai.azure.com
Deployment: your-gpt4o-deployment-name
API Version: 2024-10-21
Custom OpenAI-Compatible Endpoints
For self-hosted models (Ollama, vLLM) or third-party providers:
Cursor Settings > Models > Add Model
- Model name: e.g.,
llama-3.1-70b
- Check
Override OpenAI Base URL
- Enter base URL:
Ollama: http://localhost:11434/v1
LM Studio: http://localhost:1234/v1
Together AI: https://api.together.xyz/v1
- Enter API key if required by the provider
- The model appears in the Chat/Composer model dropdown
What BYOK Covers (and What It Does Not)
BYOK key used: Cursor model (always):
┌──────────────────────┐ ┌──────────────────────┐
│ Chat (Cmd+L) │ │ Tab Completion │
│ Composer (Cmd+I) │ │ Apply from Chat │
│ Agent Mode │ │ (diff application) │
│ Inline Edit (Cmd+K) │ │ │
└──────────────────────┘ └──────────────────────┘
Tab Completion and Apply always use Cursor's proprietary models. You cannot route these through your own API key.
Cost Management
Monitoring Usage
With BYOK, you pay the provider directly. Monitor costs at:
Setting Spending Limits
Set monthly spending limits at the provider level:
- OpenAI: Settings > Limits > Set monthly budget
- Anthropic: Settings > Limits > Set spending limit
- Azure: Create budget alerts in Azure Cost Management
Cost-Saving Strategies
- Use Auto mode: Cursor selects cheaper models for simple tasks
- Default to Sonnet/GPT-4o: Reserve Opus/o1 for hard problems
- Shorter context: Use
@Files not @Codebase when you know the location
- Fewer round-trips: Write detailed prompts to reduce back-and-forth
Approximate Token Costs (as of early 2026)
| Model |
Input (per 1M tokens) |
Output (per 1M tokens) |
| GPT-4o |
$2.50 |
$10.00 |
| GPT-4o-mini |
$0.15 |
$0.60 |
| Claude Sonnet |
$3.00 |
$15.00 |
| Claude Opus |
$15.00 |
$75.00 |
| o1 |
$15.00 |
$60.00 |
A typical Composer session generating multi-file code uses 5K-20K tokens.
Security Best Practices
Key Storage
Cursor stores API keys locally in its settings database:
- macOS:
~/Library/Application Support/Cursor/
- Linux:
~/.config/Cursor/
- Windows:
%APPDATA%\Cursor\
Keys are stored in the local Cursor configuration, not in project files. They do not sync between machines.
Rotation
- Generate a new key at the provider
- Update the key in
Cursor Settings > Models
- Revoke the old key at the provider
- Verify Chat/Composer work with the new key
Team Key Management
For teams using BYOK:
- Individual keys: Each developer uses their own key. Simplest setup, hardest to audit.
- Shared project key: Create a project-scoped key at the provider. Share via secure channel. Track usage per project.
- Azure gateway: Route all requests through a central Azure OpenAI deployment. Full audit logging, spending controls, model governance.
Troubleshooting
| Error |
Cause |
Fix |
401 Unauthorized |
Invalid or expired API key |
Regenerate key at provider |
429 Rate Limited |
Too many requests |
Wait, or upgrade provider plan |
403 Forbidden |
Key lacks model access |
Enable model access at provider |
| Model not appearing |
Key not saved or wrong provider |
Re-enter key in Cursor Settings |
| Azure connection refused |
Wrong endpoint or API version |
Verify endpoint URL and version |
| Slow responses with BYOK |
Provider rate limits apply |
Check provider dashboard |
Enterprise Considerations
- Compliance: BYOK routes requests directly to the provider, bypassing Cursor's infrastructure. Verify this meets your data governance requirements.
- Azure private endpoints: Enterprise Azure deployments can use private endpoints for network-level isolation
- Key rotation policy: Implement quarterly key rotation as standard practice
- SSO + BYOK: Team admins can configure shared BYOK keys via the admin dashboard (Enterprise plan)
Resources
1---2name: cursor-api-key-management3description: Configure BYOK API keys for OpenAI, Anthropic, Google, Azure, and custom models in Cursor. Triggers on "cursor api key", "cursor openai key", "cursor anthropic key", "own api key cursor", "BYOK cursor", "cursor azure key".4license: MIT5---6# Cursor API Key Management
7
8## Overview
9
10Manage any Cursor BYOK/provider credentials as individual, least-privilege secrets with approved routing, ownership, rotation, spending limits, and exposure response.
11
12## Prerequisites
13
14- An approved provider/model route, named key owner, secrets-manager integration, and budget policy.
15- Confirmation that BYOK is permitted for the intended data classification and tenant configuration.
16
17## Instructions
18
191. Issue one scoped key per owner or approved service through the provider/secrets manager.
202. Configure it through the approved UI/injection path; never commit it, paste it into rules, or share it between users.
213. Set provider spending/rate controls, review usage, and rotate on schedule or suspected exposure.
224. Revoke first, then investigate, when a key is lost, leaked, or no longer required.
23
24## Output
25
26- An attributable, scoped credential with rotation, budget, and revocation evidence.
27
28## Examples
29
30Create a personal provider key in the approved secret manager, configure it only in the local secure setting, verify a low-cost non-sensitive request, and confirm usage attribution. If it appears in logs, chat, or git, revoke it immediately and replace it; do not attempt to redact history before revocation.
31
32Configure Bring Your Own Key (BYOK) for AI model providers in Cursor. BYOK lets you use your own API keys to bypass Cursor's monthly quota, pay per token directly, and access models not included in Cursor's subscription.
33
34## Supported Providers
35
36| Provider | Key Format | Models Available |
37|----------|-----------|-----------------|
38| OpenAI | `sk-proj-...` or `sk-...` | GPT-4o, GPT-4o-mini, o1, o3, GPT-5 |
39| Anthropic | `sk-ant-api03-...` | Claude Sonnet, Claude Opus, Claude Haiku |
40| Google | `AIzaSy...` | Gemini 2.5 Pro, Gemini Flash |
41| Azure OpenAI | Azure portal key | Any deployed Azure OpenAI model |
42| AWS Bedrock | IAM credentials | Claude, Titan, Llama models |
43| OpenAI-compatible | Varies | Ollama, LM Studio, Together AI, etc. |
44
45## Configuration Steps
46
47### OpenAI
48
491. Go to [platform.openai.com/api-keys](https://platform.openai.com/api-keys)
502. Create a new API key (project-scoped recommended)
513. In Cursor: `Cursor Settings` > `Models` > check `Use own API key`
524. Paste key in the OpenAI API Key field
535. Select model from dropdown (e.g., `gpt-4o`)
54
55### Anthropic
56
571. Go to [console.anthropic.com/settings/keys](https://console.anthropic.com/settings/keys)
582. Create a new API key
593. In Cursor: `Cursor Settings` > `Models` > check `Use own API key`
604. Paste key in the Anthropic API Key field
615. Select Claude model from dropdown
62
63### Google (Gemini)
64
651. Go to [aistudio.google.com/apikey](https://aistudio.google.com/apikey)
662. Create API key
673. In Cursor: `Cursor Settings` > `Models` > check `Use own API key`
684. Paste key in the Google API Key field
69
70### Azure OpenAI
71
72Azure requires additional configuration beyond a simple API key:
73
741. In Azure Portal: create an Azure OpenAI resource
752. Deploy your desired model (e.g., `gpt-4o`)
763. Note the **Endpoint URL** and **API Key** from the resource
774. In Cursor: `Cursor Settings` > `Models`:
78
79```
80Azure Configuration:
81 API Key: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
82 Endpoint: https://your-instance.openai.azure.com
83 Deployment: your-gpt4o-deployment-name
84 API Version: 2024-10-21
85```
86
87### Custom OpenAI-Compatible Endpoints
88
89For self-hosted models (Ollama, vLLM) or third-party providers:
90
911. `Cursor Settings` > `Models` > `Add Model`
922. Model name: e.g., `llama-3.1-70b`
933. Check `Override OpenAI Base URL`
944. Enter base URL:
95
96```
97Ollama: http://localhost:11434/v1
98LM Studio: http://localhost:1234/v1
99Together AI: https://api.together.xyz/v1
100```
101
1021. Enter API key if required by the provider
1032. The model appears in the Chat/Composer model dropdown
104
105## What BYOK Covers (and What It Does Not)
106
107```
108BYOK key used: Cursor model (always):
109┌──────────────────────┐ ┌──────────────────────┐
110│ Chat (Cmd+L) │ │ Tab Completion │
111│ Composer (Cmd+I) │ │ Apply from Chat │
112│ Agent Mode │ │ (diff application) │
113│ Inline Edit (Cmd+K) │ │ │
114└──────────────────────┘ └──────────────────────┘
115```
116
117**Tab Completion and Apply always use Cursor's proprietary models.** You cannot route these through your own API key.
118
119## Cost Management
120
121### Monitoring Usage
122
123With BYOK, you pay the provider directly. Monitor costs at:
124
125- OpenAI: [platform.openai.com/usage](https://platform.openai.com/usage)
126- Anthropic: [console.anthropic.com/settings/billing](https://console.anthropic.com/settings/billing)
127- Azure: Azure Cost Management portal
128
129### Setting Spending Limits
130
131Set monthly spending limits at the provider level:
132
133- **OpenAI**: Settings > Limits > Set monthly budget
134- **Anthropic**: Settings > Limits > Set spending limit
135- **Azure**: Create budget alerts in Azure Cost Management
136
137### Cost-Saving Strategies
138
1391. **Use Auto mode**: Cursor selects cheaper models for simple tasks
1402. **Default to Sonnet/GPT-4o**: Reserve Opus/o1 for hard problems
1413. **Shorter context**: Use `@Files` not `@Codebase` when you know the location
1424. **Fewer round-trips**: Write detailed prompts to reduce back-and-forth
143
144### Approximate Token Costs (as of early 2026)
145
146| Model | Input (per 1M tokens) | Output (per 1M tokens) |
147|-------|----------------------|----------------------|
148| GPT-4o | $2.50 | $10.00 |
149| GPT-4o-mini | $0.15 | $0.60 |
150| Claude Sonnet | $3.00 | $15.00 |
151| Claude Opus | $15.00 | $75.00 |
152| o1 | $15.00 | $60.00 |
153
154A typical Composer session generating multi-file code uses 5K-20K tokens.
155
156## Security Best Practices
157
158### Key Storage
159
160Cursor stores API keys locally in its settings database:
161
162- macOS: `~/Library/Application Support/Cursor/`
163- Linux: `~/.config/Cursor/`
164- Windows: `%APPDATA%\Cursor\`
165
166Keys are stored in the local Cursor configuration, not in project files. They do not sync between machines.
167
168### Rotation
169
1701. Generate a new key at the provider
1712. Update the key in `Cursor Settings` > `Models`
1723. Revoke the old key at the provider
1734. Verify Chat/Composer work with the new key
174
175### Team Key Management
176
177For teams using BYOK:
178
179- **Individual keys**: Each developer uses their own key. Simplest setup, hardest to audit.
180- **Shared project key**: Create a project-scoped key at the provider. Share via secure channel. Track usage per project.
181- **Azure gateway**: Route all requests through a central Azure OpenAI deployment. Full audit logging, spending controls, model governance.
182
183## Troubleshooting
184
185| Error | Cause | Fix |
186|-------|-------|-----|
187| `401 Unauthorized` | Invalid or expired API key | Regenerate key at provider |
188| `429 Rate Limited` | Too many requests | Wait, or upgrade provider plan |
189| `403 Forbidden` | Key lacks model access | Enable model access at provider |
190| Model not appearing | Key not saved or wrong provider | Re-enter key in Cursor Settings |
191| Azure connection refused | Wrong endpoint or API version | Verify endpoint URL and version |
192| Slow responses with BYOK | Provider rate limits apply | Check provider dashboard |
193
194## Enterprise Considerations
195
196- **Compliance**: BYOK routes requests directly to the provider, bypassing Cursor's infrastructure. Verify this meets your data governance requirements.
197- **Azure private endpoints**: Enterprise Azure deployments can use private endpoints for network-level isolation
198- **Key rotation policy**: Implement quarterly key rotation as standard practice
199- **SSO + BYOK**: Team admins can configure shared BYOK keys via the admin dashboard (Enterprise plan)
200
201## Resources
202
203- [Cursor API Keys Documentation](https://docs.cursor.com/advanced/api-keys)
204- [Cursor Data Use Policy](https://cursor.com/data-use)
205- [OpenAI API Reference](https://platform.openai.com/docs/api-reference)
206- [Anthropic API Reference](https://docs.anthropic.com/en/api)