D-206 Use
Model keys
The agent needs a key to call its model. The key stays on your machine, in the sandbox runtime's credential store. Inside the sandbox the agent holds a placeholder, and the real key is added only on requests to that model's own API.
Store a key
boundlane key set claudePaste the key at the prompt. It is not shown, and it does not land in your shell history. In a script, pipe it in instead; Boundlane reads one line from standard input.
printf '%s\n' "$ANTHROPIC_API_KEY" | boundlane key set claudeThe key is handed to the runtime in the environment of that one command, never as an argument, so it does not show up in the process list.
Which key each agent needs
| Agent | Key | Bound to |
|---|---|---|
| Claude Code | ANTHROPIC_API_KEY | api.anthropic.com |
| Codex | OPENAI_API_KEY | api.openai.com |
| OpenCode | ANTHROPIC_API_KEY | api.anthropic.com |
| Grok | XAI_API_KEY | api.x.ai |
boundlane key listagent key stored
claude ANTHROPIC_API_KEY yes, on this machine
codex OPENAI_API_KEY no
opencode ANTHROPIC_API_KEY no
grok XAI_API_KEY nolist never prints a key.
What the agent sees
The agent's environment has ANTHROPIC_API_KEY, set to a placeholder. When the agent calls the model, the request goes through the sandbox's proxy, which replaces the placeholder with the real key. It does that only for requests that already match the policy, to the endpoints bound to that key. Requests anywhere else do not get the key.
So a prompt that convinces the agent to print its environment, or to send its key to another host, gets nothing worth having.
The key and its endpoint stay together
Each agent's key comes with a profile: the endpoints it may be sent to and the programs allowed to send it. Boundlane ships a reviewed copy of that profile for each agent, with the real program paths and without telemetry hosts. The model API is not in your policy file for the same reason. If it were, a policy edit could send the key somewhere new.
Rotate a key
Run boundlane key set again. It replaces the stored key. New sandboxes use the new one. Restart a running agent to be sure it does.
Remove a key
boundlane key remove claudeRemove refuses while a Boundlane sandbox is running. Stop it first with boundlane stop.
Subscription logins
Signing in with a Claude, ChatGPT, or Grok account instead of an API key is not supported. A subscription login keeps its token in the agent's own files. Inside the sandbox, the agent could read it. Use an API key, which the runtime holds outside.
On Team
Keys never leave the developer's machine. The console does not ask for them, store them, or see them. Each developer stores their own key with boundlane key set, the same as on Free. The same goes for Git tokens: we do not hold them in our cloud.