Boundlane Sheet D-206 / Model keys

D-206 Use

Model keys

The agent needs a key to call its model. The key stays on your machine, in the sandbox runtime's credential store. Inside the sandbox the agent holds a placeholder, and the real key is added only on requests to that model's own API.

API keys onlyNever sent to our cloud

Store a key

boundlane key set claude

Paste the key at the prompt. It is not shown, and it does not land in your shell history. In a script, pipe it in instead; Boundlane reads one line from standard input.

printf '%s\n' "$ANTHROPIC_API_KEY" | boundlane key set claude

The key is handed to the runtime in the environment of that one command, never as an argument, so it does not show up in the process list.

Which key each agent needs

AgentKeyBound to
Claude CodeANTHROPIC_API_KEYapi.anthropic.com
CodexOPENAI_API_KEYapi.openai.com
OpenCodeANTHROPIC_API_KEYapi.anthropic.com
GrokXAI_API_KEYapi.x.ai
boundlane key list
Example output
agent     key                stored
claude    ANTHROPIC_API_KEY  yes, on this machine
codex     OPENAI_API_KEY     no
opencode  ANTHROPIC_API_KEY  no
grok      XAI_API_KEY        no

list never prints a key.

What the agent sees

The agent's environment has ANTHROPIC_API_KEY, set to a placeholder. When the agent calls the model, the request goes through the sandbox's proxy, which replaces the placeholder with the real key. It does that only for requests that already match the policy, to the endpoints bound to that key. Requests anywhere else do not get the key.

So a prompt that convinces the agent to print its environment, or to send its key to another host, gets nothing worth having.

The key and its endpoint stay together

Each agent's key comes with a profile: the endpoints it may be sent to and the programs allowed to send it. Boundlane ships a reviewed copy of that profile for each agent, with the real program paths and without telemetry hosts. The model API is not in your policy file for the same reason. If it were, a policy edit could send the key somewhere new.

Rotate a key

Run boundlane key set again. It replaces the stored key. New sandboxes use the new one. Restart a running agent to be sure it does.

Remove a key

boundlane key remove claude

Remove refuses while a Boundlane sandbox is running. Stop it first with boundlane stop.

Subscription logins

Signing in with a Claude, ChatGPT, or Grok account instead of an API key is not supported. A subscription login keeps its token in the agent's own files. Inside the sandbox, the agent could read it. Use an API key, which the runtime holds outside.

On Team

Keys never leave the developer's machine. The console does not ask for them, store them, or see them. Each developer stores their own key with boundlane key set, the same as on Free. The same goes for Git tokens: we do not hold them in our cloud.