Skip to main content
At the end of this page, your organization’s model calls run through your own OpenRouter key. You also know how to read the key card, replace the key, revoke it, and act on a key failure.
This capability needs the plan or higher.

Before you start

Before you start, sign in to the dashboard and select the organization you want to work in.
  • You need the Admin role on a Premium or Enterprise plan. Other members do not see the Integrations page, and Free organizations do not see the Model Provider tab.
  • Have an OpenRouter API key ready. Keys start with sk-or-. You create them on the OpenRouter keys page, which the add dialog links to.
  • The key is used for the model calls of your agents’ AI Agent gambits. See AI Agent gambit for where an agent picks its model.

Open the Model Provider tab

Open Settings, select Integrations, then select the Model Provider tab. The Integrations page has three tabs: API Keys, Identity Verification, and Model Provider. Before a key exists, the tab shows one OpenRouter card. The card says the key unlocks any model on OpenRouter, is encrypted at rest, and is decrypted only at request time. Below the text sits a single Add OpenRouter Key button.
The Model Provider tab on the Integrations page with the empty OpenRouter card and the Add OpenRouter Key button

Add your key

1

Select Add OpenRouter Key

The Add OpenRouter API Key dialog opens.
2

Enter a label if you want one

The Label (optional) field names the key on the card, for example Production.
3

Paste the key into OpenRouter API Key

The field hides the key. Select the eye icon to show or hide it while you check it.
4

Tick the acknowledgement

The checkbox reads I understand TARS will use this key for all model calls in this org.
5

Select Validate & Save

The button reads Validating… while Tars checks the key with OpenRouter. On success a toast reads OpenRouter key saved (…1234).
The Add OpenRouter API Key dialog with the Label field, the hidden OpenRouter API Key field, the acknowledgement checkbox, and the Validate & Save button
Validate & Save stays disabled until the key field has a value and the checkbox is ticked. The dialog says Validated against OpenRouter before saving, and that is the whole rule. A key that does not start with sk-or-, or that OpenRouter rejects, is not saved and the dialog shows the error. If OpenRouter cannot be reached, nothing is saved either, so try again later. Your organization holds one OpenRouter key at a time. Saving a key when one already exists replaces it.

Read the key card

Once a key is saved, the OpenRouter card shows an Active badge and a one-row table. Below the table sit two buttons, Replace Key and Revoke.

Replace the key

Select Replace Key to rotate to a new key. The Replace OpenRouter Key dialog has the same fields, checkbox, and Validate & Save button as the add dialog. The new key is validated the same way, and on success it takes over immediately while the old key is discarded. There is no gap in which model calls fail, so rotate whenever your OpenRouter account requires it.

Revoke the key

Revoking is immediate. Agents whose AI Agent gambits use an OpenRouter-only model show an error on their next turn until you add a key again or change the model.
Select Revoke to open the confirmation dialog, which is titled Revoke OpenRouter key? and repeats that warning. Select Revoke key to confirm. A toast reads OpenRouter key revoked, and the tab returns to the empty OpenRouter card. Model calls go back to the Tars key.

When the key fails

If a recent model call failed because OpenRouter rejected your key, a red alert appears above the card. It reads Your OpenRouter key returned an error (HTTP_401) on the last request, with the code OpenRouter returned. A second line reads Model calls routed through your key error out until it is updated. The alert has two buttons:
  • Update Key opens the Replace OpenRouter Key dialog.
  • Revoke Key opens the Revoke OpenRouter key? confirmation.
The alert clears on its own once the failure is no longer recent. Fix the key first, or agents keep failing on every model call. Authentication failures, key additions, and key removals are also recorded in the audit log. See Search and export the audit log.

What changes when a key is active

  • Every model call from your agents’ AI Agent gambits, in the builder preview and in live conversations, is sent to OpenRouter with your key. OpenRouter bills those calls to your account. Your Tars plan and conversation usage do not change.
  • In the builder, the model picker in the Model region shows a BYOK · OpenRouter banner with the last four characters of the key. The banner also has a Manage link back to the Model Provider tab. When a model outside the curated list is selected, the picker also shows a small BYOK badge next to the model name.
  • The key does not change which models the picker offers. Premium and Enterprise plans already offer the full catalog. See Plans overview.
  • The key is stored encrypted and is decrypted only for the request being made. It is never shown again after you save it, only its last four characters. See How Tars protects files, data, and identity.

Verify

Open an agent whose AI Agent gambit uses a model from the catalog and send it a message in the builder preview. Return to the Model Provider tab. The Last used column now shows the time of that call.