Using your own API keys to cut AI costs, and when not to

BYOK means the tool does the work and your provider account pays for it. Real savings for heavy users, a bad trade for everybody else. Here's how to tell which one you are.

RIZZ AI LAB / 16 February 2026 / 5 min read

BYOK stands for bring your own key. It means a tool does the work but you supply the account it bills to. You paste your own API key from a model provider, the tool sends requests with your key attached, and the usage lands on your invoice rather than the tool's.

It's a real cost lever for a specific kind of user and a bad idea for most people. Here's how to tell which one you are.

What an API key actually is

Model providers sell access two ways. There's the consumer product, a monthly subscription for a chat interface. And there's the API, where you create a key in a developer console, load some credit, and pay per unit of text processed.

The API is much cheaper per unit than the consumer subscription implies, because you aren't paying for the interface, the apps, the support or the unlimited use of people who leave a tab open all day. You're paying for compute.

An API key is a long string that authenticates requests. Anyone holding it can spend your balance. Providers let you set spending caps and revoke keys, and you should use both.

Where the money actually goes

A tool like this makes two kinds of call. Understanding the split matters, because they price very differently.

Speech to text. Turning audio into words. This is the expensive one, priced per minute of audio, and it dominates the bill on long material.

Language model calls. Reading the transcript and producing the summary, the ideas, the quotes. Priced by amount of text in and out. On a two hour transcript this isn't nothing, but it's smaller than the speech step.

If most of your volume is long audio, your bill is a speech to text bill and the model provider you pick barely moves it. If most of your volume is short clips or text you already have, the reverse is true.

When bringing your own keys pays

Run the arithmetic rather than the vibe.

With credits, Drop charges one credit per started minute. Whether that beats direct API pricing depends on your volume, because with your own keys you also pay for the failures, the retries and the runs you abandon halfway.

Bringing your own keys makes sense when:

  • You process a lot, consistently. Occasional users never recover the setup effort.
  • You already have provider accounts with committed spend or negotiated rates.
  • You need a specific model that the default doesn't use.
  • Your organisation requires that data goes to an account it controls.

It doesn't make sense when:

  • You run a few things a week. The credits are cheaper than your time.
  • You don't want to manage keys, caps and invoices.
  • You want one predictable number rather than a variable bill.

That last point is underrated. Per unit pricing means a heavy week produces a bill you didn't plan for. Credits are prepaid and can't surprise you.

The security part, stated plainly

If you do this, three rules.

Set a hard spending cap in the provider console. Not a warning, a cap. This is the single protection that matters.

Use one key per tool. When you stop using something, revoke its key and nothing else breaks.

Know where the key is stored. In Drop, keys stay in your browser and are sent with the request that uses them. They aren't kept on the server. If a tool asks you to store a key in its database, that's a different risk profile and you should be deliberate about accepting it.

How it works in Drop

Bringing your own keys is behind the Key Pass, which is five euro a month or forty eight a year, and it's included in Go Annual and in Lifetime. See pricing for the full picture.

The reason it isn't free is straightforward. Someone running on their own keys spends no credits, so the usual pricing doesn't apply to them, and the plumbing still has to be built and maintained. The Key Pass covers that and nothing more.

With the pass active and keys entered, runs use your keys and burn no credits. Without the pass, or with the pass and no keys entered, runs use the server keys and cost credits as normal. There's no half state where you supply a key and get charged anyway.

The honest recommendation

Most people shouldn't do this. Prepaid credits with no expiry and no invoice to reconcile is the better deal for anyone processing less than several hours of material a week.

If you're past that line, or you've a policy reason, the Key Pass is the cheapest part of the decision and the provider bill is the part to model carefully.

Either way, the cost only matters if the output is worth keeping. That side of it's in watch less, keep more, and if you want to see what a long run actually produces before paying for anything, summarising a two hour talk walks through one.

Try it

Paste a link or drop a file in the box on the home page. One credit per started minute, and the first run on a new account is free.

Open the drop box

Read next