Bring your own key, or let Inkwell carry the bill
Every AI pass runs on somebody's account with a model provider. Inkwell gives you a clear choice of whose: ours, or yours. Both paths run the same skills through the same picker, and the difference comes down to two practical questions — who holds the key, and who pays the provider.
Bundled: no key, no setup
The default is Inkwell-bundled. Passes run on Inkwell's own provider keys, your plan carries a monthly allowance, and each pass draws against that allowance in proportion to the model tier behind it. Free and Pro both include hosted passes, so you can write with AI from the first minute of an account without touching a provider dashboard. You never see a provider bill; the allowance is the whole story.
Your own key: Anthropic or OpenAI
If you already have a provider account, paste its key into Settings and your passes run against it instead. Your provider bills you directly at their published rates, and Inkwell's bundled allowance is not drawn at all. The same three-tier model picker applies — it simply resolves to the corresponding models on the ladder your key belongs to.
Your keys
Bring your own provider key in settings — or use Inkwell's hosted passes on Free and Pro.
Model provider
Skills send scoped context for the pass — scene ranges, not your whole drive.
Suggestion only
Output is a reviewable diff — nothing writes through until you accept it.
You authorize each pass. We do not train on your scripts.
One default route at a time
Your account routes through one provider by default: bundled, Anthropic, or OpenAI. There is no per-project mixing and no fallback chain from your key to ours. Switching is a single settings change rather than a migration — and it is not destructive. Moving back to bundled stops sending passes to your key but keeps it stored, so model picks from that provider stay available and switching back later takes no re-pasting. When you want a key gone, deleting it is its own explicit step: the Remove button beside it under Stored API keys in Settings.
Your key is checked the moment you save it
A wrong key that saves silently is a trap that springs later, usually mid-scene. So Inkwell probes every new key against its provider before storing it, with a request capped at a single token — enough for the provider to authenticate you, small enough to cost effectively nothing.
- A key the provider rejects outright is refused on the spot, with a clear error at save time instead of a confusing failure on tomorrow's first pass.
- If the provider is briefly unreachable, the key saves anyway and is marked unconfirmed, so a network blip on their end never locks you out of your own settings.
What we hold, and what leaves
The trust posture is the same whichever path you choose, and it is short enough to state in full:
- Your key is encrypted at rest and decrypted only to make your call.
- A pass sends the context its scope needs. A scene- or act-scoped pass sends that range plus supporting context drawn from the same script — character voices, the pages leading in. Document-scoped skills and agent runs send the full script. Nothing from your other projects, ever.
- Output comes back as reviewable changes; nothing writes through until you accept it.
- We do not train on your scripts.
The security page covers the full posture, including how to report anything that looks off.