cursor-api-key-management
Manage and configure your own API keys for AI model providers in Cursor to bypass quotas and use specific model versions.
Install
mkdir -p .claude/skills/cursor-api-key-management && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/7622" && unzip -o skill.zip -d .claude/skills/cursor-api-key-management && rm skill.zipInstalls to .claude/skills/cursor-api-key-management
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Configure BYOK API keys for OpenAI, Anthropic, Google, Azure, and customKey capabilities
- →Configure API keys for OpenAI models like GPT-4o and GPT-5.
- →Set up API keys for Anthropic models such as Claude Sonnet and Claude Opus.
- →Integrate Google Gemini models using API keys.
- →Configure Azure OpenAI resources with endpoint URLs and API keys.
- →Connect AWS Bedrock models using IAM credentials.
- →Add custom OpenAI-compatible endpoints for models like Ollama and LM Studio.
How it works
This skill guides the user to input their API keys and configuration details into Cursor's settings for various AI model providers. Cursor then routes requests through these personal keys, bypassing its own quota system.
Inputs & outputs
When to use cursor-api-key-management
- →Configure OpenAI API keys for specific project-scoped model access
- →Setup Anthropic API credentials for Claude model usage
- →Connect Azure OpenAI or AWS Bedrock model endpoints to Cursor
- →Integrate local models via OpenAI-compatible endpoints
About this skill
Cursor API Key Management
Configure Bring Your Own Key (BYOK) for AI model providers in Cursor. BYOK lets you use your own API keys to bypass Cursor's monthly quota, pay per token directly, and access models not included in Cursor's subscription.
Supported Providers
| Provider | Key Format | Models Available |
|---|---|---|
| OpenAI | sk-proj-... or sk-... | GPT-4o, GPT-4o-mini, o1, o3, GPT-5 |
| Anthropic | sk-ant-api03-... | Claude Sonnet, Claude Opus, Claude Haiku |
AIzaSy... | Gemini 2.5 Pro, Gemini Flash | |
| Azure OpenAI | Azure portal key | Any deployed Azure OpenAI model |
| AWS Bedrock | IAM credentials | Claude, Titan, Llama models |
| OpenAI-compatible | Varies | Ollama, LM Studio, Together AI, etc. |
Configuration Steps
OpenAI
- Go to platform.openai.com/api-keys
- Create a new API key (project-scoped recommended)
- In Cursor:
Cursor Settings>Models> checkUse own API key - Paste key in the OpenAI API Key field
- Select model from dropdown (e.g.,
gpt-4o)
Anthropic
- Go to console.anthropic.com/settings/keys
- Create a new API key
- In Cursor:
Cursor Settings>Models> checkUse own API key - Paste key in the Anthropic API Key field
- Select Claude model from dropdown
Google (Gemini)
- Go to aistudio.google.com/apikey
- Create API key
- In Cursor:
Cursor Settings>Models> checkUse own API key - Paste key in the Google API Key field
Azure OpenAI
Azure requires additional configuration beyond a simple API key:
- In Azure Portal: create an Azure OpenAI resource
- Deploy your desired model (e.g.,
gpt-4o) - Note the Endpoint URL and API Key from the resource
- In Cursor:
Cursor Settings>Models:
Azure Configuration:
API Key: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Endpoint: https://your-instance.openai.azure.com
Deployment: your-gpt4o-deployment-name
API Version: 2024-10-21
Custom OpenAI-Compatible Endpoints
For self-hosted models (Ollama, vLLM) or third-party providers:
Cursor Settings>Models>Add Model- Model name: e.g.,
llama-3.1-70b - Check
Override OpenAI Base URL - Enter base URL:
Ollama: http://localhost:11434/v1
LM Studio: http://localhost:1234/v1
Together AI: https://api.together.xyz/v1
- Enter API key if required by the provider
- The model appears in the Chat/Composer model dropdown
What BYOK Covers (and What It Does Not)
BYOK key used: Cursor model (always):
┌──────────────────────┐ ┌──────────────────────┐
│ Chat (Cmd+L) │ │ Tab Completion │
│ Composer (Cmd+I) │ │ Apply from Chat │
│ Agent Mode │ │ (diff application) │
│ Inline Edit (Cmd+K) │ │ │
└──────────────────────┘ └──────────────────────┘
Tab Completion and Apply always use Cursor's proprietary models. You cannot route these through your own API key.
Cost Management
Monitoring Usage
With BYOK, you pay the provider directly. Monitor costs at:
- OpenAI: platform.openai.com/usage
- Anthropic: console.anthropic.com/settings/billing
- Azure: Azure Cost Management portal
Setting Spending Limits
Set monthly spending limits at the provider level:
- OpenAI: Settings > Limits > Set monthly budget
- Anthropic: Settings > Limits > Set spending limit
- Azure: Create budget alerts in Azure Cost Management
Cost-Saving Strategies
- Use Auto mode: Cursor selects cheaper models for simple tasks
- Default to Sonnet/GPT-4o: Reserve Opus/o1 for hard problems
- Shorter context: Use
@Filesnot@Codebasewhen you know the location - Fewer round-trips: Write detailed prompts to reduce back-and-forth
Approximate Token Costs (as of early 2026)
| Model | Input (per 1M tokens) | Output (per 1M tokens) |
|---|---|---|
| GPT-4o | $2.50 | $10.00 |
| GPT-4o-mini | $0.15 | $0.60 |
| Claude Sonnet | $3.00 | $15.00 |
| Claude Opus | $15.00 | $75.00 |
| o1 | $15.00 | $60.00 |
A typical Composer session generating multi-file code uses 5K-20K tokens.
Security Best Practices
Key Storage
Cursor stores API keys locally in its settings database:
- macOS:
~/Library/Application Support/Cursor/ - Linux:
~/.config/Cursor/ - Windows:
%APPDATA%\Cursor\
Keys are stored in the local Cursor configuration, not in project files. They do not sync between machines.
Rotation
- Generate a new key at the provider
- Update the key in
Cursor Settings>Models - Revoke the old key at the provider
- Verify Chat/Composer work with the new key
Team Key Management
For teams using BYOK:
- Individual keys: Each developer uses their own key. Simplest setup, hardest to audit.
- Shared project key: Create a project-scoped key at the provider. Share via secure channel. Track usage per project.
- Azure gateway: Route all requests through a central Azure OpenAI deployment. Full audit logging, spending controls, model governance.
Troubleshooting
| Error | Cause | Fix |
|---|---|---|
401 Unauthorized | Invalid or expired API key | Regenerate key at provider |
429 Rate Limited | Too many requests | Wait, or upgrade provider plan |
403 Forbidden | Key lacks model access | Enable model access at provider |
| Model not appearing | Key not saved or wrong provider | Re-enter key in Cursor Settings |
| Azure connection refused | Wrong endpoint or API version | Verify endpoint URL and version |
| Slow responses with BYOK | Provider rate limits apply | Check provider dashboard |
Enterprise Considerations
- Compliance: BYOK routes requests directly to the provider, bypassing Cursor's infrastructure. Verify this meets your data governance requirements.
- Azure private endpoints: Enterprise Azure deployments can use private endpoints for network-level isolation
- Key rotation policy: Implement quarterly key rotation as standard practice
- SSO + BYOK: Team admins can configure shared BYOK keys via the admin dashboard (Enterprise plan)
Resources
When not to use it
- →When using Cursor's Tab Completion feature.
- →When using Cursor's Apply from Chat feature.
Limitations
- →Tab Completion always uses Cursor's proprietary models.
- →Apply from Chat always uses Cursor's proprietary models.
How it compares
This workflow allows direct payment to AI model providers and access to models not included in Cursor's subscription, unlike relying solely on Cursor's default model access.
Compared to similar skills
cursor-api-key-management side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| cursor-api-key-management (this skill) | 1 | 25d | Review | Beginner |
| 1password | 27 | 2mo | Review | Intermediate |
| security-compliance | 19 | 7mo | Review | Advanced |
| information-security-manager-iso27001 | 11 | 7mo | Review | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
1password
openclaw
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.
security-compliance
davila7
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and risk assessments, managing security operations and incident response, and embedding security throughout the SDLC.
information-security-manager-iso27001
davila7
Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies. Provides ISMS implementation, cybersecurity risk assessment, security controls management, and compliance oversight. Use for ISMS design, security risk assessments, control implementation, and ISO 27001 certification activities.
cursor-sso-integration
jeremylongshore
Configure SSO and enterprise authentication in Cursor. Triggers on "cursor sso", "cursor saml", "cursor oauth", "enterprise cursor auth", "cursor okta". Use when working with cursor sso integration functionality. Trigger with phrases like "cursor sso integration", "cursor integration", "cursor".
springboot-security
affaan-m
Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
django-security
affaan-m
Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.