API Keys
Give agents model access with your own provider keys, from the environment or in code.
An agent calls the model from your worker, so its keys stay in your backend and never enter the sandbox. It looks for a key in this order:
apiKeyspassed topi().- The
credentialsActor, when your users bring their own subscriptions. - The worker’s environment.
The agent never reads Pi’s local ~/.pi/agent/auth.json or models.json.
Environment variables
Set the key for your model provider in the environment of the process that runs your Actors:
ANTHROPIC_API_KEY=sk-ant-...
Pi reads the provider-named variable, such as ANTHROPIC_API_KEY, OPENAI_API_KEY, GEMINI_API_KEY, or OPENROUTER_API_KEY. See Pi’s provider list for the rest.
Keys in code
Pass apiKeys to set keys by provider id in code, for example when they come from a secret manager or differ per deployment. Here it’s added to the Quickstart agent. The keys stay in the Actor’s memory and win over every other source.
import { pi } from "@rivet-dev/pi";
import { agentOSProvider } from "@rivet-dev/sandbox-adapter/agentos";
import { setup } from "rivetkit";
const agent = pi({
model: "anthropic/claude-opus-5-5",
sandbox: agentOSProvider(),
apiKeys: { anthropic: process.env.MY_ANTHROPIC_KEY ?? "" },
});
export const registry = setup({ use: { agent } });
registry.start();
Custom providers
To use a provider Pi does not know, register it with providers, in the shape of Pi’s models.json, and give it a key the same way.
Next: Custom Tools, tools that run in your backend.