Enter the OpenAI API key
Store the provider credential used to construct the OpenAI client. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.
Where to goAdmin Area → Setup → Settings → AI → OpenAI
Before you start
- Use an account with Settings: Edit and confirm the intended record or setting before making a change.
- Follow the exact route above. If the screen or action is absent, check module activation, ownership and permissions rather than using another person’s account.
- Use controlled test data for configuration, integration, email, AI, payment, portal or automation changes before production-wide use.
What you’ll accomplish
Store the provider credential used to construct the OpenAI client. The instructions reflect the supplied module’s registered menus, controller actions, views, settings and code-backed validation flow.
Follow these steps
- Go to Admin Area → Setup → Settings → AI → OpenAI.
- Select the exact record or option described in this guide.
- Complete the displayed fields or action using the rules below.
- Save or submit once and resolve any validation response.
- Check the resulting record, status, file, notification or integration effect.
Fields and options to review
OpenAI API keyPassword-type settings field; the stored value is supplied to OpenAI::factory()->withApiKey().
HTTP headersThe provider sends Content-Type: application/json and Accept: application/json.
VerificationSave, then run a controlled AI request; a bad or missing key is surfaced through the provider error path.
Rules the system enforces
- The module does not implement key generation, expiry, rotation or usage metadata.
- Treat the setting as a secret and restrict access to settings administrators.
How to confirm it worked
- The supported enter the openai api key flow completes without bypassing permission or validation checks.
- The resulting record, setting, status, file, delivery event or external response is visible from the relevant workspace.
- Unexpected validation, provider or linked-record errors are investigated before retrying.
Security, privacy and operational checks
- Restrict the API key and AI settings to authorised administrators.
- Do not submit confidential, special-category or unnecessary personal data to the external AI provider.
- Check generated text before using it in customer, staff, legal, financial or compliance communication.
- Monitor provider billing and retention independently because this module has no built-in cost dashboard.
Continue with related guidance
Was this guide useful?Your response is stored only in this browser.
