> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pinework.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Add a provider key or subscription

> Agents run only when Pinework holds a credential for the model's vendor: an API key, a saved subscription, or a harness signed in on your device.

A **provider key** is a credential for a model vendor that Pinework uses when your agents run. It is either an API key or a subscription. This guide connects one so your agents can run.

## Pick the kind you need

| You have | What to connect | Who can use it |
| - | - | - |
| Claude Code or Codex signed in on your Mac | Nothing in Pinework | Agents that run on that Mac |
| A Claude or ChatGPT plan | A saved subscription | Agents you own, on device or in the cloud |
| A vendor API key | An API key | Every agent in the workspace |

A harness signed in on your Mac stays on that Mac. A saved subscription is the only kind of subscription a cloud run can use. When both a subscription and an API key are ready, Pinework uses the subscription first.

## Before you start

* You can sign in to the Pinework dashboard.
* For the CLI tab, you have run `pinework login`.
* Only a signed-in person can connect a subscription. An agent cannot.

## Add an API key

The dashboard offers Anthropic, Deep Infra, Google and OpenAI. Cursor has its own row because it runs its own models.

<Tabs>
  <Tab title="Dashboard">
    <Steps>
      <Step title="Open the Providers page">
        Open the account menu at the bottom of the sidebar and click **Settings**. Then click **Providers**.
      </Step>

      <Step title="Pick the vendor">
        In **Your API keys**, find the **Add provider** row. Pick the vendor in the **Provider** box.
      </Step>

      <Step title="Paste the key">
        Paste the key into **API key** and click **Connect**. The key appears in the **Your API keys** list with a masked hint and today's date.
      </Step>
    </Steps>

    For Cursor, paste the key into the **Cursor** row below and click **Save key**.
  </Tab>

  <Tab title="CLI">
    <Steps>
      <Step title="Save the key">
        Put the provider name before `set-key`.

        ```bash theme={null}
        pinework provider anthropic set-key --api-key sk-ant-...
        ```

        You see `Connected provider "anthropic" successfully.`
      </Step>

      <Step title="Check it">
        ```bash theme={null}
        pinework provider anthropic status
        ```

        The output shows `"connected": true` and lists the key.
      </Step>
    </Steps>
  </Tab>
</Tabs>

Pinework does not test an API key when you save it. A wrong key shows up when a run fails.

## Connect a subscription

A saved subscription belongs to you alone. Nobody else in the workspace can see it or use it. It serves the agents you own.

<Tabs>
  <Tab title="Dashboard">
    <Steps>
      <Step title="Start the sign-in">
        On the **Providers** page, find **Connect a subscription** under **Subscriptions**. Pick **Anthropic** or **OpenAI** in the **Provider** box. **Name this subscription** is optional.
      </Step>

      <Step title="Sign in to Claude (Anthropic)">
        Type your **Claude account email** and click **Connect**. The Anthropic sign-in page opens in a new tab. Sign in with that account, then copy the code it shows. Paste it into **Code** and click **Connect subscription**.
      </Step>

      <Step title="Sign in to ChatGPT (OpenAI)">
        Click **Connect**. The sign-in page opens on one of your online computers, so be at that computer. Finish signing in to ChatGPT there. Nothing needs copying.
      </Step>

      <Step title="Confirm it landed">
        You see a "Connected Anthropic" or "Connected OpenAI" toast. The subscription appears in the **Subscriptions** list.
      </Step>
    </Steps>

    The sign-in has a countdown. Nothing is saved until you finish. If it runs out, click **Start again**.
  </Tab>

  <Tab title="CLI">
    <Steps>
      <Step title="Connect a Claude subscription">
        Run `claude setup-token` and save only the token line to a file. Then pass that file.

        ```bash theme={null}
        pinework provider-key connect anthropic \
          --auth-method subscription \
          --account-email you@example.com \
          --token-file ./claude-token.txt
        ```

        Without `--token-file`, the CLI tries to run the Claude sign-in for you on this computer. If it cannot, it asks for the token at a hidden prompt.
      </Step>

      <Step title="Connect a ChatGPT subscription">
        ```bash theme={null}
        pinework provider openai login --browser
        ```

        A browser opens on this computer. Finish signing in to ChatGPT there. The CLI waits and then prints `"connected": true`.
      </Step>

      <Step title="Check it">
        ```bash theme={null}
        pinework provider-key list --auth-method subscription
        ```

        Each saved subscription appears with its status.
      </Step>
    </Steps>
  </Tab>
</Tabs>

## Use a harness signed in on your Mac

If your agents run on your Mac, you may not need to save anything. Sign in to the harness itself, for example with `/login` in Claude Code. Pinework reads that sign-in where the agent runs.

The **Harnesses** section on the **Providers** page shows each harness on each connected device. It says whether each one is signed in and ready. See [Run agents on your Mac](/guides/run-on-your-mac).

## Troubleshooting

**The ChatGPT sign-in says no computer of yours is online.** The browser sign-in needs a computer running the Pinework app. Open the app and try again. Or click **Use a code instead** and enter the code on any device. The code needs device-code authorization turned on in your ChatGPT security settings. In the CLI, run `pinework provider openai login --device-code`.

**The sign-in says port 1455 is in use.** Your own `codex login` is probably holding it. Close it and connect again.

**A key shows "Paused until" a time.** The vendor rate-limited that key. Pinework skips it until then. Click **Reopen now** to use it again at once. In the CLI, run `pinework provider-key cooldown clear <provider-key-id>`.

**A key row shows failures and an error message.** The row counts successes and failures over recent hours. It shows the last error. A key marked "Credential invalid" or "Credential expired" needs replacing. Remove it and add a fresh one.

**A second subscription asks for a name.** You already saved one for that vendor. A new name adds the second one. Reusing a saved name replaces that one.

<CardGroup cols={2}>
  <Card title="Create an agent" href="/guides/create-an-agent">
    Pick the model your new credential unlocks.
  </Card>

  <Card title="Access modes" href="/concepts/access-modes">
    How subscriptions and API keys differ.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.