How bring-your-own OpenAI key works for dashboard AI
Setup
September 29, 2026
The short answer
Save your own OpenAI key if you want DashCanopy’s AI features. Every paid plan lists those features as bring-your-own-key. DashCanopy uses the saved key server-side when you run a compatible action. OpenAI bills the OpenAI account that owns the key. The Starter, Pro, or Agency price does not include a pool of model usage. If you do not save a key, use the rest of the dashboard — health checks, stats, alerts — and leave the AI actions alone.
That split is the whole model. Monitoring does not require the key. AI actions do.
What the product says it does with the key
The privacy-by-design page describes the flow in plain language. You trigger an AI action in the dashboard. The server prepares the provider request and uses the configured key. The page names actions such as Diagnose Site and Find Content Gaps as examples of tools that follow that path. Settings for keys describe the OpenAI key as the way to power site diagnosis, content gap analysis, and weekly briefings. The landing page also describes a content brief, a site-description assist, anomaly explanations, and the Dash agent. Use the screen in front of you for the exact list on the day you click. This article will not add tools that are not shown there.
The same privacy page says BYOK keys are stored encrypted, and that provider-account billing applies. Read Privacy by Design for that description, and the main privacy policy for how the account itself is handled. Do not take this article as a privacy agreement. The agreement is the policy you accept in the product.
“Server-side” means your browser is not the thing calling OpenAI with the key sitting in a front-end script you can view-source. You still should not paste the key into chat, email, or a ticket. Put it in the key settings the product provides, under the BYOK or secrets area for your account. If the product offers a way to remove the key, removing it is how you stop new AI calls that depend on it. Do that when someone who knew the key leaves, and rotate the key at OpenAI as well so a copied value stops working.
What you pay, and to whom
Plan prices on the pricing page are Starter $19 per month, Pro $69, and Agency $149, with annual amounts of $190, $690, and $1,490. Those prices cover the plan’s monitoring features. They are not an OpenAI invoice.
OpenAI’s own pricing applies to the model calls the key makes. It can change, and it depends on which model the feature uses and how much text you send. DashCanopy does not publish a per-diagnosis dollar amount in the pricing table, so this article will not invent one. Check the provider’s current rates in your OpenAI account before you run a large batch of sites through an AI action. A five-site Starter portfolio and a large Agency roster do not cost the same at the provider, even though both plans “include AI features” in the sense that both allow a key.
You might be thinking the key is a workaround you can skip with a shared demo key. Do not look for one. The published model is your key. A shared key you do not control is a billing and privacy problem on an account you cannot revoke.
Which plan you need
You do not need Pro or Agency only to save an OpenAI key. Starter lists AI features with bring-your-own OpenAI key, and so do the higher tiers. Choose the plan from site count, check interval, webhooks, SMS, seats, and the API, using the plan guide. Then add the key if you want the AI actions.
Agency’s feature list adds a line about bring-your-own-key support for the keys that plan lists. The settings screen also has slots for other credentials, such as Twilio for SMS and a Stripe secret for revenue tracking. Those are separate keys for separate jobs. An OpenAI key does not send SMS. A Twilio token does not run Diagnose Site. Fill in the key for the job you are turning on, and leave the others empty until you need them.
A safe way to try one action
Add a site and get a normal health result first. AI is a poor way to discover that the URL was wrong. The first-check sequence is in add a site and read the first health check.
Then save the OpenAI key and run one action on one site. Read the result as a draft from a model, not as a measurement. A health check is a measurement: the URL answered, or it did not, in a known number of seconds. A diagnosis, a content gap list, or a briefing is text generated from the inputs the feature sends. It can be useful and it can be wrong. Confirm anything you might tell a client or publish against the site itself and against the tile.
If the action fails, check three ordinary causes before you blame the model. The key was rejected or revoked in the provider account. The provider account has no way to pay. The feature’s inputs were empty because the site has no stats yet. Fix the key and the site data, and run the single test again. Do not paste the key into the error report.
What not to send
Do not use an AI action as a place to upload a customer database, a private key, or a medical or legal file. The monitoring dashboard is the wrong tool for those documents, and a model prompt is the wrong archive. Send the smallest site context the feature asks for.
Do not treat a generated briefing as the weekly review. The weekly review is you, reading visitor and revenue tiles against each site’s job, as the weekly review describes. A briefing can sit beside that. It does not replace the three lines you write when a number breaks its pattern.
Do not put the key in the WordPress plugin’s settings. The plugin wants the DashCanopy API key that starts with dck_, which identifies your dashboard account to the plugin. That is a different secret from the OpenAI key. Mixing them will fail the plugin and risk exposing the wrong credential in the wrong admin screen.
Limits
The key does not make checks faster. Intervals stay on the plan. The key does not raise the site cap. The key does not guarantee a particular model, a particular uptime for the AI provider, or a correct answer. If the provider is having an incident, the AI action waits, and the health checks continue, because they do not depend on that provider.
If you are unsure whether a workflow is appropriate for data you have, stop and read the privacy policy and the provider’s terms before you run it. This article is a product explanation, not legal advice.
Questions about the OpenAI key
Will I be charged by DashCanopy for each AI request?
The pricing page does not list a per-request DashCanopy fee for AI. Provider charges stay with the provider account. You still pay your plan price for the subscription. Confirm both invoices — DashCanopy’s through Stripe, and the provider’s in the provider billing page — the first month you use a key.
Can I use AI features during the 7-day trial?
The features are listed on the paid plans, which show a 7-day trial. Saving a key during the trial still spends provider credit if you run an action. Trial terms, including the card Stripe requires, are confirmed at checkout. Cancel from Manage billing if you stop before the trial ends.
What if I only want uptime monitoring?
Do not add an OpenAI key. Add sites, read the tiles, and use email alerts. The dashboard’s monitoring path does not need the key at all.