API Keys
Tempest is bring-your-own-key. You enter each provider’s API key once, and Tempest hands it to the local model calls, chat bridges, and integrations that need it — never to a Tempest server. There is no Tempest cloud account, no login, no proxy.Where keys live
Keys are stored in your operating system’s credential manager under the service nametempest-byok, one entry per provider:
They are never written to
localStorage, config files, or logs. Only the model selection and the currently-active provider live in localStorage — the secret itself sits in the keychain.
Earlier releases stored keys in localStorage. On first read after upgrading, Tempest silently promotes any legacy key into the keychain and wipes the plaintext copy.
Adding a key
Two entry points:- Onboarding — the first-run flow includes a Bring your own key step where you can enter one or more provider keys before reaching the workspace.
- Settings → API Keys — one row per provider with an input, an eye toggle to reveal the masked value, an edit button, and a trash icon. The masked preview keeps the first four and last four characters (
abcd••••••••wxyz).
Supported providers
The Settings panel exposes ten provider slots:- Anthropic — Claude (Fable, Opus, Sonnet, Haiku)
- OpenAI — GPT models via the OpenAI API
- Google Gemini
- Mistral
- DeepSeek
- xAI — Grok
- Groq
- OpenRouter — access to many models with one key
- Ollama — local, no key required
- Linear — non-LLM; powers the Tasks tab Linear integration
Which features use which keys
Agents that ship their own auth (Claude Code CLI, Gemini CLI, and similar) continue to use whatever the CLI is already logged into on your machine. Tempest doesn’t touch those.