1
Customer application
The customer calls Planck’s OpenAI-compatible endpoint with its own
sk-cp-... Planck key.2
Planck gateway
Planck identifies the customer workspace, applies its limits and access
policy, and records its usage separately.
3
Private upstream model
Planck routes the request through the consultancy-owned provider credential.
The customer never receives that credential.
Fireworks private or fine-tuned models
Fireworks is supported as a normal BYOK provider. The model does not need to be in Planck’s public registry: an unknown model with an explicit provider route stays BYOK-only and is forwarded with the exact upstream model ID. In Enterprise → Customer Portal:- Create or open a customer.
- Open Upstream model and connect a Fireworks API key owned by the consultancy.
- Pin the exact model route. For example:
- Open Planck keys, create a customer key, and copy it once.
- Give the Planck key and model route to the customer. Do not give them the Fireworks key.
Customer Portal keys do not fall back to Planck-through-billing. They use the
upstream credential assigned by the consultancy, which keeps costs and
provider ownership under the consultancy’s control.
What is isolated per customer
- Planck API keys and revocation
- Request and cost usage
- Monthly request and cost limits
- Members and workspace access
- Model-access policies when configured