# Add a vendor key (/docs/getting-started/vendor-keys)



GridRouter calls each vendor with **your** account on that vendor. At launch there are no managed
vendor accounts, so a vendor you have not connected returns
`403 vendor_key_required`, naming the vendor to add.

## Add a key [#add-a-key]

1. Open Settings → **Vendor keys** (`/settings/vendors`).
2. Pick the vendor and paste its API key. The dialog says where the key lives in the vendor's own
   dashboard (for Hunter: account menu → API).
3. Optionally choose **Test connection** first. Where the vendor has a free, read-only endpoint
   (usually its credit balance), GridRouter calls it with the key without storing anything.
4. **Save**. The stored key is tested once more and its status shows in the list.

Each vendor has a **primary** and an optional **fallback** key. A call uses the primary; when the
primary's rate limit or circuit breaker refuses, it moves to the fallback. **Swap** makes the
fallback the primary.

## What GridRouter stores [#what-gridrouter-stores]

* The secret, sealed with AES-256-GCM under a data key that only your workspace's vault can
  unwrap. It is write-only: no API, dashboard page or log ever returns it.
* A label, the last four characters, the last test result and when the key was last used.

Calls on your key are never charged by GridRouter (`cost_micro` is `0`). Your vendor bills you as
usual, and the log shows whether it billed each call by its own rules:
see [billing verification](/docs/concepts/billing-verification).

## From the API [#from-the-api]

Vendor keys are managed with the `credentials:write` scope:
[add](/docs/api/access/credentials_put), [test before saving](/docs/api/access/credentials_verify),
[test a stored key](/docs/api/access/credentials_test), [swap](/docs/api/access/credentials_swap)
and [remove](/docs/api/access/credentials_remove).

