AI_ALLOWANCE_EXHAUSTED.
Prerequisites
- You are an organisation admin with the
ai.managepermission. - An OpenRouter account at openrouter.ai with credits available.
Add the Key
1
Create an API key at OpenRouter
Sign in at openrouter.ai and create a new API key from the Keys page. Copy the key - it starts with
sk-or-.2
Save the key in Ankra
--api-key. Ankra validates the key live against OpenRouter before storing it. Two errors can come back:- Invalid key - the key was rejected by OpenRouter. Check you copied the full key and that it has not been revoked.
- No remaining credits - the key is valid but its OpenRouter account has no credits left. Top up at OpenRouter, then save again.
3
Activate the provider
4
Verify
ankra ai status shows the active provider and a masked preview of the stored key (for example sk-or-...wxyz). Open the AI Assistant (⌘J / Ctrl+J) and send a message - the run appears in your OpenRouter activity.In the portal
Go to AI → Settings → Models, expand OpenRouter (your own key), paste thesk-or-... key and save. The same validation runs, and the row then shows the masked preview. If you also hold an Anthropic key, Prefer this credential decides which of the two runs the calls both could serve.
Rotating the Key
Save a new key over the old one -ankra ai openrouter set again, or the same row in the portal. The new key goes through the same live validation, and the old one is replaced on save - no downtime and no provider switch needed.
Removing the Key
Removing the key (ankra ai openrouter remove, or Remove in the portal) switches the organisation back to the Ankra-managed provider, and the free monthly allowance rules apply again. If the allowance is already exhausted for the month, AI features pause until it resets or you add a key again.
Security
- The key is stored only in Ankra’s secret store (HashiCorp Vault or OpenBao) - never in the database.
- It is never shown again after saving; Ankra only ever displays a masked preview like
sk-or-...wxyz. - Viewing the preview, saving, and removing the key all require the
ai.managepermission. - The key is never included in exports.
Related Pages
- Models and Cost - every provider mode, the default models, and what the free allowance covers