Agent skill

Cursor API Key Management

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Configure BYOK API keys for OpenAI, Anthropic, Google, Azure, and custom models in Cursor.

MITAuto-check passedSecurity

Install Cursor API Key Management

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill cursor-api-key-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace cursor-api-key-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/cursor-api-key-management .claude/skills/cursor-api-key-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cursor-api-key-management
GitHub stars
2.8k
Token cost
~2.1k tokens
SKILL.md length
914 words
Files
10 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Configure BYOK API keys for OpenAI, Anthropic, Google, Azure, and custom models in Cursor.

  • Works in 4 steps: Issue one scoped key per owner or… → Configure it through the approved… → Set provider spending/rate controls,… → …
  • Cursor openai key
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 9 more sections
  • Calls cursor; reaches api.together.xyz

What it does

Cursor API Key Management is an agent skill from jeremylongshore/tons-of-skills-marketplace. Configure BYOK API keys for OpenAI, Anthropic, Google, Azure, and custom models in Cursor. Triggers on "cursor api key", "cursor openai key", "cursor anthropic key", "own api key cursor", "BYOK cursor", "cursor azure key".

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files (for example `references/configuration-methods.md`, `references/cost-management.md` and `references/errors.md`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Cryptography and Cloud cost optimization. It works with OpenAI, Microsoft Azure and Azure OpenAI. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Cursor openai key
  • Cursor anthropic key
  • Own api key cursor
  • Cursor azure key

Example prompts

  • “cursor api key”
  • “cursor openai key”
  • “cursor anthropic key”
  • “/cursor-api-key-management”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(cmd:*)

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Issue one scoped key per owner or approved service through the provider/secrets manager.
  2. Configure it through the approved UI/injection path; never commit it, paste it into rules, or share it between users.
  3. Set provider spending/rate controls, review usage, and rotate on schedule or suspected exposure.
  4. Revoke first, then investigate, when a key is lost, leaked, or no longer required.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(cmd:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cursor

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.together.xyz

    Also links to:

    • platform.openai.com
    • console.anthropic.com
    • aistudio.google.com
    • docs.cursor.com
    • cursor.com
    • platform.claude.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Cursor API Key Management loads about 2.1k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 62 tokens; SKILL.md has 914 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 914 words, ~2,115 tokens.

Download SKILL.mdSave it as .claude/skills/cursor-api-key-management/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
cursor-api-key-management
description
Configure BYOK API keys for OpenAI, Anthropic, Google, Azure, and custom models in Cursor. Triggers on "cursor api key", "cursor openai key", "cursor anthropic key", "own api key cursor", "BYOK cursor", "cursor azure key".
allowed-tools
Read, Write, Edit, Bash(cmd:*)
compatibility
Designed for Claude Code
version
1.19.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, cursor, api, authentication

Cursor API Key Management

Overview

Manage any Cursor BYOK/provider credentials as individual, least-privilege secrets with approved routing, ownership, rotation, spending limits, and exposure response.

Prerequisites

  • An approved provider/model route, named key owner, secrets-manager integration, and budget policy.
  • Confirmation that BYOK is permitted for the intended data classification and tenant configuration.

Instructions

  1. Issue one scoped key per owner or approved service through the provider/secrets manager.
  2. Configure it through the approved UI/injection path; never commit it, paste it into rules, or share it between users.
  3. Set provider spending/rate controls, review usage, and rotate on schedule or suspected exposure.
  4. Revoke first, then investigate, when a key is lost, leaked, or no longer required.

Output

  • An attributable, scoped credential with rotation, budget, and revocation evidence.

Examples

Create a personal provider key in the approved secret manager, configure it only in the local secure setting, verify a low-cost non-sensitive request, and confirm usage attribution. If it appears in logs, chat, or git, revoke it immediately and replace it; do not attempt to redact history before revocation.

Configure Bring Your Own Key (BYOK) for AI model providers in Cursor. BYOK lets you use your own API keys to bypass Cursor's monthly quota, pay per token directly, and access models not included in Cursor's subscription.

Supported Providers

ProviderKey FormatModels Available
OpenAIsk-proj-... or sk-...GPT-4o, GPT-4o-mini, o1, o3, GPT-5
Anthropicsk-ant-api03-...Claude Sonnet, Claude Opus, Claude Haiku
GoogleAIzaSy...Gemini 2.5 Pro, Gemini Flash
Azure OpenAIAzure portal keyAny deployed Azure OpenAI model
AWS BedrockIAM credentialsClaude, Titan, Llama models
OpenAI-compatibleVariesOllama, LM Studio, Together AI, etc.

Configuration Steps

OpenAI
  1. Go to platform.openai.com/api-keys
  2. Create a new API key (project-scoped recommended)
  3. In Cursor: Cursor Settings > Models > check Use own API key
  4. Paste key in the OpenAI API Key field
  5. Select model from dropdown (e.g., gpt-4o)
Anthropic
  1. Go to console.anthropic.com/settings/keys
  2. Create a new API key
  3. In Cursor: Cursor Settings > Models > check Use own API key
  4. Paste key in the Anthropic API Key field
  5. Select Claude model from dropdown
Google (Gemini)
  1. Go to aistudio.google.com/apikey
  2. Create API key
  3. In Cursor: Cursor Settings > Models > check Use own API key
  4. Paste key in the Google API Key field
Azure OpenAI

Azure requires additional configuration beyond a simple API key:

  1. In Azure Portal: create an Azure OpenAI resource
  2. Deploy your desired model (e.g., gpt-4o)
  3. Note the Endpoint URL and API Key from the resource
  4. In Cursor: Cursor Settings > Models:
Azure Configuration:
  API Key:        xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
  Endpoint:       https://your-instance.openai.azure.com
  Deployment:     your-gpt4o-deployment-name
  API Version:    2024-10-21
Custom OpenAI-Compatible Endpoints

For self-hosted models (Ollama, vLLM) or third-party providers:

  1. Cursor Settings > Models > Add Model
  2. Model name: e.g., llama-3.1-70b
  3. Check Override OpenAI Base URL
  4. Enter base URL:
Ollama:        http://localhost:11434/v1
LM Studio:    http://localhost:1234/v1
Together AI:  https://api.together.xyz/v1
  1. Enter API key if required by the provider
  2. The model appears in the Chat/Composer model dropdown

What BYOK Covers (and What It Does Not)

BYOK key used:                    Cursor model (always):
┌──────────────────────┐         ┌──────────────────────┐
│  Chat (Cmd+L)        │         │  Tab Completion      │
│  Composer (Cmd+I)    │         │  Apply from Chat     │
│  Agent Mode          │         │  (diff application)  │
│  Inline Edit (Cmd+K) │         │                      │
└──────────────────────┘         └──────────────────────┘

Tab Completion and Apply always use Cursor's proprietary models. You cannot route these through your own API key.

Cost Management

Monitoring Usage

With BYOK, you pay the provider directly. Monitor costs at:

Setting Spending Limits

Set monthly spending limits at the provider level:

  • OpenAI: Settings > Limits > Set monthly budget
  • Anthropic: Settings > Limits > Set spending limit
  • Azure: Create budget alerts in Azure Cost Management
Show full SKILL.md (362 more words)Show less
Cost-Saving Strategies
  1. Use Auto mode: Cursor selects cheaper models for simple tasks
  2. Default to Sonnet/GPT-4o: Reserve Opus/o1 for hard problems
  3. Shorter context: Use @Files not @Codebase when you know the location
  4. Fewer round-trips: Write detailed prompts to reduce back-and-forth
Approximate Token Costs (as of early 2026)
ModelInput (per 1M tokens)Output (per 1M tokens)
GPT-4o$2.50$10.00
GPT-4o-mini$0.15$0.60
Claude Sonnet$3.00$15.00
Claude Opus$15.00$75.00
o1$15.00$60.00

A typical Composer session generating multi-file code uses 5K-20K tokens.

Security Best Practices

Key Storage

Cursor stores API keys locally in its settings database:

  • macOS: ~/Library/Application Support/Cursor/
  • Linux: ~/.config/Cursor/
  • Windows: %APPDATA%\Cursor\

Keys are stored in the local Cursor configuration, not in project files. They do not sync between machines.

Rotation
  1. Generate a new key at the provider
  2. Update the key in Cursor Settings > Models
  3. Revoke the old key at the provider
  4. Verify Chat/Composer work with the new key
Team Key Management

For teams using BYOK:

  • Individual keys: Each developer uses their own key. Simplest setup, hardest to audit.
  • Shared project key: Create a project-scoped key at the provider. Share via secure channel. Track usage per project.
  • Azure gateway: Route all requests through a central Azure OpenAI deployment. Full audit logging, spending controls, model governance.

Troubleshooting

ErrorCauseFix
401 UnauthorizedInvalid or expired API keyRegenerate key at provider
429 Rate LimitedToo many requestsWait, or upgrade provider plan
403 ForbiddenKey lacks model accessEnable model access at provider
Model not appearingKey not saved or wrong providerRe-enter key in Cursor Settings
Azure connection refusedWrong endpoint or API versionVerify endpoint URL and version
Slow responses with BYOKProvider rate limits applyCheck provider dashboard

Enterprise Considerations

  • Compliance: BYOK routes requests directly to the provider, bypassing Cursor's infrastructure. Verify this meets your data governance requirements.
  • Azure private endpoints: Enterprise Azure deployments can use private endpoints for network-level isolation
  • Key rotation policy: Implement quarterly key rotation as standard practice
  • SSO + BYOK: Team admins can configure shared BYOK keys via the admin dashboard (Enterprise plan)

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (references) in skills/.curated/cursor-api-key-management of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/configuration-methods.md
  • references/cost-management.md
  • references/errors.md
  • references/examples.md
  • references/implementation.md
  • references/security-best-practices.md
  • references/supported-providers.md
  • references/team-key-management.md
  • references/troubleshooting.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Cursor API Key Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cursor API Key Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cursor API Key Management this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.1kAutomated safety check: PassMIT
Capacitymicrosoft/GitHub-Copilot-for-Azure2551 repos~1.7kAutomated safety check: PassMIT
Deploy Modelmicrosoft/GitHub-Copilot-for-Azure2551 repos~1.8kAutomated safety check: PassMIT
Teams App Developermicrosoft/work-iq1k—~1.8kAutomated safety check: NotesCustom licence
Pki Designvinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT
Azure Openai To Responsesmicrosoft/ai-agents-for-beginners77k—~6kAutomated safety check: NotesMIT

Similar skills

  • Capacity

    microsoft/GitHub-Copilot-for-Azure

    Official

    Discovers available Azure OpenAI model capacity across regions and projects.

    255 GitHub starsUsed in 1 repo~1.7k tokens
    DevOps & CloudAuto-check passed
  • Deploy Model

    microsoft/GitHub-Copilot-for-Azure

    Official

    Unified Azure OpenAI model deployment skill with intelligent intent-based routing.

    255 GitHub starsUsed in 1 repo~1.8k tokens
    DevOps & CloudAuto-check passed
  • Teams App Developer

    microsoft/work-iq

    Official

    Build, test, and deploy code-based Teams apps using the M365 Agents Toolkit CLI.

    1k GitHub stars~1.8k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Pki Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments.

    175 GitHub stars~2.1k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Azure Openai To Responses

    microsoft/ai-agents-for-beginners

    Official

    Migrate Python apps from Azure OpenAI Chat Completions to the Responses API.

    77k GitHub stars~6k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check: notes
  • Azure Openai To Responses

    microsoft/ai-agents-for-beginners

    Official

    Shift Python apps dem from Azure OpenAI Chat Completions go Responses API.

    77k GitHub stars~6k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Cursor API Key Management

What does Cursor API Key Management do?

Configure BYOK API keys for OpenAI, Anthropic, Google, Azure, and custom models in Cursor. Cursor API Key Management is an agent skill from jeremylongshore/tons-of-skills-marketplace. Configure BYOK API keys for OpenAI, Anthropic, Google, Azure, and custom models in Cursor.

When should I use Cursor API Key Management?

Cursor API Key Management fits situations like: Cursor openai key; Cursor anthropic key; own api key cursor; Cursor azure key.

How do I install Cursor API Key Management in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill cursor-api-key-management -a claude-code`. Or copy the skill folder (skills/.curated/cursor-api-key-management in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/cursor-api-key-management in your project. Claude Code loads it when a task matches its description.

How do I install Cursor API Key Management in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill cursor-api-key-management -a codex`. Or copy the skill folder (skills/.curated/cursor-api-key-management in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/cursor-api-key-management in your project. Codex loads it when a task matches its description.

Can I use Cursor API Key Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill cursor-api-key-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cursor-api-key-management, .gemini/skills/cursor-api-key-management, .github/skills/cursor-api-key-management and .opencode/skills/cursor-api-key-management in your project.

What does Cursor API Key Management need to run?

Going by SKILL.md and its folder, Cursor API Key Management needs the command-line tools its instructions call (cursor). Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(cmd:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Cursor API Key Management access the network?

SKILL.md names 7 domains. In commands or code: api.together.xyz; the agent is likely to contact it when it follows the instructions. As links in the text: platform.openai.com, console.anthropic.com, aistudio.google.com, docs.cursor.com, cursor.com and platform.claude.com. This is read from the text; nothing was executed.

Is Cursor API Key Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cursor API Key Management use?

Cursor API Key Management is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cursor API Key Management use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.

What are the alternatives to Cursor API Key Management?

Skills that share tags, products or a category with Cursor API Key Management: Capacity (microsoft/GitHub-Copilot-for-Azure, 255 stars), Deploy Model (microsoft/GitHub-Copilot-for-Azure, 255 stars), Teams App Developer (microsoft/work-iq, 1k stars) and Pki Design (vinayaklatthe/microsoft-security-skills, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cursor API Key Management?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.