Connect your Anthropic and OpenAI keys for AI agents
Cet article n'est pas encore traduit : il s'affiche en anglais.
Owners add an Anthropic key for Claude Code and an OpenAI key for Codex under Integrations. Keys are encrypted and never enter a candidate's sandbox.
Claude Code and Codex run on your organization's own vendor accounts. An owner connects them once under Integrations → AI assistants: an Anthropic key powers Claude Code, and an OpenAI key powers Codex. Usage is billed by Anthropic or OpenAI to your account, not by Kendor.
Who can manage keys
Only organization Owners can add, test, replace or remove a key, and only owners can set the monthly token cap. Editors and Viewers can open the same pages to see what is connected, with the note "Only organization owners can change keys."
Editors can still switch agents on for a screen or a live coding interview once a key exists.
Add a key
- Open Integrations in the sidebar.
- Under AI assistants, choose Connect on the Claude Code or Codex card.
- Paste the key into Anthropic API key (create one at console.anthropic.com) or OpenAI API key (create one at platform.openai.com).
- Choose Save.
Kendor checks the key with the vendor before saving it. If the vendor says the key is invalid, it isn't stored and you see the error under the field. Once saved, the card shows "Key ends in …" with the last four characters, and the agent's page has Test connection and Remove.
For Claude Code there is an optional Workspace ID field. Fill it in only if you use an organization-level Anthropic key that isn't scoped to a workspace; Anthropic then needs the workspace (wrkspc_…) on every call. Leave it empty for a workspace-scoped key.
Connect Claude Code without a key
Instead of pasting a key, you can connect your Claude Console organization through Identity federation (on the Authentication tabs of the Claude Code page). There is no key to store or rotate. The page walks you through the Claude Console's Settings → Workload identity → Connect workload wizard: copy the Issuer URL, Subject (sub) claim and Audience into it, pick a service account, run its test, then paste the Anthropic organization ID, Service account ID and Federation rule ID back into Kendor and save. The card then shows "Claude Console · no key stored".
Tip. Point the service account at an Anthropic workspace used only for Kendor. You can then see and cap candidates' spend in the Claude Console as well.
Codex connects with an OpenAI API key only.
How keys are stored
Pasted keys are encrypted at rest. After you save, Kendor only ever shows the last four characters, never the key itself. To change a key, paste a new one over it; to stop using a vendor, choose Remove.
Why keys never enter the sandbox
Candidate code is untrusted, so nothing in the sandbox holds your key. Each sandbox gets the address of Kendor's AI gateway and a token that only works for that session. When Claude Code or Codex makes a call:
- The gateway checks the session and its token budget.
- It replaces the session token with your organization's key, or with a short-lived token from your Claude Console when you use identity federation.
- It forwards the call to Anthropic or OpenAI and streams the answer back.
There is nothing in the environment for a candidate to print or copy. The gateway only forwards to Anthropic and OpenAI; it isn't a general way out to the internet.
What happens without a key
| Connected | Result |
|---|---|
| Anthropic and OpenAI | Candidates can run claude and codex |
| Anthropic only | claude works; codex answers "codex is not enabled for this assessment — use claude." |
| OpenAI only | codex works; claude answers that it isn't enabled and to use codex |
| Neither | Agents don't run, and the candidate's start page doesn't mention them |
The screen builder warns you when assistants are on but no key is connected, and a live coding interview shows which agent won't work.
Removing a key takes effect immediately. The confirmation reads: "Screens with AI assistants enabled lose this vendor immediately. Candidates mid-screen will see it as unavailable."
Which agents and models
Kendor runs two agents in the sandbox terminal: Claude Code, Anthropic's coding agent, and Codex, OpenAI's coding agent. Kendor installs and updates both, so there is nothing to set up in the challenge itself.
Kendor doesn't pick or limit the model. The agent uses the models your vendor account allows, and every call is billed to that account. Reviewers can see which model answered each turn in the AI agents tab.