Openbook

AI configuration

Who runs the models for your organization — your own provider keys, or ours. Where the page is now, the two modes, what self hosted asks for, what managed costs, and who is allowed to change it.

Openbook does not hold your AI provider keys. Which models your organization can call, and whose account pays for them, is configured once in the Vibeforce account service — the same place that holds your sign-in, your organizations and your files. Openbook asks it a question every time something needs a model, and gets back an answer; no key ever reaches Openbook, and none ever reaches your browser.

That is why the same configuration answers in Madebook and CodeBook too. One organization, one arrangement, every product.

The page

The organization's AI is configured on its page at your Vibeforce account, under AI self hosted in that page's sidebar. To get there from Openbook, open your organization, press Members & access on its Home — the account page opens in a new tab — and choose AI self hosted.

Two other doors lead to the organization's page there: the link on the AI tokens meter at the foot of Openbook's account menu, and Go to Organization AI at Vibeforce in the help tutorials (shown to the organization's owner).

Openbook's own AI page is gone. It used to sit in the organization sidebar at /organizations/<id>/ai, as a front for the same settings. The settings were always stored at the account service; now the page is there too. Openbook keeps only what a room needs to read — the list of models a picker may offer — and its own agent gates, which moved to the organization's Settings page.

The sidebar item is called AI self hosted whichever mode you are in. It does not rename itself when you hand the models back to us — so do not read the label as a statement about the current setting. The switch at the top of the page is the statement.

The one decision

At the top of the page is a pair of cards under Who runs the models:

This decides whose key every model call is paid with. Neither mode falls back to the other.

Mode What it means
Self hosted Your own provider keys and your own models, including your own OpenAI-compatible server. The provider bills you directly.
Managed by Vibeforce The platform runs the models and pays for them. Nothing to configure, and no key of yours involved.

Neither mode falls back to the other, and that is deliberate. An organization that switched to its own key and then removed it gets a plain error naming the fix, not somebody else's bill. Equally, a managed organization never quietly reaches for a customer's key.

Switching is one click and takes effect on the next call. A toast confirms it: Vibeforce runs the models now, or This organization runs its own models now.

Managed by Vibeforce is greyed out when there is nothing to be managed by: "Nothing is on offer yet — the platform has no model configured." That means whoever operates this installation has not configured a platform key or a model catalog at the account service. Until they do, self hosted is the only working choice.

Under the two cards is the switch for personal keys: Let members run agents on their own personal API keys in this organization. It is on by default. See Reusable & personal agents for what a personal key does.

Which to pick

  • Self hosted if you already have a provider account, if your procurement or compliance people need the contract to be with the model vendor rather than with us, or if you want a model we do not offer — including one running on your own hardware.
  • Managed by Vibeforce if you would rather not hold a key at all. Nothing to paste, nothing to rotate, nothing to be invoiced for by a third party.

Self hosted

Three cards appear, in the order you need them: Provider keys, Add a model and Models. A Usage card closes the page in either mode.

Provider keys

Checked against the provider before they are stored, then encrypted. Only the last four characters are ever shown, and adding a key for a provider replaces the one it already has. Removing a key removes the models bound to it.

Choose a Provider, give it an optional Label (Production key), paste the API key, and press Add key. On success: Key verified and saved. A key the provider rejects is never kept.

Seven choices take a key here:

Provider Where the key comes from The key looks like
OpenAI platform.openai.com → API keys sk-…
Anthropic console.anthropic.com → API keys sk-ant-…
DeepSeek platform.deepseek.com → API keys sk-…
xAI (Grok) console.x.ai xai-…
Google (Gemini) aistudio.google.com → Get API key AIza…
Azure OpenAI the Azure portal, on your OpenAI resource 32 hex characters
Self-hosted / OpenAI-compatible your own server optional

Azure OpenAI and Self-hosted / OpenAI-compatible also ask for a Base URL, because neither has a fixed host — the field appears when you pick one. Azure's looks like https://<resource>.openai.azure.com/openai.

Each stored key shows its provider, its label, a hint of the key, when it was added, any error the provider last reported, and an Active tick box. The bin removes it.

  • One key per provider. Adding a second OpenAI key replaces the first.
  • Removing a key removes the models bound to it — the toast says so: Key removed — the models bound to it went with it. A model with no key behind it could never run again.
  • Unticking Active is the non-destructive way to take a provider out of service. The key and its models stay.

Without any key, the card says so: No keys yet. Without one, nothing in this organization can call a model.

What each provider can actually do

This is not uniform, and it is the thing most likely to waste an afternoon. Chat is universal; images and embeddings are not.

Provider Chat Images Embeddings
OpenAI yes yes yes
Google (Gemini) yes yes yes
Azure OpenAI yes yes, deployment-addressed yes, deployment-addressed
xAI (Grok) yes yes no
Anthropic yes no no
DeepSeek yes no no
Your own OpenAI-compatible server yes whatever it implements whatever it implements

A no is refused with a sentence naming a provider that can, rather than sent and failed:

This organization has a DeepSeek key, which cannot generate images. Add an OpenAI or Google (Gemini) key in its AI settings.

Anthropic has no API that can produce embeddings — OpenAI, Google (Gemini), Azure OpenAI or your own OpenAI-compatible server can.

With one exception. A key whose address is your own gateway or proxy is not going to that vendor at all, so the request is attempted and whatever your endpoint answers comes back verbatim. That is the escape hatch for a real deployment that does implement it.

Your own server

Pick Self-hosted / OpenAI-compatible as the provider. It is for a vLLM, Ollama or LM Studio server of yours, or any gateway in front of one, and the whole contract is this: it must answer POST {base URL}/chat/completions in the OpenAI chat-completions shape. If it does, it works here; nothing else about it matters.

  • Base URL — for example http://vllm.internal:8000/v1.
  • API key — optional. Leave it empty if your server has no auth, which many do not.

Two things the page says that are worth repeating, because each one is a support ticket otherwise:

  • The server must be reachable from Vibeforce, not only from your laptop. The call is made by the account service, from wherever it runs — not by your browser. localhost, 127.0.0.1, a machine on your desk and anything behind a VPN the platform is not on will all fail, however well they work in a terminal on your own machine. If the server is inside a private network, it needs an address the platform can route to: a public hostname, a tunnel, or a gateway you expose deliberately.
  • A server with no model list is fine. If it publishes none, the key is still accepted and the reason is recorded against it. Add the model by its identifier instead, below.

Add a model

Browse what the provider offers right now on this organization's key. Models released after this page was built appear on their own.

Pick a provider and browse. Only providers that already have a key are offered — Add a provider key first until one does. What comes back is what the provider offers right now, minus what you already have. Pick one and it is added. If there is nothing new: Nothing new to add.

Underneath, Add a model by identifier — for a server that publishes no model list takes a Provider, the Model identifier exactly as your server names it (for example llama-3.1-8b-instruct), a Display name and a Kind: Chat, Embedding or Image.

Each model is labelled with its kind — Chat, Embedding, Image, Speech to text, Text to speech, Realtime. For browsed models the kind is worked out from the model's identifier, because no provider's model list reports what its models can do. Well-known families are recognised; anything unfamiliar arrives as a plain chat model rather than being hidden, so a model released this morning is still selectable this afternoon.

Models

Only active models appear in pickers. The starred default is what a run uses unless it names another — it must support tools, or nothing that asks for a structured answer can use it.

Column What it is
Model The display name. Click it and type to rename.
Provider Which provider.
Identifier The provider's own name for it.
Capabilities Badges: Tools, Vision, Voice, Streaming.
Active Whether anything may pick it.
Default The star.

Starring a model makes it the default for its kind and clears the star from every other model of that kind. Only chat models can be starred from this table; other kinds show Defaults apply to chat models.

If you have chat models but none is switched on, an amber note appears: No chat model is active, so nothing in this organization can call one yet.

Managed by Vibeforce

The key and model cards are replaced by one: The platform catalog. The Provider keys card is not disabled — it is absent. There is no key of yours in this arrangement, so there is nothing to show you.

What Vibeforce runs for organizations in managed mode, and offers them. Reference only: nothing here needs a decision from you, and nothing here costs you a provider account.

It names the model a call runs on unless a product picks another, and lists what the platform offers — model, provider, identifier and kind. If it is empty: The catalog is empty. A platform administrator fills it in.

You cannot pick from the catalog. What runs is the platform's default; the list is there so you can see what you are getting.

Usage

The last card on the page, in either mode:

  • A bar — N of M tokens used this month (or week), against the owner's allowance, with the date it resets.
  • This organization, by product — how many managed tokens Openbook, Madebook and CodeBook each spent here, and in how many runs.
  • On the organization's own keys — what ran in Self hosted mode and on Members' personal keys. These are recorded, never metered, and never folded into the bar.

When the allowance is spent it says so: The allowance is used up. Managed runs are refused until the window resets or a platform admin raises it. See AI usage & the token allowance.

What each mode means for the bill

Self hosted Managed by Vibeforce
Whose provider account is charged Yours, directly by the provider The platform's
What you paste A key per provider Nothing
Which models are available The ones you added The platform's active models
What Openbook adds on top Nothing — it does not resell tokens Nothing extra beyond your plan

This switch is what decides whether anything is metered at all. Every model call in Openbook — the assistant, the build agent, a workflow, the concierge, an image, an embedding — goes through the Vibeforce account service, which records what it cost as the tokens are spent.

Self hosted Managed by Vibeforce
Counted against the token allowance Recorded, but as zero Yes
Can be refused for being over it Never Yes, before any provider is called

The allowance caps what the platform pays for, not what you may use. An organization on its own key costs the platform nothing, so there is nothing to cap. See AI usage & the token allowance.

Openbook's credits are gone. There is no balance, no monthly top-up and no per-plan credit allowance any more; tokens are metered once, at the account service, against the organization owner's account and shared with every Vibeforce product. Any balance you had was carried across as one-off headroom. See What happened to credits.

Who can change these settings

The organization's owner and its admins. Everyone else in the organization sees the page read-only, and the top card says Only an owner or an admin can change this. You can see what is available. That is deliberate — a model picker in a room needs the list of models, so members must be able to read it.

Action Who
Open the page and read what runs Any member of the organization
Read the usage card Any member
Switch between self hosted and managed Owner or admin
Allow or stop members' personal keys Owner or admin
Add, deactivate or remove a provider key Owner or admin
Browse, add, rename, activate, star or remove a model Owner or admin
Set the per-workspace agent gates Owner or admin, in Openbook's organization Settings
Configure the platform's keys and catalog A platform admin, at the account service

Ownership itself is changed at the Vibeforce account — see Transferring ownership.

The platform's own keys

The key the platform runs on, and the catalog it offers organizations in managed mode, are a platform administrator's job and are set at the account service, not in Openbook:

  • Platform AI — /admin/ai at the account service. The platform's own provider keys and models.
  • Model catalog — /admin/model-catalog there. What organizations are offered in managed mode.

Openbook's own admin area has no AI page. Its The platform brain section carries two outbound links, Platform AI ↗ and Model catalog ↗, which open those pages. See Platform administration.

When something will not run

The refusals name the fix and say where, and which one you get depends on the mode:

In self hosted mode In managed mode
This organization has no chat model. Add a provider key and a model in this organization's AI settings. The platform has no chat model. A platform administrator configures it at Vibeforce SSO — or switch this organization to self hosted and use your own key.
This organization has chat models but none are switched on. The platform has chat models but none are switched on.

"This organization's AI settings" means the AI self hosted page at your Vibeforce account, above.

And in either mode, when the model that is running cannot call tools:

The active models here cannot call tools, so the agent cannot read a file or write a story. Activate one that supports tools (GPT-4o or Claude Sonnet, for example).

If keys cannot be stored at all, an amber strip reads "Keys cannot be stored yet" with the reason. That means the account service has no encryption key configured — there is deliberately no plaintext fallback — and it is for whoever operates the installation to fix.

Where to go next