AI provider policy

AI provider policy

Bystep only uses paths AI providers allow. This table shows every provider in five ways of use, when we last checked, and the source.

Bystep never stores your subscription token

Subscription logins (Claude Pro/Max, ChatGPT Plus/Pro and the like) stay in the official agent on your own computer. Bystep's servers only keep API keys you paste yourself, encrypted.

Last checked Sep 10, 2026

Five ways of use

  • On your computerOffered by Bystep

    The official agent on your computer, started by Bystep on that computer.

  • Subscription login stored by BystepNot offered

    A subscription login code kept on Bystep's servers. Never offered.

  • Private cloud space with your loginNot offered

    The official agent in a per-user cloud space you sign in to yourself. Not offered.

  • Bystep cloud · your API keyOffered by Bystep

    An API key you own, billed to your provider account.

  • Bystep cloud · Bystep's keyOffered by Bystep

    Bystep's own key, paid from the Bystep step allowance.

Provider × way of use

Scroll the table sideways to see every column.

ProviderOn your computerSubscription login stored by BystepPrivate cloud space with your loginBystep cloud · your API keyBystep cloud · Bystep's key
Anthropic (Claude Code · Claude Pro/Max)
AllowedUnmodified Claude Code binary signed in by the user; ordinary individual usage limits apply; no ANTHROPIC_BASE_URL proxy for subscription traffic.Checked Sep 10, 2026Source
Not allowedThird parties may not collect, store, or intermediate Claude.ai credentials or session tokens.Checked Sep 10, 2026Source
Gray areaHosting the unmodified binary requires Commercial Terms and no vendor-login button in Bystep; not offered.Checked Sep 10, 2026Source
AllowedUser-owned API key billed to the key owner.Checked Sep 10, 2026Source
AllowedBystep API key via Agent SDK / Messages API; branded 'Powered by Claude', not 'Claude Code'.Checked Sep 10, 2026Source
OpenAI (Codex CLI · ChatGPT Plus/Pro)
Gray areaTechnically supported by the official CLI; no written OpenAI statement for third-party tools as of 2026-09-10.Checked Sep 10, 2026Source
Not allowedauth.json is a credential; Bystep does not store it.Checked Sep 10, 2026Source
Gray areaNot offered.Checked Sep 10, 2026Source
AllowedAPI key for programmatic workflows.Checked Sep 10, 2026Source
AllowedBystep-owned API key.Checked Sep 10, 2026Source
Google (Gemini CLI · Google AI Pro/Ultra)
Not allowedConsumer Login with Google for Gemini CLI was discontinued on 2026-06-18; Antigravity terms bar third-party tools.Checked Sep 10, 2026Source
Not allowedNo subscription token path.Checked Sep 10, 2026Source
Not allowedNo subscription token path.Checked Sep 10, 2026Source
AllowedAI Studio / Vertex API key only.Checked Sep 10, 2026Source
AllowedBystep-owned API key.Checked Sep 10, 2026Source
GitHub Copilot (CLI · SDK)
AllowedOfficial Copilot CLI on the user's computer.Checked Sep 10, 2026Source
Gray areaOnly via Copilot SDK + OAuth App (requests on behalf of each user); not implemented.Checked Sep 10, 2026Source
Gray areaNot offered.Checked Sep 10, 2026Source
AllowedBYOK supported by the SDK.Checked Sep 10, 2026Source
Gray areaNot applicable.Checked Sep 10, 2026Source
Cursor (cursor-agent · Cloud Agents)
Gray areaAcceptable Use Policy restricts automated access; the user runs cursor-agent themselves.Checked Sep 10, 2026Source
Not allowedNo token storage.Checked Sep 10, 2026Source
Not allowedNot offered.Checked Sep 10, 2026Source
AllowedCloud Agents API key owned by the user (existing one-shot integration).Checked Sep 10, 2026Source
Gray areaNot applicable.Checked Sep 10, 2026Source
OpenRouter / custom OpenAI-compatible endpoints
AllowedLocal agents with the user's own key.Checked Sep 10, 2026Source
Not allowedKeys only, never session tokens.Checked Sep 10, 2026Source
Gray areaNot offered.Checked Sep 10, 2026Source
AllowedBYOK (encrypted at rest).Checked Sep 10, 2026Source
AllowedBystep gateway key.Checked Sep 10, 2026Source

What the colours mean

Allowed
The provider allows this in writing.
Gray area
No written statement yet. Bystep still shows it, with a gray label and the date we checked.
Not allowed
The provider does not allow this. Bystep hides the option.

This table is data we update when a provider changes its rules, not legal advice. Cell notes are in the language of the original source.