BYOK boundaries
- credentials are scoped to the project or workspace scope exposed by the product;
- secrets are stored as managed references and are not returned to browser clients;
- provider-specific setup is shown only when that provider is intentionally connected;
- rotate or revoke credentials through the connection settings;
- usage and P2HS orchestration charges depend on the project’s plan and the configured execution path.
Check the dashboard for the current eligibility, connection fields, and billing treatment of BYOK for your workspace.

