Connecting a ChatGPT Enterprise or Edu account
Connect your ChatGPT Enterprise or Edu organization to DigiUsher with an Admin API key and Organization ID to track AI spend and usage across your organization.
Overview
To connect your ChatGPT Enterprise or Edu organization to DigiUsher, find your Organization ID. Then create an Admin API key with the scope of the compliance cost data endpoint, and enter both values in DigiUsher. This page gives the access that DigiUsher asks for, the reason for that access, and the credentials that you enter.
This connection is not the same as the connection of an OpenAI Platform account. You manage ChatGPT Enterprise at chatgpt.com. The OpenAI API Platform is at platform.openai.com. The two products use separate credential systems, and a Platform API key does not work here.
ChatGPT Enterprise or Edu subscription required
The Free, Plus, and Pro plans give no access to the Admin API. Only a member with the Owner role on the ChatGPT organization can create an Admin API key.
Summary of Access Required
| Component | Details |
|---|---|
| Identity | ChatGPT Enterprise Admin API key for programmatic access only |
| Access level | Read-only. Cost and usage data at the level of the organization |
| Data | Daily cost and usage data per user, workspace, and model |
| Scope | A single ChatGPT organization (identified by Organization ID) |
| Capability | What It Provides |
|---|---|
| Usage cost | Spend attributed per user and per workspace |
| Model breakdown | Cost by GPT model |
| Credit rows | Negative-value rows captured as credits |
DigiUsher cannot send messages, cannot read conversation content, and cannot change anything in your ChatGPT organization.
The key needs the compliance costs scope
The Admin API key must have the scope chatgpt.enterprise.compliance_logs_platform.costs.read. A workspace Owner on an Enterprise plan or an Edu plan must create the key. DigiUsher rejects a key without this scope at the connection.
Prerequisites
Information to Gather
| Item | How to Find | DigiUsher Field |
|---|---|---|
| Organization ID | Sign in to chatgpt.com, open chatgpt.com/admin/settings, and read the Organization ID field in the Workspace Details section. It starts with org-. | organization_id |
| Admin API Key | Created in the ChatGPT admin console under Credentials > Admin keys, with the compliance costs scope. The Setup section gives the steps. | admin_api_key |
Roles Required by the Person Performing Setup
| Role / Permission | Why |
|---|---|
| Owner on the ChatGPT Enterprise or Edu organization | Only Owners can create Admin API keys. |
Network & Email Access (For Regulated Environments)
If your organization restricts outbound internet access or email domains, make sure that these two items are in place before you start:
- Domain allowlist. Add
*.digiusher.comto the allowlist of your network and your firewall. The users of your organization can then open the DigiUsher platform in their browsers. - Email allowlist. Add
digiusher.comas a permitted sender domain in your email security gateway. DigiUsher sends onboarding confirmations, alerts, and reports from@digiusher.comaddresses.
Setup
Locate Your Organization ID
- Sign in to chatgpt.com as an Owner of your Enterprise or Edu organization.
- Go to chatgpt.com/admin/settings.
- In the Workspace Details section, copy the Organization ID value. It starts with
org-.
Keep this value. You enter it in DigiUsher together with your API key.
Create an Admin API Key with the Required Scope
DigiUsher reads the ChatGPT Enterprise cost data from the compliance COSTS feed. This feed needs a specific scope on the key. You create an Admin key in the ChatGPT admin console, and not at platform.openai.com.
- Sign in to chatgpt.com/admin as an Owner of your Enterprise or Edu organization.
- Go to Credentials > Admin keys and click Create new Admin key.
- On the scope selection screen, select
chatgpt.enterprise.compliance_logs_platform.costs.read. To find it quickly, search forcostsorcompliancein the scope list. - Give the key a name that you know again, for example
digiusher-cost-reader. - Create the key and copy the value.
Save your credential
CAUTION: Copy the API key now and save it in a safe place. The page shows the key one time only, and you cannot read it again.
Make Sure You Have the Credentials
Before you connect DigiUsher, make sure that you have these two values:
- The Organization ID from chatgpt.com/admin/settings > Workspace Details. It starts with
org-. - The Admin API key with the scope
chatgpt.enterprise.compliance_logs_platform.costs.read.
Connect in DigiUsher
In DigiUsher, go to Connectors > Add Source > ChatGPT Enterprise. In the Configure step, enter the values in the table. Then click Review, and complete the Connect step with Connect source:
| Field | Where to Find |
|---|---|
| Display Name | Any label you prefer, for example ChatGPT Enterprise |
| Organization ID | From Step 1. It starts with org- |
| Admin API Key | From Step 2 |
At the connection, DigiUsher makes sure that the key and the Organization ID work, and starts to import the cost data and the usage data. The first sync reads the last 30 days, and it extends this period back to the start of that month. The COSTS feed keeps approximately 30 days of history, so DigiUsher cannot import an earlier period. After the first sync, DigiUsher reads the current month again each day. It therefore gets the usage values that OpenAI changes until it finalizes them.
Setup Checklist
- Active ChatGPT Enterprise or Edu subscription
- You have the Owner role on the ChatGPT organization
- Organization ID copied from chatgpt.com/admin/settings > Workspace Details. It starts with
org- - Admin API key created with the scope
chatgpt.enterprise.compliance_logs_platform.costs.read - API key saved in a safe place
- Organization ID and API key entered in DigiUsher
-
*.digiusher.comin the allowlist of your network and firewall (if your organization restricts this) -
digiusher.comin the allowlist of permitted sender domains in your email security gateway (if your organization restricts this)
Security
What DigiUsher CAN Access (Read-Only)
- Cost data of the organization, grouped by user, workspace, model, and date
- Usage quantities of each person and each workspace
What DigiUsher CANNOT Do
- Send a message, or read the conversation history, the prompts, or the responses
- Create, change, or delete a user, a workspace, or an organization setting
- Read uploaded files, system prompts, or other content of your users
- Read or change the payment methods, the seat counts, or the plan configuration
- Buy a product or change your account
Monitoring
Open the Admin keys in the ChatGPT admin console under Credentials > Admin keys. There you see the keys that exist and the last time each key was used. Delete every key that you do not know.
Credential Rotation
- In the ChatGPT admin console, go to Credentials > Admin keys and create a new Admin API key with the compliance costs scope.
- Enter the new key in DigiUsher immediately.
- Delete the old key.
Avoid ingestion gaps
Create the new key and enter it in DigiUsher before you delete the old key. This prevents an interruption of the data collection.
Revocation
Delete the Admin key in the ChatGPT admin console under Credentials > Admin keys. ChatGPT then immediately invalidates the key and stops all access. DigiUsher cannot read cost data again until you give it a new key.
Troubleshooting
403 / unauthorized after providing a valid key
The usual cause is an absent scope. Make sure that a workspace Owner created the key with the scope chatgpt.enterprise.compliance_logs_platform.costs.read. Revoke the key and create a new one. Select the scope by its name.
Wrong key type / 401 error
Make sure that this is an Admin API key of your Enterprise organization, created in the ChatGPT admin console under Credentials > Admin keys. A standard user API key does not work, and a project key from platform.openai.com does not work. The key must have the compliance costs scope.
Organization ID not recognized
Make sure that you copied the Organization ID from Workspace Details at chatgpt.com/admin/settings, and that it starts with org-. Do not use a workspace ID or a project ID from another settings page. DigiUsher also gives this error when the organization has no COSTS logs. These logs need an Enterprise plan or an Edu plan.
No cost data after connecting
- After a new connection, the data can take up to 24 hours to appear.
- The usage of the current day appears at the next daily sync.
- Make sure that the Organization ID belongs to the Enterprise organization with the usage.
- The COSTS feed keeps approximately 30 days of history. DigiUsher cannot import an earlier period.
Need Help?
If this page does not answer your question, write to DigiUsher support at support@digiusher.com. The team will help you.
Connecting an OpenAI Platform organization
Connect your OpenAI Platform organization to DigiUsher with an Admin API key to track cost and token usage per API key, project, and model.
Connecting a Cloudflare account
Connect your Cloudflare account to DigiUsher with an Account ID and a read-only Billing API token to track usage-based spend across Cloudflare products.
DigiUsher Documentation