Data Connections

Connecting an OpenAI Platform organization

Connect your OpenAI Platform organization to DigiUsher with an Admin API key to track cost and token usage per API key, project, and model.

Overview

To connect your OpenAI Platform organization to DigiUsher, create an Admin API key in the OpenAI Platform dashboard. Then enter that key in DigiUsher. This page gives the access that DigiUsher asks for, the reason for that access, and the credential that you enter.

A paid OpenAI Platform account is required

A free account and a trial account cannot create an Admin API key. You need an active paid OpenAI Platform account. Only a member with the Organization Owner role can create an Admin API key. A Member role and a project role cannot.


Summary of Access Required

ComponentDetails
IdentityAdmin API key (prefix sk-admin) for programmatic access only
Access levelRead-only. Cost and usage data at the level of the organization
DataDaily cost and token usage data
ScopeYour whole OpenAI organization. The key belongs to the organization, so DigiUsher needs no separate organization identifier
CapabilityWhat It Provides
Per-user cost attributionSpend attributed to each API key owner (by email for human users, by service account name for automated keys)
Model breakdownCost and token usage per model
Token usageInput, output, cached-input, input-audio, and output-audio token counts (completions only)
Credit rowsNegative-value rows, such as refunds, captured as credits

DigiUsher cannot send requests, cannot consume tokens, and cannot create, change, or delete anything in your OpenAI organization.

Token counts are available for completions only

Token counts exist for the Completions API only. The other product lines are Embeddings, Images, Audio, the Assistants API, and Evals. They appear in the cost data, but they have no token quantity.

An OpenAI project appears as a cost group in your data, and not as a separate data source. All spend goes to one DigiUsher connection.


Prerequisites

Information to Gather

ItemHow to FindDigiUsher Field
Admin API KeyOpenAI Platform dashboard > Settings > Organization > Admin Keys > Create new admin key. The page shows the key one time only, so save it in a safe place.admin_api_key

Roles Required by the Person Performing Setup

Role / PermissionWhy
Organization Owner on the OpenAI Platform organizationOnly Organization Owners can create Admin API keys.

Network & Email Access (For Regulated Environments)

If your organization restricts outbound internet access or email domains, make sure that these two items are in place before you start:

  • Domain allowlist. Add *.digiusher.com to the allowlist of your network and your firewall. The users of your organization can then open the DigiUsher platform in their browsers.
  • Email allowlist. Add digiusher.com as a permitted sender domain in your email security gateway. DigiUsher sends onboarding confirmations, alerts, and reports from @digiusher.com addresses.

Setup

Make Sure You Have a Paid Account and the Owner Role

The Admin API needs a paid OpenAI Platform account and the Organization Owner role.

  1. Sign in to the OpenAI Platform dashboard with an account that has the Organization Owner role.
  2. Make sure that your account has an active paid plan. A free account and a trial account cannot create an Admin API key.
  3. Make sure that your role is Organization Owner. If it is not, ask an owner to give you the role, or to do the next step for you.

Don't see Admin Keys under Settings?

If Admin Keys does not appear under Settings > Organization, your account does not have the Organization Owner role. Ask an owner to create the key or to give you the role.

Create an Admin API Key

Create a separate Admin API key for DigiUsher, with the necessary scope.

  1. In the OpenAI Platform dashboard, open Settings > Organization > Admin Keys.
  2. Click Create new admin key. Give the key a name that you know again, for example digiusher-cost-reader.
  3. In the scope picker, select api.usage.read.
  4. Copy the value of the new key. It starts with sk-admin-.

Save your credential

CAUTION: Copy the Admin API key now and save it in a safe place. The page shows the key one time only, and you cannot read it again. You enter this key in DigiUsher in the next section.

Note Your Key

Make sure that the key that you copied:

  • Starts with sk-admin-, and not with sk-proj- or sk-.
  • Has the scope api.usage.read from the scope picker.

DigiUsher needs no separate Organization ID. The Admin key already belongs to your organization.


Connect in DigiUsher

In DigiUsher, go to Connectors > Add Source > OpenAI. In the Configure step, enter the values in the table. Then click Review, and complete the Connect step with Connect source:

FieldWhere to Find
Display NameAny label you prefer, for example OpenAI Production
Admin API KeyThe sk-admin-… key from Step 2

At the connection, DigiUsher makes sure that the key works and starts to import the cost data and the usage data of your organization. The first sync reads approximately 31 days, from the start of the current month. After that, DigiUsher reads the new data one time each day.

OpenAI changes the usage data until it finalizes it. The last one or two days can therefore be incomplete.


Setup Checklist

  • Active paid OpenAI Platform account
  • You have the Organization Owner role
  • Admin API key created at Settings > Organization > Admin Keys, with the scope api.usage.read
  • The key starts with sk-admin-, and you saved it in a safe place
  • Connection details entered in DigiUsher
  • *.digiusher.com in the allowlist of your network and firewall (if your organization restricts this)
  • digiusher.com in the allowlist of permitted sender domains in your email security gateway (if your organization restricts this)

Security

What DigiUsher CAN Access (Read-Only)

  • Cost data of the organization, grouped by API key, line item, project, and date
  • Completions token usage for each API key, model, and batch flag
  • The project list and the API key metadata: the key name, the owner email or the service account name, and the project membership

What DigiUsher CANNOT Do

  • Send a completions request or consume tokens
  • Create, change, or delete an API key, a project, a user, or an organization setting
  • Read prompt content, completion text, conversation history, or fine-tuning data
  • Read or change the billing configuration, the payment methods, the spending limits, or the rate limits
  • Buy a product or change your account

Monitoring

Open the Admin Keys in your OpenAI Platform settings to see the keys that exist and the last time each key was used. Delete every key that you do not know.

Credential Rotation

  1. In the OpenAI Platform dashboard, create a new Admin API key with the scope api.usage.read.
  2. Enter the new key in DigiUsher immediately.
  3. Delete the old key in the OpenAI Platform dashboard.

Avoid ingestion gaps

Create the new key and enter it in DigiUsher before you delete the old key. This prevents an interruption of the data collection.

Revocation

Delete the Admin API key in your OpenAI Platform settings. OpenAI then immediately invalidates the key and stops all access. DigiUsher cannot read cost data again until you give it a new key.


Troubleshooting

Invalid key or 403 on validation

Make sure that the key starts with sk-admin-. DigiUsher rejects a project key (sk-proj-) and an old user key (sk-). Only an Admin API key works. Create the key again in the OpenAI Platform dashboard and enter it again in DigiUsher.

Missing scopes / 403 after a valid key

The key has no api.usage.read scope. Revoke the key and create a new one. This time, select api.usage.read in the scope picker.

Organization Owner role required

If Admin Keys does not appear under Settings > Organization, your account does not have the Organization Owner role. Ask an owner to create the key or to give you the role.

No cost data / data lower than expected

OpenAI changes the usage data until it finalizes it, so the last one or two days can be incomplete. DigiUsher reads the current month again each day, so the data completes itself when OpenAI processes the usage.

Token counts missing for some line items

Token counts exist for completions only. Embeddings, Images, Audio, the Assistants API, and Evals appear in the cost data, but they show no token usage.


Need Help?

If this page does not answer your question, write to DigiUsher support at support@digiusher.com. The team will help you.

On this page