Connecting an OpenAI Platform organization
Connect your OpenAI Platform organization to DigiUsher with an Admin API key to track cost and token usage per API key, project, and model.
Overview
To connect your OpenAI Platform organization to DigiUsher, create an Admin API key in the OpenAI Platform dashboard. Then enter that key in DigiUsher. This page gives the access that DigiUsher asks for, the reason for that access, and the credential that you enter.
A paid OpenAI Platform account is required
A free account and a trial account cannot create an Admin API key. You need an active paid OpenAI Platform account. Only a member with the Organization Owner role can create an Admin API key. A Member role and a project role cannot.
Summary of Access Required
| Component | Details |
|---|---|
| Identity | Admin API key (prefix sk-admin) for programmatic access only |
| Access level | Read-only. Cost and usage data at the level of the organization |
| Data | Daily cost and token usage data |
| Scope | Your whole OpenAI organization. The key belongs to the organization, so DigiUsher needs no separate organization identifier |
| Capability | What It Provides |
|---|---|
| Per-user cost attribution | Spend attributed to each API key owner (by email for human users, by service account name for automated keys) |
| Model breakdown | Cost and token usage per model |
| Token usage | Input, output, cached-input, input-audio, and output-audio token counts (completions only) |
| Credit rows | Negative-value rows, such as refunds, captured as credits |
DigiUsher cannot send requests, cannot consume tokens, and cannot create, change, or delete anything in your OpenAI organization.
Token counts are available for completions only
Token counts exist for the Completions API only. The other product lines are Embeddings, Images, Audio, the Assistants API, and Evals. They appear in the cost data, but they have no token quantity.
An OpenAI project appears as a cost group in your data, and not as a separate data source. All spend goes to one DigiUsher connection.
Prerequisites
Information to Gather
| Item | How to Find | DigiUsher Field |
|---|---|---|
| Admin API Key | OpenAI Platform dashboard > Settings > Organization > Admin Keys > Create new admin key. The page shows the key one time only, so save it in a safe place. | admin_api_key |
Roles Required by the Person Performing Setup
| Role / Permission | Why |
|---|---|
| Organization Owner on the OpenAI Platform organization | Only Organization Owners can create Admin API keys. |
Network & Email Access (For Regulated Environments)
If your organization restricts outbound internet access or email domains, make sure that these two items are in place before you start:
- Domain allowlist. Add
*.digiusher.comto the allowlist of your network and your firewall. The users of your organization can then open the DigiUsher platform in their browsers. - Email allowlist. Add
digiusher.comas a permitted sender domain in your email security gateway. DigiUsher sends onboarding confirmations, alerts, and reports from@digiusher.comaddresses.
Setup
Make Sure You Have a Paid Account and the Owner Role
The Admin API needs a paid OpenAI Platform account and the Organization Owner role.
- Sign in to the OpenAI Platform dashboard with an account that has the Organization Owner role.
- Make sure that your account has an active paid plan. A free account and a trial account cannot create an Admin API key.
- Make sure that your role is Organization Owner. If it is not, ask an owner to give you the role, or to do the next step for you.
Don't see Admin Keys under Settings?
If Admin Keys does not appear under Settings > Organization, your account does not have the Organization Owner role. Ask an owner to create the key or to give you the role.
Create an Admin API Key
Create a separate Admin API key for DigiUsher, with the necessary scope.
- In the OpenAI Platform dashboard, open Settings > Organization > Admin Keys.
- Click Create new admin key. Give the key a name that you know again, for example
digiusher-cost-reader. - In the scope picker, select
api.usage.read. - Copy the value of the new key. It starts with
sk-admin-.
Save your credential
CAUTION: Copy the Admin API key now and save it in a safe place. The page shows the key one time only, and you cannot read it again. You enter this key in DigiUsher in the next section.
Note Your Key
Make sure that the key that you copied:
- Starts with
sk-admin-, and not withsk-proj-orsk-. - Has the scope
api.usage.readfrom the scope picker.
DigiUsher needs no separate Organization ID. The Admin key already belongs to your organization.
Connect in DigiUsher
In DigiUsher, go to Connectors > Add Source > OpenAI. In the Configure step, enter the values in the table. Then click Review, and complete the Connect step with Connect source:
| Field | Where to Find |
|---|---|
| Display Name | Any label you prefer, for example OpenAI Production |
| Admin API Key | The sk-admin-… key from Step 2 |
At the connection, DigiUsher makes sure that the key works and starts to import the cost data and the usage data of your organization. The first sync reads approximately 31 days, from the start of the current month. After that, DigiUsher reads the new data one time each day.
OpenAI changes the usage data until it finalizes it. The last one or two days can therefore be incomplete.
Setup Checklist
- Active paid OpenAI Platform account
- You have the Organization Owner role
- Admin API key created at Settings > Organization > Admin Keys, with the scope
api.usage.read - The key starts with
sk-admin-, and you saved it in a safe place - Connection details entered in DigiUsher
-
*.digiusher.comin the allowlist of your network and firewall (if your organization restricts this) -
digiusher.comin the allowlist of permitted sender domains in your email security gateway (if your organization restricts this)
Security
What DigiUsher CAN Access (Read-Only)
- Cost data of the organization, grouped by API key, line item, project, and date
- Completions token usage for each API key, model, and batch flag
- The project list and the API key metadata: the key name, the owner email or the service account name, and the project membership
What DigiUsher CANNOT Do
- Send a completions request or consume tokens
- Create, change, or delete an API key, a project, a user, or an organization setting
- Read prompt content, completion text, conversation history, or fine-tuning data
- Read or change the billing configuration, the payment methods, the spending limits, or the rate limits
- Buy a product or change your account
Monitoring
Open the Admin Keys in your OpenAI Platform settings to see the keys that exist and the last time each key was used. Delete every key that you do not know.
Credential Rotation
- In the OpenAI Platform dashboard, create a new Admin API key with the scope
api.usage.read. - Enter the new key in DigiUsher immediately.
- Delete the old key in the OpenAI Platform dashboard.
Avoid ingestion gaps
Create the new key and enter it in DigiUsher before you delete the old key. This prevents an interruption of the data collection.
Revocation
Delete the Admin API key in your OpenAI Platform settings. OpenAI then immediately invalidates the key and stops all access. DigiUsher cannot read cost data again until you give it a new key.
Troubleshooting
Invalid key or 403 on validation
Make sure that the key starts with sk-admin-. DigiUsher rejects a project key (sk-proj-) and an old user key (sk-). Only an Admin API key works. Create the key again in the OpenAI Platform dashboard and enter it again in DigiUsher.
Missing scopes / 403 after a valid key
The key has no api.usage.read scope. Revoke the key and create a new one. This time, select api.usage.read in the scope picker.
Organization Owner role required
If Admin Keys does not appear under Settings > Organization, your account does not have the Organization Owner role. Ask an owner to create the key or to give you the role.
No cost data / data lower than expected
OpenAI changes the usage data until it finalizes it, so the last one or two days can be incomplete. DigiUsher reads the current month again each day, so the data completes itself when OpenAI processes the usage.
Token counts missing for some line items
Token counts exist for completions only. Embeddings, Images, Audio, the Assistants API, and Evals appear in the cost data, but they show no token usage.
Need Help?
If this page does not answer your question, write to DigiUsher support at support@digiusher.com. The team will help you.
DigiUsher Documentation