Provider key statuses and errors

What each provider key badge, access check result, and error message means in Settings → Providers, and how to fix it.

Every key you save in Settings → Providers shows a status badge, when the key was last checked, and the result of each access check. This page explains each one and what to do when something goes wrong.

Who can do this: Admins.

Status badges

BadgeWhat it meansWhat to do
savedThe provider accepted the key and the main check passed.Nothing.
unverifiedOpenAI Enterprise only. The key can read Codex analytics but can't read or change usage limits.Create a key with Usage limits: Write and save it again. See Connect OpenAI.
invalidThe provider no longer accepts the key, for example because it was revoked or expired. You see "This key failed verification. Paste a new key to reconnect."Create a new key and paste it into the form. Click Replace.
unreadableTokenize can no longer read the stored key, so nothing that uses it is running. The key itself is probably fine.Paste the same key again to restore it.

To swap a working key for a new one, click Revoke, then paste the new key and click Save. The Compliance API key panels have a Replace button instead.

Access check results

Under each key, Tokenize lists the features the key powers and whether it could use them. For example, a Claude Enterprise key shows "Analytics", "Member directory", "Read budgets", and "Change budgets". Access can change later on the provider side, so the line "Permissions checked … Access can change later." shows when the check ran.

ResultWhat to do
"Available"Nothing.
"Access unavailable. Check the permissions in the key setup instructions."The key is missing a scope or permission. Open How to create a key, create a key with every listed permission, and replace the old one.
"Not yet verified. We will report the result when you change a budget."Normal for budget write access. Tokenize confirms it the first time someone changes a budget. See Budgets.
"Connect the required provider key first."This key depends on another one. For example, Cursor Cloud Sessions needs a working Team Admin API key.
"Could not check: the provider is rate limiting requests."Wait, then replace the key to check again.
"Could not check: the provider did not complete the request." or "Could not check within the time limit."The provider didn't answer in time. Replace the key later to check again.
"Could not check: the provider returned an unexpected response."Try again later. If it keeps happening, contact your Tokenize account team.
"No suitable resource was available to check."There was nothing to test against yet. Replace the key later to check again.
"The sampled session has expired; access is not yet verified."The session Tokenize tried to test with was no longer available.
"A sampled resource was checked; broader access is not verified."One item was checked. Other access wasn't confirmed.
"Permissions not checked. Replace the key to check access."Tokenize has no access check on record for this key. Paste the key again to run one.

After a budget change, you may also see a line like "Last requested budget change for a checked account: applied." It reports whether that change reached the provider. "access denied" means the key lacks write access.

Error messages when saving

MessageFix
"Enter an API key to save."Paste a key before you click Save.
"Enter a Workspace ID for the OpenAI Enterprise credential."Add the Workspace ID from your ChatGPT Admin workspace settings.
"Enter the Workspace ID from ChatGPT Admin settings."The Workspace ID was rejected. Copy it again from your ChatGPT Admin workspace settings.
"Key not accepted. Check the key and its permissions."The provider refused the key. Check that it's the right key type for the slot and has the listed permissions. A regular model API key won't work in an admin slot.
"Key not accepted. Use a read-only management key."OpenRouter only. Create a management key, not an inference key. See Connect OpenRouter.
"Check the key and required fields." or "Connection rejected. Check the key and required fields."Check the key and, for OpenAI Enterprise and OpenAI Compliance, the Workspace ID.
"Enter a key between 1 and 4,096 characters."The pasted value is empty or too long. Copy the key again.
"Too many requests. Try again in …" or "Too many requests. Try again shortly."Wait, then try again.
"Provider unavailable. Try again shortly."The provider didn't respond. Try again in a few minutes.
"You need provider settings access. Ask an admin."Your role can't manage provider keys.
"Tokenize couldn't complete the request. Try again."Try again. If it keeps happening, contact your Tokenize account team.
"Couldn't connect. Check your connection and try again."Check your network connection and try again.

If the page itself shows "Couldn't load providers:", click Retry. If you see "Your role does not include provider credential management.", ask an admin.