Does TokenAtlas require API keys?
No. TokenAtlas never needs provider API keys, secrets, or credentials — please don't paste them anywhere in the product.
TokenAtlas is designed with privacy, transparency, and responsible data handling in mind.
TokenAtlas models AI cost scenarios from information you provide. It does not observe your systems, ingest provider usage, or run in the background.
TokenAtlas prices the workload inputs you enter — model, token volumes, request counts — against a maintained pricing catalog. It works on the numbers you describe, not on live traffic.
TokenAtlas does not need provider API keys, secrets, or credentials. Please do not paste them into any field, including support messages.
TokenAtlas does not connect to OpenAI, Anthropic, Google, or any other provider account, and does not read your provider billing or usage history.
TokenAtlas is not an LLM proxy. Your prompts and model outputs never pass through it, so there is nothing for us to log or store.
We ask for what the product needs to work: your workload inputs, and account details if you choose to create an account.
What we collect and why is described here and in the Privacy Policy in plain language, without claims we cannot back up.
You can use the calculator without an account. If you have one, you can delete saved scenarios and request account deletion.
We do not sell your data and do not use it to train third-party AI models.
Full details of what we process and why are in the Privacy Policy.
The controls below are implemented in the product today. We list only what exists.
Secure authentication with email verification and supported sign-in providers.
Authenticated areas are protected to ensure users can only access permitted parts of the application.
Row-level security policies help ensure users can only access data they are authorized to view.
Payments are handled by an external payment provider. TokenAtlas does not store card payment details.
A note on compliance: TokenAtlas does not currently hold SOC 2, ISO 27001, or similar third-party certifications, and we will not claim ones we do not have. If your procurement team needs a security review, please contact us and we will respond with the information we do have.
We welcome responsible disclosure. Please report suspected vulnerabilities through our contact page with a description and steps to reproduce, and give us reasonable time to investigate before sharing details publicly. Please do not include credentials, personal data, or API keys in your report.
No. TokenAtlas never needs provider API keys, secrets, or credentials — please don't paste them anywhere in the product.
No. TokenAtlas does not connect to OpenAI, Anthropic, Google, or any other provider account, and does not read your provider billing or usage history.
Only what the product needs: the workload inputs you enter, plus your account details if you create an account.
No. TokenAtlas is a cost modelling tool, not an LLM proxy. It does not receive, log, or store your prompts or model completions.
No. TokenAtlas does not currently hold SOC 2, ISO 27001, or similar third-party certifications, and we do not claim ones we do not have.