Cloudflare Workers AI BYOK means running Insulin’s agents on Workers AI chat models through your own Workers AI API token and Cloudflare account ID, with Cloudflare billing the usage to your account. DigitalOcean GradientAI works the same way with a model access key. Either way, the connect check proves the provider accepted your credential, and nothing more.
If your company already buys AI inference from Cloudflare or DigitalOcean, two questions follow. Can your agents run on those models under your own account? And what has to be in place before they actually do?
The first answer is yes. Insulin connects both as model providers with your own credential, for the whole organization or just for you, and each adds five chat models to Insulin’s model pickers. The second answer is spread across the workspace: what the connect check proved, the level you connected at, your organization’s AI Model Policy, and a separate provider for knowledge bases. This post puts them in one place, with a checklist at the end.
What is Cloudflare Workers AI BYOK in Insulin?
Cloudflare Workers AI BYOK (bring your own key) is connecting your own Workers AI API token and Cloudflare account ID so that Insulin’s AI features can run on Workers AI models, with the usage billed to your Cloudflare account. DigitalOcean GradientAI is the same arrangement with a DigitalOcean model access key, billed to your DigitalOcean account.
Both connect from Settings → Integrations. Insulin offers a fixed set of five chat models from each, not either provider’s whole catalog:
| Provider | The five chat models Insulin offers |
|---|---|
| Cloudflare Workers AI | Llama 3.3 70B Instruct (fast), Llama 3.1 8B Instruct (fp8), GPT-OSS 120B, Qwen2.5 Coder 32B Instruct, Mistral Small 3.1 24B Instruct |
| DigitalOcean GradientAI | Llama 4 Maverick, GPT-OSS 120B, Claude Sonnet 5, DeepSeek V4 Pro, Qwen 3.5 397B A17B |
They are chat models only. Neither provider adds an embedding model, which matters for knowledge bases, covered below.
Which agents can use the connection?
The level you connect at decides it: an organization connection serves organization agents and apps, and a personal connection serves only you. Connect from the Integrations grid for the organization, which only an org ADMIN can do, or under User Integrations for yourself. The models then appear here:
| Where | Organization connection | Personal connection |
|---|---|---|
| An agent’s Default model picker, searchable and grouped by provider | Organization agents | Your personal agents |
| The built-in Insulin assistant’s model settings | Not offered: the assistant never reaches the organization’s keys | Offered |
| The Custom Apps builder’s model picker, as a provider group | Organization apps | Your personal apps |
| Inbox | Not used: Inbox uses the providers you connected yourself | Used, although the AI model card in Settings → Account doesn’t list them |
Two consequences follow. An organization connection alone doesn’t put the built-in assistant or Inbox on Cloudflare or DigitalOcean; each person who wants that connects their own. And a personal credential never serves anyone else in your organization.
What does the connect check prove?
That the provider accepted your credential, and nothing more. Before storing anything, Insulin uses the credential to ask the provider for its list of models. For Cloudflare, it first checks that the Account ID is 32 hexadecimal characters, the only form it accepts. The connect form then ends in one of four results:
| Result | What the form shows | What it means |
|---|---|---|
| Connected | No error | The provider accepted the credential, and it is stored |
| Rejected: the Account ID (Cloudflare only) | Invalid connection config field "accountId": must be a 32-character hexadecimal Cloudflare account id | The Account ID is the wrong shape, so nothing is stored. Copy it again |
| Rejected: the credential | Cloudflare Workers AI rejected the supplied API key or DigitalOcean GradientAI rejected the supplied API key | The provider refused it, so nothing is stored. Check that you pasted all of it and that it hasn’t been revoked, deleted or regenerated |
| Not confirmed | … could not confirm the key right now (status …) or Could not reach … to verify the key | No usable answer: a timeout, a rate limit or an outage, or on Cloudflare an account it doesn’t recognise. The credential was not judged invalid and nothing is stored. Check the Account ID if it’s Cloudflare, and try again |
What passing doesn’t prove. The check lists models; it doesn’t run one. So a passing connection doesn’t show whether the credential may run the five models you’re about to pick. What a credential may do is set on the provider’s side: see Cloudflare’s documentation for a Workers AI API token and your Account ID, or DigitalOcean’s documentation for a model access key. Fours’ integration guide for each provider, cited below, says what to set.
Then prove it with one real run. Make one of the five models the Default model of a test agent with the same ownership as the connection, and send it a message. When a model call fails, a rejected key included, Insulin retries on your next connected provider and says so: the reply ends with a short italic note that names both models and says the first was unavailable. If your test reply carries that note, it came from a different model.
What has to line up in the AI Model Policy?
If your organization’s Allowed AI integrations list has any rows, the provider must be one of them, or requests on its models are refused whichever key they would use. The list sits under Settings → Organization → AI Model Policy, which only an org ADMIN can change. What to do depends on its state:
- The list is empty. There is nothing to add: “No restriction — every connected provider is allowed.” Don’t add a first row just for this provider. AI features may use only the integrations the list names, so the first row you add shuts out every provider not on it, the Fours-hosted models included unless you also add Fours Hosted (DeepInfra).
- The list has rows. Add Cloudflare Workers AI or DigitalOcean GradientAI. Until you do, saving an agent with one of their models as a new Default model is refused for AI policy, and the Custom Apps builder still shows your own-key rows for them but rejects the model when the app runs.
- Allow Fours platform key is off, and you want one of them on top. The top row is the organization default for every feature without a model picker of its own, and with the switch off it must be a provider your organization has connected and verified. The tab marks an OpenAI, Anthropic or Gemini row not connected as you edit when it has no verified connection. Cloudflare Workers AI and DigitalOcean GradientAI rows never show that marker: when one of them is the top row, its connection is checked when you click Save, and the save is refused unless it is verified.
For what the allow-list and the platform-key switch each guarantee, see how an AI model allowlist decides which vendors see your prompts.
Can a knowledge base use these models?
No. Both serve chat models only: Insulin registers no embedding model for either, so connecting one adds nothing to the knowledge-base embedding chooser. That bites hardest with Allow Fours platform key off. The Fours-hosted embedding models then leave the chooser, and an organization with no embedding provider connected cannot create a knowledge base. Connect one of the providers in the embedding model reference as well: for the organization, and per person for personal knowledge bases.
What does it cost?
Your provider bills you for the tokens under your own contract, and Insulin adds a flat platform fee. Insulin’s pricing page sets that fee at $0.10 per million tokens, input and output, the same whichever model you run; what each model costs is between you and your provider.
One thing doesn’t change with your own key: a zero Insulin balance still pauses these requests, because the per-token fee is still owed.
Whether to bring your own keys at all is a separate decision about cost structure, control and the data path, and BYOK vs managed models for enterprise AI walks through it.
How do you rotate or remove the credential?
Reconnect to replace it and Disconnect to remove it; there is no Edit. To swap in a new token, key or Account ID, open the card’s ⋯ menu and choose Details, then Reconnect and Start connection, enter the new values and click Save credentials. The new values get the same check as a first connect, and the stored credential is replaced only if they pass, so a rejected replacement leaves the previous one in place. Reconnecting an organization connection takes the org ADMIN role.
Reconnect every time you rotate on the provider’s side. Insulin checks the credential only when you connect or reconnect, and the card won’t warn you in between: the Connection expired alert covers only the sign-in-based Claude Code and Codex connections, and connections made with an API key never show it. Until you reconnect, calls on a revoked credential are rejected, and turns fail over to your next connected provider with the note saying the model was unavailable.
Disconnecting is visible, not silent. Choose Disconnect from the ⋯ menu, and the provider’s models can no longer run on that credential. An agent whose Default model was one of them shows it marked unavailable in its model picker, with a hint to reconnect the provider or choose another model. The agent never silently switches to a different model: a turn that can’t reach its saved default stops with an error saying the model is not available.
What should you check before agents depend on it?
Nine checks, one column per provider: read down the column for yours.
| Check | Cloudflare Workers AI | DigitalOcean GradientAI |
|---|---|---|
| 1. The credential | A Workers AI API token and your Account ID, created as Cloudflare’s documentation describes. The Account ID must be 32 hexadecimal characters | A model access key for serverless inference, created as DigitalOcean’s documentation describes |
| 2. The level | The Integrations grid for the organization (org ADMIN only), or User Integrations for yourself | The Integrations grid for the organization (org ADMIN only), or User Integrations for yourself |
| 3. The result | Connected. A rejection means fix the Account ID or the token; could not confirm means try again | Connected. A rejection means fix the key; could not confirm means try again |
| 4. One real run | A test agent with a Workers AI Default model replies with no was unavailable note | A test agent with a GradientAI Default model replies with no was unavailable note |
| 5. The policy | If Allowed AI integrations has rows, Cloudflare Workers AI is one of them | If Allowed AI integrations has rows, DigitalOcean GradientAI is one of them |
| 6. The people | Each person who wants it in the built-in assistant or Inbox connects their own | Each person who wants it in the built-in assistant or Inbox connects their own |
| 7. Knowledge bases | With the platform key off, a separate embedding provider is connected | With the platform key off, a separate embedding provider is connected |
| 8. Rotation | Reconnect after you revoke or replace the token | Reconnect after you delete or regenerate the key |
| 9. Removal | Disconnect; agents defaulting to its models show them as unavailable | Disconnect; agents defaulting to its models show them as unavailable |
Frequently asked questions
Can Insulin agents run on Cloudflare Workers AI with our own key?
Yes. Connect a Workers AI API token and your Cloudflare account ID under Settings → Integrations, for the organization or just for yourself. Five Workers AI chat models then appear in the model pickers, including an agent’s Default model, and Cloudflare bills the usage to your account.
Which DigitalOcean models can Insulin use?
Five GradientAI chat models, through your own model access key: Llama 4 Maverick, GPT-OSS 120B, Claude Sonnet 5, DeepSeek V4 Pro and Qwen 3.5 397B A17B. Insulin offers that fixed set, not DigitalOcean’s whole catalog, and none of them is an embedding model.
Does a successful connection prove the key can run the models?
No. The connect check asks the provider for its model list with your credential, which proves the provider accepted it. It doesn’t run a model. Send one message to an agent whose Default model is one of the five, and check the reply carries no failover note.
Why are requests on a Cloudflare or DigitalOcean model refused?
Check the AI Model Policy first. When its Allowed AI integrations list has rows, AI features may use only the integrations on it, so add Cloudflare Workers AI or DigitalOcean GradientAI. An empty list allows every connected provider, so leave an empty list alone.
What happens to our agents if we disconnect the provider?
Its models can no longer run on that credential. An agent whose Default model was one of them shows it as unavailable in its model picker, with a hint to reconnect the provider or choose another model. The agent never silently switches to a different model.
Who pays for the tokens when we bring our own key?
Your provider bills the tokens to your account, under your own contract. Insulin adds a flat per-token platform fee, the same whichever model you run, and a zero Insulin balance still pauses these requests, because that fee is still owed.
Takeaways
- Both providers connect with your own credential and add five chat models each to Insulin, not their full catalogs.
- The connect check proves the provider accepted the credential. It runs no model, so send one real message and look for a failover note.
- An organization connection serves organization agents and apps; the built-in assistant and Inbox need a personal one.
- With a non-empty AI Model Policy allow-list, add the provider. Leave an empty list empty.
- Neither provider supplies embeddings. Rotate with Reconnect, and expect a disconnected default to show as unavailable rather than switch silently.
Bringing your own inference is one way to run AI agents in Insulin on contracts your company already holds. For the organization-level controls around it, the AI Model Policy reference documents the allow-list and the platform-key switch in full.
Sources
Primary sources for the platform rules cited above. Last verified September 28, 2026. Cloud providers change fees, eligibility, and program terms without notice — check the source before relying on a figure.
- Cloudflare Workers AI — Fours Doc — The five Workers AI chat models offered; organization and user connections and who can connect them; the 32-character hexadecimal Account ID check and the models-list check; the connected, rejected and could-not-confirm results and their messages; no Edit, only Reconnect; the credential checked only at connect or reconnect; Disconnect and the unavailable default; chat models only, no embedding model; adding the provider to Allowed AI integrations
- DigitalOcean GradientAI — Fours Doc — The five GradientAI chat models offered; organization and user connections; the models-list check proving the key is accepted, not which models it may use; the rejected and could-not-confirm results and their messages; Reconnect; the key checked only at connect or reconnect; Disconnect and the unavailable default; chat models only; adding the provider to Allowed AI integrations
- Insulin Getting Started — Fours Doc — The AI Model Policy: Allowed AI integrations as an ordered allow-list whose top row is the organization default; the empty-list no-restriction state; the Fours Hosted (DeepInfra) row; the not connected marker, and the Save-time check on Cloudflare Workers AI and DigitalOcean GradientAI rows; Allow Fours platform key; the Connection expired alert covering Claude Code and Codex only
- Insulin Agents — Fours Doc — The Default model picker, searchable and grouped by provider, and whose connected providers join it; the unavailable marker after a disconnect; an agent never silently switching models; a turn that cannot reach its default stopping with an error; a Default model refused on save for AI policy
- Insulin Agents — Fours Doc: When a model fails over — Failover when a model call fails, a rejected key included, and the closing note naming both models; the built-in Insulin assistant using only the providers you connected, never the organization's keys
- Insulin Custom Apps — Fours Doc — The builder's model picker grouped by provider; organization and personal apps each listing Your key rows from their own scope; a restricted provider's Your key rows still listed and rejected when the app runs
- Insulin Inbox — Fours Doc — The AI model card's five listed providers, and Inbox using other providers you connected yourself, Cloudflare Workers AI and DigitalOcean GradientAI included
- Insulin Knowledge Bases — Fours Doc — The embedding providers the chooser offers; Fours-hosted embedding models offered only while the platform key is on; a bring-your-own-key organization with no embedding provider cannot create a knowledge base
- Insulin Metering — Fours Doc — With your own key, the provider bills the tokens under your own contract and Fours charges a flat fee per unit; a zero balance still pauses bring-your-own-key requests
Keep reading
Stay Updated
New posts, product updates and marketplace strategy are shared on LinkedIn as they publish.
Follow Fours on LinkedIn