Connect OpenAI
Connect your OpenAI organisation with an organization admin API key so leancosts shows who holds a seat, what each person and project used through the API, and what the organisation was billed per project, next to your cloud spend. leancosts is read-only here as everywhere: every call it makes to OpenAI is a GET. For the full posture see Security and data handling. Connecting Anthropic instead? See Connect Anthropic.
Before you start
Section titled “Before you start”- You need the Owner role in your OpenAI organisation to create an admin API key, and the connections-manage permission in leancosts to add a connection.
- This connects the OpenAI Platform (API usage). Codex seat analytics is not supported yet and is offered nowhere in the product.
- OpenAI and Anthropic are two separate connectors, each switched on independently. These connections are being validated against real organisations, so if the OpenAI row in the Add-connection picker is disabled and reads “Not enabled in this deployment”, there is nothing to set up yet; it opens when it is ready. Anthropic being available says nothing about OpenAI, and the other way round.
What leancosts reads, and what the key allows
Section titled “What leancosts reads, and what the key allows”- What we read. The organisation’s member list (name, email, role, and whether the member is a service account) and daily API usage per project, user, API key and model, plus the daily cost report per project and line item. Check that this is acceptable under your privacy obligations (LGPD, GDPR or your own policy) before connecting; the people on the roster are your users.
- What the key can do. An OpenAI admin key is organisation-wide and grants
far more than we use: it can create and delete API keys and invite users.
leancosts only calls GET endpoints:
organization/users,organization/projectsand each project’sservice_accounts(so a CI bot is never counted as a person),organization/usage/completionsandorganization/costs. It never creates, edits or deletes anything. We recommend rotating the key after the first backfill. - How it is stored. AES-256-GCM encrypted, the same primitive Azure service-principal secrets use, and never logged or echoed back.
1. Create an admin API key
Section titled “1. Create an admin API key”In the OpenAI platform, open Settings → Organization → Admin keys and create a key. Only organisation owners see this page. Copy the key once; OpenAI will not show it again.
2. Add the connection
Section titled “2. Add the connection”- In leancosts go to Admin → Connections and click Add connection.
- Pick OpenAI. The form asks only for a nickname, a schedule and the key. Picking the row already told leancosts the vendor, and the key is always an OpenAI Platform admin key.
- Give the connection a nickname, paste the key (
sk-admin-...), pick a sync schedule (default every 6 hours) and click Create connection. - The row shows Validating… while leancosts proves the key against your organisation, then Connected. Test re-runs that check any time and reports the organisation id and member count.
The first sync backfills the roster, the last 90 days of per-project usage and the cost report, then runs on the schedule you chose. Sync now and Force refresh work like the cloud connectors; Pause stops the schedule without removing anything.
3. Where the data lands
Section titled “3. Where the data lands”-
Costs gains an OpenAI lens of its own in the cloud focus control once the connection is active (not a shared “LLM vendors” leg) so OpenAI spend is reconcilable on its own and no longer an unexplained delta under “All”. Each OpenAI project is a workspace and each billed line item is its own cost line, so the numbers reconcile to the OpenAI cost report per project.
-
Service accounts on the roster are not counted as seats.
-
If the same workspace already syncs Anthropic, nothing crosses over: the token-trend alert judges each vendor’s token total separately, so the first OpenAI day is measured against OpenAI’s own (still empty) history rather than reading as a spike on Anthropic’s.
-
AI usage (
LLM usagein the sidebar, under Inform & plan) is one page over both vendors, and it opens as soon as either one is connected. It shows: tokens per day, a breakdown by model, workspace, surface and service tier, the effective rate you are paying per million tokens, and a CSV export. Every money figure there is what the vendor billed; anything the vendor reported without attributing it is shown as such rather than spread across models or people. -
Per-person usage is off by default. The page is team grain until a governance admin turns named individuals on under Admin → Workspace → AI usage privacy. Reading it then needs a specific permission, is written to the audit log every time, and is refused to API tokens entirely. The same screen sets how long identities are kept; past that, usage is anonymised: the identity is folded out and the tokens and cost stay on the day, so your cost history does not move. A single person can also be erased on request.
Removing a connection
Section titled “Removing a connection”Open → Settings → Remove purges the roster, every per-person usage row and every vendor cost row the connection ingested. The data cannot be refreshed once the connection is gone, so removal always purges. Rotate or delete the admin key in the OpenAI platform afterwards.