BYOK changes who bills you

Bring your own key connects the IDE to an AI provider account you control. The provider meters usage directly; the IDE does not turn a consumer subscription into API access.

For developers bringing provider keys to web tools, the practical question is not whether the feature exists in a demo. It is whether the complete workflow remains understandable when files, model context, verification output, credentials, and recovery all interact. A useful Web browser workflow keeps those boundaries visible instead of hiding them behind a single generated answer.

Apply this as an operational rule: define the intended result, inspect what the agent can access, review the proposed change at file level, and verify behavior before sharing or committing it. That sequence turns convenience into a repeatable engineering process and makes failures easier to diagnose.

Encryption at rest is specific

CodeWinger Web can protect saved keys with a passphrase-derived AES-GCM vault. This reduces plaintext-at-rest exposure but cannot protect a key after the user unlocks it for a legitimate request.

For developers bringing provider keys to web tools, the practical question is not whether the feature exists in a demo. It is whether the complete workflow remains understandable when files, model context, verification output, credentials, and recovery all interact. A useful Web browser workflow keeps those boundaries visible instead of hiding them behind a single generated answer.

Apply this as an operational rule: define the intended result, inspect what the agent can access, review the proposed change at file level, and verify behavior before sharing or committing it. That sequence turns convenience into a repeatable engineering process and makes failures easier to diagnose.

Session-only mode reduces persistence

A session-only key disappears when the browser session ends. It is useful on shared or temporary machines, but users must re-enter the key later.

For developers bringing provider keys to web tools, the practical question is not whether the feature exists in a demo. It is whether the complete workflow remains understandable when files, model context, verification output, credentials, and recovery all interact. A useful Web browser workflow keeps those boundaries visible instead of hiding them behind a single generated answer.

Apply this as an operational rule: define the intended result, inspect what the agent can access, review the proposed change at file level, and verify behavior before sharing or committing it. That sequence turns convenience into a repeatable engineering process and makes failures easier to diagnose.

The provider still receives requests

BYOK does not mean prompts stay offline. Code, prompts, and selected context are sent to the configured provider when the user asks the model to work.

For developers bringing provider keys to web tools, the practical question is not whether the feature exists in a demo. It is whether the complete workflow remains understandable when files, model context, verification output, credentials, and recovery all interact. A useful Web browser workflow keeps those boundaries visible instead of hiding them behind a single generated answer.

Apply this as an operational rule: define the intended result, inspect what the agent can access, review the proposed change at file level, and verify behavior before sharing or committing it. That sequence turns convenience into a repeatable engineering process and makes failures easier to diagnose.

CORS affects provider connectivity

Some providers and Git operations cannot be called reliably from browser JavaScript. An optional proxy may be required, changing the network path without changing key ownership.

For developers bringing provider keys to web tools, the practical question is not whether the feature exists in a demo. It is whether the complete workflow remains understandable when files, model context, verification output, credentials, and recovery all interact. A useful Web browser workflow keeps those boundaries visible instead of hiding them behind a single generated answer.

Apply this as an operational rule: define the intended result, inspect what the agent can access, review the proposed change at file level, and verify behavior before sharing or committing it. That sequence turns convenience into a repeatable engineering process and makes failures easier to diagnose.

Key hygiene still matters

Use scoped keys where available, set provider budgets, rotate exposed credentials, and never store keys in repositories, project ZIPs, screenshots, or chat content.

For developers bringing provider keys to web tools, the practical question is not whether the feature exists in a demo. It is whether the complete workflow remains understandable when files, model context, verification output, credentials, and recovery all interact. A useful Web browser workflow keeps those boundaries visible instead of hiding them behind a single generated answer.

Apply this as an operational rule: define the intended result, inspect what the agent can access, review the proposed change at file level, and verify behavior before sharing or committing it. That sequence turns convenience into a repeatable engineering process and makes failures easier to diagnose.

A practical workflow you can repeat

  1. Define a narrow outcome. State the behavior, affected files, and acceptance criteria before asking an agent to act.
  2. Prepare local context. Open only the relevant project and confirm that secrets, generated files, and unrelated repositories are outside the task.
  3. Choose the right surface. Use Web Beta for immediate browser access, Android Beta for focused mobile work, and Desktop when native terminal, system Git, external LSP, or large folders matter.
  4. Review every proposed hunk. Read surrounding code and reject opportunistic cleanup that was not part of the request.
  5. Verify locally. Run preview, build, diagnostics, terminal checks, or tests appropriate to the project.
  6. Create an exit point. Export ZIP or make a reviewed Git commit before changing device or beginning a new agent task.

This loop is intentionally conservative. AI saves time when it shortens exploration and drafting, not when it removes ownership. The developer still controls credentials, defines the task boundary, approves persistence, and decides whether the observed result is ready to keep.

Product limits and privacy boundaries

CodeWinger stores projects and configured credentials locally on the selected platform. That does not mean model work is offline: prompts, code, and selected context are sent directly to the AI provider configured by the user. In Web Beta, some provider and remote Git operations may require an optional proxy because browsers enforce CORS. The operator of any configured proxy becomes part of the trust boundary.

Claude provides the primary tool-using file-editing loop. Other providers may be available as chat rather than equivalent agents, depending on platform and transport support. Android 1.0.0 is a directly distributed public beta. iOS, provider-subscription OAuth, and one-click deploy are not available. Browser terminal behavior is not a native PTY, and mobile package support cannot match an unrestricted desktop toolchain.

These constraints are not footnotes: they determine which projects fit the workflow. Keep provider-side budgets, use encrypted or operating-system credential storage, export backups, inspect diffs, and move work to Desktop when native dependencies or repository scale exceed the browser or phone surface.

Try the workflow

CodeWinger on Windows, Web, and Android

Desktop 0.3.0 is the stable Windows release. Web and Android are beta surfaces built around the same principle: the agent proposes, and the developer decides what becomes code.

Launch Web BetaCompare platforms

Bottom line

Use scoped keys where available, set provider budgets, rotate exposed credentials, and never store keys in repositories, project ZIPs, screenshots, or chat content. Choose the surface that matches the task, preserve a portable copy, and keep review and verification between generation and release. That is the difference between using an AI coding tool and handing control of the project to it.

FAQ

What does BYOK mean?

It means using an API key from your own AI provider account.

Does BYOK use my ChatGPT Plus or Claude Pro subscription?

No. Consumer subscriptions and API billing are separate products.

Are browser keys stored as plaintext?

CodeWinger Web offers an encrypted passphrase vault or a session-only mode rather than persistent plaintext storage.

Can CodeWinger see my key?

The local app handles it to make provider requests; it is not sent to CodeWinger infrastructure. A configured proxy changes the route and must be trusted accordingly.

Does encryption make a compromised browser safe?

No. Encryption at rest cannot defeat malicious extensions, an infected device, or code running after the vault is unlocked.

How do I limit cost?

Use provider-side budgets together with CodeWinger’s local cost estimates and limits.

How to Move Coding Projects Between Android, Browser, and PCA practical workflow for moving local coding projects between Android, a browser IDE, and a Windows PC without locking code into one device.AI IDE for Chromebook: A Local-First Browser WorkflowHow to use a browser-based, local-first AI IDE on a Chromebook with project storage, BYOK, preview, Git limitations, and offline PWA behavior.Inline Diff Review on Mobile: Safely Approving AI Code ChangesLearn why per-hunk inline diff review matters on a phone and how to inspect, accept, reject, undo, and verify AI-generated code safely.What is a local-first AI IDE?Privacy, BYOK, and agent control explained.