---
title: "Cloudflare Workers AI BYOK and DigitalOcean Models"
url: https://www.insulin.dev/blog/cloudflare-workers-ai-byok/
canonical: https://www.insulin.dev/blog/cloudflare-workers-ai-byok/
type: Blog
description: "Run Insulin agents on Cloudflare Workers AI or DigitalOcean with your own key: the five models each, what the connect check proves, and what else to set."
---

# Cloudflare Workers AI BYOK and DigitalOcean Models

> Canonical HTML version: https://www.insulin.dev/blog/cloudflare-workers-ai-byok/

1.  [Home](/)
2.  /
3.  [Blog](/blog/)
4.  /
5.  Cloudflare Workers AI BYOK and DigitalOcean Models

# Cloudflare Workers AI BYOK and DigitalOcean Models

Run Insulin agents on Cloudflare Workers AI or DigitalOcean with your own key: the five models each, what the connect check proves, and what else to set.

![Shirley Guo](/authors/shirley-guo.jpg)

Shirley Guo

Sep 28, 2026

 ![Cloudflare Workers AI BYOK and DigitalOcean Models](/images/blog/cloudflare-workers-ai-byok/hero.png)

Explore AI Summary

 [![](/logos/company/openai.svg)](https://chat.openai.com/?q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fcloudflare-workers-ai-byok%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Integrations%2C%20Agents. "Summarize with ChatGPT")[![](/logos/company/anthropic.svg) ](https://claude.ai/new?q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fcloudflare-workers-ai-byok%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Integrations%2C%20Agents. "Summarize with Claude")[![](/logos/company/gemini.svg)](https://www.google.com/search?udm=50&aep=11&q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fcloudflare-workers-ai-byok%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Integrations%2C%20Agents. "Summarize with Gemini")[](https://www.perplexity.ai/search/new?q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fcloudflare-workers-ai-byok%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Integrations%2C%20Agents. "Summarize with Perplexity")

Table of Contents

-   [What is Cloudflare Workers AI BYOK in Insulin?](#what-is-cloudflare-workers-ai-byok-in-insulin)
-   [Which agents can use the connection?](#which-agents-can-use-the-connection)
-   [What does the connect check prove?](#what-does-the-connect-check-prove)
-   [What has to line up in the AI Model Policy?](#what-has-to-line-up-in-the-ai-model-policy)
-   [Can a knowledge base use these models?](#can-a-knowledge-base-use-these-models)
-   [What does it cost?](#what-does-it-cost)
-   [How do you rotate or remove the credential?](#how-do-you-rotate-or-remove-the-credential)
-   [What should you check before agents depend on it?](#what-should-you-check-before-agents-depend-on-it)
-   [Frequently asked questions](#frequently-asked-questions)
-   [Takeaways](#takeaways)

_Cloudflare Workers AI BYOK means running Insulin’s agents on Workers AI chat models through your own Workers AI API token and Cloudflare account ID, with Cloudflare billing the usage to your account. DigitalOcean GradientAI works the same way with a model access key. Either way, the connect check proves the provider accepted your credential, and nothing more._

* * *

If your company already buys AI inference from Cloudflare or DigitalOcean, two questions follow. Can your agents run on those models under your own account? And what has to be in place before they actually do?

The first answer is yes. Insulin connects both as model providers with your own credential, for the whole organization or just for you, and each adds five chat models to Insulin’s model pickers. The second answer is spread across the workspace: what the connect check proved, the level you connected at, your organization’s AI Model Policy, and a separate provider for knowledge bases. This post puts them in one place, with a checklist at the end.

## What is Cloudflare Workers AI BYOK in Insulin?

**Cloudflare Workers AI BYOK (bring your own key) is** connecting your own Workers AI API token and Cloudflare account ID so that Insulin’s AI features can run on Workers AI models, with the usage billed to your Cloudflare account. **DigitalOcean GradientAI** is the same arrangement with a DigitalOcean model access key, billed to your DigitalOcean account.

Both connect from **Settings → Integrations**. Insulin offers a fixed set of five chat models from each, not either provider’s whole catalog:

Provider

The five chat models Insulin offers

Cloudflare Workers AI

Llama 3.3 70B Instruct (fast), Llama 3.1 8B Instruct (fp8), GPT-OSS 120B, Qwen2.5 Coder 32B Instruct, Mistral Small 3.1 24B Instruct

DigitalOcean GradientAI

Llama 4 Maverick, GPT-OSS 120B, Claude Sonnet 5, DeepSeek V4 Pro, Qwen 3.5 397B A17B

They are chat models only. Neither provider adds an embedding model, which matters for knowledge bases, covered below.

## Which agents can use the connection?

**The level you connect at decides it: an organization connection serves organization agents and apps, and a personal connection serves only you.** Connect from the **Integrations** grid for the organization, which only an org **ADMIN** can do, or under **User Integrations** for yourself. The models then appear here:

Where

Organization connection

Personal connection

An agent’s **Default model** picker, searchable and grouped by provider

Organization agents

Your personal agents

The built-in Insulin assistant’s model settings

Not offered: the assistant never reaches the organization’s keys

Offered

The Custom Apps builder’s model picker, as a provider group

Organization apps

Your personal apps

Inbox

Not used: Inbox uses the providers you connected yourself

Used, although the **AI model** card in **Settings → Account** doesn’t list them

Two consequences follow. An organization connection alone doesn’t put the built-in assistant or Inbox on Cloudflare or DigitalOcean; each person who wants that connects their own. And a personal credential never serves anyone else in your organization.

## What does the connect check prove?

**That the provider accepted your credential, and nothing more.** Before storing anything, Insulin uses the credential to ask the provider for its list of models. For Cloudflare, it first checks that the Account ID is 32 hexadecimal characters, the only form it accepts. The connect form then ends in one of four results:

Result

What the form shows

What it means

**Connected**

No error

The provider accepted the credential, and it is stored

**Rejected: the Account ID** (Cloudflare only)

`Invalid connection config field "accountId": must be a 32-character hexadecimal Cloudflare account id`

The Account ID is the wrong shape, so nothing is stored. Copy it again

**Rejected: the credential**

`Cloudflare Workers AI rejected the supplied API key` or `DigitalOcean GradientAI rejected the supplied API key`

The provider refused it, so nothing is stored. Check that you pasted all of it and that it hasn’t been revoked, deleted or regenerated

**Not confirmed**

`… could not confirm the key right now (status …)` or `Could not reach … to verify the key`

No usable answer: a timeout, a rate limit or an outage, or on Cloudflare an account it doesn’t recognise. The credential was **not** judged invalid and nothing is stored. Check the Account ID if it’s Cloudflare, and try again

**What passing doesn’t prove.** The check lists models; it doesn’t run one. So a passing connection doesn’t show whether the credential may run the five models you’re about to pick. What a credential may do is set on the provider’s side: see [Cloudflare’s documentation](https://developers.cloudflare.com/workers-ai/get-started/rest-api/) for a Workers AI API token and your Account ID, or [DigitalOcean’s documentation](https://docs.digitalocean.com/products/inference/how-to/manage-model-access-keys/) for a model access key. Fours’ integration guide for each provider, cited below, says what to set.

**Then prove it with one real run.** Make one of the five models the **Default model** of a test agent with the same ownership as the connection, and send it a message. When a model call fails, a rejected key included, Insulin retries on your next connected provider and says so: the reply ends with a short italic note that names both models and says the first [was unavailable](https://doc.fours.com/insulin/agents/#when-a-model-fails-over). If your test reply carries that note, it came from a different model.

## What has to line up in the AI Model Policy?

**If your organization’s Allowed AI integrations list has any rows, the provider must be one of them, or requests on its models are refused whichever key they would use.** The list sits under **Settings → Organization → AI Model Policy**, which only an org **ADMIN** can change. What to do depends on its state:

-   **The list is empty.** There is nothing to add: _“No restriction — every connected provider is allowed.”_ Don’t add a first row just for this provider. AI features may use only the integrations the list names, so the first row you add shuts out every provider not on it, the Fours-hosted models included unless you also add **Fours Hosted (DeepInfra)**.
-   **The list has rows.** Add **Cloudflare Workers AI** or **DigitalOcean GradientAI**. Until you do, saving an agent with one of their models as a new **Default model** is refused for **AI policy**, and the Custom Apps builder still shows your own-key rows for them but rejects the model when the app runs.
-   **Allow Fours platform key is off, and you want one of them on top.** The top row is the organization default for every feature without a model picker of its own, and with the switch off it must be a provider your organization has connected and verified. The tab marks an OpenAI, Anthropic or Gemini row **not connected** as you edit when it has no verified connection. Cloudflare Workers AI and DigitalOcean GradientAI rows never show that marker: when one of them is the top row, its connection is checked when you click **Save**, and the save is refused unless it is verified.

For what the allow-list and the platform-key switch each guarantee, see [how an AI model allowlist decides which vendors see your prompts](/blog/ai-model-allowlist/).

## Can a knowledge base use these models?

**No. Both serve chat models only: Insulin registers no embedding model for either, so connecting one adds nothing to the knowledge-base embedding chooser.** That bites hardest with **Allow Fours platform key** off. The Fours-hosted embedding models then leave the chooser, and an organization with no embedding provider connected cannot create a knowledge base. Connect one of the providers in the [embedding model reference](https://doc.fours.com/insulin/knowledge-base/#choosing-an-embedding-model) as well: for the organization, and per person for personal knowledge bases.

## What does it cost?

**Your provider bills you for the tokens under your own contract, and Insulin adds a flat platform fee.** Insulin’s [pricing page](/pricing/) sets that fee at $0.10 per million tokens, input and output, the same whichever model you run; what each model costs is between you and your provider.

One thing doesn’t change with your own key: **a zero Insulin balance still pauses these requests**, because the per-token fee is still owed.

Whether to bring your own keys at all is a separate decision about cost structure, control and the data path, and [BYOK vs managed models for enterprise AI](/blog/byok-vs-managed-models-for-enterprise-ai/) walks through it.

## How do you rotate or remove the credential?

**Reconnect to replace it and Disconnect to remove it; there is no Edit.** To swap in a new token, key or Account ID, open the card’s **⋯** menu and choose **Details**, then **Reconnect** and **Start connection**, enter the new values and click **Save credentials**. The new values get the same check as a first connect, and the stored credential is replaced only if they pass, so a rejected replacement leaves the previous one in place. Reconnecting an organization connection takes the org **ADMIN** role.

**Reconnect every time you rotate on the provider’s side.** Insulin checks the credential only when you connect or reconnect, and the card won’t warn you in between: the _Connection expired_ alert covers only the sign-in-based Claude Code and Codex connections, and connections made with an API key never show it. Until you reconnect, calls on a revoked credential are rejected, and turns fail over to your next connected provider with the note saying the model was unavailable.

**Disconnecting is visible, not silent.** Choose **Disconnect** from the **⋯** menu, and the provider’s models can no longer run on that credential. An agent whose **Default model** was one of them shows it marked **unavailable** in its model picker, with a hint to reconnect the provider or choose another model. The agent never silently switches to a different model: a turn that can’t reach its saved default stops with an error saying the model is not available.

## What should you check before agents depend on it?

**Nine checks, one column per provider: read down the column for yours.**

Check

Cloudflare Workers AI

DigitalOcean GradientAI

1\. The credential

A Workers AI API token and your Account ID, created as [Cloudflare’s documentation](https://developers.cloudflare.com/workers-ai/get-started/rest-api/) describes. The Account ID must be 32 hexadecimal characters

A model access key for serverless inference, created as [DigitalOcean’s documentation](https://docs.digitalocean.com/products/inference/how-to/manage-model-access-keys/) describes

2\. The level

The **Integrations** grid for the organization (org ADMIN only), or **User Integrations** for yourself

The **Integrations** grid for the organization (org ADMIN only), or **User Integrations** for yourself

3\. The result

**Connected**. A rejection means fix the Account ID or the token; _could not confirm_ means try again

**Connected**. A rejection means fix the key; _could not confirm_ means try again

4\. One real run

A test agent with a Workers AI **Default model** replies with no _was unavailable_ note

A test agent with a GradientAI **Default model** replies with no _was unavailable_ note

5\. The policy

If **Allowed AI integrations** has rows, **Cloudflare Workers AI** is one of them

If **Allowed AI integrations** has rows, **DigitalOcean GradientAI** is one of them

6\. The people

Each person who wants it in the built-in assistant or Inbox connects their own

Each person who wants it in the built-in assistant or Inbox connects their own

7\. Knowledge bases

With the platform key off, a separate embedding provider is connected

With the platform key off, a separate embedding provider is connected

8\. Rotation

Reconnect after you revoke or replace the token

Reconnect after you delete or regenerate the key

9\. Removal

**Disconnect**; agents defaulting to its models show them as **unavailable**

**Disconnect**; agents defaulting to its models show them as **unavailable**

## Frequently asked questions

### Can Insulin agents run on Cloudflare Workers AI with our own key?

Yes. Connect a Workers AI API token and your Cloudflare account ID under Settings → Integrations, for the organization or just for yourself. Five Workers AI chat models then appear in the model pickers, including an agent’s Default model, and Cloudflare bills the usage to your account.

### Which DigitalOcean models can Insulin use?

Five GradientAI chat models, through your own model access key: Llama 4 Maverick, GPT-OSS 120B, Claude Sonnet 5, DeepSeek V4 Pro and Qwen 3.5 397B A17B. Insulin offers that fixed set, not DigitalOcean’s whole catalog, and none of them is an embedding model.

### Does a successful connection prove the key can run the models?

No. The connect check asks the provider for its model list with your credential, which proves the provider accepted it. It doesn’t run a model. Send one message to an agent whose Default model is one of the five, and check the reply carries no failover note.

### Why are requests on a Cloudflare or DigitalOcean model refused?

Check the AI Model Policy first. When its Allowed AI integrations list has rows, AI features may use only the integrations on it, so add Cloudflare Workers AI or DigitalOcean GradientAI. An empty list allows every connected provider, so leave an empty list alone.

### What happens to our agents if we disconnect the provider?

Its models can no longer run on that credential. An agent whose Default model was one of them shows it as unavailable in its model picker, with a hint to reconnect the provider or choose another model. The agent never silently switches to a different model.

### Who pays for the tokens when we bring our own key?

Your provider bills the tokens to your account, under your own contract. Insulin adds a flat per-token platform fee, the same whichever model you run, and a zero Insulin balance still pauses these requests, because that fee is still owed.

## Takeaways

-   Both providers connect with your own credential and add five chat models each to Insulin, not their full catalogs.
-   The connect check proves the provider accepted the credential. It runs no model, so send one real message and look for a failover note.
-   An organization connection serves organization agents and apps; the built-in assistant and Inbox need a personal one.
-   With a non-empty AI Model Policy allow-list, add the provider. Leave an empty list empty.
-   Neither provider supplies embeddings. Rotate with **Reconnect**, and expect a disconnected default to show as **unavailable** rather than switch silently.

Bringing your own inference is one way to run [AI agents in Insulin](/agents/) on contracts your company already holds. For the organization-level controls around it, the [AI Model Policy reference](https://doc.fours.com/insulin/getting-started/#ai-model-policy) documents the allow-list and the platform-key switch in full.

## Sources

Primary sources for the platform rules cited above. Last verified September 28, 2026. Cloud providers change fees, eligibility, and program terms without notice — check the source before relying on a figure.

-   [Cloudflare Workers AI — Fours Doc](https://doc.fours.com/integrations/cloudflare/) — The five Workers AI chat models offered; organization and user connections and who can connect them; the 32-character hexadecimal Account ID check and the models-list check; the connected, rejected and could-not-confirm results and their messages; no Edit, only Reconnect; the credential checked only at connect or reconnect; Disconnect and the unavailable default; chat models only, no embedding model; adding the provider to Allowed AI integrations
-   [DigitalOcean GradientAI — Fours Doc](https://doc.fours.com/integrations/digitalocean/) — The five GradientAI chat models offered; organization and user connections; the models-list check proving the key is accepted, not which models it may use; the rejected and could-not-confirm results and their messages; Reconnect; the key checked only at connect or reconnect; Disconnect and the unavailable default; chat models only; adding the provider to Allowed AI integrations
-   [Insulin Getting Started — Fours Doc](https://doc.fours.com/insulin/getting-started/) — The AI Model Policy: Allowed AI integrations as an ordered allow-list whose top row is the organization default; the empty-list no-restriction state; the Fours Hosted (DeepInfra) row; the not connected marker, and the Save-time check on Cloudflare Workers AI and DigitalOcean GradientAI rows; Allow Fours platform key; the Connection expired alert covering Claude Code and Codex only
-   [Insulin Agents — Fours Doc](https://doc.fours.com/insulin/agents/) — The Default model picker, searchable and grouped by provider, and whose connected providers join it; the unavailable marker after a disconnect; an agent never silently switching models; a turn that cannot reach its default stopping with an error; a Default model refused on save for AI policy
-   [Insulin Agents — Fours Doc: When a model fails over](https://doc.fours.com/insulin/agents/#when-a-model-fails-over) — Failover when a model call fails, a rejected key included, and the closing note naming both models; the built-in Insulin assistant using only the providers you connected, never the organization's keys
-   [Insulin Custom Apps — Fours Doc](https://doc.fours.com/insulin/custom-apps/) — The builder's model picker grouped by provider; organization and personal apps each listing Your key rows from their own scope; a restricted provider's Your key rows still listed and rejected when the app runs
-   [Insulin Inbox — Fours Doc](https://doc.fours.com/insulin/inbox/) — The AI model card's five listed providers, and Inbox using other providers you connected yourself, Cloudflare Workers AI and DigitalOcean GradientAI included
-   [Insulin Knowledge Bases — Fours Doc](https://doc.fours.com/insulin/knowledge-base/) — The embedding providers the chooser offers; Fours-hosted embedding models offered only while the platform key is on; a bring-your-own-key organization with no embedding provider cannot create a knowledge base
-   [Insulin Metering — Fours Doc](https://doc.fours.com/insulin/billing/metering/) — With your own key, the provider bills the tokens under your own contract and Fours charges a flat fee per unit; a zero balance still pauses bring-your-own-key requests

## Keep reading

-   [IntegrationsAI Agent for BigQuery: Let It Query, Not ChangeOct 7, 2026](/blog/ai-agent-for-bigquery/)
-   [IntegrationsAI Model Retirement: What Happens to Your AgentsOct 7, 2026](/blog/ai-model-retirement/)
-   [IntegrationsEWS Retirement and Your AI Email AssistantOct 8, 2026](/blog/ews-retirement-ai-email-assistant/)
-   [SecurityRead-Only Access for AI Agents: Where It's SetOct 8, 2026](/blog/read-only-access-for-ai-agents/)

[Browse every post on the Insulin Blog](/blog/)

### Stay Updated

New posts, product updates and marketplace strategy are shared on LinkedIn as they publish.

[Follow Fours on LinkedIn](https://www.linkedin.com/company/suger-inc)
