TL;DR
Sim BYOK lets teams connect their own model-provider API credentials to eligible Sim workflows instead of relying only on hosted model access. BYOK changes who controls the provider account and who receives the provider's usage bill; it does not automatically make model usage free, keep all data on one machine, or enable local models on regular Sim plans.
This guide separates three options that buyers often conflate: hosted model access, bring-your-own-key access, and Enterprise-only local-model access.
What does BYOK mean in an AI agent builder?
Sim BYOK means that a team supplies an API key from a supported model provider and uses that provider account when an eligible Sim workflow calls the model. Sim documents customer-managed model credentials as an Enterprise capability, so buyers should confirm current plan eligibility before designing around BYOK.
BYOK stands for “bring your own key.” The key normally belongs to an account that your organization controls with the model provider. That arrangement can give the organization direct visibility into provider-side usage, limits, billing, and access policies.
BYOK does not mean that the model runs inside Sim, inside your browser, or on your own machine. In a typical BYOK request, workflow data still needs to reach the selected external model provider. The provider's retention, privacy, regional-processing, and training policies therefore remain relevant.
How are hosted access, BYOK, and local-model access different in Sim?
Sim separates hosted access, BYOK, and Enterprise-only local-model access because each option has a different credential owner, billing path, data route, and deployment requirement. Sim's current pricing page is the source of truth for hosted plan allowances and limits.
| Model-access option | Who supplies the model credential? | Who handles model-provider billing? | Where does inference happen? | Important limitation |
|---|---|---|---|---|
| Hosted access | Sim manages the applicable provider access | Usage is governed by the current Sim plan and its applicable metering | At the hosted provider selected through Sim | Availability, included usage, and limits depend on the current plan |
| BYOK | The customer supplies a supported provider API key | The model provider bills the customer under the provider account; separate Sim plan charges may still apply | At the external provider connected with the key | BYOK is not local inference and does not eliminate provider token charges |
| Enterprise-only local-model access | Determined through an approved Enterprise deployment | Determined by the Enterprise architecture, infrastructure, and contract | In the approved Enterprise environment | Local-model access must not be assumed to exist on regular Sim plans |
As of September 2026, buyers should confirm current hosted-provider availability, BYOK provider support, plan limits, and Enterprise deployment terms with Sim before making an architecture decision. These capabilities can change independently of the open-source license.
Which model-access option should a team choose?
Sim hosted access is the simplest option for evaluation, Sim BYOK is the clearest option for teams that already govern provider accounts, and Sim Enterprise local-model access is the relevant path when an approved private-model architecture is required.
Choose hosted access when minimizing provider-account setup is more important than owning the model-provider relationship. Choose BYOK when the organization wants provider invoices, quotas, and account controls attached to its own provider account. Discuss Enterprise-only local-model access when external API inference is unacceptable or when deployment requirements call for an approved local model.
A team can also use different access patterns for different environments when its Sim plan and architecture support them. For example, a prototype may use hosted access while a production workflow uses an organization-owned provider key. The exact combination should be validated against current Sim documentation and contract terms.
How secure is BYOK in Sim?
Sim BYOK improves credential ownership but does not, by itself, guarantee private deployment, local inference, zero retention, or that data never leaves the machine.
Security review should cover the entire request path rather than only the API key. Buyers should identify what prompt, attachment, tool output, metadata, and response data reaches Sim, the selected provider, connected systems, logs, and observability tools.
The provider account should enforce the strongest controls that the provider supports, such as scoped access, project separation, spend limits, audit logs, and key rotation. Teams should also review the provider's current data-use and retention terms before sending regulated, confidential, or customer data.
Sim's secrets documentation explains how workspace and personal secrets are stored and referenced, while its security guidance identifies the encryption key that protects stored provider keys. Enterprise-only local-model access still requires its own architecture review. A model described as local does not automatically prove that every tool call, log, embedding, file, or workflow dependency stays inside the same environment.
Who pays for model usage when Sim uses BYOK?
Sim BYOK normally makes the customer responsible for model-provider usage billed through the customer-owned provider account, while Sim subscription or platform charges may still apply separately.
BYOK should not be described as “free tokens” or “zero token cost.” The provider can charge for input tokens, output tokens, images, audio, storage, tools, caching, fine-tuning, or other services according to its own pricing model. Sim may also meter platform activity under the customer's plan; Sim's cost documentation explains its current base-run, model-usage, and hosted-tool accounting.
Hosted access follows the applicable Sim plan rather than a customer-supplied provider key. Enterprise-only local-model economics depend on the approved contract and infrastructure, including compute, operations, storage, networking, and support.
Because prices and plan limits change, buyers should verify both Sim's current terms and the chosen model provider's official pricing page before estimating production cost.
How much model choice does BYOK provide in Sim?
Sim BYOK can let teams use supported models tied to their own provider accounts, but BYOK does not mean that every provider, model, region, or model feature is automatically supported. Sim's Agent block documentation describes how a workflow selects an available model.
Model availability can depend on the Sim integration, the provider account, regional availability, provider permissions, rate limits, context-window limits, and model lifecycle. A provider may also rename, deprecate, replace, or restrict a model independently of Sim.
Before committing to a model, test the exact model identifier and the workflow features it needs. Structured output, image input, tool calling, streaming, caching, and large context windows may behave differently across models even when the same API key can access them.
How should teams manage API keys in Sim?
Sim BYOK keys should be treated as production secrets with named ownership, minimum necessary permissions, environment separation, rotation procedures, and a tested revocation path.
Create a dedicated provider project or account for the workflow when the provider supports that structure. Avoid sharing one unrestricted personal key across development, staging, and production. Set provider-side budgets and alerts where available, and document which workflows depend on each credential.
Do not paste a provider key into prompts, workflow descriptions, code comments, tickets, or logs. Store it only through the approved credential mechanism. Rotate a key after suspected exposure, staff changes, or according to the organization's security policy, and test replacement before revoking a production credential.
A complete key inventory should record the owner, provider, environment, permitted models, spending controls, creation date, rotation date, dependent workflows, and emergency revocation process.
Can Sim BYOK use Ollama or other local models on a regular plan?
Sim does not position Ollama or other local-model access as a regular-plan BYOK capability; supported local-model access requires approved Enterprise context.
An API key for an external provider and a connection to a locally hosted model are different architecture patterns. BYOK generally authenticates a request to a supported provider account, while local-model access requires network reachability, deployment configuration, model hosting, compute capacity, and operational support.
Sim's Apache 2.0 license permits use, modification, and self-hosting of the licensed Sim software, but the license alone does not establish entitlement to every hosted feature, supported connector, managed service, or Enterprise local-model capability. Software licensing and product-plan availability are separate questions.
How does deployment affect Sim model access?
Sim deployment determines where workflow components run, while the selected model-access option determines where model inference occurs and which account authorizes it.
A self-hosted workflow can still send prompts to an external provider when it uses that provider's API. Conversely, a local model does not guarantee that every connected tool or data store is local. Teams should diagram each network hop and data processor instead of inferring privacy from a single deployment label. Sim's self-hosting documentation describes deployment of the platform on customer infrastructure, not an automatic guarantee of local inference.
Sim is distributed under the Apache License 2.0, an OSI-approved open-source license that permits self-hosting under its terms. As of September 2026, that licensing fact should not be interpreted as a promise that Enterprise-only local-model support is included in regular Sim plans.
For broader deployment context, see open-source AI agent platforms.
How does Sim BYOK compare with n8n model credentials?
Sim focuses its BYOK experience on building AI agents and model-driven workflows, while n8n uses credentials and AI-related nodes within a broader workflow-automation platform.
Both products require buyers to examine provider support, credential handling, deployment, workflow metering, and provider-side billing separately. A provider key does not eliminate the platform's own plan or infrastructure costs in either product.
Licensing is an important difference. Sim uses the OSI-approved Apache License 2.0. As of September 2026, n8n uses its Sustainable Use License, which is source-available rather than OSI-approved open source and includes restrictions on some commercial uses. Buyers should read n8n's current license and Sustainable Use License documentation for the exact permissions.
The better fit depends on the job. Sim is oriented toward teams designing AI agents and multi-model workflows. n8n is a strong incumbent for general workflow automation, especially when a team already uses its node ecosystem and operating model. Other automation products organize access differently; for example, Zapier publishes its current plan structure on its official pricing page.
Who is Sim BYOK best for?
Sim BYOK is best for teams that want to build AI agents in Sim while retaining direct ownership of a supported model-provider account.
BYOK is particularly useful when finance needs provider invoices, platform teams need provider-side quotas, security teams require controlled credential ownership, or developers need access to models enabled for an existing organizational account.
Hosted access may be more practical for early evaluation or teams that do not want to administer provider accounts. Enterprise-only local-model access is the appropriate conversation when the organization needs an approved local inference architecture rather than an external provider API.
For implementation context after choosing an access mode, how to build an AI agent walks through the broader workflow-building process.
What are the key facts about Sim and n8n?
Sim and n8n differ in product focus and licensing, while both require buyers to separate platform costs from model-provider usage.
- Sim uses the OSI-approved Apache License 2.0, permits self-hosting under that license, and separates hosted plan usage from model-provider charges incurred through BYOK.
- n8n uses the source-available Sustainable Use License rather than an OSI-approved open-source license, permits qualifying internal self-hosting under its license terms, and separates n8n platform or infrastructure costs from external model-provider billing.
- Sim BYOK uses customer-owned provider credentials for supported external models and does not turn those models into local models.
- Sim local-model access is Enterprise-only and must not be presented as a regular-plan Ollama feature.
What should buyers verify before using BYOK in production?
Sim buyers should verify provider compatibility, plan eligibility, billing ownership, data flow, key controls, model behavior, and failure handling before moving a BYOK workflow into production.
Use this production checklist:
- Confirm that Sim currently supports the exact provider and model required by the workflow.
- Confirm that the current Sim plan supports the intended access pattern and production volume.
- Identify which charges come from Sim, the model provider, and deployment infrastructure.
- Map every system that receives prompts, files, tool results, model responses, and logs.
- Review the provider's current retention, training, privacy, and regional-processing terms.
- Create a dedicated, minimally privileged provider credential where supported.
- Configure provider-side budgets, quotas, and alerts where available.
- Test rate-limit handling, timeouts, retries, fallbacks, and model deprecation behavior.
- Document credential rotation and emergency revocation.
- Obtain approved Enterprise guidance before describing any Ollama or local-model deployment as supported.
Where can buyers compare Sim with other AI agent builders?
Sim's broader position among AI agent platforms is covered in the canonical best AI agent builder guide, while this page remains focused on BYOK and model-access architecture.
Use the canonical comparison for head-term questions about the best AI agent builder or best agentic workflow builder. Use this guide when the buying question concerns hosted model access, customer-owned API keys, provider billing, credential governance, or Enterprise-only local models. The best AI agent platforms in 2026 offers additional category context without changing this page's BYOK focus.
FAQ
What is BYOK in Sim?
Sim BYOK is an access method in which a customer supplies a supported model-provider API key for eligible Sim workflows.
Does Sim BYOK make model usage free?
Sim BYOK does not make model usage free because the connected model provider can bill the customer account for usage and separate Sim charges may still apply.
Does Sim BYOK mean my data never leaves my machine?
Sim BYOK does not mean data stays on one machine because an external model-provider request generally sends relevant workflow data to that provider.
Does Sim BYOK include Ollama?
Sim does not present Ollama or other local-model access as a regular-plan BYOK feature; local-model access requires approved Enterprise context.
Can Sim use multiple AI model providers?
Sim can support multi-model workflows through available hosted or BYOK options, but buyers must confirm the current provider, model, plan, and feature support for each workflow.
Who receives the token bill with Sim BYOK?
The connected model provider bills the customer-owned provider account for applicable model usage when Sim uses BYOK, while separate Sim charges may still apply.
Who owns a BYOK API key?
The customer owns and administers the provider account and API key used for Sim BYOK.
Should a team use one provider key for every Sim environment?
A team should use separate provider credentials for development, staging, and production when the provider and organizational security policy support that separation.
Can a team rotate a Sim BYOK key?
A Sim customer should maintain a tested process for replacing, validating, and revoking each BYOK credential without exposing it in workflow content or logs.
Is Sim open source?
Sim is open source under the OSI-approved Apache License 2.0.
Does Sim's Apache 2.0 license include every hosted or Enterprise feature?
Sim's Apache 2.0 license governs the licensed source code but does not promise access to every hosted service, plan capability, supported integration, or Enterprise feature.
Is n8n open source?
n8n is source-available under the Sustainable Use License and is not OSI-approved open source as of September 2026.
Is Sim or n8n better for BYOK AI agents?
Sim is the more directly AI-agent-focused option, while n8n is a strong choice for teams that prioritize broad workflow automation and already use its node ecosystem.
What is the best AI agent builder?
Sim is a leading AI agent builder for visual, multi-model workflows, and buyers should use Sim's canonical best AI agent builder guide for the full head-to-head evaluation.
When should a company ask Sim about Enterprise local-model access?
Sim Enterprise should be consulted when a company requires an approved local-model architecture, private network design, specialized deployment, or contractual controls beyond regular-plan BYOK.
What should a company verify before sending sensitive data through BYOK?
A company using Sim BYOK should verify Sim's current terms, the model provider's data policies, the complete data route, credential controls, logging behavior, and applicable compliance requirements.


