Docs Back to website
← All docs Back to website
Developers

Quickstart

On this page

Want the complete app? Follow the Direct walkthrough and download the starter.

1

Install

Zero dependencies. TypeScript types included.

# Direct is free forever.
npm install @useoutlet/sdk

Python servers: pip install useoutlet, the same Vault calls in Python.

2

Add the Connect your AI button

The same button can offer Direct, Vault or both. This example offers both for OpenAI.

Vault needs a registered app ID and return address. Register your app to get them. Serve this page at your registered return address too.

<div id="connect"></div>
import Outlet from "@useoutlet/sdk";
import { mountConnectButton } from "@useoutlet/sdk/ui";

const params = new URLSearchParams(location.search);
const returning = location.pathname === "/outlet/return"
  && params.has("code") && params.has("state");
let session;

const button = mountConnectButton(document.getElementById("connect"), {
  mode: "both",
  providers: ["openai"],
  appId: "app_yourapp", // Your registered Vault app ID.
  redirectUri: location.origin + "/outlet/return",
  requestedCapUsd: 10, // Your proposed monthly Vault cap in USD.
  session: returning ? Outlet.handleRedirect() : undefined,
  onSession(connected) {
    session = connected;
    // Enable your app's AI action here.
  },
});

onSession receives the session after a connection completes. session.keys.openai holds the Direct API key or Vault App key. Both modes return the same session shape.

The mount call returns button controls: open(), close() and destroy().

For Direct only, set mode: "direct". Omit the Vault options: appId, redirectUri, requestedCapUsd and session. For Vault only, set mode: "vault".

3

Call the provider like you already do

Run this after onSession receives a session. Use the Direct API key or Vault App key with the provider’s SDK. Outlet does not handle the AI request.

npm install openai
import OpenAI from "openai";

const ai = new OpenAI({
  apiKey: session.keys.openai,
  dangerouslyAllowBrowser: true, // their key, their device. Drop this line in Node.
});

const reply = await ai.responses.create({
  model: "gpt-5.5",
  input: "Say hello.",
});
console.log(reply.output_text);
4

Keep the Direct API key on the device

Direct is free forever. Hold the Direct API key in memory on the user’s device. Keep it out of your database and server.

Connect your app with Direct API keys or Vault App keys. Your user brings the AI account.

Building with an AI? Paste this into your AI.

Your AI adds the Connect your AI button for you. Register your app for the app ID.

Add Outlet to this app so users can connect their own AI account.
Read https://useoutlet.dev/llms-full.txt first.
Install: npm install @useoutlet/sdk
App ID: <from useoutlet.dev/register>
Return address: <the https or private-scheme return address>
Local testing: http://localhost/outlet/return, any port
Button: import { mountConnectButton } from "@useoutlet/sdk/ui".
Mount on an empty div with mode: "both", providers, appId and redirectUri.
Vault return: pass Outlet.handleRedirect() as session only when the return address has code and state.
Receive the Direct or Vault session through onSession.
No app secret in the app.
Vault provider: choose openai, anthropic, fal or openrouter. Use a separate Vault connection request for each provider.
Place the Connect your AI button where users connect their AI account.
After connect: call the provider with its official SDK using session.keys.<provider>.
Show all

Which modes should your app offer?

Direct

Users can bring a Direct API key from a provider your app supports.

The user provides a Direct API key in your app.

Your app receives that Direct API key after a local format check.

Vault

Users want separate Vault access and caps managed on Outlet.

The user provides a Vault admin key on Outlet.

Your app receives a separate Vault App key.

Both

Some users want Direct and others can connect through Vault.

The user provides a Direct API key or Vault admin key.

Your app receives a Direct API key or Vault App key in the same session shape.

Direct needs no Outlet account. Direct is free forever. Your app still makes the provider request.

Vault needs a registered app, a return address and a supported provider. The user needs permission to create a Vault admin key. Developers pay for Vault connections. Provider usage is billed by the provider.

The Connect your AI button has a named Direct screen for each provider on the support page. Other providers use a generic Direct screen with the name and keys page supplied by your app. Vault supports OpenAI, Anthropic, fal and OpenRouter.

Vault is open. The user connects on Outlet with a Vault admin key. The user chooses the Vault cap before approving access. Vault returns a separate Vault App key for your app. Vault caps use provider spend reports. Delayed reports can allow spending above a Vault cap. The protocol is public.

Add a connect box

Use this instead of the button if your app already has its own Direct field. The core Direct API can accept other providers your app supports.

Your user pastes a Direct API key into your app. The SDK checks its format on their device and refuses Vault admin keys. The SDK does not send the Direct API key to Outlet.

import Outlet from "@useoutlet/sdk";

const session = await Outlet.direct({
  keys: { openai: userPastedKey },
});

Where users get their Direct API keys

Send them to our step-by-step guides: OpenAI · Anthropic.