Valta Docs

Set up the OpenAI proxy (8 steps to your first deny)

By the end of this page:

  • Your agent talks to OpenAI through Valta, using a Valta virtual key (vk_live_…) instead of your OpenAI key.
  • Every call is checked against the agent's spend cap before it's sent. If it's over the cap, the agent is frozen, or Valta can't decide, OpenAI is never called.
  • You'll have watched a real call get denied — no OpenAI credit needed for that part.

If you want the "why" first, read Enforced proxy. This page is just the steps.

Before you start

  • A Valta account. Free works for everything on this page.
  • An OpenAI API key (sk-…) from platform.openai.com.
    • A key with no credit is fine for setup and for seeing a deny. Denied calls never reach OpenAI.
    • Approved calls do go to OpenAI, so they need credit on that OpenAI account. A test run costs a fraction of a cent.

Everything is per agent. Each agent has its own OpenAI key, its own Cap limits, and its own virtual keys. If you set things up on one agent and then open a different agent, that page will look empty — nothing is lost. On Free, you get 1 active virtual key per account, so if you already made one, it's on the agent you made it on.

Step 1 — Open My Agents

Sign in at valta.co/dashboard and click My Agents in the sidebar.

Step 2 — Open the agent's page

Click the agent you want to govern. The address will be valta.co/dashboard/agents/<agentId>.

Built your agent with the API or SDK? Use Configure by Agent ID on the My Agents page and paste its id.

Scroll down to the Cap card. Everything below happens in that card.

Step 3 — Turn on Cap and set a limit

  1. Click Enable Cap.
  2. Put 0.06 in Per run (USD) and leave the daily and monthly fields empty.
  3. Click Save limits.

A per-run limit caps one job, loop, or conversation — whatever you group together with a run id.

Step 4 — Save your OpenAI key

In Enforced proxy (OpenAI), under the Cap card:

  1. Paste your OpenAI key into Your OpenAI key.
  2. Click Save key.

It changes to sk-••••abcd (your last 4 characters). Valta stores the key encrypted and never shows it again. Saving a new key later replaces the old one.

Step 5 — Create a virtual key

  1. Optionally give it a name (e.g. production).
  2. Click Create virtual key.
  3. Copy the vk_live_… secret now. It's shown once. If you lose it, create a new one (on Free, revoke the old one first).
  4. Click I've saved it.

This virtual key is what your agent will hold. It only works against Valta — it is not an OpenAI key.

Step 6 — Check the proxy is up

Open this in a browser, or run it in a terminal:

bash
curl https://valta.co/v1/health

You should see "status":"ok". If it ever says "degraded", Valta is denying every call rather than forwarding any.

Step 7 — Point your agent at Valta

Change two settings. No other code changes.

bash
OPENAI_BASE_URL=https://valta.co/v1
OPENAI_API_KEY=vk_live_YOUR_VIRTUAL_KEY   # the Valta virtual key, not your OpenAI key

Remove the real OpenAI key from the agent's environment — that's the point. The agent now can't reach OpenAI except through Valta.

Python:

python
from openai import OpenAI

client = OpenAI()  # reads OPENAI_BASE_URL and OPENAI_API_KEY
client.chat.completions.create(
    model="gpt-4o-mini",
    messages=[{"role": "user", "content": "Summarize this ticket."}],
    max_tokens=300,                                    # keeps the cost estimate tight
    extra_headers={"X-Valta-Run-Id": "ticket-4812"},   # groups calls for the per-run limit
)

Node / TypeScript:

ts
import OpenAI from "openai";

const client = new OpenAI(); // reads OPENAI_BASE_URL and OPENAI_API_KEY
await client.chat.completions.create(
  {
    model: "gpt-4o-mini",
    messages: [{ role: "user", content: "Summarize this ticket." }],
    max_tokens: 300,
  },
  { headers: { "X-Valta-Run-Id": "ticket-4812" } }
);

Step 8 — Watch your first deny (no OpenAI credit needed)

Send one call that's over the $0.06 per-run cap by itself (gpt-4.1 with room for 8,000 output tokens is estimated at about $0.064):

Mac / Linux:

bash
curl https://valta.co/v1/chat/completions \
  -H "Authorization: Bearer vk_live_YOUR_VIRTUAL_KEY" \
  -H "Content-Type: application/json" \
  -d '{"model":"gpt-4.1","messages":[{"role":"user","content":"hi"}],"max_tokens":8000}'

Windows (Command Prompt) — one line, double quotes, and \" inside the JSON:

curl https://valta.co/v1/chat/completions -H "Authorization: Bearer vk_live_YOUR_VIRTUAL_KEY" -H "Content-Type: application/json" -d "{\"model\":\"gpt-4.1\",\"messages\":[{\"role\":\"user\",\"content\":\"hi\"}],\"max_tokens\":8000}"

You'll get HTTP 402 and:

json
{"approved":false,"reason":"per_run_limit","id":"allow_…","message":"Valta per-run limit reached for this run. No request was sent to OpenAI.", ...}

Refresh the agent's page: the proxy panel's Last deny shows the same reason and id. Check your OpenAI usage page — there's nothing there for this call. That's the whole product: the call that would have broken the cap never left Valta.

After the first deny

  • Send X-Valta-Run-Id with the same value for every call in one job or loop. Without it, every call counts as its own run. The run's spend is kept by Valta, so a crashed and restarted agent using the same run id is still over its cap.
  • Set max_tokens. Valta estimates each call's cost up front; without max_tokens it assumes 1,024 output tokens.
  • Treat a deny as final. The OpenAI SDK raises an error (APIStatusError in Python) with status 402 or 403. Don't catch it and retry.
  • Approved calls need OpenAI credit, because they really go to OpenAI with your key. A test run costs a fraction of a cent.
  • Want to see a whole retry loop? Valta-hq/langgraph-spend-cap runs a LangGraph retry loop through the proxy: hops 1–3 go through, hop 4 is denied, and only three requests appear on your OpenAI usage page. python demo.py --dry-run works with no keys at all.

Troubleshooting

What you seeWhyFix
My OpenAI key / virtual key "disappeared"You're on a different agent's page. Keys and limits are per agent.Open the agent you set up (My Agents). The panel also tells you which agent holds your account's key.
"Your Free plan allows 1 active virtual key…"Free allows one active virtual key per account.Use the key you already have (the message names its agent), revoke it first, or upgrade to Builder.
401 invalid_api_keyThe key is missing, mistyped, revoked, or you sent the OpenAI key instead of the virtual key.Send Authorization: Bearer vk_live_….
403 cap_disabledCap is off for this agent.Step 3.
403 no_provider_keyNo OpenAI key saved on this agent.Step 4 — on this agent.
403 frozenThe agent is frozen.Unfreeze it in My Agents (see Kill switch).
402 plan_limitYour plan's tracked spend for the month is used up.The response includes an upgrade link. Resets on the 1st (UTC).
OpenAI error insufficient_quotaValta approved the call; your OpenAI account has no credit.Add credit on OpenAI. Denies keep working without it.
Windows: "Bad hostname", "nested brace", or "Invalid API key"\ line breaks, single quotes, or a $ in front of the key don't work in Command Prompt.Use the one-line Windows version in Step 8, with no $.
Setup snippet shows a *.vercel.app addressYou're on a preview deployment.Use https://valta.co/v1, and not www.valta.co.

Plans

FreeBuilder ($29/mo)Startup ($99/mo)
Active virtual keys (per account)11050
Requests per minute, per key10120600
Tracked spend per month (all agents)$50$500$5,000

You keep paying OpenAI for tokens directly — Valta never resells or marks them up. The Valta plan is what keeps the check in front of every call.

Next