> ## Documentation Index
> Fetch the complete documentation index at: https://docs.apostra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Generative creative provider credentials

> How creative provider accounts and model keys are connected, mapped, and rotated

Organizations with generative creative enabled can connect provider API keys
for OpenAI, Gemini, and fal.ai. The key determines whose provider account pays
the model cost; it does not change which Apostra organization owns the
campaign or advertiser.

AudioStack and ElevenLabs credentials are managed under **Settings →
Connections → Creative tools**. In **Advertiser mapping**, map the AudioStack
or ElevenLabs access grant to each advertiser. The mapping determines which
provider tenant is billed. Generation for an advertiser without a
mapping fails before it starts; Apostra never falls back to another
provider account.

Replacing an AudioStack or ElevenLabs key creates a new access-grant identity.
Confirm its advertiser mappings again before generation resumes. This prevents
a key for a different provider tenant from inheriting the previous tenant's
mappings.

## How an OpenAI, Gemini, or fal.ai key is selected

Provider keys belong to the organization and have a label. You can assign one
key to several advertisers or mark one key as the organization default for that
provider.

When generation starts, an advertiser-assigned key takes precedence. If the
advertiser has no assigned key, Apostra uses the provider default only when
you explicitly set one. It never silently chooses another key, because that
could charge the wrong provider account.

## Rotate a key

A delegated call that selects a specific connection credential fails if that
credential becomes unavailable. It cannot substitute a local development
environment key for the selected credential.

In **Settings → Generative creative**, open the key's action menu and choose
**Rotate key**. Enter the replacement API key and confirm.

Rotation preserves the credential's label, advertiser assignments, and default
status. The existing key remains active unless the replacement is stored and
the credential is switched successfully. After the switch, Apostra retires
the old stored secret.

You can also rotate through the buyer API:

```http theme={null}
PATCH /api/v2/buyer/creative/model-credentials/{credentialId}
Content-Type: application/json

{ "apiKey": "your-replacement-provider-key" }
```

Provider keys are stored encrypted and are never returned by the API. List
responses include only a masked hint.

## Provider costs and Intelligence Units

Creative generated with your provider key is charged by that provider to your
provider account. Buyer-funded provider attempts are excluded from
Apostra's generated-media IU meter, including retries and discarded
variants.

AudioStack and ElevenLabs remain bring-your-own-key regardless of the
organization's other billing settings. Their credentials are managed on the
provider connection, not in **Settings → Generative creative**.

The mapped provider account controls billing; voice selection is independent.
Set the brand's durable default voice with `brand.voice_synthesis`, or set
transformer `voice_id` to override it for one build.

## Provide exact copy for ElevenLabs voice drafts

ElevenLabs speaks only explicit voice copy. Put the exact words to speak in
straight or curly quotation marks in `creative_brief.prompt`, or provide a
`creative_manifest.assets.script` text asset. For example:

```json theme={null}
{
  "creative_brief": {
    "prompt": "Friendly 15-second climbing-gym spot. \"Chalk up. Climb higher. Your first class is on us this week.\""
  }
}
```

Direction without quoted spoken copy, such as a requested tone or duration,
does not give ElevenLabs words to say. The request stops before the provider is
called and asks you to add a script. An assistant preparing a voice draft should
write a short script in quotes from the buyer's confirmed intent, or ask the
buyer to provide the exact copy first.

### Clip length follows your script

The clip is as long as it takes to speak your words, not as long as the slot you
name. A 15-word line produces a clip of about six seconds whether the slot is 15
or 30 seconds, and you can add music or silence to fill the slot later. A
duration in the brief, such as "15-second", is a target and never causes a
rejection.

Apostra checks the generated audio against your script. It estimates the spoken
length and rejects audio that is under one second or under 40% of that
estimate, because such audio cannot be your script. For space-separated
languages the estimate is about 160 words per minute. Chinese and Japanese
scripts have no spaces between words, so they are measured at about five
characters per second, and Thai at about two words per second. If Apostra
cannot estimate the length of your script, it cannot show the clip is long
enough and rejects it as `generated_audio_too_short`. Audio that cannot be
decoded is also rejected. When a leaf is rejected after the
provider was called, the generation result carries a `failureReason` on that
leaf, one of `generated_audio_too_short`, `generated_audio_undecodable`, or
`provider_error`. The provider may have charged for that attempt, so the leaf is
not retried automatically; create a new generation action to try again.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.