Every way of using Claude at Cornell needs a personal key. You create it
yourself in the JCB AI key portal.
🔌 You'll need a wired connection or the VPN
The key portal is only reachable from a wired Cornell connection or the
Cornell VPN.
This applies to the key portal only — Claude itself works from anywhere once
it's set up.
Step 1 — Create your key
- Go to https://keys.ai.business.cornell.edu/ and sign in.
- Click Create key and fill in the form:
| Field |
What to enter |
| Key owner |
Myself, unless you are setting a key up on behalf of a colleague — then choose Someone else. |
| Intended use |
Claude Desktop for the standard setup. This is for reporting only; it does not limit where the key works. |
| Monthly Spend Cap ($) |
A monthly ceiling for this key. See below. |
| KFS account number |
The account your usage is attributed to. |
| Delegates (optional) |
NetIDs of anyone else who should be able to manage this key. |
- Note the expiration date shown on the form. Keys currently expire at the
end of the calendar quarter, not a fixed number of days after you create
one — so a key made in early July runs until September 30. Keys created in
the last couple of weeks of a quarter are the exception: they run to the
end of the following quarter instead, so a key made on September 25 lasts
until December 31 rather than expiring the same week. The date on your own
key is the one that applies — see Managing, Rotating, and Renewing Your Key for renewing
it.
- Click Create key.

ℹ️ A ticket is opened for you. Requesting a key for Claude Desktop use
also generates a TDX ticket automatically, and someone from Client
Services will reach out to coordinate any follow-up your machine needs. You
don't have to submit a separate request alongside the form.
Step 2 — Generate the secret
Creating the key does not give you the secret. The portal deliberately keeps
those separate.

- Find your new key in the list and click its row to expand it.
- Click Generate Key.
- Copy the secret somewhere safe — you will paste it during installation.

This panel is also where you manage the key later — adjusting the spend cap,
adding delegates, checking spend history, or disabling it. See
Managing, Rotating, and Renewing Your Key.
⚠️ Generate the secret yourself, right before you need it. If someone set
the key up for you, you should be the one to generate the secret. Treat it
like a password: don't email it, don't post it in Teams, don't paste it into a
shared document.
About the spend cap
The cap is a monthly ceiling on what this key can spend, in real dollars —
Cornell bills gateway usage at Anthropic's published rates, with no markup. AI
at Cornell lists the exact per-model rates on its
Available Models & Pricing
page (NetID sign-in).
There is no standard figure; appropriate values vary enormously depending on how
you work. Pick something that reflects your expected use, and raise, lower, or
reset it at any time from the key portal, with no ticket and no downtime.
It does two jobs. The first is keeping usage visible and attributable to a
KFS account — that part is not about rationing you.
The second is a backstop. Gateway usage is billed as it happens and
cannot be refunded, so the cap is the only thing standing between an
unexpected bill and your account. Three situations make that matter:
- A long-running or unexpectedly expensive job — a large set of documents,
or a task that turns out to need far more work than it looked like.
- A stolen secret — if one leaks, the cap bounds what someone else can spend
before you rotate it.
- Ordinary misuse — a key shared, pasted somewhere it shouldn't be, or
pointed at something it wasn't meant for.
Set it high enough not to interrupt real work, low enough that a runaway month
is survivable.
If you hit the cap, Claude stops responding — and it doesn't say so. The error
blames the server for "temporarily limiting requests" and offers a Try
again button; the real reason only appears under View details. Worth
knowing that symptom before you meet it — Managing, Rotating, and Renewing Your Key shows
both screens.
Where your key goes
One key works everywhere. A single key covers Claude Desktop, Claude Code,
and anything else on the gateway — you never need a second one.
You may still want one. Each key carries its own spend cap, KFS account, and
spend history, so a second key is the simplest way to keep two things apart:
- Separate budgets — a grant-funded project and your general teaching work,
each with its own ceiling and its own actual spend tracked separately.
- Separate billing — usage that has to be attributed to a different KFS
account.
- Separate blast radius — a key used somewhere riskier (a shared machine, an
automation) can be disabled without disturbing your day-to-day one.
If none of that applies, one key is the right answer.
Next step
Install Claude Desktop — Installing Claude Desktop on macOS (Pilot) or
Installing Claude Desktop on Windows (Pilot).
Questions? Email itrequests@business.cornell.edu.