Your Cornell AI gateway key is not permanent. This article covers rotating its
secret, renewing it before it expires, changing what it can spend, and what to
do if the secret leaks.
🔌 Key management needs a wired connection or the VPN
Everything here starts at https://keys.ai.business.cornell.edu/, which is
only reachable on a wired Cornell connection or the Cornell VPN.
Plan ahead if you travel. If your key expires while you're away and you
can't get on the VPN, Claude stops working until you can renew it. Nothing is
lost — the key is still there and still renewable — but you will be without it
until you're back on a Cornell connection.
If Claude suddenly stops working
Two different things look similar, and neither announces itself clearly.
A spend-cap stop, dressed up as a server problem
This is what you see first. It blames the server and invites you to retry:

It is not a server problem, and Try again will not help. Click View
details instead, and the real cause appears:

Budget has been exceeded! — followed by the key's current cost and its
maximum. That is your monthly spend cap, and no amount of waiting clears
it. Either raise the cap (see Changing your spend cap below) or wait for the
monthly reset.
⚠️ Always open View details before retrying. The summary line is worded
the same way for genuine, temporary rate limiting — the detail text is the
only thing that tells the two apart.
An expired key
If Claude reports an authorization problem, your key has probably expired.
It is still renewable — see Renewing your key below.
Rotating your key
Rotate immediately if you think your secret has been seen by anyone else.
✅ You do not need a new key. Rotating means generating a new secret on
the key you already have. There is no form to fill in again — your spend cap,
KFS account, delegates, and spend history all stay exactly as they are.
⚠️ Rotating does not buy you more time. Generating a new secret leaves the
expiration date untouched. If your key is also close to expiring, renewing
is a separate step — see Renewing your key below.
Step 1 — Generate a new secret in the portal
- Go to https://keys.ai.business.cornell.edu/.
- Find your existing key in the list and click its row to expand it.
- Click Generate Key.
- Copy the new secret.
The new secret replaces the old one, so anything still holding the previous
secret stops working — including Claude on your own computer. That is why Step 2
is not optional.
Creating a genuinely separate key — for a different budget or KFS account — is
a different job, covered in Getting Your Cornell AI Gateway Key.
Step 2 — Update Claude on your computer
Your computer is still holding the old secret, so you need to hand it the new
one through the same catalog you installed from.
🪟 Windows
Open Software Center, find your MD – Cornell AI Gateway – Claude entry
under Applications, and click Repair. Paste the new secret when prompted.

Repair, not Uninstall — you are re-applying settings with the new secret,
not removing the app.
🍎 Mac
Open Self Service, find Cornell AI Gateway API Key Update, and click
Update. Paste the new secret when prompted.

This is a separate item from the one you installed Claude with — you are
updating the secret, not reinstalling the app.
Restart Claude afterwards and ask it something simple to confirm it works.
Renewing your key
Keys currently expire at the end of the calendar quarter — March 31, June
30, September 30, December 31 — rather than a fixed number of days after they
are issued. A key created in early July therefore runs until September 30.
Keys issued in the last couple of weeks of a quarter are the exception: they
roll over to the end of the following quarter, so a key created on September
25 runs until December 31 rather than expiring days after you set it up. You are
not penalised for getting a key at an awkward moment.
That is the current configuration and may change, so trust the expiration date
shown on your own key rather than counting forward yourself.
When it comes up, the portal renews the key you already have — no new key and
no form to fill in again. Your spend cap, KFS account, delegates, and spend
history all carry over untouched.
⚠️ Renewing and rotating are two different jobs. Renewing moves the
expiration date. Generating a new secret does not — rotation replaces the
secret and leaves the expiry exactly where it was. A key rotated a week before
it expires still expires on its original date. If you need both, do both.
| What you need |
What to do |
Update your computer? |
| More time |
Renew — same secret, new expiration date |
No — nothing on your machine changes |
| A new secret, because the old one may have leaked |
Rotate — see Rotating your key above |
Yes — do Step 2 of Rotating your key |
| Both |
Do each in turn; neither does the other's job |
Yes — because the secret changed |
Renewing is the quiet one: no trip to Software Center or Self Service, and Claude
carries on uninterrupted, because the secret it holds hasn't changed.
✅ An expired key is not a lost key. Renewal still works after the
expiration date has passed. There is no window you can miss and nothing to
re-request — renew whenever you next reach the portal, and Claude picks up
where it left off.
Whichever you do, the expiration date shown on the key afterwards is the one
that applies — check it before you rely on it.
Check your expiration date now and put a reminder in your calendar a couple of
weeks ahead of it — particularly if you have travel planned.
Changing your spend cap
Your key's monthly spend cap is a ceiling on what it can spend each month.
It resets to zero each month — the detail panel shows the exact reset date,
along with your actual spend month-to-date and for last month. Read those
figures as actuals, not as the cap: the cap is what you are allowed to spend,
the actuals are what you have spent.
To change it: open your key's row in the portal, type a new figure under
Adjust Monthly Spend Cap, and click Save. That's the whole job — you do
not need to touch Software Center or Self Service, and you do not need to
restart Claude.
There is no standard figure. If you are hitting your cap regularly and the work
is legitimate, raise it — the cap is there to keep spending visible and
attributable to your KFS account, not to ration your usage.
Don't set it enormous, though. Gateway usage cannot be refunded, so the cap
is also your only backstop against a runaway job, a leaked secret, or misuse — see
Getting Your Cornell AI Gateway Key. Adjust it as your work changes rather than picking a
number high enough to never think about again.
Spend History at the bottom of the panel shows all-time and
quarter-to-date usage if you need to justify a higher figure.
Changing the KFS account
You can update the KFS account number from the same panel.
⚠️ This only affects future usage. Billing is locked in at the moment each
request is made, so changing the account here does not re-bill anything
that already happened. Correcting past billing requires a finance journal
transfer — email itrequests@business.cornell.edu if you need that.
If your secret is exposed
The secret is the part that can leak — a key holds exactly one secret at a
time, and rotating replaces it. So if a secret has been emailed, pasted into a
shared document, posted in Teams, or otherwise seen by anyone who shouldn't have
it:
- Rotate it. Generate a new secret on the same key, following Rotating
your key above. The moment the new secret exists, the exposed one is dead.
- Update Claude on your computer with the new secret.
- Email itrequests@business.cornell.edu to let us know.
That is the whole fix. You do not need to create a replacement key, and you do
not need to wait for anyone.
⚠️ Disabling is a pause, not a fix. The Disable button next to a key's
status stops all use of it immediately — useful if you want spending halted
right now and can't get to your computer to finish the rotation. But disabling
does not change the secret: re-enable the key later and the exposed secret
works again. Always rotate before you turn it back on.
Still stuck?
See Claude on Cornell's Gateway — Troubleshooting, or email
itrequests@business.cornell.edu with the error message you're seeing.