Getting Your Cornell AI Gateway Key

Summary

Create a key in the JCB AI key portal and generate its secret. Requires Ethernet or VPN.

Body

Every way of using Claude at Cornell needs a personal key. You create it yourself in the JCB AI key portal.

πŸ”Œ You'll need a wired connection or the VPN

The key portal is only reachable from a wired Cornell connection or the Cornell VPN.

This applies to the key portal only β€” Claude itself works from anywhere once it's set up.


Step 1 β€” Create your key

  1. Go to https://keys.ai.business.cornell.edu/ and sign in.
  2. Click Create key and fill in the form:
Field What to enter
Key owner Myself, unless you are setting a key up on behalf of a colleague β€” then choose Someone else.
Intended use Claude Desktop for the standard setup. This is for reporting only; it does not limit where the key works.
Monthly Spend Cap ($) A monthly ceiling for this key. See below.
KFS account number The account your usage is attributed to.
Delegates (optional) NetIDs of anyone else who should be able to manage this key.
  1. Note the expiration date shown on the form. Keys currently expire at the end of the calendar quarter, not a fixed number of days after you create one β€” so a key made in early July runs until September 30. Keys created in the last couple of weeks of a quarter are the exception: they run to the end of the following quarter instead, so a key made on September 25 lasts until December 31 rather than expiring the same week. The date on your own key is the one that applies β€” see Managing, Rotating, and Renewing Your Key for renewing it.
  2. Click Create key.

The key portal's create form, showing key owner, intended use, spend cap, KFS account, and delegates

ℹ️ A ticket is opened for you. Requesting a key for Claude Desktop use also generates a TDX ticket automatically, and someone from Client Services will reach out to coordinate any follow-up your machine needs. You don't have to submit a separate request alongside the form.


Step 2 β€” Generate the secret

Creating the key does not give you the secret. The portal deliberately keeps those separate.

The confirmation banner explaining that the secret is generated separately from the key's row

  1. Find your new key in the list and click its row to expand it.
  2. Click Generate Key.
  3. Copy the secret somewhere safe β€” you will paste it during installation.

A key's detail panel, showing spend cap, KFS account, delegates, the Generate Key button, and the expiration date

This panel is also where you manage the key later β€” adjusting the spend cap, adding delegates, checking spend history, or disabling it. See Managing, Rotating, and Renewing Your Key.

⚠️ Generate the secret yourself, right before you need it. If someone set the key up for you, you should be the one to generate the secret. Treat it like a password: don't email it, don't post it in Teams, don't paste it into a shared document.


About the spend cap

The cap is a monthly ceiling on what this key can spend, in real dollars β€” Cornell bills gateway usage at Anthropic's published rates, with no markup. AI at Cornell lists the exact per-model rates on its Available Models & Pricing page (NetID sign-in).

There is no standard figure; appropriate values vary enormously depending on how you work. Pick something that reflects your expected use, and raise, lower, or reset it at any time from the key portal, with no ticket and no downtime.

It does two jobs. The first is keeping usage visible and attributable to a KFS account β€” that part is not about rationing you.

The second is a backstop. Gateway usage is billed as it happens and cannot be refunded, so the cap is the only thing standing between an unexpected bill and your account. Three situations make that matter:

  • A long-running or unexpectedly expensive job β€” a large set of documents, or a task that turns out to need far more work than it looked like.
  • A stolen secret β€” if one leaks, the cap bounds what someone else can spend before you rotate it.
  • Ordinary misuse β€” a key shared, pasted somewhere it shouldn't be, or pointed at something it wasn't meant for.

Set it high enough not to interrupt real work, low enough that a runaway month is survivable.

If you hit the cap, Claude stops responding β€” and it doesn't say so. The error blames the server for "temporarily limiting requests" and offers a Try again button; the real reason only appears under View details. Worth knowing that symptom before you meet it β€” Managing, Rotating, and Renewing Your Key shows both screens.


Where your key goes

If you're using… Your key goes…
Claude Desktop on a Mac into the installer in Self Service β€” see Installing Claude Desktop on macOS (Pilot)
Claude Desktop on Windows into the installer in Software Center β€” see Installing Claude Desktop on Windows (Pilot)
Claude Code (command line) into settings.json β€” see Appendix: Claude Code (CLI) on Cornell's AI Gateway

One key works everywhere. A single key covers Claude Desktop, Claude Code, and anything else on the gateway β€” you never need a second one.

You may still want one. Each key carries its own spend cap, KFS account, and spend history, so a second key is the simplest way to keep two things apart:

  • Separate budgets β€” a grant-funded project and your general teaching work, each with its own ceiling and its own actual spend tracked separately.
  • Separate billing β€” usage that has to be attributed to a different KFS account.
  • Separate blast radius β€” a key used somewhere riskier (a shared machine, an automation) can be disabled without disturbing your day-to-day one.

If none of that applies, one key is the right answer.


Next step

Install Claude Desktop β€” Installing Claude Desktop on macOS (Pilot) or Installing Claude Desktop on Windows (Pilot).

Questions? Email itrequests@business.cornell.edu.

Details

Details

Article ID: 8244
Created
Tue 6/23/26 10:59 AM
Modified
Thu 8/13/26 5:12 PM

Related Articles

Related Articles (8)

For people who want a command line. Install Claude Code and point it at Cornell's gateway.
What carries over from a personal claude.ai account (very little) and what to save before you switch.
Fixes for the most common setup, key, and connection problems.
Install the Claude Desktop pilot from Self Service on a Cornell-managed Mac and connect it with your gateway key.
Install the Claude Desktop pilot from Software Center on a Cornell-managed PC and connect it with your gateway key.
Rotate a key, renew it before it expires, change your spend cap, and what to do if it is exposed.
What you need before you begin, and the order to do it in: request access, get a key, then install Claude Desktop.
Choosing a model and what each one costs, working with documents and your workspace folder, and the difference between skills, connectors, and capabilities.