Set up AI Token Spend Management

Overview

AI Token Spend Management gives your finance team consolidated visibility into token usage, costs by model, and spend trends across AI providers like Anthropic and OpenAI. Instead of reconciling invoices from multiple dashboards, you can track it all in one place on Ramp.

If your business uses Ramp only for AI Token Spend Management, see AI Token Spend Management for standalone businesses. That experience has different access and navigation.

Check which AI provider plan you need

Developer API usage has different requirements. To connect Claude developer API, you must belong to a Claude Platform team organization; individual organizations are not supported. To connect OpenAI developer API, you must belong to an OpenAI Platform organization; personal accounts are not supported.

Provider productPlan requirementConnect in Ramp
Claude.ai or Claude Code subscriptionClaude Enterprise is required. Claude Team is not supported.Connect Claude app
Claude developer APIYou must belong to a Claude Platform team organization. Individual organizations are not supported.Connect Claude developer API
ChatGPT or Codex via a ChatGPT subscriptionChatGPT Enterprise is required. ChatGPT Business and personal accounts are not supported.Connect ChatGPT app
OpenAI developer APIYou must belong to an OpenAI Platform organization. Personal accounts cannot connect.Connect OpenAI developer API

If your Claude.ai, Claude Code, ChatGPT, or Codex subscription does not meet the Enterprise requirement, Ramp cannot import that subscription's usage. Ramp can separately track eligible API-billed usage when you connect the applicable developer API.


Open AI Token Spend and connect providers

In the Ramp app, go to Manage Spend > Tokens.

Manage Spend menu with Tokens selected

Use Check which AI provider plan you need to connect Claude or OpenAI products. For other supported providers, use the matching connection guide: Connect Cursor, Connect Google Cloud (Gemini), Connect AWS Bedrock, or Connect Fireworks AI.

Who can access AI Token Spend Management

Access to AI Token Spend Management varies by role:

RoleView company-wide dataManage settings, API keys, and provider connectionsManage Spend Limits
OwnerYesYesYes, with paid access described below
AdminYesYesYes, with paid access described below
IT AdminYesYesNo
Finance AdminYesNoNo
View-Only AdminYesNoNo
AI Token Spend Admin roleYesYesYes, with paid access described below

Assigning the preset AI Token Spend Admin role does not require Ramp Plus. Managing Spend Limits requires separate paid access for your business: an AI Token Spend subscription grants this access without Ramp Plus; Ramp Plus includes it only for businesses that have not moved to AI Token Spend add-on pricing. Having the role alone does not unlock Spend Limits.

To check access, open AI Token Spend and select Set soft limit or Edit limit for an API key. If your business lacks paid access, Ramp displays an access prompt. Ask your Ramp Admin to review that prompt if you cannot proceed. User limits are available only for businesses with that capability enabled.

To add a user to the AI Token Spend Admin role, go to Company > People and select Edit Profile or Invite People. Under Additional Roles, select AI Token Spend Admin.

Employees with access to their own AI Spend data can view it from My AI Spend after their business completes AI Token Spend onboarding. They cannot access company-wide data or settings.

Manage provider connections and data sync in AI Token Spend Management

Add multiple keys for one provider

AI Token Spend Management data and sync details

DetailDescription
Sync frequencyData syncs daily. Expect data to reflect T-1 day.
Initial backfillUp to 24 hours depending on account size and provider rate limits (Anthropic rate limits are currently 1 request per minute).
Cost calculationFor OpenAI credit-based plans, Costs and Unified Daily Usage do not distinguish included or prepaid credit consumption from overage usage. Dollar estimates value all consumption at the workspace's overage rate, so they are not actual billed spend. Costs can show consumption breakdowns but not the overage-spend split.

Troubleshoot missing or unexpected AI Token Spend data

AI Token Spend Management displays usage and cost data exposed by the provider connection. Data syncs daily and normally reflects T-1 day. A new connection can take up to 24 hours to complete its initial backfill, and larger Anthropic accounts can take longer because of provider rate limits.

Check the provider connection and data source

Use the connection guide that matches the provider product that generated the missing usage. Claude developer API and Claude app are separate connections, as are OpenAI developer API and ChatGPT app. Google Cloud data comes from the Cloud Billing export for the selected billing account, which covers only projects paid by that account.

For ChatGPT app, the API key's organization must match the ChatGPT workspace organization, and it must include codex.enterprise.analytics.read and chatgpt.enterprise.usage_limit.read. If you plan to use Ramp to control workspace usage limits, it must also include chatgpt.enterprise.usage_limit.write. For Claude developer API and OpenAI developer API, personal accounts cannot connect.

Check how usage is attributed

Ramp can display provider-provided reporting dimensions such as user, email address, internal user or team label, API-key label, provider, and model. A breakdown is available only when the connected provider exposes the relevant identifier or dimension in its usage export.

Get help with unresolved data differences

If the expected refresh window has passed and the connection guide confirms the correct provider account and credentials, contact Ramp Support. Include the provider, connected account type, affected date range, and the missing or unexpected provider, user, or API-key data.


Security and data handling

Ramp takes the security of your provider credentials and usage data very seriously.

Credential storage

Ramp stores the API keys you provide for Claude developer API, OpenAI developer API, ChatGPT app, and Fireworks AI in an encrypted format consistent with Ramp's existing integration security standards. Decrypted keys are not stored by Ramp; we decrypt your key when the system calls the relevant provider API. For GCP, Ramp stores only the BigQuery billing table ID you provide — Ramp does not store any GCP credentials.

Access control

Access to AI Token Spend data and provider administration is role- and permission-based. See Who can access AI Token Spend Management for the current access scopes.

Data minimization

AI Token Spend Management is designed to ingest the fields needed to power spend reporting and analytics and does not require you to provide prompts or message content.

How the product works

For Claude developer API and OpenAI developer API, AI Token Spend Management uses the Admin API keys you provide to call the provider's Admin APIs. For Claude developer API, Ramp also uses the key's write access to lock API keys when you use API-key controls. For ChatGPT app, Ramp uses an Admin API key with Codex analytics API read access to import usage and billing-related data, such as token usage, cost, provider and model identifiers, and provider-provided reporting dimensions. Ramp uses chatgpt.enterprise.usage_limit.read to read workspace usage-limit settings. If you plan to use Ramp to control those limits, it also uses chatgpt.enterprise.usage_limit.write to change them. For GCP, Ramp reads cost and usage data directly from the BigQuery billing export table you configure — no API key is involved.

Retention

Ramp retains imported spend and usage data to provide historical reporting and trend analysis. Disconnecting a provider stops subsequent scheduled imports but does not delete previously imported data, which remains subject to Ramp's standard retention and deletion practices and contractual obligations. For Fireworks AI, usage and cost data from the disconnected configuration no longer appears in reporting.

Disconnecting Anthropic, OpenAI, Cursor, or Fireworks AI immediately clears the stored encrypted API-key value. Disconnecting GCP retains the configured billing table ID. Disconnecting AWS retains the role ARN, account information, and External ID. The table below summarizes these outcomes:

ProviderStored connection details after disconnecting
AnthropicRamp immediately clears the encrypted API-key value.
OpenAIRamp immediately clears the encrypted API-key value.
CursorRamp immediately clears the encrypted API-key value.
Fireworks AIRamp immediately clears the encrypted API-key value.
GCPRamp retains the configured billing table ID.
AWSRamp retains the role ARN, account information, and External ID.

Manage AI Token Spend after setup

Investigate unexpected activation or invitations

Connecting your first provider creates an AI Token Spend Admin role for your business, but it does not by itself send Ramp invitations. If you see an unexpected pending invitation, review it from Invited and select Revoke invite before it is accepted.

Review AI Token Spend activity and export spend data

The AI Token Spend Activity tabs record the actor and timestamp for user or API-key soft-limit creation, changes, and deletion; supported key locks and unlocks; and API-key owner reassignment. They do not show provider-connection or provider-credential history, and activity events cannot be exported from AI Token Spend Management.

CSV exports are separate from the Activity tabs. When available, the API-key and people tables export spend and inventory data, not an activity log. Reports and CSV exports require company-wide view access and are not available with team access.

Controlling your access

For Claude developer API, Claude app, OpenAI developer API, ChatGPT app, Cursor, and Fireworks AI, delete the specific connected key in the provider's credential settings to revoke access through that key; other active connections continue to work. For GCP, remove Ramp's read access to the configured BigQuery data. For AWS, remove the IAM role deployment to block new sessions; temporary sessions issued before removal remain active until they expire. Disconnecting GCP or AWS in Ramp does not revoke access by itself. Use the provider-specific destinations below:

ProviderHow to revoke Ramp's access
Claude developer APIDelete the key from Admin API keys.
Claude appDelete the key from organization API settings.
OpenAI developer APIDelete the key from OpenAI Admin API keys.
ChatGPT appDelete the key under Credentials > Admin keys in the OpenAI Admin Console.
CursorDelete the key from Cursor API Keys.
Fireworks AIDelete the key from Fireworks AI API keys.
GCPRemove Ramp's read access to the configured BigQuery data in the Google Cloud console.
AWSRemove the IAM role deployment to block new sessions by following Disconnect AWS Bedrock. Temporary sessions issued before removal remain active until they expire.

Frequently asked questions

What data does Ramp import from my AI providers?

Ramp imports usage and cost data exposed through the provider APIs you connect. For example: token usage, spend/cost, provider/model identifiers, and time-based usage metrics. This data is used to power spend reporting and analytics in AI Token Spend Management.

Does Ramp ingest prompts, message content, or model outputs?

AI Token Spend Management is designed for spend and usage reporting and does not require prompts or message content. Ramp uses provider APIs to import usage and cost information rather than application content.

Which providers require an Admin API key?

The credentials required depend on the provider:

For every provider, AI Token Spend Management imports data needed for spend reporting and does not retrieve prompts, message content, or model outputs.

Is any of this personal data?

Typically, the imported data is business account usage and cost data. Depending on your provider configuration, the usage export may include identifiers like a user name, email address, or internal user/team label. If present, Ramp uses those identifiers only to provide spend breakdowns and access-controlled reporting.

How does Ramp use this data?

Ramp uses imported usage/cost data to provide reporting, trend analysis, and cost allocation insights inside AI Token Spend Management. Aggregated or anonymized information may be included in Ramp reports or benchmarks, unless this is precluded by your company's agreement with Ramp. Other Ramp customers do not see your company's provider-level, model-level, team-level, user-level, or API key-level data.

Can Ramp employees see my usage data?

Access is restricted and role-based. Only authorized personnel may access customer data for limited purposes such as support, troubleshooting, and maintaining the service, consistent with Ramp's access controls and logging practices.

How long does Ramp retain this data?

Ramp retains imported data under its standard retention and deletion practices and contractual obligations. Fireworks AI usage and cost data no longer appears in reporting after disconnecting. See Retention for provider-specific disconnect behavior.

Does Ramp use this data to train AI models?

AI Token Spend Management uses your provider data to display reporting and analytics. Ramp does not use your company's provider credentials to perform actions in your provider account beyond retrieving usage and cost data, except when you use API-key controls to lock Anthropic API keys or use Ramp to control ChatGPT app workspace usage limits. In that case, Ramp uses chatgpt.enterprise.usage_limit.read to read settings and chatgpt.enterprise.usage_limit.write to change them.

Can other Ramp customers see my company's AI usage data?

No. Other customers do not see your company's provider-level, model-level, team-level, user-level, or API key-level data.

How does Ramp aggregate and de-identify AI spend data for benchmarks?

Ramp may use aggregated and anonymized customer data to report industry-level AI spending trends and benchmarks. Benchmark reporting is not intended to identify your business, individual users, API keys, or provider account details.

Why is my data taking a long time to load?

Anthropic rate limits are currently 1 request per minute, so larger accounts may take longer to import. We recommend waiting overnight for the initial data load to complete in the background.

How are OpenAI costs calculated for credit-based plans?

For OpenAI credit-based plans, dollar estimates are not actual billed spend. See AI Token Spend Management data and sync details for how Ramp calculates these estimates and what Costs can report.

How often does data sync?

Data syncs daily and should be up to date with T-1 day.

Can Ramp track AI agent spend?

AI Token Spend Management can track AI agent spend when the connected provider exposes the usage data. The available attribution depends on the identifiers and reporting dimensions that the provider includes in its usage export.

How can we set AI Spend Limits?

Owners, Admins, and users with the AI Token Spend Admin role can manage limits for API keys and, when available, users from AI Token Spend, subject to the paid-access requirements above. Hard limits apply only to ChatGPT Enterprise workspace usage limits and prevent additional workspace usage after the configured threshold is reached. For Anthropic Platform and OpenAI Platform, limits send notifications and do not prevent provider charges.

How can we monitor unexpected AI spending?

Use AI Token Spend to set spend-limit thresholds and review unusual spikes. Ramp can alert you when spend reaches configured thresholds and uses anomaly detection to identify unexpected spending patterns.

What permissions are needed?

Claude developer API requires an Admin API key with write access to retrieve usage and billing data and lock API keys when you use API-key controls. OpenAI developer API requires an Admin API key limited to read-only permissions for the provider endpoints needed to retrieve usage and billing data. ChatGPT app requires an Admin API key with Codex analytics API set to Read and chatgpt.enterprise.usage_limit.read. If you plan to use Ramp to control workspace usage limits, also grant chatgpt.enterprise.usage_limit.write. Ramp uses the read scope to read usage-limit settings and the write scope to change them. For GCP, you need Billing Account Costs Manager or Billing Account Administrator on the billing account, plus BigQuery User on the dataset project.