Sign in, or bring a key
What you'll get. Connect the AI account you already have — by signing in, or by putting a key in the vault.

E:Voice does not sell you tokens. It talks to the AI account you already have. There are two ways to hand it one — sign in, or paste a key — and you only need to do it once.
Everything is under Settings → Providers & Models, in a card headed AI & providers.
Sign in with OAuth
Two providers let you sign in with the account you already pay for, no key to copy anywhere.
- Open Main Provider. The first section of the AI & providers card.
- Choose the provider. “Select the provider lane E:Voice should prepare for.”
- Set Auth mode to OAuth. The screen explains itself: “OAuth stays preferred for supported OpenAI account flows. API keys are only used for selected API-key features.”
- Tap Connect. OpenAI sign-in opens inside E:Voice — the app captures the callback itself so Android can't drop you on a “site not reached” page. xAI uses a device code and an in-app browser, and tells you where it is up to: requesting, waiting for approval, connected.
- Check the status rows. Session state: Connected · Stage: Authenticated · Execution status: Ready, plus the account and when the session expires.
If in-app sign-in is blocked on your phone, Device code fallback gives you a code to type into the provider's own verification page. The app is careful to warn you what that code is not: “The E:Voice device code is not your authenticator or two-step verification code.”
Your tokens are never displayed: “OAuth tokens are stored securely after sign-in. They are not shown or pasted here.” And signing in this way does not quietly start spending API credit — “OAuth sign-in does not automatically spend API balance.”
OpenAI and xAI. That's the list today. Anthropic, Gemini, OpenRouter and custom endpoints connect with an API key instead — the Auth mode dropdown simply won't offer OAuth for them. If you have seen “sign in with Anthropic” written somewhere, it isn't in the app yet.

Or bring a key
Keys live in the API Key Vault, one encrypted place for all of them. Two things have to be true before it will open: you are signed into your E:Voice account, and your phone has a real screen lock or biometric set up. If it doesn't, the vault tells you and offers to open Android's security settings.
- Unlock the vault. Android runs the prompt — “Confirm with Android biometric or screen lock” — and E:Voice only ever learns whether it succeeded.
- Give the key a name you'll recognise. The Friendly label field suggests something like “ElevenLabs personal”.
- Paste the key. The input is masked and the saved value stays hidden. Known key shapes are detected automatically; anything unrecognised is still saved, honestly labelled as a custom credential.
- Confirm the provider, then Save key.
The vault holds OpenAI, OpenRouter, Anthropic, Gemini, xAI Grok, ElevenLabs, Deepgram, Honcho, mem0, Brave Search and custom credentials. Saved keys can be edited, rechecked, copied, set as default, disabled or deleted. Keys are tied to your account, and the screen blocks screenshots while it is open.
Slots, and the five models
A slot is a credential lane. There are four — Main, Secondary, Third and Fourth — and each keeps its own provider, auth mode, model and credential. “Credentials are isolated to Secondary.” A new slot appears once the previous one has something in it, via Add provider, and duplicate providers are allowed on purpose.
Agents don't see slots. They see Preferred models — “Choose and order up to five brains. Agents see model names only; E:Voice binds each choice to one ready credential route.” A model is one choice however you reach it, so the same model through a key and through OpenRouter is not two entries.
Which route answered you
Open the chat menu and choose Model & Usage. It names the model, the provider and the slot route, and shows usage where the provider reports it. The same dialog has a Next-turn model row for switching — “Applies to the next message after runtime verification.” A switch never rewrites the answer already being written.
You can also just say it. Telling an agent to use a different model works by name, and if the name is ambiguous it asks which one rather than guessing.
When something is wrong
The messages are written as sentences, not codes. A rejected key reads “Provider rejected this key — edit and recheck.” An exhausted allowance says the account has reached its usage limit and that “switching provider or model in Settings is the way through.” A rate limit says nothing is wrong and it usually clears within a minute. And with no signal at all, E:Voice holds your question and sends it when the connection comes back, as long as that is within the next half hour.
The same settings page has an “Optional Codex Work-Order Worker”. That is a narrow, older lane for approved work orders — it is not how you pair a Codex agent. Full Codex contacts are paired from Bridge → Add Agent, which is chapter 07.