Connections
Ghostwriter → Connections is where an app sets up every outside service Ghostwriter uses. Only people who manage Ghostwriter see it. On a panel with tenancy, each tenant sets up its own, as it connects its own accounts.
The cards come in three groups:
- Writing: Anthropic, OpenAI, Gemini and OpenRouter. OpenAI, Gemini and OpenRouter also make images; there are no separate image cards.
- Images: Unsplash, Pexels and Pixabay (free photo libraries), and Openverse, which needs no key.
- Stock photos: Shutterstock (consumer key and secret, then Connect account to license).
Setting one up
- Click Set up on the card.
- Open {Service} opens the page where its key is made, in a new tab. Follow the two or three steps on the card.
- Paste the key (and the secret, for Shutterstock) and click Check & save. Ghostwriter makes one small call to the service with it (a list of one model, or a search for one photo). If the service refuses it, the card says why, plainly, and nothing is kept.
The card then says Connected · key ending ••a1b2. Ghostwriter never shows more of a key than its last four characters. Replace key swaps it; Disconnect (after Filament's confirm) forgets it. The key still works at the service until you delete it there.
OpenRouter can also Connect with OpenRouter from its card: sign in, and OpenRouter makes the key for you.
If a service starts refusing a key that was working, the card says Key stopped working the next time Ghostwriter uses it. Replace the key, and it clears.
.env and config always win
Every key can still be set in .env (read through config/ghostwriter.php): ANTHROPIC_API_KEY, OPENAI_API_KEY, GEMINI_API_KEY, OPENROUTER_API_KEY, UNSPLASH_ACCESS_KEY, PEXELS_API_KEY, PIXABAY_API_KEY, SHUTTERSTOCK_API_KEY and SHUTTERSTOCK_API_SECRET. When one is set, it is used for every tenant, its card says Set in .env (or Set in config, when config/ghostwriter.php sets it some other way), and Set up and Replace key aren't offered.
The page says which environment you're on ("You're on local."). What is set up in Connections lives in that environment's database, so your local, staging and production apps each keep their own keys. Use .env to give every environment the same keys.
Where keys are kept
In the ghostwriter_credentials table (with your table prefix), per workspace, each value encrypted with your APP_KEY (Laravel's Crypt). Changing APP_KEY makes kept keys unreadable: their cards go back to Not set up; set them up again.
The plugin publishes its migrations rather than loading them. Publish this one with the others (ghostwriter-migrations), or alone:
php artisan vendor:publish --tag=ghostwriter-connections-migrations
php artisan migrate
Until it runs, nothing set up in Connections is kept, and the page says what to run. The migration also moves what Ghostwriter kept before (Connect with OpenRouter's key, connected accounts' tokens) out of ghostwriter_states.
Keys never reach us
A key goes only to the service it belongs to: in the check, and in every call afterwards. Ghostwriter has no servers of its own that a key could be sent to.