BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.

AnythingLLM

All-in-one local-first AI app for document chat (RAG) and agents, with bring-your-own-key support for nearly every LLM provider.

Website Source code

Category:
Knowledge Management
Maintenance:
Actively developed (last commit 3 days ago)
Pricing:
Freemium
Open source:
Yes (MIT)
Self-hostable:
Yes
Local-first:
Yes
Platforms:
Desktop, Self-hosted, Docker
AI providers (bring your own key):
OpenAI, Anthropic, Google Gemini, Azure OpenAI, OpenRouter, Groq, Mistral, Cohere, Perplexity, DeepSeek, xAI Grok, Ollama, Together AI, Fireworks, Custom / OpenAI-compatible
API key storage:
Stored locally on device
Key risk level:
LOW
Trust score:
82/100

AnythingLLM is an open-source (MIT) all-in-one AI application that lets users chat with their documents, build no-code AI agents, and run a private RAG workspace either as a free desktop app (Mac/Windows/Linux) or self-hosted via Docker. It is bring-your-own-key: users obtain their own API keys from each provider and enter them in AnythingLLM's settings, or point it at local engines (Ollama, LM Studio, llama.cpp) or any custom OpenAI-compatible base URL. Confirmed providers where the user supplies their own key include OpenAI, Anthropic, Google Gemini, Azure OpenAI, AWS Bedrock, Groq, Mistral, DeepSeek, xAI Grok, OpenRouter, Perplexity, Cohere, Together AI, Fireworks AI, and generic OpenAI-compatible endpoints. The project is highly popular (~62k GitHub stars) and actively maintained (v1.14.1 released June 2026). A paid hosted Cloud tier and enterprise plans also exist, but the desktop and self-hosted BYOK paths are free.

Why this trust score (82/100)

Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.

  • Key Safety 23/25: The key is held on your own device.
  • Request Routing 17/20: Requests go straight from you to the AI provider.
  • Transparency 20/20: Source is public under MIT, so anyone can check how the key is handled.
  • Privacy 11/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control. Analytics or error-reporting libraries are present; what they send was not established.
  • Maintenance 10/10: Actively developed: commits within the last three months.
  • Verification Confidence 1/10: Compiled from public documentation by an AI-assisted pass, not independently confirmed.

What was checked

Verification tier RESEARCH_ASSISTED, derived from the evidence below and not set by hand.

  • [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
  • [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
  • [REPORTED · SOURCE_SCAN] References PostHog, so some analytics or error reporting is present. This scan cannot tell whether it is opt-in or what it sends. source
  • [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-13, about 0 month(s) ago. source

How your API key is handled

Your API key is stored locally on your device. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.

Setup

Open settings, paste your provider API key, choose a model, and start. The key stays on your device.