BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.

bolt.diy

Open-source in-browser full-stack app builder that runs on any LLM you wire up with your own key.

Website Source code

Category:
Coding Assistants
Maintenance:
Stale (last commit about 7 months ago)
Pricing:
Open Source
Open source:
Yes (MIT)
Self-hostable:
Yes
Local-first:
Yes
Platforms:
Web, Self-hosted, Docker
AI providers (bring your own key):
OpenAI, Anthropic, Google Gemini, OpenRouter, Groq, Mistral, Cohere, Perplexity, DeepSeek, xAI Grok, Ollama, Hugging Face, Together AI, Custom / OpenAI-compatible
API key storage:
User controls deployment
Key risk level:
LOW
Trust score:
84/100

bolt.diy is the community-driven open-source fork of Bolt.new (originally started by Cole Medin, now maintained under stackblitz-labs). It lets you prompt, run, edit, and deploy full-stack web apps entirely in the browser, choosing the LLM per prompt. Users bring their own provider API keys, configured either through the in-app Providers settings tab (with real-time validation and secure browser-cookie storage) or via a .env.local file (e.g. ANTHROPIC_API_KEY=...). It supports 19+ providers including OpenAI, Anthropic, Google Gemini, Groq, xAI Grok, DeepSeek, Mistral, Cohere, Together, Perplexity, HuggingFace, OpenRouter, Amazon Bedrock, plus local runtimes (Ollama, LM Studio) and any OpenAI-compatible endpoint. It is MIT-licensed, self-hostable (run locally or deploy to Vercel/Netlify/Cloudflare), and bolt.diy itself does not resell model access. Latest milestone release v1.0.0 (May 2025) added Supabase, Vercel deployment, and Expo support; the repo shows active maintenance with 1,600+ commits.

Why this trust score (84/100)

Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.

  • Key Safety 21/25: The key lives in a deployment you run yourself.
  • Request Routing 17/20: Requests go straight from you to the AI provider.
  • Transparency 20/20: Source is public under MIT, so anyone can check how the key is handled. Key handling was located in the published source.
  • Privacy 14/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control.
  • Maintenance 5/10: Last commit was within the last year.
  • Verification Confidence 7/10: Key handling was found in the published source by BYOAIK's scanner.

What was checked

Verification tier SOURCE_VERIFIED, derived from the evidence below and not set by hand.

  • [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
  • [STRONG · SOURCE_SCAN] The user supplies their own OpenAI key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Anthropic key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Groq key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Mistral key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own DeepSeek key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Together AI key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Cohere key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own xAI Grok key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Fireworks key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Perplexity key: the project references its API key variable. source
  • [CONFIRMED · SOURCE_SCAN] Ships a container definition, so it can be self-hosted on your own infrastructure. source
  • [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-02-07, about 6 month(s) ago. source

How your API key is handled

You self-host the app, so your API key lives in your own deployment. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.

Setup

Deploy it (Docker/compose), add your provider API key in the admin or environment config, then select models.