BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.
Helicone
Self-hostable observability proxy for LLM calls, which means it sees the prompts it logs.
- Category:
- Developer Infrastructure
- Maintenance:
- Actively developed (last commit 4 days ago)
- Pricing:
- Open Source
- Open source:
- Yes (Apache-2.0)
- Self-hostable:
- Yes
- Local-first:
- No
- Platforms:
- Self-hosted, Docker, Web
- AI providers (bring your own key):
- OpenAI, Anthropic, Google Gemini, Azure OpenAI, OpenRouter, Custom / OpenAI-compatible
- API key storage:
- User controls deployment
- Key risk level:
- LOW
- Trust score:
- 82/100
Helicone sits in front of your model provider and records requests, latency, cost and errors, so you can see what an application is actually spending and sending. Be clear about the trade that involves: a logging proxy reads every prompt and response and holds the upstream key while forwarding. Running it yourself is what decides whether those logs sit with you or with a vendor, and this one is Apache-2.0 and self-hostable, alongside a hosted service from the same company.
Why this trust score (82/100)
Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.
- Key Safety 21/25: The key lives in a deployment you run yourself.
- Request Routing 17/20: Requests go straight from you to the AI provider.
- Transparency 20/20: Source is public under Apache-2.0, so anyone can check how the key is handled.
- Privacy 7/15: Can be self-hosted, so the data path stays inside infrastructure you control. Analytics or error-reporting libraries are present; what they send was not established.
- Maintenance 10/10: Actively developed, with commits within the last three months.
- Verification Confidence 7/10: Key handling was found in the published source by BYOAIK's scanner.
What was checked
Verification tier SOURCE_VERIFIED, derived from the evidence below and not set by hand.
- [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
- [STRONG · SOURCE_SCAN] Reads the API key from an environment variable at runtime. source
- [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
- [REPORTED · SOURCE_SCAN] References PostHog, so some analytics or error reporting is present. This scan cannot tell whether it is opt-in or what it sends. source
- [CONFIRMED · SOURCE_SCAN] Ships a container definition, so it can be self-hosted on your own infrastructure. source
- [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-09-11, about 0 month(s) ago. source
How your API key is handled
You self-host the app, so your API key lives in your own deployment. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.
Setup
Deploy it (Docker/compose), add your provider API key in the admin or environment config, then select models.