BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.

Hermes Agent

Terminal agent from Nous Research that runs on any provider, or seven different backends.

Website Source code

Category:
Agent Frameworks
Maintenance:
Actively developed (last commit today)
Pricing:
Open Source
Open source:
Yes (MIT)
Self-hostable:
Yes
Local-first:
Yes
Platforms:
CLI, Self-hosted, Docker, Local-only
AI providers (bring your own key):
OpenAI, Anthropic, Google Gemini, OpenRouter, Ollama, Custom / OpenAI-compatible
API key storage:
Configured by environment variable
Key risk level:
LOW
Trust score:
90/100

Hermes is a coding and general-purpose agent from Nous Research that is explicit about not locking you in: use Nous Portal, OpenRouter, OpenAI or your own endpoint, and switch with one command and no code changes. It runs across seven terminal backends from local and Docker through SSH to serverless sandboxes, so the same agent works on a laptop or a GPU cluster. Nous Portal is the company's own subscription bundling model, search, image, speech and browser keys under one bill, which is a convenience option beside bring-your-own-key rather than a requirement. MIT.

How this tool was scored

Key handling 88/100 (where your key rests and who sees it, comparable across any licence) and verifiability 90/100 (how much of that BYOAIK could confirm, lower for closed source). Neither contains a popularity signal.

  • Key Safety 22/25: The key is supplied by an environment variable or local config file you control.
  • Request Routing 17/20: Requests go straight from you to the AI provider.
  • Transparency 20/20: Source is public under MIT, so anyone can check how the key is handled. Key handling was located in the published source.
  • Privacy 14/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control.
  • Maintenance 10/10: Actively developed, with commits within the last three months.
  • Verification Confidence 7/10: Key handling was found in the published source by BYOAIK's scanner.

What was checked

Verification tier SOURCE_VERIFIED, derived from the evidence below and not set by hand.

  • [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
  • [STRONG · SOURCE_SCAN] The user supplies their own Google Gemini key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own OpenRouter key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Groq key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Hugging Face key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Fireworks key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
  • [CONFIRMED · SOURCE_SCAN] Ships a container definition, so it can be self-hosted on your own infrastructure. source
  • [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-09-29, about 0 month(s) ago. source

How your API key is handled

Your API key is supplied via an environment variable or local config file. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.

Setup

Install the tool, set your provider API key as an environment variable (or in its config file), and pick a model.