BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.
Hugging Face Chat UI
Open-source SvelteKit chat interface powering HuggingChat, self-hostable against any OpenAI-compatible endpoint with your own API key.
- Category:
- AI Chat Interfaces
- Maintenance:
- Actively developed (last commit today)
- Pricing:
- Open Source
- Open source:
- Yes (Apache-2.0)
- Self-hostable:
- Yes
- Local-first:
- Yes
- Platforms:
- Web, Self-hosted, Docker
- AI providers (bring your own key):
- OpenAI, Ollama, Hugging Face, OpenRouter, Custom / OpenAI-compatible
- API key storage:
- User controls deployment
- Key risk level:
- LOW
- Trust score:
- 92/100
Chat UI is the open-source codebase behind Hugging Face's HuggingChat. It is a SvelteKit web app (MongoDB optional; an embedded DB is used in dev) that you self-host and point at any OpenAI-compatible API. BYOK is the core configuration path: you create a .env.local file and supply OPENAI_BASE_URL plus OPENAI_API_KEY, and Chat UI auto-discovers available models from your endpoint. The docs give ready-made base-URL/key pairs for the Hugging Face Inference Providers router (hf_xxx), Ollama (local), llama.cpp (local), and OpenRouter (sk-or-v1-xxx), and state that any service speaking the OpenAI protocol works by default. It supports MCP tool/function calling, multimodal image input on vision models, an LLM router for model selection, and optional OpenID authentication. Note: recent versions (v0.10.0, May 2026) speak the OpenAI protocol only and removed legacy provider-specific integrations, so non-OpenAI providers like Anthropic or Gemini must be reached through an OpenAI-compatible proxy/router rather than a native key field.
Why this trust score (92/100)
Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.
- Key Safety 21/25: The key lives in a deployment you run yourself.
- Request Routing 20/20: Requests go straight from you to the AI provider. The provider endpoint is configurable, so you can point it at the provider or your own gateway.
- Transparency 20/20: Source is public under Apache-2.0, so anyone can check how the key is handled. Key handling was located in the published source.
- Privacy 14/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control.
- Maintenance 10/10: Actively developed: commits within the last three months.
- Verification Confidence 7/10: Key handling was found in the published source by BYOAIK's scanner.
What was checked
Verification tier SOURCE_VERIFIED, derived from the evidence below and not set by hand.
- [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
- [STRONG · SOURCE_SCAN] The user supplies their own OpenAI key: the project references its API key variable. source
- [STRONG · SOURCE_SCAN] The user supplies their own Hugging Face key: the project references its API key variable. source
- [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
- [STRONG · SOURCE_SCAN] The provider endpoint is configurable, so requests can be pointed straight at the provider or at your own gateway. source
- [CONFIRMED · SOURCE_SCAN] Ships a container definition, so it can be self-hosted on your own infrastructure. source
- [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-15, about 0 month(s) ago. source
How your API key is handled
You self-host the app, so your API key lives in your own deployment. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.
Setup
Deploy it (Docker/compose), add your provider API key in the admin or environment config, then select models.