BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.

Inbox Zero

Open-source AI email assistant that automates triage, replies, and inbox cleanup.

Website Source code

Category:
Productivity Tools
Maintenance:
Actively developed (last commit today)
Pricing:
Open Source
Open source:
Yes (AGPL-3.0 (with additional commercial/enterprise restrictions))
Self-hostable:
Yes
Local-first:
Yes
Platforms:
Web, Self-hosted, Docker
AI providers (bring your own key):
OpenAI, Anthropic, Google Gemini, Azure OpenAI, OpenRouter, Groq, Ollama, Custom / OpenAI-compatible
API key storage:
User controls deployment
Key risk level:
LOW
Trust score:
83/100

Inbox Zero (elie222/inbox-zero) is a source-available, self-hostable AI personal assistant for email. It connects to Gmail/Outlook and uses LLMs to organize mail, pre-draft replies, automate plain-English rules, track replies, bulk unsubscribe/archive, block cold emails, and generate analytics. It is a Next.js/TypeScript app with Postgres/Prisma, deployable via Docker, Vercel, or local dev. BYOK is confirmed: when self-hosting, the end user supplies their own LLM provider API key. The repo's apps/web/.env.example exposes per-role provider:model config (DEFAULT_LLMS, ECONOMY_LLMS, CHAT_LLMS, NANO_LLMS, DRAFT_LLMS) plus LLM_API_KEY and provider-specific credentials for Azure OpenAI (AZURE_RESOURCE_NAME/AZURE_FOUNDRY_*), Google Vertex (GOOGLE_VERTEX_*), AWS Bedrock (BEDROCK_ACCESS_KEY/SECRET_KEY), Ollama (OLLAMA_BASE_URL/MODEL), and a generic OpenAI-compatible endpoint (OPENAI_COMPATIBLE_BASE_URL/MODEL/AUTH_HEADER). Documented providers include OpenAI, Anthropic, Google Gemini/Vertex, Azure OpenAI, OpenRouter, Groq, AWS Bedrock, Ollama, and any OpenAI-compatible API. A hosted SaaS at getinboxzero.com also exists (paid), but the self-hosted path is fully BYOK. License is AGPL-3.0 with added commercial-use/enterprise restrictions (org with 5+ business users needs an enterprise license; no reselling), so it is source-available rather than permissively open source.

Why this trust score (83/100)

Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.

  • Key Safety 21/25: The key lives in a deployment you run yourself.
  • Request Routing 17/20: Requests go straight from you to the AI provider.
  • Transparency 20/20: Source is public under AGPL-3.0 (with additional commercial/enterprise restrictions), so anyone can check how the key is handled.
  • Privacy 14/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control.
  • Maintenance 10/10: Actively developed: commits within the last three months.
  • Verification Confidence 1/10: Compiled from public documentation by an AI-assisted pass, not independently confirmed.

What was checked

Verification tier RESEARCH_ASSISTED, derived from the evidence below and not set by hand.

  • [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
  • [CONFIRMED · SOURCE_SCAN] Ships a container definition, so it can be self-hosted on your own infrastructure. source
  • [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-14, about 0 month(s) ago. source

How your API key is handled

You self-host the app, so your API key lives in your own deployment. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.

Setup

Deploy it (Docker/compose), add your provider API key in the admin or environment config, then select models.