BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.

Jan

Open-source local-first desktop AI assistant that runs models offline or via your own cloud provider keys.

Website Source code

Category:
Desktop AI Assistants
Maintenance:
Actively developed (last commit today)
Pricing:
Open Source
Open source:
Yes (Apache-2.0)
Self-hostable:
Yes
Local-first:
Yes
Platforms:
Desktop, CLI, Self-hosted, Docker
AI providers (bring your own key):
OpenAI, Anthropic, Google Gemini, Azure OpenAI, OpenRouter, Groq, Mistral, Hugging Face, Ollama, Custom / OpenAI-compatible
API key storage:
Stored locally on device
Key risk level:
LOW
Trust score:
85/100

Jan is an open-source (Apache 2.0) desktop AI assistant from Menlo Research positioned as a private, local-first alternative to ChatGPT. It bundles local inference (HuggingFace models like Llama, Gemma, Qwen, GPT-oss) and runs fully offline when desired, exposing a local OpenAI-compatible API server at localhost:1337. Crucially for a BYOK directory, its documented Settings -> Model Providers flow lets a user paste their own API key for cloud providers and pick a model from that provider. Official docs (jan.ai/docs/desktop/remote-models/*) walk through the identical "create & copy an API key -> Settings -> Model Providers -> insert your API Key" flow for OpenAI, Anthropic, Google Gemini, Groq, Mistral, Azure OpenAI, OpenRouter, and Hugging Face, plus Custom Endpoints for any OpenAI- or Anthropic-compatible base URL. It also supports MCP for agentic features and ships a CLI. Available for Windows 10+, macOS 13.6+, and Linux (deb/AppImage/Arm64), with Microsoft Store and Flathub distribution. ~43k GitHub stars and active (latest release v0.8.2, 100+ releases). Note: the candidate's claimed MIT license is incorrect; the actual license is Apache 2.0.

Why this trust score (85/100)

Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.

  • Key Safety 23/25: The key is held on your own device.
  • Request Routing 17/20: Requests go straight from you to the AI provider.
  • Transparency 20/20: Source is public under Apache-2.0, so anyone can check how the key is handled.
  • Privacy 14/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control.
  • Maintenance 10/10: Actively developed: commits within the last three months.
  • Verification Confidence 1/10: Compiled from public documentation by an AI-assisted pass, not independently confirmed.

What was checked

Verification tier RESEARCH_ASSISTED, derived from the evidence below and not set by hand.

  • [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
  • [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
  • [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-13, about 0 month(s) ago. source

How your API key is handled

Your API key is stored locally on your device. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.

Setup

Open settings, paste your provider API key, choose a model, and start. The key stays on your device.