BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.
Karakeep
Self-hostable bookmark-everything app with AI tagging and full-text search
- Category:
- Productivity Tools
- Maintenance:
- Actively developed (last commit today)
- Pricing:
- Open Source
- Open source:
- Yes (AGPL-3.0)
- Self-hostable:
- Yes
- Local-first:
- Yes
- Platforms:
- Self-hosted, Web, Mobile, Browser Extension, Docker
- AI providers (bring your own key):
- OpenAI, Azure OpenAI, Ollama, Custom / OpenAI-compatible
- API key storage:
- Stored in browser storage
- Key risk level:
- MEDIUM
- Trust score:
- 75/100
Karakeep (formerly Hoarder) is an open-source, self-hostable "bookmark everything" app: save links, notes, images, and PDFs with automatic AI tagging, summarization, OCR, and Meilisearch-powered full-text search. Self-hosters bring their own AI provider by setting OPENAI_API_KEY (with optional OPENAI_BASE_URL for any OpenAI-compatible endpoint such as Azure OpenAI) or pointing OLLAMA_BASE_URL at a local Ollama instance, and can pick their own text/image/embedding models via INFERENCE_TEXT_MODEL, INFERENCE_IMAGE_MODEL, and EMBEDDING_TEXT_MODEL. Ships as a Docker/Kubernetes web app plus browser extensions (Chrome/Firefox/Safari) and iOS/Android apps. A hosted Karakeep Cloud (free tier, $4/mo Pro) also exists, but BYOK applies to the self-hosted deployment.
Why this trust score (75/100)
Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.
- Key Safety 13/25: The key is persisted in browser local storage, which any script on the page can read.
- Request Routing 17/20: Requests go straight from you to the AI provider.
- Transparency 20/20: Source is public under AGPL-3.0, so anyone can check how the key is handled.
- Privacy 14/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control.
- Maintenance 10/10: Actively developed: commits within the last three months.
- Verification Confidence 1/10: Compiled from public documentation by an AI-assisted pass, not independently confirmed.
What was checked
Verification tier RESEARCH_ASSISTED, derived from the evidence below and not set by hand.
- [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
- [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
- [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-13, about 0 month(s) ago. source
How your API key is handled
Your API key is stored in your browser's local storage. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.
Setup
Open the extension/app settings, paste your provider API key (kept in your browser), and pick a model.