BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.

Khoj

Open-source, self-hostable AI second brain that chats with your documents and the web.

Website Source code

Category:
Knowledge Management
Maintenance:
Maintained (last commit about 1 month ago)
Pricing:
Open Source
Open source:
Yes (AGPL-3.0)
Self-hostable:
Yes
Local-first:
Yes
Platforms:
Web, Desktop, Mobile, Self-hosted, Docker
AI providers (bring your own key):
OpenAI, Anthropic, Google Gemini, DeepSeek, OpenRouter, Hugging Face, Ollama, Custom / OpenAI-compatible
API key storage:
Stored locally on device
Key risk level:
LOW
Trust score:
94/100

Khoj is an open-source (AGPL-3.0), self-hostable personal AI application that lets you chat with LLMs grounded in your own documents and online sources, and build custom agents. It is accessible via web, desktop, mobile, an Obsidian plugin, an Emacs package, and WhatsApp. Self-hosting users bring their own provider API keys: the admin panel and environment variables accept OPENAI_API_KEY, ANTHROPIC_API_KEY, and GEMINI_API_KEY, plus a configurable OpenAI-compatible API base URL that points Khoj at Ollama, LMStudio, LiteLLM, vLLM, Hugging Face, OpenRouter, and any other OpenAI-compatible endpoint. A managed cloud version is also offered.

Why this trust score (94/100)

Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.

  • Key Safety 23/25: The key is held on your own device.
  • Request Routing 20/20: Requests go straight from you to the AI provider. The provider endpoint is configurable, so you can point it at the provider or your own gateway.
  • Transparency 20/20: Source is public under AGPL-3.0, so anyone can check how the key is handled. Key handling was located in the published source.
  • Privacy 14/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control.
  • Maintenance 10/10: Actively developed: commits within the last three months.
  • Verification Confidence 7/10: Key handling was found in the published source by BYOAIK's scanner.

What was checked

Verification tier SOURCE_VERIFIED, derived from the evidence below and not set by hand.

  • [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
  • [STRONG · SOURCE_SCAN] The user supplies their own OpenAI key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Anthropic key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Google Gemini key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
  • [STRONG · SOURCE_SCAN] The provider endpoint is configurable, so requests can be pointed straight at the provider or at your own gateway. source
  • [CONFIRMED · SOURCE_SCAN] Ships a container definition, so it can be self-hosted on your own infrastructure. source
  • [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-02, about 0 month(s) ago. source

How your API key is handled

Your API key is stored locally on your device. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.

Setup

Open settings, paste your provider API key, choose a model, and start. The key stays on your device.