BYOAIK — Bring Your Own AI Key: a directory of AI tools that run on your own API key.
Kotaemon
Self-hosted chat-with-your-documents RAG interface with citation highlighting, running on your own API key or a local model.
- Category:
- Document Analysis
- Pricing:
- Open Source
- Open source:
- Yes (Apache-2.0)
- Self-hostable:
- Yes
- Local-first:
- Yes
- Platforms:
- Self-hosted, Docker, Web
- AI providers (bring your own key):
- OpenAI, Azure OpenAI, Ollama, Custom / OpenAI-compatible
- API key storage:
- User controls deployment
- Key risk level:
- LOW
- Trust score:
- 92/100
Kotaemon is an open-source RAG web app for chatting with your own documents, built by Cinnamon AI, with citation highlighting aimed at both end users and developers customising the pipeline. Credentials are set in the .env file or through the in-app Resources tab, where the README instructs users to set OPENAI_API_KEY and check that the configured api_key is present for LLMs and embeddings. Supports OpenAI, Azure OpenAI and local models via Ollama or llama.cpp, self-hosted through Docker. Apache-2.0, 25,696 stars.
Why this trust score (92/100)
Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.
- Key Safety 21/25 — The key lives in a deployment you run yourself.
- Request Routing 20/20 — Requests go straight from you to the AI provider. The provider endpoint is configurable, so you can point it at the provider or your own gateway.
- Transparency 20/20 — Source is public under Apache-2.0, so anyone can check how the key is handled. Key handling was located in the published source.
- Privacy 14/15 — Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control.
- Maintenance 10/10 — Actively developed — commits within the last three months.
- Verification Confidence 7/10 — Key handling was found in the published source by BYOAIK's scanner.
What was checked
Verification tier: SOURCE_VERIFIED — derived from the evidence below, not set by hand.
- [STRONG · SOURCE_SCAN] The user supplies their own OpenAI key: the project references its API key variable. source
- [STRONG · SOURCE_SCAN] The user supplies their own Azure OpenAI key: the project references its API key variable. source
- [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
- [STRONG · SOURCE_SCAN] The provider endpoint is configurable, so requests can be pointed straight at the provider or at your own gateway. source
- [STRONG · SOURCE_SCAN] The user supplies their own Mistral key: the project references its API key variable. source
- [STRONG · SOURCE_SCAN] The user supplies their own Cohere key: the project references its API key variable. source
- [CONFIRMED · SOURCE_SCAN] Ships a container definition, so it can be self-hosted on your own infrastructure. source
- [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-05-30 — about 2 month(s) ago. source
How your API key is handled
You self-host the app, so your API key lives in your own deployment. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.
Setup
Deploy it (Docker/compose), add your provider API key in the admin or environment config, then select models.