BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.

Mastra

Open-source TypeScript framework for building AI agents and graph-based workflows.

Website Source code

Category:
Agent Frameworks
Maintenance:
Actively developed (last commit today)
Pricing:
Open Source
Open source:
Yes (Apache-2.0 (core); Mastra Enterprise License (enterprise add-ons))
Self-hostable:
Yes
Local-first:
Yes
Platforms:
Library/SDK, Self-hosted, Docker
AI providers (bring your own key):
OpenAI, Anthropic, Google Gemini, Azure OpenAI, OpenRouter, Groq, Mistral, DeepSeek, xAI Grok, Ollama, Together AI, Fireworks, Custom / OpenAI-compatible
API key storage:
User controls deployment
Key risk level:
LOW
Trust score:
83/100

Mastra is an open-source TypeScript framework for building AI agents, copilots, and graph-based workflows with human-in-the-loop, memory, RAG, evals, and observability. Created by the Gatsby team (YC W25), it reached v1.0 in January 2026 and integrates with React/Next.js/Node or deploys as a standalone Hono server. Its model routing connects to 90+ providers through one standard interface (built on the Vercel AI SDK plus Mastra's own model gateway), so developers supply their own provider API keys (typically via environment variables) for OpenAI, Anthropic, Gemini and many others. It supports configurable OpenAI-compatible base URLs and local models via Ollama, making BYOK first-class. The core framework is Apache 2.0; only enterprise add-ons are source-available under a separate license.

Why this trust score (83/100)

Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.

  • Key Safety 21/25: The key lives in a deployment you run yourself.
  • Request Routing 17/20: Requests go straight from you to the AI provider.
  • Transparency 20/20: Source is public under Apache-2.0 (core); Mastra Enterprise License (enterprise add-ons), so anyone can check how the key is handled.
  • Privacy 14/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control.
  • Maintenance 10/10: Actively developed: commits within the last three months.
  • Verification Confidence 1/10: Compiled from public documentation by an AI-assisted pass, not independently confirmed.

What was checked

Verification tier RESEARCH_ASSISTED, derived from the evidence below and not set by hand.

  • [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
  • [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-15, about 0 month(s) ago. source

How your API key is handled

You self-host the app, so your API key lives in your own deployment. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.

Setup

Deploy it (Docker/compose), add your provider API key in the admin or environment config, then select models.