BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.

Morphic

Open-source AI answer engine with a generative UI, bring your own provider key

Website Source code

Category:
Research Tools
Maintenance:
Actively developed (last commit today)
Pricing:
Open Source
Open source:
Yes (Apache-2.0)
Self-hostable:
Yes
Local-first:
Yes
Platforms:
Web, Self-hosted, Docker
AI providers (bring your own key):
OpenAI, Anthropic, Google Gemini, Ollama, Custom / OpenAI-compatible
API key storage:
User controls deployment
Key risk level:
LOW
Trust score:
86/100

Morphic is an open-source, self-hostable AI-powered answer/search engine with a generative UI built on Next.js and the Vercel AI SDK. It understands a question, runs web search (via Tavily, Exa, Brave, SearXNG, Firecrawl, or Jina), and streams a cited answer rendered with interactive generative-UI components, plus chat history (PostgreSQL/Supabase), file upload, and Quick/Adaptive research modes. It is bring-your-own-key: the end user edits .env.local and supplies their own LLM provider credentials (OPENAI_API_KEY, ANTHROPIC_API_KEY, GOOGLE_GENERATIVE_AI_API_KEY, AI_GATEWAY_API_KEY, OLLAMA_BASE_URL, plus OPENAI_COMPATIBLE_* variables for any OpenAI-compatible endpoint). The model selector uses dynamic provider detection, so configured providers appear automatically. Deployable via Vercel one-click, Docker Compose, Cloudflare Pages, or local dev. At least one AI provider key is required to run.

Why this trust score (86/100)

Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.

  • Key Safety 21/25: The key lives in a deployment you run yourself.
  • Request Routing 17/20: Requests go straight from you to the AI provider.
  • Transparency 20/20: Source is public under Apache-2.0, so anyone can check how the key is handled. Key handling was located in the published source.
  • Privacy 11/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control. Analytics or error-reporting libraries are present; what they send was not established.
  • Maintenance 10/10: Actively developed: commits within the last three months.
  • Verification Confidence 7/10: Key handling was found in the published source by BYOAIK's scanner.

What was checked

Verification tier SOURCE_VERIFIED, derived from the evidence below and not set by hand.

  • [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
  • [STRONG · SOURCE_SCAN] The user supplies their own OpenAI key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
  • [CONFIRMED · SOURCE_SCAN] Ships a container definition, so it can be self-hosted on your own infrastructure. source
  • [REPORTED · SOURCE_SCAN] References PostHog, so some analytics or error reporting is present. This scan cannot tell whether it is opt-in or what it sends. source
  • [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-15, about 0 month(s) ago. source

How your API key is handled

You self-host the app, so your API key lives in your own deployment. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.

Setup

Deploy it (Docker/compose), add your provider API key in the admin or environment config, then select models.