BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.

Onyx

Open-source enterprise search and AI assistant that works with every LLM and connects to your knowledge sources.

Website Source code

Category:
Knowledge Management
Maintenance:
Actively developed (last commit today)
Pricing:
Freemium
Open source:
Yes (MIT (Community Edition))
Self-hostable:
Yes
Local-first:
Yes
Platforms:
Web, Self-hosted, Docker
AI providers (bring your own key):
OpenAI, Anthropic, Google Gemini, Azure OpenAI, OpenRouter, Ollama, Custom / OpenAI-compatible
API key storage:
User controls deployment
Key risk level:
LOW
Trust score:
80/100

Onyx (formerly Danswer) is an open-source AI platform for enterprise search and chat. It connects to 40+ knowledge sources (Slack, GitHub, Confluence, Google Drive, etc.) and grounds answers using hybrid search and advanced agentic RAG, with deep research, MCP, code interpreter, and web search. Admins configure their own LLM providers in the admin UI by pasting their own API keys, and it works with both proprietary providers (OpenAI, Anthropic, Gemini/Vertex, Azure OpenAI, Bedrock) and self-hosted/local models (Ollama, LM Studio, vLLM, LiteLLM), plus any OpenAI-compatible endpoint via a dedicated Custom Inference Provider config. The Community Edition is MIT-licensed and fully self-hostable via Docker/Kubernetes/Helm; a managed cloud and a feature-richer Enterprise Edition are also offered.

Why this trust score (80/100)

Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.

  • Key Safety 21/25: The key lives in a deployment you run yourself.
  • Request Routing 17/20: Requests go straight from you to the AI provider.
  • Transparency 20/20: Source is public under MIT (Community Edition), so anyone can check how the key is handled.
  • Privacy 11/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control. Analytics or error-reporting libraries are present; what they send was not established.
  • Maintenance 10/10: Actively developed: commits within the last three months.
  • Verification Confidence 1/10: Compiled from public documentation by an AI-assisted pass, not independently confirmed.

What was checked

Verification tier RESEARCH_ASSISTED, derived from the evidence below and not set by hand.

  • [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
  • [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
  • [REPORTED · SOURCE_SCAN] References PostHog, so some analytics or error reporting is present. This scan cannot tell whether it is opt-in or what it sends. source
  • [REPORTED · SOURCE_SCAN] References Sentry, so some analytics or error reporting is present. This scan cannot tell whether it is opt-in or what it sends. source
  • [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-14, about 0 month(s) ago. source

How your API key is handled

You self-host the app, so your API key lives in your own deployment. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.

Setup

Deploy it (Docker/compose), add your provider API key in the admin or environment config, then select models.