BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.

OpenHands

Open-source autonomous AI software-engineering agent that runs on any LLM you supply.

Website Source code

Category:
Coding Assistants
Maintenance:
Actively developed (last commit today)
Pricing:
Open Source
Open source:
Yes (MIT)
Self-hostable:
Yes
Local-first:
Yes
Platforms:
Self-hosted, CLI, Web, Library/SDK, Docker
AI providers (bring your own key):
OpenAI, Anthropic, Google Gemini, Azure OpenAI, Mistral, Ollama, Custom / OpenAI-compatible
API key storage:
Configured by environment variable
Key risk level:
LOW
Trust score:
81/100

OpenHands (formerly OpenDevin) is an open-source, self-hostable autonomous coding agent that can write code, run commands, browse the web, and call APIs to complete software-engineering tasks. It is BYOK by design: the LLM settings let users bring their own model and API key, with a configurable Base URL for custom and OpenAI-compatible endpoints, plus CLI/env config via LLM_MODEL, LLM_API_KEY, and LLM_BASE_URL. Because it is built on LiteLLM, it works with virtually any provider; Anthropic, OpenAI, and Mistral are explicitly verified, and the custom Base URL covers Azure OpenAI, Gemini, and local servers like Ollama and vLLM. Available as a self-hosted web UI, a CLI, and a Python SDK/library. MIT-licensed with ~77.8k GitHub stars and active releases (v1.8.0, June 2026); an optional paid OpenHands Cloud is also offered.

Why this trust score (81/100)

Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.

  • Key Safety 22/25: The key is supplied by an environment variable or local config file you control.
  • Request Routing 17/20: Requests go straight from you to the AI provider.
  • Transparency 20/20: Source is public under MIT, so anyone can check how the key is handled.
  • Privacy 11/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control. Analytics or error-reporting libraries are present; what they send was not established.
  • Maintenance 10/10: Actively developed: commits within the last three months.
  • Verification Confidence 1/10: Compiled from public documentation by an AI-assisted pass, not independently confirmed.

What was checked

Verification tier RESEARCH_ASSISTED, derived from the evidence below and not set by hand.

  • [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
  • [REPORTED · SOURCE_SCAN] References PostHog, so some analytics or error reporting is present. This scan cannot tell whether it is opt-in or what it sends. source
  • [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-15, about 0 month(s) ago. source

How your API key is handled

Your API key is supplied via an environment variable or local config file. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.

Setup

Install the tool, set your provider API key as an environment variable (or in its config file), and pick a model.