BYOAIK — Bring Your Own AI Key: a directory of AI tools that run on your own API key.

PaperQA2

Citation-backed question answering over your own library of scientific PDFs, on whichever provider key you export.

Website Source code

Category:
Research Tools
Pricing:
Open Source
Open source:
Yes (Apache-2.0)
Self-hostable:
Yes
Local-first:
Yes
Platforms:
CLI, Library/SDK, Self-hosted, Docker
AI providers (bring your own key):
OpenAI, Anthropic, Google Gemini, Ollama, Custom / OpenAI-compatible
API key storage:
Configured by environment variable
Key risk level:
LOW
Trust score:
90/100

PaperQA2 is a Python library and CLI that performs retrieval-augmented question answering over a collection of scientific papers you supply, answering with citations into the source documents rather than free-form text. The README instructs users to set an API key environment variable such as OPENAI_API_KEY, and states that any LiteLLM-compatible model can be configured, which covers Anthropic, Gemini and local backends through llama.cpp or Ollama. It is library-first rather than a graphical app. Apache-2.0, 9,015 stars.

Why this trust score (90/100)

Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.

  • Key Safety 22/25 — The key is supplied by an environment variable or local config file you control.
  • Request Routing 17/20 — Requests go straight from you to the AI provider.
  • Transparency 20/20 — Source is public under Apache-2.0, so anyone can check how the key is handled. Key handling was located in the published source.
  • Privacy 14/15 — Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control.
  • Maintenance 10/10 — Actively developed — commits within the last three months.
  • Verification Confidence 7/10 — Key handling was found in the published source by BYOAIK's scanner.

What was checked

Verification tier: SOURCE_VERIFIED — derived from the evidence below, not set by hand.

  • [STRONG · SOURCE_SCAN] The user supplies their own OpenAI key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Anthropic key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Google Gemini key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
  • [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-06-05 — about 2 month(s) ago. source

How your API key is handled

Your API key is supplied via an environment variable or local config file. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.

Setup

Install the tool, set your provider API key as an environment variable (or in its config file), and pick a model.