BYOAIK — Bring Your Own AI Key: a directory of AI tools that run on your own API key.
Postiz
Self-hosted social scheduler whose AI copilot and image generation run on the OpenAI key in your own deployment.
- Category:
- Marketing and SEO Tools
- Pricing:
- Open Source
- Open source:
- Yes (AGPL-3.0)
- Self-hostable:
- Yes
- Local-first:
- No
- Platforms:
- Self-hosted, Docker, Web
- AI providers (bring your own key):
- OpenAI
- API key storage:
- User controls deployment
- Key risk level:
- LOW
- Trust score:
- 82/100
Postiz is an open-source alternative to Buffer and Hootsuite for scheduling and analysing posts across more than 35 platforms. Self-hosted deployments set an OPENAI_API_KEY environment variable, documented as the key used for the copilot and AI image generation, which powers the in-app writing assistant — there is no separate paid AI tier in the self-hosted edition. Ships as a Docker Compose stack you run on your own server, so you pay for hosting and your own OpenAI usage. AGPL-3.0, 34,530 stars, daily commits. A managed cloud plan exists separately.
Why this trust score (82/100)
Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.
- Key Safety 21/25 — The key lives in a deployment you run yourself.
- Request Routing 17/20 — Requests go straight from you to the AI provider.
- Transparency 20/20 — Source is public under AGPL-3.0, so anyone can check how the key is handled. Key handling was located in the published source.
- Privacy 7/15 — Can be self-hosted, so the data path stays inside infrastructure you control. Analytics or error-reporting libraries are present; what they send was not established.
- Maintenance 10/10 — Actively developed — commits within the last three months.
- Verification Confidence 7/10 — Key handling was found in the published source by BYOAIK's scanner.
What was checked
Verification tier: SOURCE_VERIFIED — derived from the evidence below, not set by hand.
- [STRONG · SOURCE_SCAN] The user supplies their own OpenAI key: the project references its API key variable. source
- [CONFIRMED · SOURCE_SCAN] Ships a container definition, so it can be self-hosted on your own infrastructure. source
- [REPORTED · SOURCE_SCAN] References PostHog, so some analytics or error reporting is present. This scan cannot tell whether it is opt-in or what it sends. source
- [REPORTED · SOURCE_SCAN] References Sentry, so some analytics or error reporting is present. This scan cannot tell whether it is opt-in or what it sends. source
- [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-11 — about 0 month(s) ago. source
How your API key is handled
You self-host the app, so your API key lives in your own deployment. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.
Setup
Deploy it (Docker/compose), add your provider API key in the admin or environment config, then select models.