BYOAIK — Bring Your Own AI Key: a directory of AI tools that run on your own API key.
promptfoo
CLI and library for testing, comparing and red-teaming prompts across providers on your own keys.
- Category:
- Prompt Engineering Tools
- Pricing:
- Open Source
- Open source:
- Yes (MIT)
- Self-hostable:
- Yes
- Local-first:
- Yes
- Platforms:
- CLI, Self-hosted, Web, Docker
- AI providers (bring your own key):
- OpenAI, Anthropic, Google Gemini, Azure OpenAI, Mistral, DeepSeek, Ollama, Custom / OpenAI-compatible
- API key storage:
- Configured by environment variable
- Key risk level:
- LOW
- Trust score:
- 87/100
promptfoo is an open-source CLI and library for testing prompts, evaluating outputs, comparing models and red-teaming AI applications. You supply your own provider keys as environment variables or in YAML provider configs, and every call to OpenAI, Anthropic, Gemini, DeepSeek, Azure, a local Ollama model or any OpenAI-compatible endpoint goes directly from your machine with nothing proxied. Ships as a Node CLI with a local web viewer for results. MIT licensed, 24,256 stars, last commit the day of review. An optional paid enterprise tier exists alongside the free core.
Why this trust score (87/100)
Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.
- Key Safety 22/25 — The key is supplied by an environment variable or local config file you control.
- Request Routing 17/20 — Requests go straight from you to the AI provider.
- Transparency 20/20 — Source is public under MIT, so anyone can check how the key is handled. Key handling was located in the published source.
- Privacy 11/15 — Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control. Analytics or error-reporting libraries are present; what they send was not established.
- Maintenance 10/10 — Actively developed — commits within the last three months.
- Verification Confidence 7/10 — Key handling was found in the published source by BYOAIK's scanner.
What was checked
Verification tier: SOURCE_VERIFIED — derived from the evidence below, not set by hand.
- [STRONG · SOURCE_SCAN] The user supplies their own OpenAI key: the project references its API key variable. source
- [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
- [CONFIRMED · SOURCE_SCAN] Ships a container definition, so it can be self-hosted on your own infrastructure. source
- [REPORTED · SOURCE_SCAN] References PostHog, so some analytics or error reporting is present. This scan cannot tell whether it is opt-in or what it sends. source
- [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-15 — about 0 month(s) ago. source
How your API key is handled
Your API key is supplied via an environment variable or local config file. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.
Setup
Install the tool, set your provider API key as an environment variable (or in its config file), and pick a model.