BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.
Scira
Open-source agentic AI search engine that plans, retrieves, and cites sources inline.
- Category:
- Research Tools
- Maintenance:
- Maintained (last commit about 1 month ago)
- Pricing:
- Open Source
- Open source:
- Yes (AGPL-3.0)
- Self-hostable:
- Yes
- Local-first:
- No
- Platforms:
- Web, Self-hosted, Docker
- AI providers (bring your own key):
- xAI Grok, OpenAI, Anthropic, Google Gemini, Mistral, Groq, Cohere, DeepSeek, OpenRouter, Custom / OpenAI-compatible
- API key storage:
- User controls deployment
- Key risk level:
- LOW
- Trust score:
- 82/100
Scira (formerly MiniPerplx) is an open-source, agentic AI-powered search engine built on the Vercel AI SDK. It decomposes a question into sub-tasks, runs live web/academic/social searches (Exa, Firecrawl, Tavily, Parallel), cross-checks evidence, and returns answers with inline citations. The hosted product runs at scira.ai (1M+ monthly searches, 60k+ users per third-party reporting), but the full app is self-hostable under AGPL-3.0 via Docker Compose, Vercel, or Node/pnpm. When self-hosting, the operator brings their own provider API keys: the .env.example defines XAI_API_KEY, OPENAI_API_KEY, ANTHROPIC_API_KEY, GROQ_API_KEY, GOOGLE_GENERATIVE_AI_API_KEY (plus Inception) and search keys EXA_API_KEY, FIRECRAWL_API_KEY, TAVILY_API_KEY. The ai/providers.ts wires direct SDKs for OpenAI, Anthropic, Google Gemini, Mistral, Groq, xAI Grok, and Cohere, an OpenRouter custom provider, OpenAI-compatible providers (Z.AI/GLM, HuggingFace, Novita, MiniMax, etc.), and Vercel AI Gateway routing for DeepSeek, Qwen/Alibaba, Kimi and others.
Why this trust score (82/100)
Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.
- Key Safety 21/25: The key lives in a deployment you run yourself.
- Request Routing 17/20: Requests go straight from you to the AI provider.
- Transparency 20/20: Source is public under AGPL-3.0, so anyone can check how the key is handled. Key handling was located in the published source.
- Privacy 7/15: Can be self-hosted, so the data path stays inside infrastructure you control. Analytics or error-reporting libraries are present; what they send was not established.
- Maintenance 10/10: Actively developed: commits within the last three months.
- Verification Confidence 7/10: Key handling was found in the published source by BYOAIK's scanner.
What was checked
Verification tier SOURCE_VERIFIED, derived from the evidence below and not set by hand.
- [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
- [STRONG · SOURCE_SCAN] The user supplies their own OpenAI key: the project references its API key variable. source
- [STRONG · SOURCE_SCAN] The user supplies their own Anthropic key: the project references its API key variable. source
- [STRONG · SOURCE_SCAN] The user supplies their own Groq key: the project references its API key variable. source
- [STRONG · SOURCE_SCAN] The user supplies their own xAI Grok key: the project references its API key variable. source
- [REPORTED · SOURCE_SCAN] References PostHog, so some analytics or error reporting is present. This scan cannot tell whether it is opt-in or what it sends. source
- [CONFIRMED · SOURCE_SCAN] Ships a container definition, so it can be self-hosted on your own infrastructure. source
- [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
- [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-12, about 0 month(s) ago. source
How your API key is handled
You self-host the app, so your API key lives in your own deployment. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.
Setup
Deploy it (Docker/compose), add your provider API key in the admin or environment config, then select models.