BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.

Skyvern

Automate browser-based workflows with LLMs and computer vision instead of brittle selectors.

Website Source code

Category:
Agent Frameworks
Maintenance:
Actively developed (last commit today)
Pricing:
Open Source
Open source:
Yes (AGPL-3.0)
Self-hostable:
Yes
Local-first:
Yes
Platforms:
Self-hosted, Library/SDK, CLI, Web, Docker
AI providers (bring your own key):
OpenAI, Anthropic, Google Gemini, Azure OpenAI, OpenRouter, Groq, Ollama, Custom / OpenAI-compatible
API key storage:
Configured by environment variable
Key risk level:
LOW
Trust score:
90/100

Skyvern is an open-source AI agent that automates browser-based workflows using LLMs and computer vision rather than brittle XPath/CSS selectors, letting it operate on websites it has never seen before. It exposes a Playwright-compatible SDK plus an API and workflow builder, and runs self-hosted (Python, Docker) or via Skyvern Cloud. Users bring their own LLM provider key: the .env.example ships empty OPENAI_API_KEY / ANTHROPIC_API_KEY / GEMINI_API_KEY fields, and the self-hosted LLM Configuration docs document an ENABLE_<PROVIDER>=true + <PROVIDER>_API_KEY pattern across OpenAI, Anthropic, Azure OpenAI, Google Gemini/Vertex, AWS Bedrock, Ollama (local), OpenRouter, Groq, plus an OpenAI-compatible/custom-endpoint option and several regional providers (MiniMax, VolcEngine, Novita, Moonshot). Licensed AGPL-3.0; anti-bot detection, proxy network, and CAPTCHA solvers are reserved for the managed cloud offering. ~22k GitHub stars; latest release v1.0.43 (June 18, 2026).

Why this trust score (90/100)

Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.

  • Key Safety 22/25: The key is supplied by an environment variable or local config file you control.
  • Request Routing 20/20: Requests go straight from you to the AI provider. The provider endpoint is configurable, so you can point it at the provider or your own gateway.
  • Transparency 20/20: Source is public under AGPL-3.0, so anyone can check how the key is handled. Key handling was located in the published source.
  • Privacy 11/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control. Analytics or error-reporting libraries are present; what they send was not established.
  • Maintenance 10/10: Actively developed: commits within the last three months.
  • Verification Confidence 7/10: Key handling was found in the published source by BYOAIK's scanner.

What was checked

Verification tier SOURCE_VERIFIED, derived from the evidence below and not set by hand.

  • [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
  • [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
  • [STRONG · SOURCE_SCAN] The provider endpoint is configurable, so requests can be pointed straight at the provider or at your own gateway. source
  • [STRONG · SOURCE_SCAN] The user supplies their own OpenAI key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Anthropic key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Google Gemini key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own xAI Grok key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own OpenRouter key: the project references its API key variable. source
  • [STRONG · SOURCE_SCAN] The user supplies their own Groq key: the project references its API key variable. source
  • [CONFIRMED · SOURCE_SCAN] Ships a container definition, so it can be self-hosted on your own infrastructure. source
  • [REPORTED · SOURCE_SCAN] References PostHog, so some analytics or error reporting is present. This scan cannot tell whether it is opt-in or what it sends. source
  • [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-14, about 0 month(s) ago. source

How your API key is handled

Your API key is supplied via an environment variable or local config file. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.

Setup

Install the tool, set your provider API key as an environment variable (or in its config file), and pick a model.