BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.
Tabby
Self-hosted, open-source AI coding assistant (Copilot alternative) you point at the models and providers you choose.
- Category:
- Coding Assistants
- Maintenance:
- Maintained (last commit about 2 months ago)
- Pricing:
- Open Source
- Open source:
- Yes (Apache-2.0 (core); separate enterprise license for the ee/ directory)
- Self-hostable:
- Yes
- Local-first:
- Yes
- Platforms:
- Self-hosted, VS Code Extension, JetBrains Plugin, CLI, Docker
- AI providers (bring your own key):
- OpenAI, Anthropic, Azure OpenAI, OpenRouter, Mistral, Perplexity, DeepSeek, Fireworks, Hugging Face, Ollama, Custom / OpenAI-compatible
- API key storage:
- Configured by environment variable
- Key risk level:
- LOW
- Trust score:
- 84/100
Tabby is a self-hosted AI coding assistant that runs as a server (binary, Docker, or Homebrew) and provides code completion and chat as an open-source, on-premises alternative to GitHub Copilot, with IDE extensions for VS Code, JetBrains/IntelliJ, and Vim/Neovim. It is BYOK: via ~/.tabby/config.toml's HTTP Model Connector you configure completion, chat, and embedding models against external providers using your own api_key and api_endpoint. The docs include dedicated configuration pages for OpenAI, Azure OpenAI, Anthropic Claude, Mistral AI, OpenRouter, DeepSeek, Perplexity, Fireworks, Hugging Face, Amazon Bedrock, plus local engines (Ollama, vLLM, llama.cpp, LM Studio) and arbitrary OpenAI-compatible endpoints. Core is Apache 2.0; an "ee/" enterprise directory carries a separate license. ~33.6k GitHub stars, actively maintained (v0.32.0, Jan 2026).
Why this trust score (84/100)
Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.
- Key Safety 22/25: The key is supplied by an environment variable or local config file you control.
- Request Routing 17/20: Requests go straight from you to the AI provider.
- Transparency 20/20: Source is public under Apache-2.0 (core); separate enterprise license for the ee/ directory, so anyone can check how the key is handled.
- Privacy 14/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control.
- Maintenance 10/10: Actively developed: commits within the last three months.
- Verification Confidence 1/10: Compiled from public documentation by an AI-assisted pass, not independently confirmed.
What was checked
Verification tier RESEARCH_ASSISTED, derived from the evidence below and not set by hand.
- [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
- [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-06-30, about 2 month(s) ago. source
How your API key is handled
Your API key is supplied via an environment variable or local config file. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.
Setup
Install the tool, set your provider API key as an environment variable (or in its config file), and pick a model.