BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.
Twenty CRM
Open-source, AI-first CRM (Salesforce alternative) with bring-your-own-key AI agents.
- Category:
- Enterprise AI Tools
- Maintenance:
- Actively developed (last commit today)
- Pricing:
- Open Source
- Open source:
- Yes (AGPLv3 (with commercial/enterprise license for enterprise-flagged files))
- Self-hostable:
- Yes
- Local-first:
- Yes
- Platforms:
- Web, Self-hosted, Docker
- AI providers (bring your own key):
- OpenAI, Anthropic, Google Gemini, xAI Grok, Groq, Mistral, OpenRouter, Ollama, Custom / OpenAI-compatible
- API key storage:
- User controls deployment
- Key risk level:
- LOW
- Trust score:
- 75/100
Twenty is an open-source CRM positioned as "the open alternative to Salesforce, designed for AI." Built with TypeScript, NestJS, React, and PostgreSQL, it offers customizable objects, workflow automation, and AI agents/chats for tasks like prospect research, record updates, and summaries. On self-hosted deployments, AI is fully BYOK: the server's .env.example exposes native API-key slots for OpenAI, Anthropic (Claude), Google, xAI (Grok), Groq, and Mistral, plus an AI_PROVIDERS JSON variable supporting custom "openai-compatible" providers with a configurable baseUrl and apiKey (covering OpenRouter, local/Ollama gateways, and any OpenAI-compatible endpoint). Default model configs reference current OpenAI GPT-5.x and Anthropic Claude Sonnet/Haiku 4.x models. The repo is very actively maintained (last push 2026-06-20, ~50.7k stars). Licensed under AGPLv3 with a separate commercial license for enterprise-flagged files. A paid hosted cloud is also offered.
Why this trust score (75/100)
Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.
- Key Safety 21/25: The key lives in a deployment you run yourself.
- Request Routing 17/20: Requests go straight from you to the AI provider.
- Transparency 15/20: Source is public, though the licence is unclear or non-standard.
- Privacy 11/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control. Analytics or error-reporting libraries are present; what they send was not established.
- Maintenance 10/10: Actively developed: commits within the last three months.
- Verification Confidence 1/10: Compiled from public documentation by an AI-assisted pass, not independently confirmed.
What was checked
Verification tier RESEARCH_ASSISTED, derived from the evidence below and not set by hand.
- [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
- [REPORTED · SOURCE_SCAN] References Sentry, so some analytics or error reporting is present. This scan cannot tell whether it is opt-in or what it sends. source
- [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-15, about 0 month(s) ago. source
How your API key is handled
You self-host the app, so your API key lives in your own deployment. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.
Setup
Deploy it (Docker/compose), add your provider API key in the admin or environment config, then select models.