Skip to the integration form
Early accessWe're rolling out to AI apps in batches. Request an integration for early access.

Build Your AI App.
Users Bring Their AI.

Users connect their own AI through a standard OAuth 2.1 consent screen. Your app gets a scoped token for one OpenAI-compatible endpoint. No user keys to hold, no inference bill to pay.

  1. Send users to the consent screen
  2. Complete OAuth 2.1 flow, get scoped token
  3. Call OpenAI-compatible endpoint
Works with
  • OpenAI
  • Anthropic
  • Google Gemini
  • OpenRouter
  • Any compatible endpoint

Request integration

We integrate openbyo.ai with you. Tell us about your app and we'll reply within a day.

How do your users get AI today?

We only use your details to plan your integration. You can unsubscribe at any time.

How it works

Connect to your users' AI.
Get a token for one endpoint.

  1. Step 1: Send users to the consent screen

    A standard OAuth 2.1 authorization request with PKCE opens the consent screen on openbyo.ai.

    Authorization URL
    https://app.openbyo.ai/oauth/authorize
    ?client_id=YOUR_APP
    &redirect_uri=https://yourapp.com/callback
    &response_type=code
    &scope=offline_access ai.invoke
    &resource=https://api.openbyo.ai/v1
    &state=…
    &code_challenge=…
    &code_challenge_method=S256
  2. Step 2: What your users see

    Users choose the connections and models your app may use. They see your app's usage and can edit or revoke its access at any time. That's a reason for them to say yes.

    Example screen. Notewise is requesting access to your AI. All of OpenAI and one Anthropic model are selected, with Allow and Not now at the bottom.
  3. Step 3: Exchange the code for a scoped access token

    Your server exchanges the code for an access token limited to what the user approved. Renew it with the refresh token until the user revokes access.

    Token request
    // On your server, at redirect_uri
    const res = await fetch("https://app.openbyo.ai/oauth/token", {
    method: "POST",
    headers: { "Content-Type": "application/x-www-form-urlencoded" },
    body: new URLSearchParams({
    grant_type: "authorization_code",
    code, // from the redirect
    redirect_uri: "https://yourapp.com/callback",
    client_id: "YOUR_APP",
    code_verifier: verifier, // the PKCE secret you kept
    }),
    });
    const { access_token: accessToken, refresh_token } = await res.json();
  4. Step 4: Swap the base URL in any OpenAI SDK

    Call one OpenAI-compatible API with the user's token. Requests run on the user's own AI, with the models they allowed. Your app never sees or stores their keys, and you stop writing a login per provider.

    OpenAI SDK
    import OpenAI from "openai";
    const client = new OpenAI({
    baseURL: "https://api.openbyo.ai/v1", // was https://api.openai.com/v1
    apiKey: accessToken, // from the consent flow, not your key
    });
    const reply = await client.chat.completions.create({
    model: "claude-sonnet-4", // any model the user allowed
    messages: [{ role: "user", content: "Summarise this document" }],
    });
Providers

Your users can bring any of these.

AI labs

  • OpenAI
  • Anthropic
  • Google Gemini
  • Mistral AI
  • DeepSeek
  • Meta Llama
  • xAI
  • Qwen
  • Moonshot AI
  • MiniMax
  • Zhipu AI
  • Cohere
  • AI21 Labs
  • Perplexity
  • 01.AI
  • StepFun
  • Upstage

Routers and gateways

  • OpenRouter
  • Vercel AI Gateway
  • AIHubMix
  • Helicone

Inference platforms

  • Hugging Face
  • Together AI
  • Fireworks AI
  • Groq
  • Cerebras
  • SambaNova
  • DeepInfra
  • NVIDIA NIM
  • Novita AI
  • Hyperbolic
  • Featherless
  • Nebius
  • Baseten
  • Lambda
  • Kluster.ai
  • SiliconFlow
  • Venice
  • Chutes
  • Parasail

Cloud platforms

  • Azure OpenAI
  • Amazon Bedrock
  • Google Vertex AI
  • Cloudflare Workers AI
  • Alibaba Cloud
  • Volcengine
  • Tencent Cloud
  • Baidu AI Cloud

Any compatible endpoint

Uses the OpenAI, Anthropic or Gemini API format

Security

Your app gets a token.
Never a key.

You never hold user credentials

Provider keys stay with openbyo.ai. Your app only holds a token for its own access.

Scoped, revocable tokens

Each token covers what the user approved for your app. Users can revoke it at any time.

Users choose providers and models per app

On the consent screen, users pick which providers and models your app may use.

Per-user envelope encryption

Each key is encrypted with a data key that belongs to its user alone.

Cost and token budgets

Users can set a cost or token budget for your app, per period or over a rolling window.

Activity log per app

Users see every request your app makes, with its time, model, tokens and estimated cost.

Metadata-only logging

We log request details, never prompts or answers.

Never pooled or shared

A user's keys only ever serve that user's requests. They're never pooled or shared between users.
FAQ

Questions, answered.

You can, but then your app stores every user's provider keys and has to keep them safe. You write and maintain a login for each provider, and your users can't see or limit what your app uses.

With openbyo.ai, users connect their AI once and approve your app on one consent screen. Your app gets a scoped token instead of a key.

An openbyo.ai account is one extra step the first time. After that, connecting any app that uses openbyo.ai is a single approval, with no key to find and paste.

Today every app that asks for keys stores them with its own security. With openbyo.ai the keys sit in one place built only for this: encrypted per user, never shown again, never pooled, and never sent to your app.

Requests go through openbyo.ai so we can enforce what each app may use, show users its activity and stop it the moment they revoke it. We're in pre-launch beta and haven't been independently audited yet. We're working towards the security and trust certifications that are the industry's gold standard.

AI apps get a freemium tier: up to 1,000 monthly active users (MAU) at no charge. Above 1,000 MAU, every active user is charged at $0.05.

We support you to get traction, you support us post traction. Your users' AI usage runs on their own AI provider, so your app doesn't pay for their inference.

We log the metadata for each request so users can see what each app does: time, app, connection, model, tokens, estimated cost and success or failure. We don't collect or log API request or response bodies.

Early access

Stop worrying about AI costs.
We do the integration with you.

Tell us about your app and we'll reply within a day.