A secure browser wallet for your LLM API keys and setup tokens. Connect to any app — your keys never leave the extension.
Add the Byoky extension to Chrome, Firefox, or Safari. Set a master password to encrypt your vault.
Paste API keys or add a Claude setup token. Everything is encrypted locally with AES-256-GCM. Multiple keys per provider.
Visit any Byoky-enabled app. Approve access in one click. Your keys stay in the vault — always.
Use your favorite provider SDK with Byoky's fetch proxy. Two extra lines. Full API compatibility. Keys never touch your app.
npm install @byoky/sdkWorks with official SDKs from Anthropic, OpenAI, Gemini, Mistral, and 11 more providers. Just swap in Byoky's fetch.
Full SSE streaming support through the extension proxy. No special handling needed.
Your server makes LLM calls through the user's browser via WebSocket. Keys never leave the extension — even server-side.
The Byoky Bridge lets CLI tools and desktop apps route through the wallet via a local HTTP proxy. Keys stay in the extension.
import Anthropic from '@anthropic-ai/sdk';
import { Byoky } from '@byoky/sdk';
const byoky = new Byoky();
const session = await byoky.connect({
providers: [{ id: 'anthropic', required: true }]
});
// Use the native Anthropic SDK — keys never exposed
const client = new Anthropic({
apiKey: session.sessionKey,
fetch: session.createFetch('anthropic'),
});Security isn't a feature — it's the entire point.
Keys encrypted with PBKDF2 (600K iterations). 12-character minimum with real-time strength meter. Web Crypto API — no dependencies.
API keys never leave the extension process. Apps receive temporary session tokens. The extension proxies every request.
Every API request is logged with the app origin, provider, status, and timestamp. Complete visibility into credential usage.
Set token allowances per app — total or per provider. The proxy enforces limits so no app can overspend.
Export your vault as an encrypted .byoky file with a separate backup password. Import on any device.
No cloud. No telemetry. No tracking. Everything is stored on your device, encrypted behind your master password.
15 providers supported. Bring credentials from any of them.
Use your Byoky wallet as the key provider for OpenClaw.
The OpenClaw plugin connects through the Byoky Bridge — a local HTTP proxy that routes every API call through your extension. Your keys never leave the wallet, even when OpenClaw makes requests from the CLI.
Byoky is fully open source under the MIT license. Audit the code, contribute, or fork it.
Star on GitHubMIT License — free forever.