Feature · Built for Mac

Bring your own key

Direct frontier model access without middleman markup or subscription lock-in.

Shipped in Mac AppProven in codebase: main/ai/key-store.ts (as of 2026-10-03)

What this helps you achieve

  • Pay only for the exact tokens you consume directly to model providers
  • Hardware-backed security via native macOS Keychain encryption
  • Zero proxy architecture: requests travel straight from your Mac to the provider

Most modern productivity applications that advertise artificial intelligence features bundle cloud LLMs behind expensive monthly subscription tiers. Users are routinely forced into $20 to $30 per-month plans, even if they only generate a handful of meeting summaries each week.

Worse, many of these tools route your prompts and sensitive transcripts through intermediate company proxy servers. This multi-tenant middleman architecture introduces unnecessary latency, inflates per-token costs with proprietary markups, and creates another corporate silo holding your confidential data.

Oyma rejects this model. While we prioritize local AI with Ollama as our sovereign default, we recognize that users occasionally demand the massive context windows and complex reasoning of frontier cloud models like Claude 3.5 Sonnet and GPT-4o.

For these workflows, Oyma implements a pure Bring Your Own Key (BYOK) architecture proven in src/main/ai/key-store.ts.

Direct provider connection: Zero middleman proxies

When you supply your own API key in Oyma, the application acts purely as a client interface communicating directly with model providers:

  1. Direct TLS connections: When you request a summary or invoke the ask workbench, Oyma opens a direct HTTPS connection from your Mac to api.anthropic.com or api.openai.com.
  2. Zero intermediate servers: There is no Oyma cloud proxy, no relay server, and no remote prompt queue. Your prompts and note excerpts travel straight from your machine to your chosen provider.
  3. Transparent token pricing: You pay the AI provider directly at their standard wholesale developer rates. Instead of paying $240/year for an arbitrary bundled AI seat, a typical user running dozens of meeting summaries spends mere cents per month.
  4. Data retention control: Because you connect directly via your own developer account, your usage is governed by enterprise terms that prohibit model training on API payloads.

Native macOS Keychain encryption

Storing sensitive API keys in unencrypted plain text JSON files or plaintext dotfiles on disk leaves credentials vulnerable to malicious scripts or accidental exposure in backups.

Oyma secures your credentials using Apple’s native macOS Keychain Services API:

  • Hardware-backed security: Keys are encrypted using Apple Silicon Secure Enclave hardware protections and system-level cryptographic primitives.
  • Strict process sandboxing: Only the signed Oyma application binary can read your stored credentials from the Keychain.
  • Zero plain text persistence: When the application terminates, keys are purged from memory. They are retrieved on demand only when an inference request is explicitly confirmed.

If you ever wish to revoke or rotate a key, updating it in Oyma‘s settings updates the macOS Keychain entry instantly.

Flexible model selection: Pick the right tool for the job

Different intellectual tasks demand different model capabilities. Oyma lets you alternate seamlessly between local and cloud models depending on the task:

  • Local Ollama for everyday private meetings: Use fast 8-billion parameter models running locally on your Mac for daily 1-on-1s, confidential internal check-ins, and offline flights.
  • Claude 3.5 Sonnet for deep analytical briefs: Switch to Anthropic when synthesizing multi-hour conferences, messy technical debates, or nuanced legal contract negotiations.
  • GPT-4o for rapid general synthesis: Switch to OpenAI when you need rapid structured table generation or multi-step reasoning across extensive transcripts.

Model selection is a simple dropdown in the summary and ask panels. You choose the intelligence tier that fits your budget and privacy criteria for each individual document.

Credential rotation and token quota safeguards

Managing API keys responsibly requires clear safeguards against unexpected bills or runaway loops:

  • Per-request confirmation: Oyma requires explicit user interaction to trigger any cloud LLM call. Background indexing processes and automated watchers never issue requests to external APIs automatically.
  • Immediate token usage feedback: Following each completed cloud request, Oyma reports input and output token counts, allowing you to monitor consumption against your provider limits.
  • Effortless key revocation: If you rotate your credentials or switch developer organizations, you can update or clear your stored key in seconds. Revoking a key removes it immediately from your macOS Keychain.

Total sovereignty and privacy boundaries

Even when cloud keys are configured, Oyma gives you complete authority over outbound network boundaries:

  • Strict host whitelisting: Outbound connections are constrained strictly to verified API endpoints (api.anthropic.com and api.openai.com). No telemetry or user telemetry is bundled alongside inference payloads.
  • Instant local-only toggle: If you enter a high-security environment or need to conduct an air-gapped review, toggle local-only mode in our privacy architecture to sever all cloud connections instantly.

Experience the full power of frontier artificial intelligence on your own terms, at wholesale developer rates, with Oyma.

Where are my API keys stored on my Mac?

API keys are encrypted and stored inside the native macOS Keychain (main/ai/key-store.ts). They are never saved in plain text configuration files or synced to the cloud.

Does Oyma take a markup on my API usage?

Zero markup. Requests travel directly from your computer to Anthropic or OpenAI. You pay your provider directly at standard developer token rates.

Can I use Oyma without providing any API keys at all?

Yes. Oyma is fully functional without external keys using local Ollama models for AI, local Whisper for transcription, and SQLite for search.

Which cloud providers and models can I configure with my own keys?

Anthropic (Claude 3.5 Sonnet, Claude 3 Opus) and OpenAI (GPT-4o, GPT-4o mini) are natively supported with easy toggle switching.

Your notes, in plain Markdown.

Free during the private beta. Apple silicon Macs, macOS 14 or later.

One email when your invite is ready. No newsletter.