Bring Your Own Agent BYOA
Draft · specification v0.1 in progress

Bring Your Own Agent

An open protocol that lets websites and apps use the visitor's own AI agents — their subscriptions, API keys or local models — within limits the visitor sets.

First published 10 October 2026 Open and vendor-neutral CC BY 4.0 · Apache 2.0

Sites ask for skills

Speech recognition, text understanding, vision, generation — not a particular company's model.

Visitors bring the AI

Subscriptions where the vendor allows it, API keys, connected accounts — and models on their own hardware.

The visitor stays in control

Budgets per site and per hour, the real cost shown, keys that never leave the visitor's wallet.

01 · The problem

Every site pays for every visitor's AI.

A site that wants voice input, smart search or a helpful assistant has to buy AI models and pay for every request of every visitor. So it is left with three bad options:

  • 01Charge visitors and build accounts, billing and metering just to cover the model costs.
  • 02Drop the feature — no voice, no understanding, a plain form instead.
  • 03Make people type exact keywords, because nothing on the page can understand them.

Meanwhile, visitors already pay for AI — subscriptions, API keys, credits — or own a GPU that sits idle. None of it can be used on someone else's site.

The web has a protocol for signing in and a protocol for paying. It has no protocol for bringing your own AI.

02 · How it works

A site declares what it needs. Your agents do the work.

People no longer browse alone: everyone arrives with their own set of agents. BYOA defines how a site asks for skills, how the visitor's agent wallet answers, and how the cost stays under the visitor's control.

STEP 1 · MANIFEST

The site asks

Which skills it needs, with parameters, and what for — its declared purpose.

STEP 2 · APPROVE

You decide

A quick budget slider and rules: “20¢ for this site”, “50¢ an hour”, “local models only”.

STEP 3 · GRANT

The wallet answers

A grant with skills, budget, time limit and privacy rules — never a key.

STEPS 4–5 · CALL

Your agents work

The wallet routes each call, meters it, checks the purpose and returns the result with a receipt.

One manifest, any provider

The site describes skills and purpose. It does not name a vendor or hold a key. Whether the work runs on a subscription, an API key or the visitor's own GPU is the visitor's choice.

“Sign in” and “pay” already have open protocols. BYOA adds the missing one: bring your own AI.

Illustrative · the format will be defined in spec v0.1
// manifest sent by the site
{
  "byoa": "0.1-draft",
  "purpose": {
    "summary": "Family geography game: recognise country names",
    "limits": { "maxClipSeconds": 15, "maxCallsPerMinute": 20 }
  },
  "skills": {
    "audio.transcribe": { "languages": ["ru", "sk"], "required": true },
    "text.understand":  { "size": "small", "required": false }
  },
  "privacy": "personal-voice",
  "expectedCost": { "perSession": "0.06 USD" }
}

03 · Declared purpose

Every request is checked against what the site promised.

A site states why it needs your agents. You can add your own conditions in plain words. The wallet checks every call against both — what code can verify is checked by code; the rest by a small model, preferably running locally. Anything that does not fit is stopped.

Request

From the site — for example, a 9-second voice clip.

Hard limits · code

Allowed skill? Clip ≤ 15 s? Within budget and rate?

Purpose check · small model

Does the content fit “a family geography game”?

Outcome
AllowWarnAsk youBlock
The site declares

Game. Only short voice clips with country names, up to 15 seconds.

You add

Only while I'm playing. Warn me if it starts sending text or longer audio.

04 · Who it is for

Good for visitors, sites and model providers.

For visitors

Use the AI you already pay for — or run it free on your own hardware — on any site. Set a budget, see the real cost, revoke access at any moment. Your keys never leave your wallet.

For sites and apps

Add voice, vision and language features without paying for every visitor's requests, building billing, or holding anyone's keys. No wallet? Fall back to your own mode.

For model providers

Your subscribers and API customers can use what they bought in more places, under limits they control, through one open interface.

01

Skills, not vendors

Sites ask for capabilities; preferences and minimum quality are optional.

02

Every provider is first-class

Subscriptions where allowed, API keys, OAuth accounts, local models, home servers.

03

Keys never leave the wallet

Sites get results and receipts — never credentials.

04

The visitor pays and decides

Budgets per site and per time window; grants can be revoked at any time.

05

Privacy in the protocol

Sites mark data sensitivity; visitors can require “local models only”.

06

Graceful fallback

No wallet — the site falls back to its own paid, reduced or text-only mode.

07

One core, many transports

Browser first; then desktop apps on Windows, macOS and Linux; then agent to agent.

08

Built on what exists

OpenAI-compatible model APIs, OAuth, MCP and WebMCP, A2A agent cards.

05 · For everyone

Not against anyone. Built to connect everyone.

BYOA does not compete with AI companies — it connects them. The most capable agents today come with subscriptions from the large providers, and they are at the heart of BYOA. Next to them stand API keys, open models and the model on your own GPU.

The protocol gives every provider the same way into every site, and every person the same right to choose which agent to bring — or to use several at once.

Subscriptions are first-class

The smartest agents often come with a subscription. Wherever a provider allows it, your plan works on any BYOA site.

Equal terms for every provider

Large or small, cloud or local — one open interface, no favourites.

Your choice, your mix

A subscription for reasoning, a local model for voice, an API key as a backup — all in one wallet.

06 · Local models

Your own GPU is a provider too.

More and more people run models at home — on a laptop GPU or a small server — so their data never leaves the house. BYOA treats a local model exactly like a subscription or an API key. A 16 GB laptop GPU runs speech recognition and a small language model with room to spare.

Sites never talk to a local model directly — a model server open to any page would let any page use your GPU. The wallet always stands in between.

Private

Voice, text and images stay on your machine or your home network.

Free per request

No tokens to buy — the hardware you already own does the work.

Always at hand

Works offline and side by side with your subscriptions and keys.

07 · Where it came from

It started with a family game.

Players name countries out loud in turns, and the map fills in with their colours. The game needs two models — speech recognition and a small text model — and every spoken phrase costs the site owner money.

The players' own laptops could do both for free, and many players already pay for AI subscriptions. There was no standard way to use either. That gap is not specific to one game — it is the same on millions of sites.

08 · Roadmap

The idea is public. The specification is next.

More details soon — follow the repository for updates.

  1. 10 October 2026 · done

    Idea published

    The concept, principles and related work are on GitHub.

  2. Later

    Desktop apps and agents

    The same protocol for apps on Windows, macOS and Linux, and for agent-to-agent work.

09 · Questions

Frequently asked

Is BYOA a product or a company?

It is an open protocol. Documents and the specification are published under CC BY 4.0, code under Apache 2.0, and reference implementations will be open source. No vendor owns it.

Will sites see my API keys or subscriptions?

No. Keys stay in your agent wallet. A site receives results and a receipt with the cost — not the key, and not necessarily which provider did the work.

Can I use my ChatGPT, Claude or Gemini subscription?

Where the vendor allows it. Terms differ between vendors and change over time; BYOA stays neutral and uses what each vendor permits. API keys and local models work regardless.

How is this different from “Sign in with ChatGPT” or OpenRouter OAuth?

They are valuable building blocks: each connects one provider's accounts to an app. BYOA is the neutral layer that brings them together: a site asks for skills once, and your wallet can use any of your providers — a subscription, an aggregator, an API key or a local model — with budgets, purpose checks and privacy rules in one place. See related work.

Do I need a powerful computer?

No. Local models are optional. If you have a GPU or a home server you can run speech recognition and small language models for free; otherwise use a subscription or an API key.

Bring your own agent.

The idea is open. Watch the repository, open an issue, or bring your own ideas.

Follow on GitHub ↗