How to tell, before installing, whether a tool needs a paid API key
Last updated 2026-10-09
You install a “free, open-source AI tool”, run it, and the first screen asks for an API key. It happens often, because open source means the code is open, not that using it costs nothing. This note sets out the order in which to check, from the repository page alone and before installing, whether a tool needs a paid API. Every example is a line pinned to a commit in a real repository.
1. Open the example settings file first
A tool that needs a key usually keeps an example settings file at the top of the repository, named something like .env.example, .env.sample, config.example.yaml or settings.example.json. The names in it that end in _API_KEY, _TOKEN or _SECRET show most of the services the tool leans on.
Many key names do not mean all of them are needed, though. Lines 1–17 of .env.example in TauricResearch/TradingAgents list 16 provider keys — OpenAI, Google, Anthropic, DeepSeek, Groq and more — but the comment on the first line says to set the one you use. Lines 30–39 of the same file have a setting for local servers such as vLLM, LM Studio and llama.cpp, and a comment that an unset Ollama address goes to your own computer (localhost:11434). This one file already answers: one cloud key, or a local model.
So read the comments in this file before the key names. Words like “one”, “optional” or “local” decide how many keys you actually need.
2. Look for provider SDKs in the dependency list
Without an example settings file, read the dependency list: requirements.txt or pyproject.toml for Python, package.json for JavaScript and TypeScript, go.mod for Go, Cargo.toml for Rust. If one of these names appears, there is likely code that calls that provider's API.
| Provider | Python | JavaScript · TypeScript |
|---|---|---|
| OpenAI | openai, langchain-openai | openai, @ai-sdk/openai |
| Anthropic | anthropic, langchain-anthropic | @anthropic-ai/sdk, @ai-sdk/anthropic |
| Google Gemini | google-genai, langchain-google-genai | @google/genai, @ai-sdk/google |
| Many providers at once | litellm | ai (Vercel AI SDK) |
Two cautions. First, a dependency is not a call. Lines 13–15 of TradingAgents' pyproject.toml install the Anthropic, Google and OpenAI libraries as core dependencies, but the tool calls the one provider picked in the settings. A library that bundles many providers, such as litellm, also leaves the choice to the settings. Second, no dependency is not no call. Code that calls an API address directly with requests or fetch, without an SDK, is common. That is what the next step is for.
3. Search the code for addresses and setting names
On a GitHub repository page, signed in, press / to search the code in that repository. Try these in turn:
- API addresses:
api.openai.com,api.anthropic.com,generativelanguage.googleapis.com,openrouter.ai - Key names:
OPENAI_API_KEY,ANTHROPIC_API_KEY,GEMINI_API_KEY - Settings that change the address:
base_url,baseURL,api_base,BASE_URL - Local runner addresses:
localhost:11434(Ollama),localhost:1234(LM Studio)
Look at where the hits are, too. If they appear only under tests/, examples/ or docs/, the tool itself may not call that API. If an address setting and a local address appear together, that call can run against a local model (Going local with one line).
4. What the README is for
The “Requirements”, “Prerequisites” and “Configuration” sections of a README usually mention keys. The “free”, “open-source” and “local” at the top of a README, though, are often used more broadly than the code bears out. Whether “local” covers every core feature or only some of them is more accurately checked with steps 1–3. When the README and the code say different things, the code is what actually happens.
If you decide to put in a key
- The bill goes to the key's owner. It is charged by use to whoever put the key in, not to whoever wrote the tool. Most providers bill a chat subscription and API use separately, so API use with a key can be charged even if you have a subscription.
- An agent-style tool calls the model many times per request. Planning, using a tool and reading the result back are each a call, so the bill grows faster than the number of questions you send.
- Make a separate key for each tool. You can then see each tool's use in the provider's console, and delete only that key when you stop using it. If the console lets you set a usage limit or an alert, set it at the start.
- Do not commit the
.envfile that holds the key. Check that the repository's.gitignorelists.env, and add it if it does not.
Seeing it all at once here
Change github.com in a repository's address to whatitcalls.com, and this site shows the result of steps 1–3 checked in the code: which feature calls which provider, whether a key is needed, and whether there is a setting to go local, each with line numbers pinned to the commit. This site, too, only reads code and does not run it, so whatever it could not read stays “Needs review” (see Why “Needs review” remains).