Website · Documentation · Security
ThinkWatch places a gateway between AI clients and model providers, so that every request is routed, inspected and recorded in one place. It comes in three products that share one engine.
A desktop app that runs a local gateway for Claude Code, Codex and other AI clients. Clients connect once; changing upstreams or models afterwards needs no change to the client.
- Connect once, switch freely. Seven clients are set up in one step, with the change previewed and the original file backed up.
- Protection against relays. A relay sees every request and can rewrite every answer. API keys can be replaced before a request leaves the machine, and a tool call slipped into an answer that downloads and runs code or sends out credentials can be cut off before the client runs it. MCP servers, skills, hooks and client configuration are scanned for hidden characters and prompt injection.
- Every request traceable. Each request records the rule it matched, every failover attempt and its cost, and can be replayed against another upstream.
- Honest cost. Estimates are marked as estimates, and unpriced requests are counted separately rather than as zero.
Runs on macOS, Windows and Linux; MIT licensed. Download · Source code
brew install --cask thinkwatchproject/tap/thinkwatch-lite
A self-hosted AI API and MCP gateway for organizations, with a web console. It is the single entry point for a company's model requests and MCP tool calls.
- Access control. Single sign-on through any OIDC provider, role-based access and virtual API keys with their own scopes and expiry.
- Per-user MCP identity. Upstream MCP servers receive the calling user's own token instead of a shared service account.
- Limits and budgets. Request and token limits and spending budgets per user, API key or role; rate limits cover MCP tool calls as well.
- Audit and cost. Every request and tool call is logged, with usage and cost analytics.
Deployed with Docker Compose or Kubernetes; Business Source License 1.1. Quick start · Source code
The MIT-licensed gateway engine: Rust crates and the twcore binary. It runs
inside ThinkWatch Lite, or on its own as a gateway on a Linux server that Lite
manages remotely over an encrypted channel. ThinkWatch Enterprise builds on
four of its crates.
curl -fsSL https://raw.githubusercontent.com/ThinkWatchProject/ThinkWatch-Core/main/scripts/install.sh | sudo shRunning core on a server · Source code
| Need | Product |
|---|---|
| One developer's AI clients: switching, security, request records | Lite |
| A gateway on a Linux server, managed from the desktop | Core on the server, managed from Lite |
| AI and MCP access for a team: SSO, permissions, audit, budgets | Enterprise |
Lite and Core are MIT. Enterprise is free for non-production use and for production use below the monthly thresholds in LICENSING.md; thinkwat.ch/license covers commercial licenses.