A local gateway for Claude Code, Codex and other AI clients, on macOS, Windows and Linux. Each client is connected once; after that, upstreams and models change without touching its configuration. Every request is recorded with its cost and route; the API keys in it can be replaced before it leaves the machine, and dangerous tool calls a relay slips into an answer can be cut off before the client runs them.
- Connect once, switch freely. Claude Code, Claude Desktop, Codex, opencode, Pi, oh-my-pi, Grok Build, Qwen Code, Hermes Agent, Zed, Aider and DeepSeek Harness are pointed at the gateway in one step, with the change previewed, the original file backed up and a restore always available; Cursor, Continue and Antigravity CLI come with instructions. Switching upstreams then happens in the gateway alone.
- Protection against relays. A relay sees every request in full and can rewrite every answer. Outbound redaction swaps API keys, private keys, JWTs, connection-string passwords, Chinese resident ID numbers and bank card numbers for placeholders before a request leaves, so the relay never holds the real values. When an answer carries a tool call that downloads and runs code, sends out environment variables or credential files, reads private keys or installs a startup item or scheduled job, tool-call inspection cuts the answer off before the client can run it. Hidden characters and prompt injection can be refused as well. The protections start in Observe and switch to Enforce one by one.
- Upstream check-up. Each upstream is compared with the others serving the same model: answers naming a different model, reported input well above or below theirs and low prompt-cache reads are marked, with sample sizes.
- MCP servers, skills and hooks, scanned. The MCP servers of thirteen clients side by side, with third-party servers marked, and a scan of client configuration, skills, hooks and project instructions for hidden characters, prompt injection, dangerous commands and overly broad permissions.
- Every request traceable. The rule a request matched, each upstream it tried, any conversion between API formats and how its cost was calculated; a finished request can be replayed against another upstream and compared side by side. The whole history can be searched, including the text of requests and answers.
- Routing and failover. Rules by model, tools, images, extended thinking and more. When an upstream fails before the answer begins the next one takes over, and each session stays on one upstream so its prompt cache keeps hitting. Auxiliary requests such as title generation can be answered locally.
- Any upstream, any API format. API keys, Amazon Bedrock, ChatGPT and Z.ai accounts, relays such as OpenRouter and local models, with conversion between the Anthropic, OpenAI and Gemini APIs.
- Costs stated as they are. Estimated amounts are marked and requests without a price are counted separately instead of as zero.
- Remote core. The gateway can also run on a Linux server; the app connects to it over an encrypted control channel.
| Platform | Install |
|---|---|
| macOS 12 or later, Apple silicon | brew install --cask thinkwatchproject/tap/thinkwatch-lite, or ThinkWatch-Lite-<version>-arm64.dmg |
| Windows 10 21H2 or later, x64 | ThinkWatch-Lite-<version>-x64-setup.exe |
| Windows 10 21H2 or later, ARM64 | ThinkWatch-Lite-<version>-arm64-setup.exe |
| Linux, x86_64 or aarch64 | curl -fsSL https://github.com/ThinkWatchProject/ThinkWatch-Lite/releases/latest/download/install.sh | sh, or ThinkWatch-Lite-<version>-<arch>.AppImage |
The gateway, ThinkWatch Core, ships inside the app. The app is not signed by Apple or Microsoft, so the first launch needs one extra step; Install and update covers it, along with how updates arrive. The interface is in English and Simplified Chinese, and the app updates itself (a Homebrew installation updates through Homebrew).
- Features: every page, in detail
- Install and update
- Connecting to a remote core and server deployment
- Import links, for relays and vendors
- Architecture
pnpm install
bash src-tauri/scripts/fetch-core.sh
pnpm tauri devfetch-core.sh downloads the twcore release that Cargo.lock pins into
src-tauri/resources/. See CONTRIBUTING.md for the layout
of the repository and the checks to run before opening a pull request.
MIT. See LICENSE.