
Description
Switch relays and Claude Code needs reconfiguring, then Codex needs it again, and the bill at month end never says which model ate the money. Worse, a relay sees every request in full, API keys included. ThinkWatch Lite runs a gateway on your machine so Claude Code, Codex and other clients connect to one local address once, and switching upstreams or models happens in the gateway without touching client configs.
Before a request leaves, API keys, private keys, JWTs, connection-string passwords, ID numbers and bank card numbers are swapped for placeholders, so the relay never holds the real values. If an answer slips in a tool call that downloads and runs code, reads private keys or installs a startup item, it is cut off before the client runs it. Every request is recorded with the rule it matched, each upstream tried and how its cost was calculated, and a finished request can be replayed against another upstream for comparison.
One-step client setup: Claude Code, Claude Desktop, Codex, opencode, Zed, Aider and a dozen more are pointed at the gateway with the change previewed, the original file backed up and a restore always available.
Outbound redaction: API keys, private keys, JWTs and similar secrets become placeholders before the request leaves; each protection starts in observe-only mode and is switched on one at a time.
Tool-call inspection: dangerous tool calls such as download-and-run, exfiltrating environment variables or reading credentials are cut off before the client executes them.
Upstream cross-checks: upstreams serving the same model are compared, and ones that name a different model, report skewed input or show low cache reads are marked in the list.
Routing and failover: rules by model, tools, images or extended thinking; if an upstream fails before the answer starts the next takes over, and each session sticks to one upstream so prompt caching keeps hitting.
Cost and history: estimated amounts are marked, unpriced requests are counted separately instead of as zero, and the full history including request and answer text is searchable.
MCP and skill scanning: see the MCP servers of thirteen clients side by side and scan configs, skills and hooks for hidden characters, prompt injection and overly broad permissions.
Cross-platform with a remote core: desktop apps for macOS, Windows and Linux, and the gateway can also run on a Linux server that the app reaches over an encrypted channel.
Before a request leaves, API keys, private keys, JWTs, connection-string passwords, ID numbers and bank card numbers are swapped for placeholders, so the relay never holds the real values. If an answer slips in a tool call that downloads and runs code, reads private keys or installs a startup item, it is cut off before the client runs it. Every request is recorded with the rule it matched, each upstream tried and how its cost was calculated, and a finished request can be replayed against another upstream for comparison.
Features
One-step client setup: Claude Code, Claude Desktop, Codex, opencode, Zed, Aider and a dozen more are pointed at the gateway with the change previewed, the original file backed up and a restore always available.
Outbound redaction: API keys, private keys, JWTs and similar secrets become placeholders before the request leaves; each protection starts in observe-only mode and is switched on one at a time.
Tool-call inspection: dangerous tool calls such as download-and-run, exfiltrating environment variables or reading credentials are cut off before the client executes them.
Upstream cross-checks: upstreams serving the same model are compared, and ones that name a different model, report skewed input or show low cache reads are marked in the list.
Routing and failover: rules by model, tools, images or extended thinking; if an upstream fails before the answer starts the next takes over, and each session sticks to one upstream so prompt caching keeps hitting.
Cost and history: estimated amounts are marked, unpriced requests are counted separately instead of as zero, and the full history including request and answer text is searchable.
MCP and skill scanning: see the MCP servers of thirteen clients side by side and scan configs, skills and hooks for hidden characters, prompt injection and overly broad permissions.
Cross-platform with a remote core: desktop apps for macOS, Windows and Linux, and the gateway can also run on a Linux server that the app reaches over an encrypted channel.
