Skip to content
@ThinkWatchProject

ThinkWatch

AI API and MCP gateways: ThinkWatch Enterprise for organizations, ThinkWatch Lite for individual developers, and ThinkWatch Core, the gateway engine they share.

ThinkWatch

AI API and MCP gateways

Website · Documentation · Security

ThinkWatch places a gateway between AI clients and model providers, so that every request is routed, inspected and recorded in one place. It comes in three products that share one engine.

ThinkWatch Lite

A desktop app that runs a local gateway for Claude Code, Codex and other AI clients. Clients connect once; changing upstreams or models afterwards needs no change to the client.

  • Connect once, switch freely. Seven clients are set up in one step, with the change previewed and the original file backed up.
  • Protection against relays. A relay sees every request and can rewrite every answer. API keys can be replaced before a request leaves the machine, and a tool call slipped into an answer that downloads and runs code or sends out credentials can be cut off before the client runs it. MCP servers, skills, hooks and client configuration are scanned for hidden characters and prompt injection.
  • Every request traceable. Each request records the rule it matched, every failover attempt and its cost, and can be replayed against another upstream.
  • Honest cost. Estimates are marked as estimates, and unpriced requests are counted separately rather than as zero.

Runs on macOS, Windows and Linux; MIT licensed. Download · Source code

brew install --cask thinkwatchproject/tap/thinkwatch-lite
The ThinkWatch Lite overview page: tokens, cost and requests for the last seven days compared with the seven days before, a trend chart by model with periods of failures marked, and usage by model

ThinkWatch Enterprise

A self-hosted AI API and MCP gateway for organizations, with a web console. It is the single entry point for a company's model requests and MCP tool calls.

  • Access control. Single sign-on through any OIDC provider, role-based access and virtual API keys with their own scopes and expiry.
  • Per-user MCP identity. Upstream MCP servers receive the calling user's own token instead of a shared service account.
  • Limits and budgets. Request and token limits and spending budgets per user, API key or role; rate limits cover MCP tool calls as well.
  • Audit and cost. Every request and tool call is logged, with usage and cost analytics.

Deployed with Docker Compose or Kubernetes; Business Source License 1.1. Quick start · Source code

ThinkWatch Core

The MIT-licensed gateway engine: Rust crates and the twcore binary. It runs inside ThinkWatch Lite, or on its own as a gateway on a Linux server that Lite manages remotely over an encrypted channel. ThinkWatch Enterprise builds on four of its crates.

curl -fsSL https://raw.githubusercontent.com/ThinkWatchProject/ThinkWatch-Core/main/scripts/install.sh | sudo sh

Running core on a server · Source code

Choosing a product

Need Product
One developer's AI clients: switching, security, request records Lite
A gateway on a Linux server, managed from the desktop Core on the server, managed from Lite
AI and MCP access for a team: SSO, permissions, audit, budgets Enterprise

Lite and Core are MIT. Enterprise is free for non-production use and for production use below the monthly thresholds in LICENSING.md; thinkwat.ch/license covers commercial licenses.

Pinned Loading

  1. ThinkWatch ThinkWatch Public

    Self-hosted AI API and MCP gateway for organizations: SSO and RBAC, per-user identity for MCP tool calls, PII redaction and tool-call guards, rate limits, budgets, cost accounting and audit logs.

    Rust 815 22

Repositories

Showing 6 of 6 repositories
  • homebrew-tap Public

    Install ThinkWatch Lite, the local gateway for Claude Code, Codex and other AI clients, with one brew command. macOS 12 or later on Apple silicon.

    ThinkWatchProject/homebrew-tap's past year of commit activity
    Ruby 1 MIT 0 0 0 Updated Oct 1, 2026
  • ThinkWatch-Lite Public

    Local gateway for Claude Code, Codex and other AI clients on macOS, Windows and Linux: switch upstreams without touching clients, keep API keys from relays, cut off malicious tool calls, trace every request.

    ThinkWatchProject/ThinkWatch-Lite's past year of commit activity
    TypeScript 299 MIT 3 0 0 Updated Oct 1, 2026
  • thinkwatch.github.io Public

    Source of thinkwat.ch, the official ThinkWatch website: product pages, documentation, changelog and licensing for ThinkWatch Enterprise, ThinkWatch Lite and ThinkWatch Core, in English and Simplified Chinese.

    ThinkWatchProject/thinkwatch.github.io's past year of commit activity
    Astro 1 0 0 0 Updated Oct 1, 2026
  • ThinkWatch-Core Public

    Gateway engine for Claude Code, Codex and other AI clients, inside ThinkWatch Lite or on a Linux server: credential redaction, tool-call inspection, rule-based routing, per-request cost. Rust, MIT.

    ThinkWatchProject/ThinkWatch-Core's past year of commit activity
    Rust 1 MIT 0 0 0 Updated Oct 1, 2026
  • .github Public

    Organization profile for ThinkWatch, AI API and MCP gateways: Lite for individual developers, Enterprise for organizations, and the Core engine they share.

    ThinkWatchProject/.github's past year of commit activity
    1 0 0 0 Updated Oct 1, 2026
  • ThinkWatch Public

    Self-hosted AI API and MCP gateway for organizations: SSO and RBAC, per-user identity for MCP tool calls, PII redaction and tool-call guards, rate limits, budgets, cost accounting and audit logs.

    ThinkWatchProject/ThinkWatch's past year of commit activity
    Rust 815 22 0 0 Updated Sep 30, 2026

People

This organization has no public members. You must be a member to see who’s a part of this organization.