ThinkWatch Lite#
ThinkWatch Lite is a local gateway for Claude Code, Codex and other AI clients, on macOS, Windows and Linux. Each client is connected once; after that, upstreams and models change in the gateway without touching the client. Every request is recorded with its cost and route, and the API keys in it can be replaced before it leaves the machine.
It runs on macOS 12 or later on Apple silicon, on Windows 10 21H2 or later on x64 or ARM64 and on Linux on x86_64 or aarch64, is installed with Homebrew, a disk image, the Windows installer or an AppImage, and updates itself.
Highlights#
- Connect once, switch freely. Seven clients are pointed at the gateway in one step, with the change previewed and the original backed up; Cursor, Continue and Antigravity CLI come with instructions.
- Protection against relays. A relay sees every request and can rewrite every answer. Outbound redaction can replace credentials before a request leaves, and tool-call inspection can cut off an answer that carries a dangerous tool call, such as download-and-run or sending out credential files, before the client runs it. Hidden-character detection, a content filter and an output limit complete the five protections, each in Off, Observe or Enforce.
- MCP servers, skills and hooks, scanned. The MCP servers of eight clients side by side, and a scan of client configuration for hidden characters, prompt injection, dangerous commands and overly broad permissions.
- Every request traceable. The matched rule, each attempt, any format conversion and the cost, with replay against another upstream.
- Routing and failover. Rules by model, tools, images and more; groups that fail over before the answer begins and keep each session on one upstream.
- Any upstream. API keys, Amazon Bedrock, ChatGPT and Z.ai accounts, relays and local models, with conversion between the Anthropic, OpenAI and Gemini APIs.
- Costs stated as they are. Estimates marked, unpriced requests counted separately rather than as zero.
Pages#
| Page | Contents |
|---|---|
| Overview | Tokens, cost and requests over a period, trends by model, cache, latency, generation speed and security results |
| Traffic | Every request, or requests grouped into sessions, with the details of each |
| Clients | Pointing clients at the gateway, and restoring them |
| Keys | The gateway keys clients connect with, each with its route and limits |
| Upstreams | Upstreams, outbound proxies and price sheets |
| Routing | Routes, rules and groups, auxiliary requests, and the dry run |
| Security | The security log and the five protections with their rules |
| MCP | MCP servers, skills and hooks in each client, and the configuration scan |
| Settings | Connection, language, appearance, menu bar, notifications, listening, retention, updates and uninstall |
Each page is described in Features.
Further reading#
- Install and update
- Connecting to a remote core: the gateway is ThinkWatch Core, which runs beside the app or on a Linux server.
- Architecture: Lite holds no routing, forwarding or accounting logic; it controls Core over an encrypted control channel.
- Build from source
ThinkWatch Lite is licensed under the MIT License.
01 Features Page by page: usage and cost, traffic, client setup, keys, upstreams, routing, the five protections, MCP, settings, the menu bar and notifications. 02 Install and update Homebrew, a disk image, the Windows installer or the Linux AppImage, the quarantine attribute and SmartScreen, and how updates reach each kind of install. 03 Connecting to a remote core Connect the app to ThinkWatch Core on a server: what the server needs, the steps in the app, what changes while connected, and how the connection is secured. 04 Build from source Run a development build with pnpm tauri dev, or build a macOS bundle, a Windows installer or a Linux AppImage. 05 Architecture A Tauri 2 shell and a React 19 frontend that supervise Core and control it over a unix socket on macOS and Linux, a loopback port on Windows or a TCP port on a server, each with an encrypted handshake. 06 Import links For relays and vendors: links that pre-fill a new upstream in the app, their parameters, what the app checks, and a link builder. 07 Contributing Branches, settled scope, and the checks required before opening a pull request.