Coding agents can read a repository, inspect configuration, trace errors, and propose changes across an entire codebase. That context is what makes them useful. It is also exactly what teams hesitate to send to an AI service they cannot verify.
Private AI Proxy puts a verification gate on your machine. Before it forwards a prompt, it checks the AI service's hardware attestation, verifies the service against the selected trust policy, and binds the TLS connection to the attested key. If that proof is unavailable or fails, the local API refuses the request.
The result is a familiar coding-agent workflow with a concrete security rule: prompts move only after the remote service proves the identity and channel that Private AI Proxy expects.

Verify before forwarding
Private AI Proxy runs a machine-local API between your coding agents and a compatible Attested Confidential Inference (ACI) service.
When protection starts, the proxy fetches fresh attestation evidence, checks the workload identity and configured trust policy, extracts the attested TLS key, and pins the remote connection to that key. A verification failure, network outage, service restart, or TLS-key mismatch pauses forwarding. Connected agents stay pointed at the local API and resume once the service verifies again.
This fail-closed behavior matters because a silent fallback would defeat the privacy boundary. Private AI Proxy keeps the boundary explicit: the verified route is available, or the request stops on your machine.

Connect the agents you already use
Each supported agent has a separate Connect switch. Private AI Proxy gives that agent a revocable local token and an API configuration generated from the verified model catalog. Your provider credential stays with the proxy instead of being copied into each agent's configuration.
The current release supports:
- Claude Code
- Codex
- DeepSeek Harness
- OpenCode
- Pi
- Oh My Pi
- Hermes Agent
- OpenClaw
Private AI Proxy 0.3.0 adds DeepSeek Harness support for new web, desktop, headless, and ACP sessions. Its own web search is disabled while connected so search queries do not bypass the proxy. Agent-specific restart and session requirements are shown in the app.
Disconnecting revokes the local token and restores the configuration that Private AI Proxy took over. User edits made outside the app are preserved.

A local API for the rest of your tools
Private AI Proxy also exposes a loopback endpoint for software that can call OpenAI- or Anthropic-compatible APIs. The implemented surfaces cover OpenAI Responses and Chat Completions, plus Anthropic Messages. Each client uses a local key rather than the provider credential.
That gives developers one verified path for supported coding agents, scripts, editors, and other local tools. The proxy handles service verification, model admission, channel binding, and forwarding in one place.

A signed receipt for each forwarded response
Attestation proves which service Private AI Proxy connected to. Signed receipts give you evidence for individual requests.
As a response streams back to the agent, the proxy computes the request and response digests. It then fetches the signed receipt, verifies the cited session and cryptographic bindings, and stores the verdict with the local usage record. The Usage view shows the agent, model, token counts, estimated cost, proof status, receipt identifier, and raw receipt details. Prompt and response content are excluded from local usage history.
Receipt auditing happens after delivery, so a later audit failure cannot retract output the agent has already received. The proof records the verified request path and digests; it does not judge whether the model's answer is correct.

Use Phala, RedPill, or another ACI service
Private AI Proxy includes built-in profiles for Phala and RedPill, with account sign-in or API-key setup. A custom profile can connect to another service that implements the ACI attestation, channel-binding, and receipt contract.
The accepted attested gateway, provider router, and model workloads process plaintext inside their protected execution environments because they perform the inference path. Private AI Proxy verifies those workloads and the channel under the configured policy. The local coding agent also sees the context it sends by design.
The project is free and Apache-2.0 open source. Provider access and inference usage are configured separately.
Download Private AI Proxy
Private AI Proxy runs on macOS, Windows, and Linux, with packages for arm64 and x64 systems.
- Mac App Store
- GitHub Releases for macOS, Windows, Linux, and standalone CLI packages
- Source code and documentation
Install the macOS desktop app with Homebrew:
brew install --cask dstack-tee/private-ai/private-ai-proxyInstall the CLI with npm:
npm install --global private-ai-proxyPrivate AI Proxy 0.3.0 is available now. Put a hardware-verified gate between your coding agents and cloud AI, while keeping the workflow local and familiar.



