Blog

Private AI Proxy: Hardware-Verified Private AI for Your Coding Agents

Sep 30, 20265 min read
Private AI Proxy: Hardware-Verified Private AI for Your Coding Agents

Coding agents can read a repository, inspect configuration, trace errors, and propose changes across an entire codebase. That context is what makes them useful. It is also exactly what teams hesitate to send to an AI service they cannot verify.

Private AI Proxy puts a verification gate on your machine. Before it forwards a prompt, it checks the AI service's hardware attestation, verifies the service against the selected trust policy, and binds the TLS connection to the attested key. If that proof is unavailable or fails, the local API refuses the request.

The result is a familiar coding-agent workflow with a concrete security rule: prompts move only after the remote service proves the identity and channel that Private AI Proxy expects.

Private AI Proxy shows protection status, connected agents, local API details, and recent verified usage in one desktop view.
Private AI Proxy shows protection status, connected agents, local API details, and recent verified usage in one desktop view.

Verify before forwarding

Private AI Proxy runs a machine-local API between your coding agents and a compatible Attested Confidential Inference (ACI) service.

When protection starts, the proxy fetches fresh attestation evidence, checks the workload identity and configured trust policy, extracts the attested TLS key, and pins the remote connection to that key. A verification failure, network outage, service restart, or TLS-key mismatch pauses forwarding. Connected agents stay pointed at the local API and resume once the service verifies again.

This fail-closed behavior matters because a silent fallback would defeat the privacy boundary. Private AI Proxy keeps the boundary explicit: the verified route is available, or the request stops on your machine.

Private AI Proxy verifies the service before enabling protection and forwarding agent traffic.
Private AI Proxy verifies the service before enabling protection and forwarding agent traffic.

Connect the agents you already use

Each supported agent has a separate Connect switch. Private AI Proxy gives that agent a revocable local token and an API configuration generated from the verified model catalog. Your provider credential stays with the proxy instead of being copied into each agent's configuration.

The current release supports:

  • Claude Code
  • Codex
  • DeepSeek Harness
  • OpenCode
  • Pi
  • Oh My Pi
  • Hermes Agent
  • OpenClaw

Private AI Proxy 0.3.0 adds DeepSeek Harness support for new web, desktop, headless, and ACP sessions. Its own web search is disabled while connected so search queries do not bypass the proxy. Agent-specific restart and session requirements are shown in the app.

Disconnecting revokes the local token and restores the configuration that Private AI Proxy took over. User edits made outside the app are preserved.

Connect supported coding agents individually and keep each integration under local control.
Connect supported coding agents individually and keep each integration under local control.

A local API for the rest of your tools

Private AI Proxy also exposes a loopback endpoint for software that can call OpenAI- or Anthropic-compatible APIs. The implemented surfaces cover OpenAI Responses and Chat Completions, plus Anthropic Messages. Each client uses a local key rather than the provider credential.

That gives developers one verified path for supported coding agents, scripts, editors, and other local tools. The proxy handles service verification, model admission, channel binding, and forwarding in one place.

The Local API provides a loopback endpoint and masked local key for compatible tools.
The Local API provides a loopback endpoint and masked local key for compatible tools.

A signed receipt for each forwarded response

Attestation proves which service Private AI Proxy connected to. Signed receipts give you evidence for individual requests.

As a response streams back to the agent, the proxy computes the request and response digests. It then fetches the signed receipt, verifies the cited session and cryptographic bindings, and stores the verdict with the local usage record. The Usage view shows the agent, model, token counts, estimated cost, proof status, receipt identifier, and raw receipt details. Prompt and response content are excluded from local usage history.

Receipt auditing happens after delivery, so a later audit failure cannot retract output the agent has already received. The proof records the verified request path and digests; it does not judge whether the model's answer is correct.

Local usage records show request status, tokens, estimated cost, and signed-receipt verification.
Local usage records show request status, tokens, estimated cost, and signed-receipt verification.

Use Phala, RedPill, or another ACI service

Private AI Proxy includes built-in profiles for Phala and RedPill, with account sign-in or API-key setup. A custom profile can connect to another service that implements the ACI attestation, channel-binding, and receipt contract.

The accepted attested gateway, provider router, and model workloads process plaintext inside their protected execution environments because they perform the inference path. Private AI Proxy verifies those workloads and the channel under the configured policy. The local coding agent also sees the context it sends by design.

The project is free and Apache-2.0 open source. Provider access and inference usage are configured separately.

Download Private AI Proxy

Private AI Proxy runs on macOS, Windows, and Linux, with packages for arm64 and x64 systems.

Install the macOS desktop app with Homebrew:

brew install --cask dstack-tee/private-ai/private-ai-proxy

Install the CLI with npm:

npm install --global private-ai-proxy

Private AI Proxy 0.3.0 is available now. Put a hardware-verified gate between your coding agents and cloud AI, while keeping the workflow local and familiar.

Read Next