Skip to content
ThinkWatch
Start typing to search the docs.
Enterprise 3.0.0 and Lite 2026.10.1 released→

AI gateways for organizations and individual developers

ThinkWatch routes, inspects, and meters model requests and MCP tool calls. It is available as a self-hosted server for organizations and as a desktop application for individual developers.

Works with the clients and SDKs teams already use

  • Claude Code
  • Codex
  • Cursor
  • Continue
  • Cline
  • OpenAI SDK
  • Anthropic SDK
  • Gemini SDK
  • opencode
  • Zed

Visibility into every request

01 · rule, hops

Routing and failover

The matched rule, the upstream that served the request, and each retry or failover along the way.

02 · cost

Cost accounting

Tokens are priced per model. Usage without a known price is reported as unknown.

03 · redaction, tool calls

Outbound data inspection

Secrets are redacted before requests reach an upstream, and high-risk tool calls are flagged.

POST /v1/messages Sample trace
  1. clientClaude Code
  2. rule[rule name] · [policy group]
  3. hop 1[upstream A] · [error status] · retried
  4. hop 2[upstream B] · [ok status] · streamed
  5. costmeasured [amount] · prices as of [date]
  6. redaction[n] secrets replaced before sending
  7. tool call[shell command] · flagged

Bracketed values are illustrative.

ThinkWatch Lite · For individual developers

A local gateway for Claude Code, Codex and other AI clients

Connect once, switch freely

Each client is pointed at the gateway once; upstreams and models then change in the gateway, with no client to reconfigure or restart.

Protection against relays

Credentials can be replaced before a request leaves, so a relay never holds them, and dangerous tool calls a relay slips into an answer can be cut off before the client runs them. MCP servers, skills and hooks are scanned as well.

Every request traceable

The matched rule, each upstream attempt and the cost of every request, with replay against another upstream.

Costs stated as they are

Estimated amounts are marked, and requests without a price are counted separately rather than as zero.

Available macOS (Apple silicon)Windows (x64, ARM64)Linux (x86_64, aarch64)
Explore ThinkWatch Lite
The Overview page for the last 7 days: 83.1M tokens, $68.11 in cost including $0.441 estimated and 13 unpriced requests, and 1,339 requests of which 11 failed, each compared with the prior 7 days; a token trend stacked by model with the periods that had failures marked; and the models ranked by tokens

ThinkWatch Enterprise · For organizations

An AI bastion host for organizations

Authentication, authorization, rate limiting, audit logging, and cost accounting for every model request, tool call, and token.

Explore ThinkWatch

AI API gateway

OpenAI, Anthropic, Gemini, Azure OpenAI, and Bedrock behind one endpoint, with scoped virtual keys.

MCP gateway with per-user identity

Per-user OAuth and tokens, tool-level RBAC, and an audit log for every call.

SSO and RBAC

Five roles and support for any OIDC provider.

Audit logs, rate limits, and budgets

Sliding-window request and token limits and spending budgets per user, API key or role.

Inside a ThinkWatch request

  1. 01 Authenticate Scoped tw- key validated
  2. 02 Authorize Role checked for model and tool
  3. 03 Rate-limit Windows and budgets enforced
  4. 04 Route and convert Provider picked, format converted
  5. 05 Stream and meter Tokens counted as they stream
  6. 06 Audit Logged and forwardable to a SIEM

Console preview

Sample data
Tokens used (MTD)
+12.4%
0
Cost (MTD)
+8.1%
$0.00
Active API keys
+3
0
Requests / min
live
0
›status:200 model:claude-*
live
user
status
  • bob@acme
    gemini-2.0-flash · 2253t
    200
  • carol@acme
    claude-sonnet-4-5 · 2641t
    200
  • dan@acme
    gpt-4o · 3029t
    200
  • eve@acme
    gemini-2.0-flash · 3417t
    200
  • alice@acme
    claude-sonnet-4-5 · 3805t
    200
  • bob@acme
    claude-opus-4-6 · 4193t
    200
  • ci-bot
    claude-haiku-4-5 · 4582t
    200
  • dan@acme
    gpt-4o-mini · 470t
    200
  • eve@acme
    claude-opus-4-6 · 858t
    200
  • alice@acme
    claude-haiku-4-5 · 1246t
    200
  • carol@acme
    gpt-4o-mini · 1634t
    200
  • ci-bot
    claude-opus-4-6 · 2022t
    200
  • dan@acme
    claude-haiku-4-5 · 2410t
    200
  • eve@acme
    gpt-4o-mini · 2798t
    200
Provider health
monitoring
  • OpenAIus-eastHealthyCB:Closed
    412 ms99.8%
  • Anthropicus-westHealthyCB:Closed
    538 ms99.6%
  • Google Geminius-centralHealthyCB:Closed
    297 ms99.9%
  • Azure OpenAIeastus2DegradedCB:HalfOpen
    1240 ms96.2%
  • AWS Bedrockus-east-1HealthyCB:Closed
    624 ms99.4%
Rate limit · sliding window
tw-prod-aH3k · 100 RPM
58 / 100
current bucket
Avg / min
61
Window
30s
Headroom
42

Per-user identity for MCP

Upstream services receive the calling user's identity instead of a shared service account.

Each MCP call carries the calling user's OAuth token or personal access token, so services such as GitHub, Linear, and Notion can attribute each action to the user on whose behalf it was performed.

ThinkWatch Enterprise and ThinkWatch Lite share ThinkWatch Core, MIT-licensed Rust crates and the twcore gateway binary. Lite runs the complete engine; Enterprise uses its format-conversion, guard and circuit-breaker crates. twcore also runs on its own on a Linux server, managed from ThinkWatch Lite.

Install twcore on a Linux server

$ curl -fsSL https://raw.githubusercontent.com/ThinkWatchProject/ThinkWatch-Core/main/scripts/install.sh | sudo sh
Server deployment guide

Compare editions

Full licensing details