01 · rule, hops
Routing and failover
The matched rule, the upstream that served the request, and each retry or failover along the way.
ThinkWatch routes, inspects, and meters model requests and MCP tool calls. It is available as a self-hosted server for organizations and as a desktop application for individual developers.
Works with the clients and SDKs teams already use
01 · rule, hops
The matched rule, the upstream that served the request, and each retry or failover along the way.
02 · cost
Tokens are priced per model. Usage without a known price is reported as unknown.
03 · redaction, tool calls
Secrets are redacted before requests reach an upstream, and high-risk tool calls are flagged.
Bracketed values are illustrative.
ThinkWatch Lite · For individual developers
Each client is pointed at the gateway once; upstreams and models then change in the gateway, with no client to reconfigure or restart.
Credentials can be replaced before a request leaves, so a relay never holds them, and dangerous tool calls a relay slips into an answer can be cut off before the client runs them. MCP servers, skills and hooks are scanned as well.
The matched rule, each upstream attempt and the cost of every request, with replay against another upstream.
Estimated amounts are marked, and requests without a price are counted separately rather than as zero.
ThinkWatch Enterprise · For organizations
Authentication, authorization, rate limiting, audit logging, and cost accounting for every model request, tool call, and token.
OpenAI, Anthropic, Gemini, Azure OpenAI, and Bedrock behind one endpoint, with scoped virtual keys.
Per-user OAuth and tokens, tool-level RBAC, and an audit log for every call.
Five roles and support for any OIDC provider.
Sliding-window request and token limits and spending budgets per user, API key or role.
Inside a ThinkWatch request
Console preview
Sample dataPer-user identity for MCP
Upstream services receive the calling user's identity instead of a shared service account.
Each MCP call carries the calling user's OAuth token or personal access token, so services such as GitHub, Linear, and Notion can attribute each action to the user on whose behalf it was performed.
ThinkWatch Enterprise and ThinkWatch Lite share ThinkWatch Core, MIT-licensed Rust crates and the twcore gateway binary. Lite runs the complete engine; Enterprise uses its format-conversion, guard and circuit-breaker crates. twcore also runs on its own on a Linux server, managed from ThinkWatch Lite.
Install twcore on a Linux server
$ curl -fsSL https://raw.githubusercontent.com/ThinkWatchProject/ThinkWatch-Core/main/scripts/install.sh | sudo sh