Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/content/docs-lite/en/overview.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ ThinkWatch Lite is a local gateway for Claude Code, Codex and other AI clients,
## Highlights

- **Connect once, switch freely.** Seven clients are pointed at the gateway in one step, with the change previewed and the original backed up; Cursor, Continue and Antigravity CLI come with instructions.
- **Keys replaced before sending.** Outbound redaction, tool-call inspection, hidden-character detection, a content filter and an output limit apply to every request, each in Off, Observe or Enforce.
- **Protection against relays.** A relay sees every request and can rewrite every answer. Outbound redaction can replace credentials before a request leaves, and tool-call inspection can cut off an answer that carries a dangerous tool call, such as download-and-run or sending out credential files, before the client runs it. Hidden-character detection, a content filter and an output limit complete the five protections, each in Off, Observe or Enforce.
- **MCP servers, skills and hooks, scanned.** The MCP servers of eight clients side by side, and a scan of client configuration for hidden characters, prompt injection, dangerous commands and overly broad permissions.
- **Every request traceable.** The matched rule, each attempt, any format conversion and the cost, with replay against another upstream.
- **Routing and failover.** Rules by model, tools, images and more; groups that fail over before the answer begins and keep each session on one upstream.
Expand Down
2 changes: 1 addition & 1 deletion src/content/docs-lite/zh-CN/overview.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ ThinkWatch Lite 是 Claude Code、Codex 等 AI 客户端的本地网关,支持
## 要点

- **一次接入,随时切换。** 七款客户端可一键指向网关,写入前预览改动并备份原文件;Cursor、Continue 与 Antigravity CLI 提供配置说明。
- **发出前替换密钥。** 出站脱敏、工具调用审查、隐藏字符检测、内容过滤与输出长度限制作用于每个请求,每项可设为关闭、观察或拦截。
- **防范中转站。** 中转站能看到每个请求,也能改写每一次回答。出站脱敏可在请求发出前替换其中的凭据;回答中出现下载即执行、外发凭据文件之类的危险工具调用时,工具调用审查可在客户端执行前切断回答。另有隐藏字符检测、内容过滤与输出长度限制,共五项防护,每项可设为关闭、观察或拦截。
- **扫描 MCP、技能与钩子。** 八款客户端的 MCP 服务器并列显示,并扫描客户端配置中的隐藏字符、提示注入、危险命令与过宽权限。
- **每个请求都可追溯。** 命中的规则、每一次尝试、格式转换与费用都有记录,也可以重放到另一个上游对比。
- **路由与故障转移。** 按模型、工具、图片等条件分流;回答开始前上游出错时换用下一个,同一会话固定使用同一上游。
Expand Down
16 changes: 8 additions & 8 deletions src/i18n/pages/home.ts
Original file line number Diff line number Diff line change
Expand Up @@ -81,11 +81,11 @@ export const homeCopy = {
title: "A local gateway for Claude Code, Codex and other AI clients",
points: [
{ t: "Connect once, switch freely", b: "Each client is pointed at the gateway once; upstreams and models then change in the gateway, with no client to reconfigure or restart." },
{ t: "Keys replaced before sending", b: "Outbound redaction can replace credentials before a request leaves, tool-call inspection can cut off dangerous commands, and MCP servers, skills and hooks are scanned." },
{ t: "Protection against relays", b: "Credentials can be replaced before a request leaves, so a relay never holds them, and dangerous tool calls a relay slips into an answer can be cut off before the client runs them. MCP servers, skills and hooks are scanned as well." },
{ t: "Every request traceable", b: "The matched rule, each upstream attempt and the cost of every request, with replay against another upstream." },
{ t: "Costs stated as they are", b: "Estimated amounts are marked, and requests without a price are counted separately rather than as zero." },
],
pills: ["Available", "macOS · Apple silicon", "Windows · x64 · ARM64", "Linux · x86_64 · aarch64", "MIT"],
pills: ["Available", "macOS (Apple silicon)", "Windows (x64, ARM64)", "Linux (x86_64, aarch64)", "MIT open source"],
shotAlt:
"The Overview page for the last 7 days: 83.1M tokens, $68.11 in cost including $0.441 estimated and 13 unpriced requests, and 1,339 requests of which 11 failed, each compared with the prior 7 days; a token trend stacked by model with the periods that had failures marked; and the models ranked by tokens",
cta: "Explore ThinkWatch Lite",
Expand Down Expand Up @@ -114,13 +114,13 @@ export const homeCopy = {
lite: {
runsAs: "Desktop app in the macOS menu bar, the Windows notification area or the Linux system tray",
builtFor: "Individual developers",
status: "Available · macOS on Apple silicon, Homebrew or disk image · Windows on x64 or ARM64, installer · Linux on x86_64 or aarch64, AppImage",
status: "Available for macOS on Apple silicon (Homebrew or disk image), Windows on x64 or ARM64 (installer) and Linux on x86_64 or aarch64 (AppImage)",
license: "MIT",
},
core: {
runsAs: "Rust crates and the twcore binary, inside ThinkWatch Lite or as a systemd service on a Linux server",
builtFor: "Developers who build on the engine or run the gateway on a server",
status: "Released · prebuilt binaries for macOS, Windows and Linux · one-command install on Linux servers",
status: "Released, with prebuilt binaries for macOS, Windows and Linux and a one-command install for Linux servers",
license: "MIT",
},
link: "Full licensing details",
Expand Down Expand Up @@ -205,11 +205,11 @@ export const homeCopy = {
title: "Claude Code、Codex 等 AI 客户端的本地网关",
points: [
{ t: "一次接入,随时切换", b: "客户端只需接入一次,此后在网关中更换上游与模型,客户端无需改配置或重启。" },
{ t: "发出前替换密钥", b: "出站脱敏可在请求发出前替换其中的凭据,工具调用审查可切断危险命令,MCP 服务器、技能与钩子也会被扫描。" },
{ t: "防范中转站", b: "请求发出前可替换其中的凭据,中转站拿不到原值;中转站在回答中塞入的危险工具调用,可在客户端执行前切断。MCP 服务器、技能与钩子也会被扫描。" },
{ t: "每个请求都可追溯", b: "每个请求命中的规则、尝试过的上游与费用都有记录,也可以重放到另一个上游对比。" },
{ t: "费用如实计算", b: "估算的金额单独标注,无法计价的请求单独计数,不按零计入。" },
],
pills: ["已发布", "macOS · Apple silicon", "Windows · x64 · ARM64", "Linux · x86_64 · aarch64", "MIT"],
pills: ["已发布", "macOS(Apple silicon)", "Windows(x64、ARM64)", "Linux(x86_64、aarch64)", "MIT 开源"],
shotAlt:
"概览页(最近 7 天):token 83.1M、费用 $68.11(含估算 $0.441,13 条无法计价)、请求 1,339 次(失败 11 次),均与上一个 7 天对比;按模型分层的 token 趋势,并标出存在失败的时段;以及按 token 排序的模型列表",
cta: "了解 ThinkWatch Lite",
Expand Down Expand Up @@ -238,13 +238,13 @@ export const homeCopy = {
lite: {
runsAs: "桌面应用,常驻 macOS 菜单栏、Windows 通知区域或 Linux 系统托盘",
builtFor: "个人开发者",
status: "已发布 · macOS(Apple silicon):Homebrew 或磁盘映像 · Windows(x64、ARM64):安装程序 · Linux(x86_64、aarch64):AppImage",
status: "已发布:macOS(Apple silicon)用 Homebrew 或磁盘映像安装,Windows(x64、ARM64)用安装程序,Linux(x86_64、aarch64)用 AppImage",
license: "MIT",
},
core: {
runsAs: "Rust crate 与 twcore 二进制,随 ThinkWatch Lite 运行,或作为 systemd 服务运行在 Linux 服务器上",
builtFor: "基于该引擎开发,或在服务器上运行网关的开发者",
status: "已发布 · 提供 macOS、Windows 与 Linux 的预编译二进制 · Linux 服务器可一条命令安装",
status: "已发布,提供 macOS、Windows 与 Linux 的预编译二进制,Linux 服务器可一条命令安装",
license: "MIT",
},
link: "查看完整许可证说明",
Expand Down
20 changes: 10 additions & 10 deletions src/i18n/pages/lite.ts
Original file line number Diff line number Diff line change
Expand Up @@ -22,13 +22,13 @@ export const liteCopy = {
meta: {
title: "ThinkWatch Lite — Local gateway for Claude Code, Codex and other AI clients",
description:
"A local gateway for Claude Code, Codex and other AI clients on macOS, Windows and Linux. Connect each client once and switch upstreams freely, replace API keys before a request leaves, stop dangerous tool calls, and see the cost and route of every request. MIT License.",
"A local gateway for Claude Code, Codex and other AI clients on macOS, Windows and Linux. Connect each client once and switch upstreams freely, replace API keys before a request leaves, cut off dangerous tool calls a relay slips into an answer, and see the cost and route of every request. MIT License.",
},
hero: {
eyebrow: "ThinkWatch Lite · For individual developers",
titleA: "A local gateway for ",
titleHighlight: "Claude Code, Codex and other AI clients",
sub: "Each client is connected once; after that, upstreams and models change without touching its configuration. Every request is recorded with its cost and route, and the API keys in it can be replaced before it leaves the machine. For macOS, Windows and Linux, under the MIT License.",
sub: "Each client is connected once; after that, upstreams and models change without touching its configuration. Every request is recorded with its cost and route; the API keys in it can be replaced before it leaves the machine, and dangerous tool calls a relay slips into an answer can be cut off before the client runs them. For macOS, Windows and Linux, under the MIT License.",
ctaSecondary: "Other platforms and installation methods",
shotAlt: overviewAlt.en,
},
Expand All @@ -55,8 +55,8 @@ export const liteCopy = {
},
{
id: "security",
title: "Keys replaced before sending, dangerous commands stopped",
body: "Outbound redaction swaps API keys, private keys, JWTs and connection-string passwords for placeholders before a request leaves and restores them in the response, so a relay never sees the real values. Tool-call inspection cuts off download-and-run commands and similar calls before the client can run them, and hidden characters and prompt injection can be refused. The five protections start in Observe, recording without changing anything, and each switches to Enforce on its own.",
title: "Protection against relays: keys replaced, malicious tool calls cut off",
body: "A relay sees every request in full and can rewrite every answer. Outbound redaction swaps API keys, private keys, JWTs and connection-string passwords for placeholders before a request leaves and restores them in the response, so the relay never holds the real values. When an answer carries a tool call that downloads and runs code, sends out environment variables or credential files, reads private keys or installs a startup item or scheduled job, tool-call inspection cuts the answer off before the client can run it; hidden characters and prompt injection can be refused as well. The five protections start in Observe, recording without changing anything, and each switches to Enforce on its own.",
alt: "The Security page log: credentials replaced before a request left, one of them matched by a custom rule; a download-and-run tool call cut off; and hidden characters, a delete command and an injected instruction recorded, each with the key, client, model and upstream of its request",
},
{
Expand Down Expand Up @@ -145,7 +145,7 @@ export const liteCopy = {
},
link: {
title: "Control channel",
lines: ["Unix socket · macOS, Linux", "Loopback port · Windows", "TCP port · remote core", "Encrypted handshake on each"],
lines: ["macOS and Linux: Unix socket", "Windows: loopback port", "Remote core: TCP port", "Every connection: encrypted handshake"],
},
core: {
title: "ThinkWatch Core",
Expand Down Expand Up @@ -200,13 +200,13 @@ export const liteCopy = {
meta: {
title: "ThinkWatch Lite — Claude Code、Codex 等 AI 客户端的本地网关",
description:
"Claude Code、Codex 等 AI 客户端的本地网关,支持 macOS、Windows 与 Linux。客户端接入一次即可随时切换上游,请求发出前可替换其中的 API 密钥、切断危险的工具调用,每个请求的费用与去向都有记录。MIT 开源。",
"Claude Code、Codex 等 AI 客户端的本地网关,支持 macOS、Windows 与 Linux。客户端接入一次即可随时切换上游,请求发出前可替换其中的 API 密钥,中转站塞入的危险工具调用可在执行前切断,每个请求的费用与去向都有记录。MIT 开源。",
},
hero: {
eyebrow: "ThinkWatch Lite · 面向个人开发者",
titleA: "Claude Code、Codex 等 AI 客户端的",
titleHighlight: "本地网关",
sub: "客户端只需接入一次,此后更换上游或模型无需改动客户端配置。每个请求的费用与去向都有记录,发出前可替换其中的 API 密钥。支持 macOS、Windows 与 Linux,MIT 开源。",
sub: "客户端只需接入一次,此后更换上游或模型无需改动客户端配置。每个请求的费用与去向都有记录;发出前可替换其中的 API 密钥,中转站在回答中塞入的危险工具调用也可以在客户端执行前拦下。支持 macOS、Windows 与 Linux,MIT 开源。",
ctaSecondary: "其他平台与安装方式",
shotAlt: overviewAlt["zh-CN"],
},
Expand All @@ -233,8 +233,8 @@ export const liteCopy = {
},
{
id: "security",
title: "发出前替换密钥,拦下危险命令",
body: "出站脱敏在请求发出前把 API 密钥、私钥、JWT 与连接串口令换成占位符,并在响应中还原,中转服务看不到原值。工具调用审查在客户端执行之前切断下载即执行等危险命令,隐藏字符与提示注入也可以直接拒绝。五项防护出厂只记录、不改动请求,逐项切换到拦截即可生效。",
title: "防范中转站:替换密钥,拦截恶意工具调用",
body: "中转站能看到请求的全部内容,也能改写每一次回答。出站脱敏在请求发出前把 API 密钥、私钥、JWT 与连接串口令换成占位符,并在响应中还原,中转站拿不到原值。回答中若出现下载即执行、外发环境变量或凭据文件、读取私钥、写入开机启动项或定时任务之类的工具调用,工具调用审查会在客户端执行之前切断回答;隐藏字符与提示注入也可以直接拒绝。五项防护出厂只记录、不改动请求,逐项切换到拦截即可生效。",
alt: "安全页日志:请求发出前替换的凭据(其中一条由自定义规则命中)、被切断的下载即执行工具调用,以及记录在案的隐藏字符、删除命令与注入指令,每条都注明所属请求的密钥、客户端、模型与上游",
},
{
Expand Down Expand Up @@ -323,7 +323,7 @@ export const liteCopy = {
},
link: {
title: "控制通道",
lines: ["unix socket · macOS、Linux", "回环端口 · Windows", "TCP 端口 · 远程 core", "均经加密握手"],
lines: ["macOS、Linux:unix socket", "Windows:本机回环端口", "远程 core:TCP 端口", "每条连接都经加密握手"],
},
core: {
title: "ThinkWatch Core",
Expand Down
Loading