ThinkWatch logo

ThinkWatch

Free

Enterprise AI bastion host for secure AI API and MCP access, with unified proxying, RBAC, audit logs, rate limiting, and cost tracking across OpenAI, Anthropic, Gemini, and self-hosted LLMs.

CybersecurityFreeFree tier
#Rust
Inputs: textOutputs: text
Type
Open Source

About ThinkWatch

ThinkWatch is the enterprise-grade secure gateway for all AI traffic — API calls and MCP tool calls alike. It solves the governance gap created by proliferating AI agents by providing a single control plane for authentication, authorization, rate limiting, routing, and observability. Deploy one Rust binary backed by PostgreSQL, Redis, and ClickHouse. Drop-in compatible with Claude Code, Cursor, Continue, Cline, and standard SDKs (OpenAI, Anthropic, LangChain, LlamaIndex). Features include multi-format proxy (OpenAI, Anthropic, Bedrock, Gemini), per-model routing with health-aware failover, virtual API keys, RBAC, real-time cost tracking, and full audit trails forwarded to SIEM. Currently in public preview v0.4.0.

Key Features

AI API Gateway supporting multiple formats (OpenAI Chat Completions, Anthropic Messages, OpenAI Responses) on a single port
MCP Gateway with per-user OAuth for tool calls
Virtual API keys scoped to team/project/developer with one-click revoke and grace window rotation
Custom RBAC controlling model and tool access per role and team
Sliding-window rate limiting (RPM/TPM) enforced via Redis per key or user
Per-model routing with auto (latency-cost, balanced, latency-only) and manual modes, plus health-aware failover via circuit breaker
Multi-provider support (OpenAI, Anthropic, Google Gemini, Azure OpenAI, AWS Bedrock, any OpenAI-compatible endpoint) with automatic format conversion
Real-time token metering and cost tracking per request, stamped with upstream_model
Comprehensive audit logs stored in ClickHouse and optionally forwarded to SIEM
Single Rust binary (2 MB distroless image) — no microservice sprawl

Pros & Cons

Pros
  • Single deployment handles both AI API and MCP traffic — simplifies infrastructure
  • Drop-in compatible with existing tools and SDKs — minimal migration effort
  • Real-time observability into every token spent and cost incurred
  • Multi-provider format conversion eliminates vendor lock-in
  • Open source (Rust) with a small, distroless binary for security
  • Comprehensive security features: authentication, RBAC, rate limiting, virtual keys
Cons
  • Requires additional infrastructure (PostgreSQL, Redis, ClickHouse) which adds operational overhead
  • Still in public preview (v0.4.0) — may have breaking changes or incomplete features
  • Configuration of RBAC and routing rules may be complex for large teams

Best For

Centralized governance and access control for multiple AI models across an organizationCost attribution and budget management for AI API usage per team or projectCompliance auditing for AI-assisted code generation and data accessSecure deployment of AI agents with least-privilege access to models and MCP toolsRate limiting and throttling to prevent budget overruns from leaked API keys

Alternatives to ThinkWatch