Bolt · Agent Gateway
Your coding agents, without the secret leak.
Engineers already run Claude Code, Codex, and Gemini against real repos and real systems, and every prompt can carry keys, tokens, and customer data straight into a vendor cloud. Bolt's Agent Gateway masks those values on the device before the request leaves, then restores them locally so the work still runs. The category everyone else builds as a network appliance, Bolt builds where the secrets actually live: the client.
How it works
Masked out-bound. Restored in place.
Bolt sits on the wire, on the device
Secrets and PII are masked out-bound
Real values are restored locally
The other half
An endpoint your whole company can point at.
The relay above governs agent CLIs that will not accept a custom base URL. Everything else, IDE assistants, internal apps, scripts, and agent frameworks, can simply point at Bolt as their AI endpoint. Same masking, same audit trail, same policy, on infrastructure you own.
Your own AI endpoint, on your own server
SSO instead of API keys
The models their role permits
Governed the same either way
Scope we state plainly: the endpoint accepts messages, a model selection, and streaming. Function calling, sampling parameters such as temperature, multiple completions per request, and embeddings are not implemented yet. If your client depends on one of those, tell us and we will test against it before you commit to anything.
Why it's different
An AI gateway that lives on the client, not in front of it.
It governs the coding-agent wire path
Layered, not bypass-by-default
No new place for your data to sit
Fits how engineers already work
Where it is today
Shipping honestly, expanding fast.
The Agent Gateway is live today for Claude (text requests, with masked secrets and a real-network path proven end to end). Streaming, full tool-call round-trips, automatic provisioning, an admin policy UI, and coverage for Codex and Gemini are on the near-term roadmap, with the redirect mechanism for each already mapped. We tell you exactly what is enabled in the build you run, with no aspirational claims. Structured secrets and PII are masked out of the box; free-text name and entity detection is an optional on-device model you enable per compliance profile.
One honest limitation we publish rather than hide: an unmanaged admin on their own machine can defeat any on-device control. The Gateway is strongest paired with managed policy and the OS network filter: layers, not a single lock.
Point your agents at the sensitive stuff, safely.
See how the Agent Gateway fits with Bolt's boundary masking, governed egress, and tamper-evident audit.