Bolt · Agent Gateway

Your coding agents, without the secret leak.

Engineers already run Claude Code, Codex, and Gemini against real repos and real systems, and every prompt can carry keys, tokens, and customer data straight into a vendor cloud. Bolt's Agent Gateway masks those values on the device before the request leaves, then restores them locally so the work still runs. The category everyone else builds as a network appliance, Bolt builds where the secrets actually live: the client.

How it works

Masked out-bound. Restored in place.

The agent runs where it always did

Your engineers keep using Claude Code, Codex, or Gemini exactly as before. No new UI to learn, no workflow change.

Bolt sits on the wire, on the device

A local relay redirects the agent's traffic through Bolt before it reaches any vendor cloud, via config and environment. An OS-level network filter watches the same path and reports what it sees, so you can tell whether anything is routing around the relay.

Secrets and PII are masked out-bound

API keys, tokens, customer records, and structured PII are replaced with reversible placeholders before the request leaves the machine. The vendor model never sees the raw value.

Real values are restored locally

When the agent's tool calls come back to run on your machine, Bolt restores the true values in place. The work still works, but the leak never happened.

The other half

An endpoint your whole company can point at.

The relay above governs agent CLIs that will not accept a custom base URL. Everything else, IDE assistants, internal apps, scripts, and agent frameworks, can simply point at Bolt as their AI endpoint. Same masking, same audit trail, same policy, on infrastructure you own.

Your own AI endpoint, on your own server

bolt-api runs where you put it: a laptop in desktop mode, or your own VPC via Docker or Helm. Point any OpenAI-compatible client at it as the base URL. Nothing about the request reaches us, because there is no us in the path.

SSO instead of API keys

People sign in through your identity provider and receive a token. They never hold a provider API key, so there is no key to leak, share, or walk out of the building. Deprovision in your IdP and access stops.

The models their role permits

A list call returns exactly the models that person is allowed to use. The list and the permission are the same answer, produced by the same code, so they cannot drift apart. Ask for a model your role does not allow and you get a clear refusal naming the administrator who can grant it, never a silent switch to a different model.

Governed the same either way

Masking, the egress gate, restoration, and the audit record apply identically whether the response streams or arrives whole. Which encoding a client asks for is not a security boundary.

Scope we state plainly: the endpoint accepts messages, a model selection, and streaming. Function calling, sampling parameters such as temperature, multiple completions per request, and embeddings are not implemented yet. If your client depends on one of those, tell us and we will test against it before you commit to anything.

Why it's different

An AI gateway that lives on the client, not in front of it.

It governs the coding-agent wire path

The whole 'AI gateway' category assumes a network appliance in front of your own apps. Bolt governs the third-party agent's own outbound traffic, client-side, where the secrets actually are.

Layered, not bypass-by-default

Environment and config redirect is the fast path. The OS network filter observes the same traffic, so a path that skips the relay is visible rather than silent. Defense in depth instead of a single hop an engineer can route around unnoticed.

No new place for your data to sit

The masking happens on the device. Bolt operates no cloud that receives your prompts, so the privacy control is not itself a new exfiltration path.

Fits how engineers already work

Bring your own coding agent. Bolt does not replace Claude Code or Codex; it makes them safe to point at sensitive repos and systems.

Where it is today

Shipping honestly, expanding fast.

The Agent Gateway is live today for Claude (text requests, with masked secrets and a real-network path proven end to end). Streaming, full tool-call round-trips, automatic provisioning, an admin policy UI, and coverage for Codex and Gemini are on the near-term roadmap, with the redirect mechanism for each already mapped. We tell you exactly what is enabled in the build you run, with no aspirational claims. Structured secrets and PII are masked out of the box; free-text name and entity detection is an optional on-device model you enable per compliance profile.

One honest limitation we publish rather than hide: an unmanaged admin on their own machine can defeat any on-device control. The Gateway is strongest paired with managed policy and the OS network filter: layers, not a single lock.

Point your agents at the sensitive stuff, safely.

See how the Agent Gateway fits with Bolt's boundary masking, governed egress, and tamper-evident audit.