{"id":51052457,"url":"https://github.com/joaoeudes7/proxy-privacy","last_synced_at":"2026-06-22T18:30:50.471Z","repository":{"id":365041199,"uuid":"1264461868","full_name":"joaoeudes7/proxy-privacy","owner":"joaoeudes7","description":"OpenAI-compatible privacy proxy for AI agents. Single-binary proxy that injects privacy controls between your AI tools and any OpenAI-compatible API provider.","archived":false,"fork":false,"pushed_at":"2026-06-15T15:02:29.000Z","size":46,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-06-15T17:05:37.916Z","etag":null,"topics":["ai-agents","claude-code","codex-cli","openai","opencode","privacy","privacy-proxy","proxy"],"latest_commit_sha":null,"homepage":"https://github.com/joaoeudes7/proxy-privacy","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/joaoeudes7.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","dco":null,"cla":null},"funding":{"github":"joaoeudes7"}},"created_at":"2026-06-09T22:54:01.000Z","updated_at":"2026-06-15T15:05:50.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/joaoeudes7/proxy-privacy","commit_stats":null,"previous_names":["joaoeudes7/proxy-privacy"],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/joaoeudes7/proxy-privacy","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/joaoeudes7%2Fproxy-privacy","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/joaoeudes7%2Fproxy-privacy/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/joaoeudes7%2Fproxy-privacy/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/joaoeudes7%2Fproxy-privacy/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/joaoeudes7","download_url":"https://codeload.github.com/joaoeudes7/proxy-privacy/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/joaoeudes7%2Fproxy-privacy/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34661702,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-22T02:00:06.391Z","response_time":106,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ai-agents","claude-code","codex-cli","openai","opencode","privacy","privacy-proxy","proxy"],"created_at":"2026-06-22T18:30:46.328Z","updated_at":"2026-06-22T18:30:50.462Z","avatar_url":"https://github.com/joaoeudes7.png","language":"Go","funding_links":["https://github.com/sponsors/joaoeudes7"],"categories":[],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n  \u003cpicture\u003e\n    \u003csource media=\"(prefers-color-scheme: light)\" srcset=\"assets/logo.svg\"\u003e\n    \u003cimg src=\"assets/logo.svg\" width=\"160\" height=\"160\" alt=\"Proxy Privacy Logo\"\u003e\n  \u003c/picture\u003e\n  \u003ch1 align=\"center\"\u003eProxy Privacy\u003c/h1\u003e\n  \u003cp align=\"center\"\u003e\u003cstrong\u003eOpenAI-compatible privacy proxy for AI agents\u003c/strong\u003e\u003c/p\u003e\n  \u003cp align=\"center\"\u003e\n    \u003ca href=\"https://github.com/joaoeudes7/proxy-privacy/actions/workflows/build.yml\"\u003e\u003cimg src=\"https://github.com/joaoeudes7/proxy-privacy/actions/workflows/build.yml/badge.svg\" alt=\"CI\"\u003e\u003c/a\u003e\n    \u003ca href=\"https://github.com/joaoeudes7/proxy-privacy/releases\"\u003e\u003cimg src=\"https://img.shields.io/github/v/release/joaoeudes7/proxy-privacy\" alt=\"Release\"\u003e\u003c/a\u003e\n    \u003ca href=\"https://go.dev\"\u003e\u003cimg src=\"https://img.shields.io/badge/Go-1.26+-00ADD8\" alt=\"Go\"\u003e\u003c/a\u003e\n    \u003ca href=\"LICENSE\"\u003e\u003cimg src=\"https://img.shields.io/badge/license-MIT-yellow\" alt=\"License\"\u003e\u003c/a\u003e\n    \u003ca href=\"https://github.com/sponsors/joaoeudes7\"\u003e\u003cimg src=\"https://img.shields.io/badge/Sponsor-%23EA4AAA?style=flat\u0026logo=github\u0026logoColor=white\" alt=\"Sponsor\"\u003e\u003c/a\u003e\n  \u003c/p\u003e\n\u003c/p\u003e\n\u003c/p\u003e\n\n\u003e Maybe you want Privacy sometimes\n\n**Proxy Privacy** is a lightweight, single-binary privacy proxy that sits between your AI agents and any OpenAI-compatible API provider. It intercepts requests to inject privacy params (`data_collection`, `zdr`) — the proxy never sends a request without them.\n\nWorks as a **drop-in proxy** for Claude Code, Codex CLI, OpenCode, Cline, Cursor, Copilot, and any OpenAI-compatible client.\n\n## AI Agent Prompt\n\nPaste this into any AI agent (Claude Code, OpenCode, Codex, Pi, etc.):\n\n\u003e Install proxy-privacy, then load the skill at `skills/proxy-provider-setup/SKILL.md` and follow its instructions to configure providers for me.\n\nThe agent will:\n\n1. Download and install the binary\n2. Load the provider-setup skill\n3. Ask which providers you want (OpenAI, OpenRouter, Anthropic, etc.)\n4. Auto-resolve their API base URLs\n5. Write `~/.proxy-privacy/configs.json` with empty API keys\n6. Tell you to fill in the keys manually\n\n## Install\n\n```bash\ncurl -fsSL https://raw.githubusercontent.com/joaoeudes7/proxy-privacy/main/install.sh | sh\n```\n\nOr build from source:\n\n```bash\ngit clone https://github.com/joaoeudes7/proxy-privacy.git\ncd proxy-privacy\nmake install\n```\n\n## Quick Start\n\nCreate `~/.proxy-privacy/configs.json` with your providers:\n\n```json\n{\n  \"privacy_mode\": \"standard\",\n  \"redact_secrets\": true,\n  \"providers\": [\n    {\n      \"id\": \"openrouter\",\n      \"name\": \"OpenRouter\",\n      \"base_url\": \"https://openrouter.ai/api/v1\",\n      \"api_key\": \"sk-or-...\",\n      \"provider_prefs\": {\n        \"order\": [\"novita\", \"deepinfra\"],\n        \"sort\": \"throughput\"\n      }\n    },\n    {\n      \"id\": \"openai\",\n      \"name\": \"OpenAI\",\n      \"base_url\": \"https://api.openai.com/v1\",\n      \"api_key\": \"sk-...\"\n    }\n  ]\n}\n```\n\nThe first provider in the array is used by default. Select a different one with `--provider`:\n\n```bash\nproxy-privacy --provider openai\n```\n\n### Launch mode (proxy + agent)\n\nStart proxy and agent in one command — env vars are set automatically:\n\n```bash\nproxy-privacy launch claude --provider openai\nproxy-privacy launch codex\nproxy-privacy launch opencode -m qwen3.5:8b -p strict\nproxy-privacy launch pi --provider openrouter\n```\n\nSupported agents: `claude`, `codex`, `opencode`, `pi`, `cline`, `hermes`, `droid`, `copilot`, `codex-app`, `cursor`, `generic`\n\n### Manual agent config\n\nRun the proxy separately and point your agent to `http://localhost:8000/v1` with API key `sk-proxy-dev`:\n\n| Agent | Environment variables |\n|-------|----------------------|\n| Claude Code | `ANTHROPIC_BASE_URL=http://localhost:8000` + `ANTHROPIC_API_KEY=sk-proxy-dev` |\n| Codex CLI | `OPENAI_BASE_URL=http://localhost:8000/v1` + `OPENAI_API_KEY=sk-proxy-dev` |\n| OpenCode | `OPENAI_BASE_URL=http://localhost:8000/v1` + `OPENAI_API_KEY=sk-proxy-dev` |\n| Cline / Cursor / Copilot | Set `base_url` to `http://localhost:8000/v1`, key `sk-proxy-dev` |\n\nOr use with any OpenAI SDK:\n\n```python\nfrom openai import OpenAI\nclient = OpenAI(api_key=\"sk-proxy-dev\", base_url=\"http://localhost:8000/v1\")\n```\n\n## Privacy\n\n### Modes\n\n| Mode | Flag | Behavior |\n|------|------|----------|\n| **Standard** (default) | `-p standard` | Tries strict first (`zdr` + no fallbacks). If rejected, falls back to `data_collection: \"deny\"` + allow fallbacks. Model is cached in memory. |\n| **Strict** | `-p strict` | Always enforces `zdr: true` + no fallbacks. If rejected, request fails. |\n\n### Params injected per request\n\n| Where | Param | Standard | Strict |\n|-------|-------|----------|--------|\n| **Body** | `provider.data_collection` | `\"deny\"` | `\"deny\"` |\n| **Body** | `provider.zdr` | — | `true` |\n| **Body** | `provider.allow_fallbacks` | `true` | `false` |\n| **Header** | `X-Title` | Project URL | Project URL |\n| **Body** | `messages[].content` | Secrets redacted* | Secrets redacted* |\n| **Body** | `messages[].content` | PII redacted† | PII redacted† |\n\n\\* API keys and tokens (`sk-...`, `AKIA...`) — on by default, toggle via `--redact-secrets`  \n† Email addresses (`user@example.com`) — opt-in via `--redact-pii`\n\n## Configuration\n\nAll config lives in a single file: `~/.proxy-privacy/configs.json`\n\n### Priority\n\n**CLI flag \u003e env var \u003e configs.json \u003e default**\n\n| Setting | CLI | Env var | configs.json field |\n|---------|-----|---------|-------------------|\n| Provider selection | `--provider` | — | `providers[].id` / `providers[].name` |\n| Upstream URL | `--upstream` | `UPSTREAM_BASE_URL` | `providers[].base_url` |\n| Upstream key | `--upstream-key` | `OPENAI_API_KEY` | `providers[].api_key` |\n| Default model | `-m` / `--model` | — | `providers[].default_model` |\n| Privacy mode | `-p` / `--privacy` | — | `privacy_mode` |\n| Redact secrets | `--redact-secrets` | `PROXY_REDACT_SECRETS` | `redact_secrets` |\n| Redact emails | `--redact-pii` | `PROXY_REDACT_PII` | `redact_pii` |\n| Provider sort | `-s` / `--sort` | — | `provider_prefs.sort` |\n| Provider order | `--provider-order` | — | `provider_prefs.order` |\n| Debug upstream | `--debug-upstream` | `PROXY_DEBUG_UPSTREAM` | — |\n| Trace directory | `--trace-dir` | `PROXY_TRACE_DIR` | — |\n| Proxy API key | `-k` / `--api-key` | `PROXY_API_KEY` | — |\n\n### configs.json reference\n\n```json\n{\n  \"privacy_mode\": \"standard\",\n  \"redact_pii\": false,\n  \"redact_secrets\": true,\n  \"allowed_models\": null,\n  \"providers\": [\n    {\n      \"id\": \"openai\",\n      \"name\": \"OpenAI\",\n      \"base_url\": \"https://api.openai.com/v1\",\n      \"api_key\": \"sk-...\",\n      \"default_model\": \"gpt-4o\"\n    }\n  ]\n}\n```\n\n| Field | Type | Default | Description |\n|-------|------|---------|-------------|\n| `privacy_mode` | string | `\"standard\"` | `\"standard\"` or `\"strict\"` |\n| `redact_pii` | bool | `false` | Redact email addresses from messages |\n| `redact_secrets` | bool | `true` | Redact API keys from messages |\n| `allowed_models` | string[] | `null` | Restrict to specific models (optional) |\n| `providers` | array | `[]` | Upstream provider configurations |\n\nEach provider object:\n\n| Field | Required | Description |\n|-------|----------|-------------|\n| `id` | yes | Unique identifier, used with `--provider` |\n| `name` | yes | Display name |\n| `base_url` | yes | Upstream API base URL |\n| `api_key` | yes | API key for the upstream provider |\n| `default_model` | no | Model to use when none specified |\n| `default` | no | If `true`, this provider is selected by default |\n| `provider_prefs` | no | OpenRouter routing prefs: `order`, `sort`, `zdr`, etc. |\n| `models` | no | Per-model params: `temperature`, `reasoning`, `max_tokens`, etc. |\n\n### CLI reference\n\n```\nproxy-privacy [OPTIONS]\n\n  -p, --privacy string     Privacy mode: standard or strict (default \"standard\")\n  -m, --model string       Default model (auto-fetches from /v1/models if empty)\n  --provider string        Provider ID from configs.json (default: first)\n  --upstream string        Upstream base URL (overrides all other config)\n  --upstream-key string    Upstream API key (overrides all other config)\n  --port int               Listen port (default 8000)\n  --host string            Bind address (default \"127.0.0.1\")\n  -k, --api-key string     Proxy API key (env: PROXY_API_KEY, default \"sk-proxy-dev\")\n  -s, --sort string        Provider sort: price, throughput, latency (OpenRouter)\n  --provider-order string  Comma-separated provider slugs for routing (OpenRouter)\n  --redact-pii             Redact email addresses (default: false)\n  --redact-secrets         Redact API keys and secrets (default: true)\n  --debug-upstream         Log upstream requests (env: PROXY_DEBUG_UPSTREAM)\n  --trace-dir string       Directory for log/trace files (env: PROXY_TRACE_DIR)\n```\n\n```\nproxy-privacy launch \u003cagent\u003e [OPTIONS]\n\n  -p, --privacy string     Privacy mode (default \"standard\")\n  -m, --model string       Model for the agent\n  --provider string        Provider ID from configs.json (default: first)\n  -k, --api-key string     Proxy API key (default \"sk-proxy-dev\")\n  --upstream string        Upstream base URL (overrides provider/config)\n  --upstream-key string    Upstream API key (overrides provider/config)\n  --debug-upstream         Log upstream requests\n  --trace-dir string       Directory for log/trace files\n  -s, --sort string        Provider sort: price, throughput, latency (OpenRouter)\n  --provider-order string  Comma-separated provider slugs for routing (OpenRouter)\n  --config-only            Configure without launching\n  --redact-pii             Redact email addresses (default: false)\n  --redact-secrets bool    Redact API keys and secrets (default: true)\n```\n\n## API Endpoints\n\n| Method | Route | Description |\n|--------|-------|-------------|\n| POST | `/v1/chat/completions` | OpenAI chat (streaming supported) |\n| POST | `/v1/completions` | Legacy completions |\n| POST | `/v1/messages` | Anthropic format (Claude Code) |\n| GET | `/v1/models` | List upstream models |\n| GET | `/health` | Health check |\n\n## Supported Providers\n\nAny OpenAI-compatible API: OpenRouter, OpenAI, Anthropic, Together, Groq, DeepSeek, Perplexity, xAI (Grok), Google (Gemini), and more.\n\n## Architecture\n\n- **Single Go binary**, zero external dependencies\n- **No database** — fully ephemeral (Ctrl+C to stop)\n- **Single config file** at `~/.proxy-privacy/configs.json` (global settings + providers)\n- **Anthropic compatibility** — `/v1/messages` translated to OpenAI on the fly\n- **Provider error messages** — upstream errors shown in a friendly format\n- **Client identification** — `X-Title` header sempre definido como URL do projeto\n\n## Development\n\n```bash\nmake test     # run all tests\nmake build    # cross-compile for all platforms\nmake clean    # remove build artifacts\n```\n\n### Agent compatibility tests\n\nThe proxy adapts model responses for different agent clients:\n\n| Agent | Model format | Detection |\n|-------|-------------|-----------|\n| Claude | Anthropic (`type`, `id`, `display_name`, `created_at`) | `anthropic-version` header or `Claude` User-Agent |\n| Codex | Codex (`slug`, `display_name`, `shell_type`, `visibility`) | `client_version` query param or `Codex` User-Agent |\n| OpenCode | Standard OpenAI | Default |\n| Pi | Standard OpenAI | Default |\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjoaoeudes7%2Fproxy-privacy","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjoaoeudes7%2Fproxy-privacy","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjoaoeudes7%2Fproxy-privacy/lists"}