@alfe.ai/ai-proxy-local
v0.0.17
Published
Loopback streaming proxy used by the Alfe gateway to inject the local agent's API key into requests for the stage-matched cloud AI service.
Readme
@alfe.ai/ai-proxy-local
Loopback streaming proxy used by the Alfe gateway to inject the local agent's API key into requests for the stage-matched cloud AI service.
Part of Alfe — the operating system for AI agents: build, deploy, and run agents with persistent memory, identity, integrations, and channels. See the documentation to get started.
Install
npm install @alfe.ai/ai-proxy-localThe gateway normally starts this package automatically. The standalone binary
reads ~/.alfe/config.toml and listens only on 127.0.0.1:
alfe-ai-proxy --port 18193Boundary guarantees
- API keys are forwarded only to the canonical Alfe AI origin derived from the
key's environment (
dev,test,demo, orlive); custom hosts, ports, paths, and redirects are not accepted. - Request targets, headers, declared and streamed request bytes, and the upstream response-header wait are bounded. Response bodies remain streamed so SSE is not buffered or given an artificial whole-response cap.
- Hop-by-hop, authorization, and caller-supplied
X-Alfe-*authority headers (identity, team/project scope, agent, and tenant) are removed. A valid caller Alfe key may intentionally override the configured agent key; diagnostics use this to attribute and authorize their own model spend. POST /__alfe/set-identityis a private, loopback-only control route. It rejects browser-originated writes, requires bounded JSON, and owns the identity header added to subsequent requests.
The current identity slot is process-global. The OpenClaw chat integration
serializes turns, awaits the identity write before dispatch, and clears it in a
finally block. A future runtime-level per-request context can remove this
remaining global seam.
Links
- 🌐 Website: https://alfe.ai
- 📚 Docs: https://docs.alfe.ai
