DocsMaple Proxy

Maple Proxy

Private AI for the tools you already use

Maple Proxy is an OpenAI-compatible server that verifies Maple's secure enclave and encrypts each request, so existing OpenAI clients can use Maple's private models.

Point any OpenAI client at Maple Proxy and it works with Maple’s end-to-end encrypted AI service. You change the base URL and the API key; the rest of your code stays the same. The proxy is open source under the MIT license.

Start here

Why a proxy?

Maple runs all model inference inside Trusted Execution Environments (TEEs): secure enclaves that keep your prompts and responses private, even from Maple. That privacy needs two extra steps for every connection:

  • Attestation. Before anything is sent, the client checks that it is talking to a genuine Maple enclave running the expected code.
  • Encryption. The client and the enclave agree on keys, and every request and response is encrypted between them.

Standard OpenAI clients can do neither. Maple Proxy does both for you and gives your tools the endpoint they already expect.

How a request moves

  1. Your tool calls the proxy It sends a normal OpenAI-style request, with your Maple API key, to the proxy on your machine.
  2. The proxy checks the enclave Before anything is sent, it verifies Maple’s enclave attestation and agrees on encryption keys with it.
  3. The request leaves encrypted Your prompt and your API key are sealed on your machine, then sent to the enclave.
  4. The answer comes back The proxy decrypts the response and hands it to your tool, streamed or all at once.

On the first request, the proxy opens one shared, attested session with the Maple backend; later requests reuse it. Each request’s API key travels inside that request’s encrypted envelope. It is never forwarded as a plain header, and the proxy does not write it to its logs.

Encryption starts at the proxy

The hop from your tool to the proxy is ordinary local traffic. Run the proxy on a machine you control, and keep it on 127.0.0.1 unless you have a reason to expose it. See how Maple’s enclaves work.

Endpoints

The proxy forwards only these routes; anything else, such as audio or the Responses API, returns 404 from the proxy itself. Request and response bodies pass through without being parsed or rewritten.

One change to your code

Python
from openai import OpenAI

client = OpenAI(
    base_url="http://127.0.0.1:8080/v1",  # Maple Proxy, on your machine
    api_key="YOUR_MAPLE_API_KEY",
)

stream = client.chat.completions.create(
    model="gpt-oss-120b",
    messages=[{"role": "user", "content": "Hello, secure world!"}],
    stream=True,
)

for chunk in stream:
    if chunk.choices and chunk.choices[0].delta.content:
        print(chunk.choices[0].delta.content, end="")
TypeScript
import OpenAI from 'openai';

const client = new OpenAI({
  baseURL: 'http://127.0.0.1:8080/v1', // Maple Proxy, on your machine
  apiKey: 'YOUR_MAPLE_API_KEY',
});

const stream = await client.chat.completions.create({
  model: 'gpt-oss-120b',
  messages: [{ role: 'user', content: 'Hello, secure world!' }],
  stream: true,
});

for await (const chunk of stream) {
  process.stdout.write(chunk.choices[0]?.delta?.content ?? '');
}
Shell
curl -N http://127.0.0.1:8080/v1/chat/completions \
  -H "Authorization: Bearer YOUR_MAPLE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "model": "gpt-oss-120b",
    "messages": [{"role": "user", "content": "Hello, secure world!"}],
    "stream": true
  }'

Two ways to run it

  • Desktop app. The easiest way to start on your own computer: turn on Local Proxy and Maple starts the proxy and can create its API key.
  • Self-hosted. Run the same proxy beside your own service with Docker or the binary, on a laptop or a server you manage.

Building in JavaScript? The @mapleai/sdk package does the same verification and encryption inside your app, so there is nothing extra to run.

Requirements

API access is a Pro feature. Max and Team include all features from Pro. API usage is billed per million tokens at each model’s rate, separately from the plan price. See pricing for plans and the current rate table.

Last updated