DocsMaple Proxy

Quickstart

Start Maple Proxy from the Maple desktop app, or self-host it with Docker or the release binary, then send your first OpenAI-compatible request.

There are two ways to run Maple Proxy. Both run the same open-source proxy.

  • Desktop app: the easiest option for local development. Maple starts and manages the proxy for you.
  • Self-hosted: run the proxy yourself, as a Docker container or a single binary, beside your own service.

You need a Maple account with API access (Pro, Max or Team). See pricing.

Desktop app

The Maple desktop app for macOS, Windows and Linux includes a built-in proxy.

  1. Download Maple and sign in.
  2. Open Settings, then API & credits under Developer.
  3. Open the Local Proxy tab and select Start proxy.

If you have not set a key for the proxy yet, Maple creates an API key for it and saves it. The proxy then listens on http://127.0.0.1:8080/v1. You can copy that base URL from the same screen.

The desktop proxy is meant for tools on the same computer:

  • Local tools can skip the key. With CORS turned off (the default), local processes can use the key Maple saved for the proxy. A key sent in the Authorization header still takes priority.
  • Browser requests are rejected. With CORS turned off, the desktop proxy refuses requests that come from a web page.
  • Keep Maple open. The proxy runs inside the app, so connected tools stop working when you quit Maple.

Under Advanced settings you can change the host and port, turn on Auto-start when Maple launches, and Enable CORS for browser clients. With CORS on, every request must carry its own API key; the saved key is never used.

Keep the host on 127.0.0.1

Any other host may expose the proxy, and the API key it holds, beyond your device. Change it only if you understand the network and billing risk.

The Local Proxy screen also has built-in setup guides for OpenCode, cURL and Python, filled in with your proxy URL and the current model list.

Self-hosted

Self-host the proxy when your tools run on a server, in CI, or anywhere the desktop app is not running. First create an API key in Maple.

Docker

The container image is published to the GitHub Container Registry for AMD64 and ARM64.

Shell
docker run --rm -p 127.0.0.1:8080:8080 ghcr.io/mapleprivacylabs/maple-proxy:latest

The image listens on port 8080 inside the container and connects to the production backend, https://enclave.trymaple.ai. Binding the published port to 127.0.0.1 keeps the proxy off your network.

CORS is on by default in the image

The Docker image sets MAPLE_ENABLE_CORS=true. In CORS mode the proxy ignores MAPLE_API_KEY, so every request must send its own key in the Authorization header. This is the safe default for a shared deployment. For a private deployment that should use one saved key, set -e MAPLE_ENABLE_CORS=false -e MAPLE_API_KEY=…. See authentication.

Older images at ghcr.io/opensecretcloud/maple-proxy still work at their existing versions but receive no updates. Change the image name to get new releases.

For Docker Compose, a health check, and production settings, see configuration.

Binary

Each Maple app release includes native proxy builds and a checksum file:

PlatformArchive
Linux x86_64maple-proxy-linux-x86_64.tar.gz
Linux ARM64maple-proxy-linux-aarch64.tar.gz
macOS (Apple silicon)maple-proxy-macos-aarch64.tar.gz
Windows x86_64maple-proxy-windows-x86_64.zip

Download, verify and run it (Linux x86_64 shown):

Shell
curl -LO https://github.com/MaplePrivacyLabs/Maple/releases/latest/download/maple-proxy-linux-x86_64.tar.gz
curl -LO https://github.com/MaplePrivacyLabs/Maple/releases/latest/download/maple-proxy-release-final.sha256
sha256sum --check --ignore-missing maple-proxy-release-final.sha256
tar -xzf maple-proxy-linux-x86_64.tar.gz

export MAPLE_API_KEY=your-maple-api-key
./maple-proxy

On macOS, use shasum -a 256 --check --ignore-missing instead of sha256sum. The macOS archive is for Apple silicon (aarch64) only.

The macOS binary isn’t notarized, and macOS blocks unsigned downloads from running. After you check the checksum and extract the archive, clear the quarantine flag once:

Shell
xattr -d com.apple.quarantine ./maple-proxy

The binary listens on 127.0.0.1:8080 by default, with CORS off, so the saved MAPLE_API_KEY is used for requests that don’t send their own key.

Build from source

Shell
git clone https://github.com/MaplePrivacyLabs/Maple.git
cd Maple/proxy
cargo build --locked --release
./target/release/maple-proxy

Send your first request

Check the proxy is up. This doesn’t contact Maple:

Shell
curl http://127.0.0.1:8080/health
JSON
{ "status": "ok", "service": "maple-proxy", "version": "0.4.1" }

List the models your key can call:

Shell
curl http://127.0.0.1:8080/v1/models \
  -H "Authorization: Bearer $MAPLE_API_KEY"

Then stream a chat completion:

Shell
curl -N http://127.0.0.1:8080/v1/chat/completions \
  -H "Authorization: Bearer $MAPLE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "model": "gpt-oss-120b",
    "messages": [{"role": "user", "content": "Write a haiku about privacy"}],
    "stream": true
  }'

The first request after the proxy starts takes a little longer, because that is when the proxy verifies the enclave and opens its encrypted session.

Next steps

Last updated