Quickstart
Start Maple Proxy from the Maple desktop app, or self-host it with Docker or the release binary, then send your first OpenAI-compatible request.
There are two ways to run Maple Proxy. Both run the same open-source proxy.
- Desktop app: the easiest option for local development. Maple starts and manages the proxy for you.
- Self-hosted: run the proxy yourself, as a Docker container or a single binary, beside your own service.
You need a Maple account with API access (Pro, Max or Team). See pricing.
Desktop app
The Maple desktop app for macOS, Windows and Linux includes a built-in proxy.
- Download Maple and sign in.
- Open Settings, then API & credits under Developer.
- Open the Local Proxy tab and select Start proxy.
If you have not set a key for the proxy yet, Maple creates an API key for it and saves it. The proxy then listens on http://127.0.0.1:8080/v1. You can copy that base URL from the same screen.
The desktop proxy is meant for tools on the same computer:
- Local tools can skip the key. With CORS turned off (the default), local processes can use the key Maple saved for the proxy. A key sent in the
Authorizationheader still takes priority. - Browser requests are rejected. With CORS turned off, the desktop proxy refuses requests that come from a web page.
- Keep Maple open. The proxy runs inside the app, so connected tools stop working when you quit Maple.
Under Advanced settings you can change the host and port, turn on Auto-start when Maple launches, and Enable CORS for browser clients. With CORS on, every request must carry its own API key; the saved key is never used.
Keep the host on 127.0.0.1
Any other host may expose the proxy, and the API key it holds, beyond your device. Change it only if you understand the network and billing risk.
The Local Proxy screen also has built-in setup guides for OpenCode, cURL and Python, filled in with your proxy URL and the current model list.
Self-hosted
Self-host the proxy when your tools run on a server, in CI, or anywhere the desktop app is not running. First create an API key in Maple.
Docker
The container image is published to the GitHub Container Registry for AMD64 and ARM64.
docker run --rm -p 127.0.0.1:8080:8080 ghcr.io/mapleprivacylabs/maple-proxy:latest The image listens on port 8080 inside the container and connects to the production backend, https://enclave.trymaple.ai. Binding the published port to 127.0.0.1 keeps the proxy off your network.
CORS is on by default in the image
The Docker image sets MAPLE_ENABLE_CORS=true. In CORS mode the proxy ignores MAPLE_API_KEY, so every request must send its own key in the Authorization header. This is the safe default for a shared deployment. For a private deployment that should use one saved key, set -e MAPLE_ENABLE_CORS=false -e MAPLE_API_KEY=…. See authentication.
Older images at ghcr.io/opensecretcloud/maple-proxy still work at their existing versions but receive no updates. Change the image name to get new releases.
For Docker Compose, a health check, and production settings, see configuration.
Binary
Each Maple app release includes native proxy builds and a checksum file:
| Platform | Archive |
|---|---|
| Linux x86_64 | maple-proxy-linux-x86_64.tar.gz |
| Linux ARM64 | maple-proxy-linux-aarch64.tar.gz |
| macOS (Apple silicon) | maple-proxy-macos-aarch64.tar.gz |
| Windows x86_64 | maple-proxy-windows-x86_64.zip |
Download, verify and run it (Linux x86_64 shown):
curl -LO https://github.com/MaplePrivacyLabs/Maple/releases/latest/download/maple-proxy-linux-x86_64.tar.gz
curl -LO https://github.com/MaplePrivacyLabs/Maple/releases/latest/download/maple-proxy-release-final.sha256
sha256sum --check --ignore-missing maple-proxy-release-final.sha256
tar -xzf maple-proxy-linux-x86_64.tar.gz
export MAPLE_API_KEY=your-maple-api-key
./maple-proxy On macOS, use shasum -a 256 --check --ignore-missing instead of sha256sum. The macOS archive is for Apple silicon (aarch64) only.
The macOS binary isn’t notarized, and macOS blocks unsigned downloads from running. After you check the checksum and extract the archive, clear the quarantine flag once:
xattr -d com.apple.quarantine ./maple-proxy The binary listens on 127.0.0.1:8080 by default, with CORS off, so the saved MAPLE_API_KEY is used for requests that don’t send their own key.
Build from source
git clone https://github.com/MaplePrivacyLabs/Maple.git
cd Maple/proxy
cargo build --locked --release
./target/release/maple-proxy Send your first request
Check the proxy is up. This doesn’t contact Maple:
curl http://127.0.0.1:8080/health { "status": "ok", "service": "maple-proxy", "version": "0.4.1" } List the models your key can call:
curl http://127.0.0.1:8080/v1/models \
-H "Authorization: Bearer $MAPLE_API_KEY" Then stream a chat completion:
curl -N http://127.0.0.1:8080/v1/chat/completions \
-H "Authorization: Bearer $MAPLE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"model": "gpt-oss-120b",
"messages": [{"role": "user", "content": "Write a haiku about privacy"}],
"stream": true
}' The first request after the proxy starts takes a little longer, because that is when the proxy verifies the enclave and opens its encrypted session.
Next steps
- Use the proxy from Python, JavaScript or cURL.
- Connect a coding agent: OpenCode or Goose.
- Tune timeouts and logging in configuration.