Back to docs

Installation Methods

In-Flight Terminal Proxy

The BLAZLE local proxy runs on your computer and checks what your AI tools send and run before it happens: prompts on their way to the model, code your editor saves, and shell commands an agent is about to run (like rm -rf, sudo or curl ... | sh). It follows your workspace rules and reports blocks to your dashboard.

Download

Run it

Create an API key in the dashboard (API Keys), then start the proxy. The examples use the Apple silicon file; use the name of the file you downloaded.

macOS / Linux

chmod +x blazle-proxy-macos-arm64
# macOS only, first run: allow the downloaded file
xattr -d com.apple.quarantine blazle-proxy-macos-arm64
BLAZLE_API_KEY="blz_live_..." ./blazle-proxy-macos-arm64

Windows (PowerShell)

$env:BLAZLE_API_KEY="blz_live_..."
.\blazle-proxy-windows-x64.exe

The proxy listens on http://127.0.0.1:8081, only on your machine. Point your tools at it (for example an OpenAI-compatible base URL of http://127.0.0.1:8081/v1), or install the VS Code extension, which uses it automatically. Requests that pass are forwarded to OpenAI; set OPENAI_UPSTREAM to use another OpenAI-compatible provider. Add --help after the file name to see all options.

Check commands before an agent runs them

With the proxy running, ask BLAZLE about a command. It answers in an instant: exit code 0 means allowed, 2 means blocked, with the reason printed.

./blazle-proxy-macos-arm64 check "rm -rf ~/projects"
# BLAZLE blocked this command: Blocked potentially destructive recursive/forced 'rm' command.

Add it as a hook so your agent checks every shell command first. For Claude Code, put this in .claude/settings.json (use the full path to the file you downloaded):

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          { "type": "command", "command": "/path/to/blazle-proxy-macos-arm64 check" }
        ]
      }
    ]
  }
}

Any agent or script can do the same: call check with the command, or send {"command": "..."} to http://127.0.0.1:8081/intercept/command. If the proxy is not running, check blocks to stay safe and tells you how to start it.

Architecture

The proxy runs on top of the ultra-low latency BLAZIL Engine.

  • Decision first: the verdict is returned before any logging or storage happens, so recording never slows your agent down.
  • Sub-millisecond rules: most commands and payloads are decided in well under a millisecond.
  • No noticeable delay: terminal commands are intercepted instantly while your agents run at full speed.