SPM — StellarPath Memory Operating System Docs

Local Proxy

Published Last reviewed Applies to SPM-Polaris and @spmos/local-proxy 0.1.x

@spmos/local-proxy runs on your machine and keeps your provider key there. Your client talks to the Local Proxy; the Local Proxy talks directly to your provider. SPM handles the memory side: recall lookups and eligible saved text still use the hosted memory service.

It is not self-hosted SPM — your memory lives in the hosted service either way. What stays local is the provider credential and the full model traffic.

Current npm release: @spmos/local-proxy@0.1.2. It adds the same conversation-continuity, capture-hygiene, and tool-output elision protections as the Hosted Provider Proxy.

Install

npm install --global @spmos/local-proxy@0.1.2
spm setup
spm doctor
spm start

Requirements:

Both spm and spm-local-proxy invoke the same CLI.

What the setup wizard asks for

Your client—not the Local Proxy—chooses the model for each request.

Default configuration

Setting Default
Bind 127.0.0.1:8765
Memory mode read-write
Compression mode deterministic
Input budget 8,192 estimated tokens
Maximum recalled context 512 estimated tokens
SPM API https://api.spmos.ai

Configuration is stored under $SPM_CONFIG_HOME, $XDG_CONFIG_HOME/spm, or ~/.config/spm, with owner-only file permissions.

Client configuration

Codex:

spm print-config codex
export SPM_LOCAL_PROXY_TOKEN="$(spm config token)"

Claude Code:

spm print-config claude
ANTHROPIC_BASE_URL="http://127.0.0.1:8765"
ANTHROPIC_API_KEY="$SPM_LOCAL_PROXY_TOKEN"

OpenAI-compatible SDKs use http://127.0.0.1:8765/v1. Anthropic Messages traffic uses the anthropic_messages API style. The Local Proxy does not translate between dialects.

What goes where

Item Stored locally Sent to SPM Sent to provider Given to your client
Provider key Yes No Yes No
SPM key Yes Used for memory calls No No
Local token Yes No No Yes
Recall query Transient Yes Only if inserted into the prompt Through the normal request
Eligible captured text Transient Yes Already part of model traffic Originates in request/response
Full provider request Transient No Yes Originates in your client

Custom headers or query values containing $API_KEY are secrets and are protected with the same local file permissions.

What 0.1.2 protects

Optional knobs: proxy.elisionEnabled (default on), proxy.elisionKeepRounds (default 4), proxy.elisionCaptureLimit (default 8).

Local endpoints

Endpoint Behavior
POST /v1/chat/completions OpenAI-compatible upstream
POST /v1/responses OpenAI-compatible upstream
POST /v1/messages Anthropic Messages upstream
GET /v1/models Direct upstream relay when the provider exposes it
GET /health / GET /livez Local process checks

JSON and SSE are supported; zstd request bodies used by Codex are decoded.

Security controls

You remain responsible for the provider URL you choose, that provider's retention/training settings, and your local machine's security.

Observability

Responses include x-spm-local-proxy, memory/compression state, original/forwarded/recalled token estimates, and x-spm-continuity-state.

Local Proxy requests do not create hosted receipts, so they do not appear in the dashboard Token savings or Recent request receipts views. Use the local response headers for per-request evidence.

Troubleshooting