{"_id":"@aion0/bastion","_rev":"11-88bd174bd5dff8d76c01c3c55730510c","name":"@aion0/bastion","dist-tags":{"latest":"0.1.16"},"versions":{"0.1.7":{"name":"@aion0/bastion","version":"0.1.7","keywords":["ai","gateway","proxy","llm","security","dlp","anthropic","openai","gemini"],"author":{"name":"aion0"},"license":"UNLICENSED","_id":"@aion0/bastion@0.1.7","maintainers":[{"name":"aion0","email":"aiwatching2024@gmail.com"}],"homepage":"https://github.com/aiwatching/bastion","bugs":{"url":"https://github.com/aiwatching/bastion/issues"},"bin":{"bastion":"dist/cli/index.js"},"dist":{"shasum":"010609ca8d7951e9597891d2ad72a41f0ce2b7bb","tarball":"https://registry.npmjs.org/@aion0/bastion/-/bastion-0.1.7.tgz","fileCount":377,"integrity":"sha512-QdQ7hjClQaEr53JZWU8Rdo0LVMNHUxuCC/Rq0F/RWLkiyB4y8DTmf1AwMntp2Br0qaACPFSte8ZziKLMgr3u7g==","signatures":[{"sig":"MEUCIQDX92EbuOMsJzWKTl+yQGOEw7UYCvGqdas3I0Qc6E4UwwIgU4G5tBxzpnqgPNyZCsgHbDG5VN+nb5Md6IXZBUGqrfI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1063100},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"85926ffb521826db8189f4ef0cb595b8c020529a","scripts":{"dev":"tsx src/cli/index.ts","lint":"eslint src/","test":"vitest run","build":"tsc -p tsconfig.build.json","dlp:test":"tsx scripts/dlp-test-env.ts","test:watch":"vitest","dlp:test:warn":"tsx scripts/dlp-test-env.ts --action warn","test:coverage":"vitest run --coverage","dlp:test:block":"tsx scripts/dlp-test-env.ts --action block","prepublishOnly":"npm run build","dlp:test:redact":"tsx scripts/dlp-test-env.ts --action redact","dlp:test:interactive":"tsx scripts/dlp-test-env.ts --interactive"},"_npmUser":{"name":"aion0","email":"aiwatching2024@gmail.com"},"repository":{"url":"git+https://github.com/aiwatching/bastion.git","type":"git"},"_npmVersion":"10.9.3","description":"Local-first AI gateway for proxying and securing LLM provider requests","directories":{},"_nodeVersion":"22.20.0","dependencies":{"js-yaml":"^4.1.0","commander":"^13.1.0","node-forge":"^1.3.3","better-sqlite3":"^11.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.3","vitest":"^3.0.5","typescript":"^5.7.3","@types/node":"^22.13.4","@types/js-yaml":"^4.0.9","@types/node-forge":"^1.3.14","@types/better-sqlite3":"^7.6.12"},"_npmOperationalInternal":{"tmp":"tmp/bastion_0.1.7_1772422975528_0.914149611052554","host":"s3://npm-registry-packages-npm-production"}},"0.1.9":{"name":"@aion0/bastion","version":"0.1.9","keywords":["ai","gateway","proxy","llm","security","dlp","anthropic","openai","gemini"],"author":{"name":"aion0"},"license":"UNLICENSED","_id":"@aion0/bastion@0.1.9","maintainers":[{"name":"aion0","email":"aiwatching2024@gmail.com"}],"homepage":"https://github.com/aiwatching/bastion","bugs":{"url":"https://github.com/aiwatching/bastion/issues"},"bin":{"bastion":"dist/cli/index.js"},"dist":{"shasum":"00eda1e70dedfcf8769f9a227c058e273c976934","tarball":"https://registry.npmjs.org/@aion0/bastion/-/bastion-0.1.9.tgz","fileCount":382,"integrity":"sha512-A8wikocpuPnDD6008YNF8EemShy31zkoVsuiiq0PFsQd+5sT5Lq5kb044Ly4PFFPXZTtTrhyfk0Xy8g0lyuK0A==","signatures":[{"sig":"MEUCIAjqjK5QVNXrKuqX4IT122Z1v+z1KnCZSHlkKPwpwdZ/AiEAskr3kEFXV1OnyYUdAKNXHwTcLemq+usSVNidvEhbkiI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1138982},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"7baa76bf502e51b6f1e9100cf0b7c68ffd7de681","scripts":{"dev":"tsx src/cli/index.ts","lint":"eslint src/","test":"vitest run","build":"tsc -p tsconfig.build.json","dlp:test":"tsx scripts/dlp-test-env.ts","test:watch":"vitest","dlp:test:warn":"tsx scripts/dlp-test-env.ts --action warn","test:coverage":"vitest run --coverage","dlp:test:block":"tsx scripts/dlp-test-env.ts --action block","prepublishOnly":"npm run build","dlp:test:redact":"tsx scripts/dlp-test-env.ts --action redact","dlp:test:interactive":"tsx scripts/dlp-test-env.ts --interactive"},"_npmUser":{"name":"aion0","email":"aiwatching2024@gmail.com"},"repository":{"url":"git+https://github.com/aiwatching/bastion.git","type":"git"},"_npmVersion":"10.9.3","description":"Local-first AI gateway for proxying and securing LLM provider requests","directories":{},"_nodeVersion":"22.20.0","dependencies":{"js-yaml":"^4.1.0","commander":"^13.1.0","node-forge":"^1.3.3","better-sqlite3":"^11.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.3","vitest":"^3.0.5","typescript":"^5.7.3","@types/node":"^22.13.4","@types/js-yaml":"^4.0.9","@types/node-forge":"^1.3.14","@types/better-sqlite3":"^7.6.12"},"_npmOperationalInternal":{"tmp":"tmp/bastion_0.1.9_1772476941707_0.22338033217704956","host":"s3://npm-registry-packages-npm-production"}},"0.1.10":{"name":"@aion0/bastion","version":"0.1.10","keywords":["ai","gateway","proxy","llm","security","dlp","anthropic","openai","gemini"],"author":{"name":"aion0"},"license":"UNLICENSED","_id":"@aion0/bastion@0.1.10","maintainers":[{"name":"aion0","email":"aiwatching2024@gmail.com"}],"homepage":"https://github.com/aiwatching/bastion","bugs":{"url":"https://github.com/aiwatching/bastion/issues"},"bin":{"bastion":"dist/cli/index.js"},"dist":{"shasum":"a5aec1b18e9ed9c6054e600117c912e32341d277","tarball":"https://registry.npmjs.org/@aion0/bastion/-/bastion-0.1.10.tgz","fileCount":390,"integrity":"sha512-LBmJz5Q36rAgmaYH7AeORtlwfZp8041BIcwjQYdAIl+rSxzI2ThUqGpDx4uUy3P93N1TF3WVZTrpK2yd40yXhw==","signatures":[{"sig":"MEUCIBSCE50/wHIscyKJT5U+nu6mOQqvjkzzRbY1kXNGTnoHAiEA0tT4Nswyr/YBMYDG6XhCt4WMExO98MvjMh8XZyZ8iRo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1162022},"main":"dist/api.js","types":"dist/api.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/api.d.ts","import":"./dist/api.js"},"./cli":{"import":"./dist/cli/index.js"}},"gitHead":"febba022e0c47f50c7529fe25e5c81872a180e5f","scripts":{"dev":"tsx src/cli/index.ts","lint":"eslint src/","test":"vitest run","build":"tsc -p tsconfig.build.json","dlp:test":"tsx scripts/dlp-test-env.ts","test:watch":"vitest","dlp:test:warn":"tsx scripts/dlp-test-env.ts --action warn","test:coverage":"vitest run --coverage","dlp:test:block":"tsx scripts/dlp-test-env.ts --action block","prepublishOnly":"npm run build","dlp:test:redact":"tsx scripts/dlp-test-env.ts --action redact","dlp:test:interactive":"tsx scripts/dlp-test-env.ts --interactive"},"_npmUser":{"name":"aion0","email":"aiwatching2024@gmail.com"},"repository":{"url":"git+https://github.com/aiwatching/bastion.git","type":"git"},"_npmVersion":"10.9.3","description":"Local-first AI gateway for proxying and securing LLM provider requests","directories":{},"_nodeVersion":"22.20.0","dependencies":{"js-yaml":"^4.1.0","commander":"^13.1.0","node-forge":"^1.3.3","better-sqlite3":"^11.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.3","vitest":"^3.0.5","typescript":"^5.7.3","@types/node":"^22.13.4","@types/js-yaml":"^4.0.9","@types/node-forge":"^1.3.14","@types/better-sqlite3":"^7.6.12"},"_npmOperationalInternal":{"tmp":"tmp/bastion_0.1.10_1772489995840_0.08435971150748833","host":"s3://npm-registry-packages-npm-production"}},"0.1.11":{"name":"@aion0/bastion","version":"0.1.11","keywords":["ai","gateway","proxy","llm","security","dlp","anthropic","openai","gemini"],"author":{"name":"aion0"},"license":"UNLICENSED","_id":"@aion0/bastion@0.1.11","maintainers":[{"name":"aion0","email":"aiwatching2024@gmail.com"}],"homepage":"https://github.com/aiwatching/bastion","bugs":{"url":"https://github.com/aiwatching/bastion/issues"},"bin":{"bastion":"dist/cli/index.js"},"dist":{"shasum":"f3879b2008ff470939cd82a073ef062afac888cf","tarball":"https://registry.npmjs.org/@aion0/bastion/-/bastion-0.1.11.tgz","fileCount":390,"integrity":"sha512-KpfqkD7vIYL2Mlhnfiab3wpBs64ZRtrqkdYU9lzmkQa+uYZ070BDD7JUWopGOviIJWai5o1TF2ClUzVN93McVA==","signatures":[{"sig":"MEQCICRJl2c0DIX/ho9cx+UsKqljQdoccJS/gWDykXY/MPgaAiBHOv1DNWgvLJ/EzgtvJBnh94qG5vfv2g0W4ba1Y+oWXQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1162118},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./api":{"types":"./dist/api.d.ts","import":"./dist/api.js"},"./cli":{"import":"./dist/cli/index.js"}},"gitHead":"febba022e0c47f50c7529fe25e5c81872a180e5f","scripts":{"dev":"tsx src/cli/index.ts","lint":"eslint src/","test":"vitest run","build":"tsc -p tsconfig.build.json","dlp:test":"tsx scripts/dlp-test-env.ts","test:watch":"vitest","dlp:test:warn":"tsx scripts/dlp-test-env.ts --action warn","test:coverage":"vitest run --coverage","dlp:test:block":"tsx scripts/dlp-test-env.ts --action block","prepublishOnly":"npm run build","dlp:test:redact":"tsx scripts/dlp-test-env.ts --action redact","dlp:test:interactive":"tsx scripts/dlp-test-env.ts --interactive"},"_npmUser":{"name":"aion0","email":"aiwatching2024@gmail.com"},"repository":{"url":"git+https://github.com/aiwatching/bastion.git","type":"git"},"_npmVersion":"10.9.3","description":"Local-first AI gateway for proxying and securing LLM provider requests","directories":{},"_nodeVersion":"22.20.0","dependencies":{"js-yaml":"^4.1.0","commander":"^13.1.0","node-forge":"^1.3.3","better-sqlite3":"^11.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.3","vitest":"^3.0.5","typescript":"^5.7.3","@types/node":"^22.13.4","@types/js-yaml":"^4.0.9","@types/node-forge":"^1.3.14","@types/better-sqlite3":"^7.6.12"},"_npmOperationalInternal":{"tmp":"tmp/bastion_0.1.11_1772491073871_0.48804486093707955","host":"s3://npm-registry-packages-npm-production"}},"0.1.12":{"name":"@aion0/bastion","version":"0.1.12","keywords":["ai","gateway","proxy","llm","security","dlp","anthropic","openai","gemini"],"author":{"name":"aion0"},"license":"UNLICENSED","_id":"@aion0/bastion@0.1.12","maintainers":[{"name":"aion0","email":"aiwatching2024@gmail.com"}],"homepage":"https://github.com/aiwatching/bastion","bugs":{"url":"https://github.com/aiwatching/bastion/issues"},"bin":{"bastion":"dist/cli/index.js"},"dist":{"shasum":"096208f5e46bf8e114ee4b79b5996e6ce9976202","tarball":"https://registry.npmjs.org/@aion0/bastion/-/bastion-0.1.12.tgz","fileCount":400,"integrity":"sha512-wUFo6FzQXmyxSE808NPrea1JR7uM8dZlCdcB251vnSfe/gWj9egNgPmCdDeqhY3lFZ6syZ/o1b9+lIu/u+3ytw==","signatures":[{"sig":"MEYCIQCAfHhZFdMJG72AXxDfOjTeNeOHB0vKcCNk24GtZ6s2RQIhAP9omO7we2GWUB9MU31AcjCImH6isqLYxoC8DjVkIdLN","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1207548},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./api":{"types":"./dist/api.d.ts","import":"./dist/api.js"},"./cli":{"import":"./dist/cli/index.js"}},"gitHead":"350c14d6f01d7c3707b6cc670b4970f164af4715","scripts":{"dev":"tsx src/cli/index.ts","lint":"eslint src/","test":"vitest run","build":"tsc -p tsconfig.build.json","dlp:test":"tsx scripts/dlp-test-env.ts","test:watch":"vitest","dlp:test:warn":"tsx scripts/dlp-test-env.ts --action warn","test:coverage":"vitest run --coverage","dlp:test:block":"tsx scripts/dlp-test-env.ts --action block","prepublishOnly":"npm run build","dlp:test:redact":"tsx scripts/dlp-test-env.ts --action redact","dlp:test:interactive":"tsx scripts/dlp-test-env.ts --interactive"},"_npmUser":{"name":"aion0","email":"aiwatching2024@gmail.com"},"repository":{"url":"git+https://github.com/aiwatching/bastion.git","type":"git"},"_npmVersion":"10.9.3","description":"Local-first AI gateway for proxying and securing LLM provider requests","directories":{},"_nodeVersion":"22.20.0","dependencies":{"js-yaml":"^4.1.0","commander":"^13.1.0","node-forge":"^1.3.3","better-sqlite3":"^11.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.3","vitest":"^3.0.5","typescript":"^5.7.3","@types/node":"^22.13.4","@types/js-yaml":"^4.0.9","@types/node-forge":"^1.3.14","@types/better-sqlite3":"^7.6.12"},"_npmOperationalInternal":{"tmp":"tmp/bastion_0.1.12_1772770105904_0.5549531897056774","host":"s3://npm-registry-packages-npm-production"}},"0.1.13":{"name":"@aion0/bastion","version":"0.1.13","keywords":["ai","gateway","proxy","llm","security","dlp","anthropic","openai","gemini"],"author":{"name":"aion0"},"license":"UNLICENSED","_id":"@aion0/bastion@0.1.13","maintainers":[{"name":"aion0","email":"aiwatching2024@gmail.com"}],"homepage":"https://github.com/aiwatching/bastion","bugs":{"url":"https://github.com/aiwatching/bastion/issues"},"bin":{"bastion":"dist/cli/index.js"},"dist":{"shasum":"69c44eeb3e23415a3651010f7242ead9e65ba03a","tarball":"https://registry.npmjs.org/@aion0/bastion/-/bastion-0.1.13.tgz","fileCount":428,"integrity":"sha512-GjyNDq9NcSIvZcBUxJ8BqeW5TSGjoI3GJfK+dzI5KiMyk5Pd//aC30q64gSwZc9e4+4HhLUePnDgdW1l3osj7Q==","signatures":[{"sig":"MEYCIQCyzUcCu3xhr1lFukui7gb18yUW1zUa3IdD6DJfBJorowIhAOLMC5I5wXfFeXXkSxn3iAV3aXCFBWIGvFYTXz7niXFA","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1260448},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./api":{"types":"./dist/api.d.ts","import":"./dist/api.js"},"./cli":{"import":"./dist/cli/index.js"}},"gitHead":"6e7582dfdadbf461d5eb2dfbe911565a7a0c9e3a","scripts":{"dev":"tsx src/cli/index.ts","lint":"eslint src/","test":"vitest run","build":"tsc -p tsconfig.build.json","dlp:test":"tsx scripts/dlp-test-env.ts","test:watch":"vitest","dlp:test:warn":"tsx scripts/dlp-test-env.ts --action warn","test:coverage":"vitest run --coverage","dlp:test:block":"tsx scripts/dlp-test-env.ts --action block","prepublishOnly":"npm run build","dlp:test:redact":"tsx scripts/dlp-test-env.ts --action redact","dlp:test:interactive":"tsx scripts/dlp-test-env.ts --interactive"},"_npmUser":{"name":"aion0","email":"aiwatching2024@gmail.com"},"repository":{"url":"git+https://github.com/aiwatching/bastion.git","type":"git"},"_npmVersion":"10.9.3","description":"Local-first AI gateway for proxying and securing LLM provider requests","directories":{},"_nodeVersion":"22.20.0","dependencies":{"js-yaml":"^4.1.0","commander":"^13.1.0","node-forge":"^1.3.3","better-sqlite3":"^11.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.3","vitest":"^3.0.5","typescript":"^5.7.3","@types/node":"^22.13.4","@types/js-yaml":"^4.0.9","@types/node-forge":"^1.3.14","@types/better-sqlite3":"^7.6.12"},"_npmOperationalInternal":{"tmp":"tmp/bastion_0.1.13_1772860970251_0.3742284648768872","host":"s3://npm-registry-packages-npm-production"}},"0.1.14":{"name":"@aion0/bastion","version":"0.1.14","keywords":["ai","gateway","proxy","llm","security","dlp","anthropic","openai","gemini"],"author":{"name":"aion0"},"license":"UNLICENSED","_id":"@aion0/bastion@0.1.14","maintainers":[{"name":"aion0","email":"aiwatching2024@gmail.com"}],"homepage":"https://github.com/aiwatching/bastion","bugs":{"url":"https://github.com/aiwatching/bastion/issues"},"bin":{"bastion":"dist/cli/index.js"},"dist":{"shasum":"7e2357c0ae2672d87dd2cfe59e827f33f4934b09","tarball":"https://registry.npmjs.org/@aion0/bastion/-/bastion-0.1.14.tgz","fileCount":440,"integrity":"sha512-f9J+JTrfQ7q+1GBMNj/7IQlmpOazi6eZtJeXEcdUzp8p/M+fBXE9xcPzRnJu1Q5uHvQKP3Aw2LoFPMhOGw4o4w==","signatures":[{"sig":"MEYCIQD6Pur3csh4VTxf3UCawHbRFmZMsKOmdDHL5DUxcOZhGgIhAOCIEuqpcUn1cewiT0pPbQ9E8sOyobuc+Nn5liBUDgh6","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1300908},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./api":{"types":"./dist/api.d.ts","import":"./dist/api.js"},"./cli":{"import":"./dist/cli/index.js"}},"gitHead":"9cdf502801b006bc6f275a03812fbb82e82a1544","scripts":{"dev":"tsx src/cli/index.ts","lint":"eslint src/","test":"vitest run","build":"tsc -p tsconfig.build.json","dlp:test":"tsx scripts/dlp-test-env.ts","test:watch":"vitest","dlp:test:warn":"tsx scripts/dlp-test-env.ts --action warn","test:coverage":"vitest run --coverage","dlp:test:block":"tsx scripts/dlp-test-env.ts --action block","prepublishOnly":"npm run build","dlp:test:redact":"tsx scripts/dlp-test-env.ts --action redact","dlp:test:interactive":"tsx scripts/dlp-test-env.ts --interactive"},"_npmUser":{"name":"aion0","email":"aiwatching2024@gmail.com"},"repository":{"url":"git+https://github.com/aiwatching/bastion.git","type":"git"},"_npmVersion":"10.9.3","description":"Local-first AI gateway for proxying and securing LLM provider requests","directories":{},"_nodeVersion":"22.20.0","dependencies":{"js-yaml":"^4.1.0","commander":"^13.1.0","node-forge":"^1.3.3","better-sqlite3":"^11.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.3","vitest":"^3.0.5","typescript":"^5.7.3","@types/node":"^22.13.4","@types/js-yaml":"^4.0.9","@types/node-forge":"^1.3.14","@types/better-sqlite3":"^7.6.12"},"_npmOperationalInternal":{"tmp":"tmp/bastion_0.1.14_1772871284082_0.957410467760389","host":"s3://npm-registry-packages-npm-production"}},"0.1.15":{"name":"@aion0/bastion","version":"0.1.15","keywords":["ai","gateway","proxy","llm","security","dlp","anthropic","openai","gemini"],"author":{"name":"aion0"},"license":"UNLICENSED","_id":"@aion0/bastion@0.1.15","maintainers":[{"name":"aion0","email":"aiwatching2024@gmail.com"}],"homepage":"https://github.com/aiwatching/bastion","bugs":{"url":"https://github.com/aiwatching/bastion/issues"},"bin":{"bastion":"dist/cli/index.js"},"dist":{"shasum":"032863f77d9a956ca184be4ff870edce236ba3aa","tarball":"https://registry.npmjs.org/@aion0/bastion/-/bastion-0.1.15.tgz","fileCount":440,"integrity":"sha512-6b9mkhWzflyVctjPYtVsRi5ZMKWkoFrLfzqF5JqlziNlx3SWPaIh+JbTnm8UvrtjITLgRM5aEDZd/EqJWFtZTg==","signatures":[{"sig":"MEUCIF1jeaPeHfkNkLmLquR0iB4RPfF21kULiktyPsbCUW3jAiEAwOpkFXpC1NSJ13lncl6nHZorRNWp7aBfchOV0Pel9kQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1301277},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./api":{"types":"./dist/api.d.ts","import":"./dist/api.js"},"./cli":{"import":"./dist/cli/index.js"}},"gitHead":"67c7b19d417c1ada542cde2c2e6e2522d4e63050","scripts":{"dev":"tsx src/cli/index.ts","lint":"eslint src/","test":"vitest run","build":"tsc -p tsconfig.build.json","dlp:test":"tsx scripts/dlp-test-env.ts","test:watch":"vitest","dlp:test:warn":"tsx scripts/dlp-test-env.ts --action warn","test:coverage":"vitest run --coverage","dlp:test:block":"tsx scripts/dlp-test-env.ts --action block","prepublishOnly":"npm run build","dlp:test:redact":"tsx scripts/dlp-test-env.ts --action redact","dlp:test:interactive":"tsx scripts/dlp-test-env.ts --interactive"},"_npmUser":{"name":"aion0","email":"aiwatching2024@gmail.com"},"repository":{"url":"git+https://github.com/aiwatching/bastion.git","type":"git"},"_npmVersion":"10.9.3","description":"Local-first AI gateway for proxying and securing LLM provider requests","directories":{},"_nodeVersion":"22.20.0","dependencies":{"js-yaml":"^4.1.0","commander":"^13.1.0","node-forge":"^1.3.3","better-sqlite3":"^11.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.3","vitest":"^3.0.5","typescript":"^5.7.3","@types/node":"^22.13.4","@types/js-yaml":"^4.0.9","@types/node-forge":"^1.3.14","@types/better-sqlite3":"^7.6.12"},"_npmOperationalInternal":{"tmp":"tmp/bastion_0.1.15_1772873381288_0.956796541541574","host":"s3://npm-registry-packages-npm-production"}},"0.1.16":{"name":"@aion0/bastion","version":"0.1.16","description":"Local-first AI gateway for proxying and securing LLM provider requests","main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"},"./api":{"import":"./dist/api.js","types":"./dist/api.d.ts"},"./cli":{"import":"./dist/cli/index.js"}},"bin":{"bastion":"dist/cli/index.js"},"scripts":{"build":"tsc -p tsconfig.build.json","dev":"tsx src/cli/index.ts","test":"vitest run","test:watch":"vitest","test:coverage":"vitest run --coverage","lint":"eslint src/","prepublishOnly":"npm run build","dlp:test":"tsx scripts/dlp-test-env.ts","dlp:test:block":"tsx scripts/dlp-test-env.ts --action block","dlp:test:redact":"tsx scripts/dlp-test-env.ts --action redact","dlp:test:warn":"tsx scripts/dlp-test-env.ts --action warn","dlp:test:interactive":"tsx scripts/dlp-test-env.ts --interactive"},"keywords":["ai","gateway","proxy","llm","security","dlp","anthropic","openai","gemini"],"author":{"name":"aion0"},"license":"UNLICENSED","homepage":"https://github.com/aiwatching/bastion","repository":{"type":"git","url":"git+https://github.com/aiwatching/bastion.git"},"publishConfig":{"access":"public"},"dependencies":{"better-sqlite3":"^11.7.0","commander":"^13.1.0","js-yaml":"^4.1.0","node-forge":"^1.3.3"},"devDependencies":{"@types/better-sqlite3":"^7.6.12","@types/js-yaml":"^4.0.9","@types/node":"^22.13.4","@types/node-forge":"^1.3.14","tsx":"^4.19.3","typescript":"^5.7.3","vitest":"^3.0.5"},"engines":{"node":">=20.0.0"},"_id":"@aion0/bastion@0.1.16","gitHead":"ae0b635ff96e63be9309603160cd1c5378ad7105","bugs":{"url":"https://github.com/aiwatching/bastion/issues"},"_nodeVersion":"22.20.0","_npmVersion":"10.9.3","dist":{"integrity":"sha512-98zleWL+Tf+iZDNfje1U4TfmEjJb4I0Ck40F9dz0i0cen/aM8FjeqF3Ax7v/pBcOKGX86J2P49m1VYJNXRNQTw==","shasum":"528c4aaad96a411038612533d5d9c4473848b9e7","tarball":"https://registry.npmjs.org/@aion0/bastion/-/bastion-0.1.16.tgz","fileCount":444,"unpackedSize":1425434,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCICITHE0DS6SYn22363mdGAvfJHJ5n3VCxs96GkSmVpwsAiEA42eMmvMAHvJMzLNysYEq9nK2/FMBEQvF/hvxLwBRKJs="}]},"_npmUser":{"name":"aion0","email":"aiwatching2024@gmail.com"},"directories":{},"maintainers":[{"name":"aion0","email":"aiwatching2024@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/bastion_0.1.16_1773164390122_0.932105857421865"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-02T03:42:55.469Z","modified":"2026-03-10T17:39:50.522Z","0.1.7":"2026-03-02T03:42:55.756Z","0.1.9":"2026-03-02T18:42:21.919Z","0.2.0":"2026-03-02T22:18:05.741Z","0.1.10":"2026-03-02T22:19:56.041Z","0.1.11":"2026-03-02T22:37:54.127Z","0.1.12":"2026-03-06T04:08:26.091Z","0.1.13":"2026-03-07T05:22:50.443Z","0.1.14":"2026-03-07T08:14:44.440Z","0.1.15":"2026-03-07T08:49:41.488Z","0.1.16":"2026-03-10T17:39:50.391Z"},"bugs":{"url":"https://github.com/aiwatching/bastion/issues"},"author":{"name":"aion0"},"license":"UNLICENSED","homepage":"https://github.com/aiwatching/bastion","keywords":["ai","gateway","proxy","llm","security","dlp","anthropic","openai","gemini"],"repository":{"type":"git","url":"git+https://github.com/aiwatching/bastion.git"},"description":"Local-first AI gateway for proxying and securing LLM provider requests","maintainers":[{"name":"aion0","email":"aiwatching2024@gmail.com"}],"readme":"[English](README.md) | **中文**\n\n# Bastion AI Gateway\n\n本地优先的 LLM 提供商代理（Anthropic、OpenAI、Gemini）。提供 DLP 扫描、工具调用监控、使用量统计、费用追踪和响应缓存——全部在本机运行。\n\n![Overview](docs/overview.png \"Overview\")\n\n![DLP Findings](docs/dlp-finding-v1.jpeg \"DLP Findings\")\n\n![Audit Log](docs/auditlog.png \"Audit Log\")\n\n\n## 安装\n\n```bash\n# npm（推荐）\nnpm install -g @aion0/bastion\n\n# macOS / Linux（从源码安装）\ncurl -fsSL https://raw.githubusercontent.com/aiwatching/bastion/main/install.sh | bash\n\n# Windows (PowerShell，从源码安装)\nirm https://raw.githubusercontent.com/aiwatching/bastion/main/install.ps1 -OutFile install.ps1; .\\install.ps1\n```\n\n需要 **Node.js 22 LTS**（推荐）。Node.js 18+ 可用，但非 LTS 版本可能需要[额外配置](docs/windows-troubleshooting.zh.md#1-better-sqlite3-编译失败非-lts-nodejs)。\n\n## 快速开始\n\n```bash\n# 启动网关\nbastion start\n\n# 方式 A：包裹单个命令（代理仅作用于该进程）\nbastion wrap claude\nbastion wrap python my_app.py\n\n# 方式 B：全局代理（所有终端、所有新进程、GUI 应用）\neval $(bastion proxy on)          # bash/zsh\nbastion proxy on | Invoke-Expression  # PowerShell\n```\n\n## OpenClaw 集成\n\nBastion 可以代理 [OpenClaw](https://github.com/openclaw/openclaw) 实例的所有 AI 流量（Docker 和本地均支持），提供 DLP 扫描、费用追踪和审计日志。\n\n### Docker\n\n```bash\n# 创建并启动 OpenClaw 实例，自动配置 Bastion 代理\nbastion openclaw docker up mywork \\\n  --port 18789 \\\n  --image openclaw:local \\\n  --config-dir ~/openclaw-data/mywork/config \\\n  --workspace ~/openclaw-data/mywork/workspace\n\n# 管理实例\nbastion openclaw docker status        # 查看所有实例\nbastion openclaw docker stop mywork   # 停止\nbastion openclaw docker logs mywork -f  # 实时日志\n```\n\n完整指南：[OpenClaw Docker 集成](docs/openclaw-docker.zh.md) | [English](docs/openclaw-docker.md)\n\n### 本地运行\n\n```bash\n# 本地启动 OpenClaw 并通过 Bastion 代理\nbastion openclaw local start mywork --port 18789\n\n# 管理\nbastion openclaw local status\nbastion openclaw local stop mywork\n```\n\n完整指南：[OpenClaw 本地安装](docs/openclaw-local.zh.md) | [English](docs/openclaw-local.md)\n\n### 接入已有容器\n\n```bash\n# 将 Bastion 代理注入到运行中的 Docker 容器\nbastion openclaw docker attach <container-name>\n```\n\n### OpenClaw Skills\n\n安装 [`@aion0/bastion-skills`](https://www.npmjs.com/package/@aion0/bastion-skills) 后，可通过自然语言在 OpenClaw 中管理 Bastion——启停网关、查看 DLP 发现、工具调用告警和用量统计。\n\n```bash\nopenclaw skill install @aion0/bastion-skills\n```\n\nDocker 环境下，skill 内置的 setup 脚本会自动 patch `docker-compose.yml`，通过 `HTTPS_PROXY` 将所有 LLM 流量路由经 Bastion：\n\n```bash\nbash ~/.openclaw/skills/bastion/scripts/docker-setup.sh\n```\n\n详见 [@aion0/bastion-skills (GitHub)](https://github.com/aiwatching/bastion-skills)\n\n## 使用方法\n\n### `bastion start`\n\n启动网关（默认后台守护进程模式）。\n\n```bash\nbastion start              # 后台守护进程\nbastion start --foreground # 前台运行（实时查看日志）\nbastion start -p 9000      # 自定义端口\n```\n\n### `bastion stop`\n\n```bash\nbastion stop\n```\n\n### `bastion proxy on/off/status`\n\n全局代理模式——将**所有** AI 流量通过 Bastion 路由，包括后台进程和 GUI 应用。\n\n```bash\neval $(bastion proxy on)              # bash/zsh：启用\neval $(bastion proxy off)             # bash/zsh：禁用\nbastion proxy on | Invoke-Expression  # PowerShell：启用\nbastion proxy off | Invoke-Expression # PowerShell：禁用\nbastion proxy status                  # 检查当前代理状态\n```\n\n`bastion proxy on` 做了什么：\n1. 将代理环境变量写入 shell 配置文件（`~/.zshrc` / `~/.bashrc` / PowerShell `$PROFILE`）——新终端自动继承\n2. 设置系统 HTTPS 代理（macOS `networksetup`、Linux GNOME `gsettings`、Windows 注册表）——GUI 应用也通过 Bastion 路由\n3. 向 stdout 输出对应 shell 语法的命令——通过 `eval` / `Invoke-Expression` 使当前 shell 立即生效\n\n设置的环境变量：\n\n| Variable | Purpose |\n|----------|---------|\n| `HTTPS_PROXY` | Standard proxy (curl, Python, Go, etc.) |\n| `NO_PROXY` | Excludes OAuth/auth domains |\n| `NODE_EXTRA_CA_CERTS` | Node.js tools trust Bastion CA cert |\n| `ANTHROPIC_BASE_URL` | Anthropic SDK direct connection |\n| `OPENAI_BASE_URL` | OpenAI SDK direct connection |\n| `GOOGLE_AI_BASE_URL` | Google AI SDK direct connection |\n\n选项：\n- `--no-system` — 跳过设置系统代理\n- `--trust-ca` — 将 CA 证书添加到系统信任存储（需要 sudo）\n\n> **注意：** `bastion stop` 会自动移除指向 Bastion 的系统代理设置，防止网络中断。\n\n支持平台：macOS、Linux（GNOME 桌面支持系统代理；无桌面服务器直接使用 `HTTPS_PROXY` 环境变量）、Windows（系统代理通过注册表设置；自动配置 PowerShell profile）。\n\n### `bastion wrap <command>`\n\n通过 Bastion 路由 AI 流量来运行单个命令。代理设置仅作用于该进程。\n\n```bash\nbastion wrap claude\nbastion wrap python app.py\nbastion wrap node server.js\n```\n\n选项：\n- `--base-url` — 使用 `ANTHROPIC_BASE_URL` 模式代替 `HTTPS_PROXY`（更简单但会影响 OAuth）\n- `--label <name>` — 用于 Dashboard 追踪的可读会话标签\n\n### `bastion env`\n\n打印 shell 环境变量导出命令，用于手动设置代理。\n\n```bash\neval $(bastion env)                        # bash/zsh\nbastion env --powershell | Invoke-Expression  # PowerShell\neval $(bastion env --unset)                # bash/zsh：取消设置\nbastion env --powershell --unset | Invoke-Expression  # PowerShell：取消设置\n```\n\n### `bastion stats`\n\n查看使用统计（请求数、费用、token 数、延迟）。\n\n```bash\nbastion stats\n```\n\n### `bastion health`\n\n检查网关是否正在运行。\n\n```bash\nbastion health\n```\n\n### `bastion trust-ca`\n\n显示 CA 证书信息，用于手动信任配置。\n\n```bash\nbastion trust-ca\n```\n\n## Dashboard\n\n网关运行时，在浏览器中打开 `http://127.0.0.1:8420/dashboard`。\n\n6 个标签页：\n- **Overview** — 请求指标、费用、token 数、按提供商/模型/会话分类的统计、威胁仪表盘\n- **DLP** — 子标签：Findings（方向、片段、钻取至审计记录）、Config（引擎开关、动作模式、AI 验证、语义规则）、Signatures（远程同步状态、版本追踪、变更日志、模式管理）、Test（独立扫描器，含预设、trace 日志）\n- **Tool Guard** — 子标签：Calls（最近工具调用历史，含严重级别、规则匹配、执行动作）、Rules（26 条内置规则 + 自定义规则管理，可逐条启用/禁用）、威胁会话、链式检测\n- **Optimizer** — 缓存命中率、节省的 token 数\n- **Audit** — 基于会话的时间线、DLP/Tool Guard 标记条目、摘要预览、格式化请求/响应查看器\n- **Settings** — 切换 plugin、可选功能管理，运行时修改无需重启\n\n## 工作原理\n\nBastion 作为 HTTPS 代理运行，对特定域名进行选择性 MITM（中间人）拦截：\n\n- **API 域名**（`api.anthropic.com`、`api.openai.com`、`generativelanguage.googleapis.com`、`claude.ai`、`api.telegram.org`、`discord.com`、`api.slack.com` 等）——流量被解密，通过 plugin 管线处理（DLP、指标、缓存），然后转发至真实上游。\n- **其他所有域名**——纯 TCP 隧道，不做任何检查。OAuth 流程、浏览器流量等原样通过。\n\n本地 CA 证书（`~/.bastion/ca.crt`）会自动生成。Node.js 工具通过 `NODE_EXTRA_CA_CERTS` 信任该证书。\n\n## Plugins\n\n### Metrics Collector\n记录每个 API 请求的提供商、模型、token 数、费用、延迟。数据存储在 SQLite（`~/.bastion/bastion.db`）中。支持按会话和 API key 过滤。\n\n### DLP Scanner\n双向扫描——同时检查**发出的请求**和**收到的响应**中的敏感数据。非流式响应在发送前拦截（可在到达客户端之前阻止/脱敏）。流式响应在发送后扫描（仅检测和审计）。\n\n任何 DLP 命中都会自动创建审计日志条目，包含完整的请求/响应内容，无论 Audit Logger plugin 是否启用。DLP 标记的审计条目在 Dashboard 中会有视觉标识。\n\n引擎使用 5 层检测管线（结构解析 -> 熵过滤 -> 正则匹配 -> 字段名语义分析 -> AI 验证）。详见 [DLP 引擎架构](docs/dlp.zh.md)。\n\n**内置模式（20 个）：**\n\n| Category | Patterns |\n|----------|----------|\n| `high-confidence` | AWS Access Key, AWS Secret Key, GitHub PAT, GitHub Fine-grained PAT, Slack Token, Stripe Secret Key, Private Key, OpenAI API Key, Anthropic API Key, Google AI / Gemini API Key, Hugging Face Token, Replicate API Token, Groq API Key, Perplexity API Key, xAI (Grok) API Key, Cohere / Mistral / Together AI API Key (context-aware), Azure OpenAI API Key (context-aware), Telegram Bot Token |\n| `validated` | Credit Card (Luhn check), US SSN (structural validation) |\n| `context-aware` | Email Address, Phone Number, IPv4 Address, Driver License, Passport Number |\n\n模式存储在 SQLite 中，可通过 Dashboard 管理（启用/禁用、添加自定义模式），无需重启。内置模式在首次启动时自动初始化。\n\n**远程签名库：**\n模式也可以从远程 Git 仓库（[bastion_signature](https://github.com/aiwatching/bastion_signature)）同步，支持独立版本控制和自动更新检测。详见 [远程签名库](docs/remote-signatures.zh.md)。\n\n**通用密钥检测：**\n敏感字段名（如 `password`、`secret`、`api_key`）中的高熵值即使没有特定正则模式也能被检测到。敏感性规则和非敏感字段名可在运行时配置。\n\n**AI 验证（可选，默认关闭）：**\n使用 LLM 过滤误报。在配置中填入 API key 即可启用——结果会被缓存（LRU）以减少 token 消耗。\n\n**独立扫描 API：**\n```bash\ncurl -X POST http://127.0.0.1:8420/api/dlp/scan \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"text\": \"my key is sk-ant-abc123...\", \"action\": \"warn\", \"trace\": true}'\n```\n\n传入 `\"trace\": true` 可获取检测管线的详细逐步 trace 日志（用于调试模式行为）。\n\n在 `~/.bastion/config.yaml` 中配置：\n```yaml\nplugins:\n  dlp:\n    action: \"warn\"    # pass | warn | redact | block\n    patterns:\n      - \"high-confidence\"\n      - \"validated\"\n      - \"context-aware\"\n    remotePatterns:\n      url: \"https://github.com/aiwatching/bastion_signature.git\"  # leave empty to disable\n      branch: \"auto\"          # \"auto\" = match Bastion VERSION, or explicit e.g. \"v0.1.0\"\n      syncOnStart: true       # pull latest on startup\n      syncIntervalMinutes: 0  # 0 = startup only, >0 = periodic sync (minutes)\n    aiValidation:\n      enabled: false          # set to true to enable LLM-based false positive filtering\n      provider: \"anthropic\"   # anthropic | openai\n      model: \"claude-haiku-4-5-20241022\"\n      apiKey: \"\"              # required if enabled\n    semantics:\n      sensitivePatterns: []   # extra regex patterns for sensitive field names\n      nonSensitiveNames: []   # extra field names to exclude from detection\n```\n\n### Tool Guard\n实时监控和阻断 AI Agent 发起的危险工具调用。检查 LLM 响应中的工具调用（Anthropic `tool_use`、OpenAI `tool_calls`、Gemini `functionCall`），并根据可配置的规则进行评估。\n\n两种动作模式：\n- **audit** — 记录所有工具调用，标记危险调用（不阻断）\n- **block** — 实时阻断危险工具调用。流式响应中，`StreamingToolGuard` 拦截 SSE 事件，将被阻断的工具调用替换为文本警告。非流式响应中，整个响应在到达客户端之前被阻止。\n\n**内置规则（26 条）：**\n\n| 类别 | 规则 | 严重级别 |\n|------|------|----------|\n| `destructive-fs` | 递归删除根目录/home、通配符递归删除、chmod 777、格式化文件系统、dd 写入块设备 | critical / high |\n| `code-execution` | curl 管道到 shell、wget 管道到 shell、eval() 动态输入、base64 解码执行 | critical / high |\n| `credential-access` | 读取 .env 文件、访问私钥、访问 AWS 凭证、输出敏感环境变量 | high |\n| `network-exfil` | curl POST 发送数据、向裸 IP 传输数据 | medium / high |\n| `git-destructive` | git force push、git reset --hard、git clean -f | high / medium |\n| `package-publish` | npm publish、pip/twine upload | medium |\n| `system-config` | sudo 命令、iptables 修改、systemctl 服务控制 | medium |\n| `file-delete` | 文件/目录删除 (rm) | medium |\n| `file-write-outside` | 写入 /etc/、写入 /usr/ | low |\n\n规则存储在 SQLite 中，可通过 Dashboard 管理（启用/禁用、添加自定义规则），无需重启。内置规则在首次启动时自动初始化，可单独禁用但不可删除。\n\n支持桌面通知和 Webhook 告警（针对高严重级别匹配）。\n\n在 `~/.bastion/config.yaml` 中配置：\n```yaml\nplugins:\n  toolGuard:\n    enabled: true\n    action: \"audit\"       # audit | block\n    recordAll: true       # 记录所有工具调用（不仅是标记的）\n    blockMinSeverity: \"critical\"  # 阻断的最低严重级别（action=block 时生效）\n    alertMinSeverity: \"high\"      # 告警的最低严重级别\n    alertDesktop: true             # macOS 桌面通知\n    alertWebhookUrl: \"\"            # Webhook URL（Slack、Discord 等）\n```\n\n### Token Optimizer\n- **响应缓存** — 对相同请求进行精确匹配缓存（AES-256-GCM 加密）\n- **空白压缩** — 折叠多余空白以节省 token\n\n### 威胁情报\n会话级威胁评分，多信号关联分析。聚合 DLP、Tool Guard、Prompt Injection 检测事件，为每个会话生成统一威胁分数。\n\n- **链式检测** — 检测多步攻击模式（如凭证访问后跟网络外泄）\n- **污点追踪** — 跟踪敏感数据指纹在工具调用间的流动，检测数据流违规\n- **威胁等级** — normal / elevated / high / critical，指数衰减评分\n- **3 条内置链式规则** — 凭证→外泄、执行→破坏、凭证→发布\n\n### Audit Logger\n存储请求/响应内容（静态加密）以供在 Dashboard 中查看。可配置保留期限，自动清理。即使此 plugin 未启用，DLP 命中也会自动记录审计日志。\n\n- **摘要** — 始终存储（可配置最大大小），在列表中显示为预览\n- **原始数据** — 完整加密内容，默认启用，可禁用以节省空间\n\n## 配置\n\n默认配置：`config/default.yaml`。通过创建 `~/.bastion/config.yaml` 来覆盖：\n\n```yaml\nserver:\n  host: \"127.0.0.1\"\n  port: 8420\n\nlogging:\n  level: \"info\"       # debug | info | warn | error\n\nplugins:\n  metrics:\n    enabled: true\n  dlp:\n    enabled: true\n    action: \"block\"    # pass | warn | redact | block\n    patterns:\n      - \"high-confidence\"\n      - \"validated\"\n      - \"context-aware\"\n    remotePatterns:\n      url: \"\"\n      branch: \"auto\"\n      syncOnStart: true\n      syncIntervalMinutes: 0\n    aiValidation:\n      enabled: false\n      provider: \"anthropic\"   # anthropic | openai\n      model: \"claude-haiku-4-5-20241022\"\n      apiKey: \"\"\n      timeoutMs: 5000\n      cacheSize: 500\n    semantics:\n      sensitivePatterns: []\n      nonSensitiveNames: []\n  optimizer:\n    enabled: true\n    cache: true\n    cacheTtlSeconds: 300\n    trimWhitespace: true\n    reorderForCache: true\n  audit:\n    enabled: true\n    retentionHours: 168    # 7 days\n    rawData: true          # store full encrypted content\n    rawMaxBytes: 524288    # 512KB max per entry\n    summaryMaxBytes: 1024  # 1KB summary\n  toolGuard:\n    enabled: true\n    action: \"audit\"        # audit | block\n    recordAll: true        # 记录所有工具调用，不仅是标记的\n    blockMinSeverity: \"critical\"  # 阻断的最低严重级别\n    alertMinSeverity: \"high\"      # 告警的最低严重级别\n    alertDesktop: true\n    alertWebhookUrl: \"\"\n\ntimeouts:\n  upstream: 120000     # 2 minutes\n  plugin: 50           # 50ms per plugin\n```\n\n环境变量覆盖：\n```bash\nBASTION_PORT=9000 bastion start\nBASTION_HOST=0.0.0.0 bastion start\nBASTION_LOG_LEVEL=debug bastion start\n```\n\n## API\n\n网关运行时，所有端点可通过 `http://127.0.0.1:8420` 访问。\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| `GET` | `/api/stats` | Usage statistics (requests, tokens, cost). Query params: `session_id`, `api_key_hash`, `hours` |\n| `GET` | `/api/sessions` | List tracked sessions |\n| `GET` | `/api/dlp/recent?limit=50&since=ISO` | Recent DLP findings. `since` returns only newer findings (for polling) |\n| `POST` | `/api/dlp/scan` | Standalone DLP scan (body: `{\"text\": \"...\", \"action\": \"warn\", \"trace\": true}`) |\n| `GET` | `/api/dlp/patterns` | List all DLP patterns |\n| `POST` | `/api/dlp/patterns` | Add custom pattern |\n| `PUT` | `/api/dlp/patterns/:id` | Update pattern (toggle enabled, edit fields) |\n| `DELETE` | `/api/dlp/patterns/:id` | Delete custom pattern (built-ins cannot be deleted) |\n| `POST` | `/api/dlp/config/apply` | Batch-apply DLP config and record history |\n| `GET` | `/api/dlp/config/history` | Last 10 DLP config changes |\n| `POST` | `/api/dlp/config/restore/:id` | Restore a previous DLP config snapshot |\n| `GET` | `/api/dlp/semantics/builtins` | Read-only built-in semantic rules |\n| `GET` | `/api/dlp/signature` | Signature version info. `?check=true` to check remote for updates |\n| `POST` | `/api/dlp/signature/sync` | Trigger manual sync of remote signature patterns |\n| `GET` | `/api/audit/recent?limit=50` | Recent audit entries |\n| `GET` | `/api/audit/sessions` | Audit sessions list |\n| `GET` | `/api/audit/session/:id` | Parsed timeline for a session |\n| `GET` | `/api/audit/:requestId` | Single request detail (parsed or summary-only fallback) |\n| `GET` | `/api/tool-guard/recent?limit=50` | 最近的工具调用记录 |\n| `GET` | `/api/tool-guard/stats` | 按严重级别、类别、工具名称统计 |\n| `GET` | `/api/tool-guard/session/:id` | 指定会话的工具调用 |\n| `GET` | `/api/tool-guard/rules` | 列出所有规则（内置 + 自定义） |\n| `POST` | `/api/tool-guard/rules` | 添加自定义规则 |\n| `PUT` | `/api/tool-guard/rules/:id` | 更新规则（切换启用、编辑字段） |\n| `DELETE` | `/api/tool-guard/rules/:id` | 删除自定义规则（内置规则不可删除） |\n| `GET` | `/api/tool-guard/alerts` | 最近告警及未确认数量 |\n| `POST` | `/api/tool-guard/alerts/ack` | 确认所有告警 |\n| `GET` | `/api/optimizer/stats` | Cache hit rate and tokens saved |\n| `GET` | `/api/optimizer/recent?limit=50` | Recent optimizer events |\n| `GET` | `/api/config` | Current configuration + plugin status |\n| `PUT` | `/api/config` | Update configuration at runtime |\n\n## 可选插件\n\nBastion 核心检测能力完全免费。如需基于 ML 的检测（ONNX Runtime，~436 MB 模型），可安装可选插件包：\n\n```bash\nbastion plugins install          # 自动检测同级 bastion-plugin-api 目录\nbastion plugins list             # 查看已安装插件\nbastion plugins uninstall        # 卸载（会提示是否同时删除模型文件）\n```\n\n也可通过 Dashboard → Settings → Optional Features 管理。\n\n详见 [@aion0/bastion-plugin-api](https://github.com/aiwatching/bastion-plugin-api)。\n\n## 文档\n\n- [DLP 引擎架构](docs/dlp.zh.md) — 5 层检测管线详解\n- [OpenClaw Docker 集成](docs/openclaw-docker.zh.md) — Docker Compose 配置（全新安装 + 已有环境）\n- [OpenClaw 本地安装](docs/openclaw-local.zh.md) — 使用 Bastion 代理原生运行 OpenClaw\n- [AI Agent 监控](docs/agent-monitoring.zh.md) — 监控任何本地 AI Agent（Claude Code、Cursor、自定义应用）\n- [远程签名库](docs/remote-signatures.zh.md) — 从 Git 仓库远程同步 DLP 模式\n- [OpenClaw DLP 告警 Skill](docs/openclaw-dlp-skill.zh.md) — 让 OpenClaw 通过 Telegram/Discord 通知 DLP 发现\n- [安全调研](docs/security-research.zh.md) — AI Agent 威胁态势、Bastion 能力分析与路线图\n- [Windows 故障排除](docs/windows-troubleshooting.zh.md) — Windows 常见问题及解决方案\n\n## 数据存储\n\n所有数据存储在本地 `~/.bastion/` 目录下：\n\n```\n~/.bastion/\n  bastion.db    # SQLite database (metrics, cache, DLP events, audit log)\n  config.yaml   # User config overrides (created by bastion proxy on / dashboard settings)\n  ca.key        # CA private key\n  ca.crt        # CA certificate\n  certs/        # Generated host certificates\n  .key          # AES encryption key for cache & audit\n  bastion.pid   # Daemon PID file\n  bastion.log   # Daemon log file\n  models/       # ML 模型（可选，安装插件后 ~436 MB）\n```\n","readmeFilename":"README.zh.md"}