Files
treg/examples/proxy-demo
UncleCode 5eefdab07e release: v0.7.0 — the local proxy, the catalog, and an install that needs no manual step
Replaces PR #40, which sat parked while main moved 85 commits ahead of it. Its own changes were only
201 lines, so re-applying them onto today's main was cleaner than rebasing 85 commits — and they
merged without conflict.

What ships, a week of work rather than one feature:

  * the LOCAL PROXY — `treg claude`, `treg node app.js`, `treg shell --proxy`, `treg serve`: put treg
    in front of any command and its calls to registered hosts are credentialed server-side;
  * the CATALOG as the front door — `treg catalog search/get`, `treg call <endpoint-id>`,
    `treg balance`, `treg topup`, the reordered help shelf, and onboarding that makes a real call
    instead of seeding a fake echo tool;
  * capability choice — observed success rate, latency and last-answered per endpoint, the decision
    procedure in llms.txt and skill.md, and `treg org pin/pins/unpin`;
  * Jason's platform keys + prepaid balance, the endpoint catalog and agent identity.

The install fix is the reason this is not just a version bump. `pip install "tools-registry[proxy]"`
is right for exactly ONE of the four ways treg is installed, and install.sh's own way is not it — a
uv-tool or Homebrew venv is not on the ambient pip's path, so that advice silently does nothing. Now
install.sh pulls the extra by default, and when the certificate library is missing treg offers to
install it correctly for THAT install and carries on.

Release checks: wheel + sdist built, light install verified (no fastapi/uvicorn/sqlmodel/asyncpg/
stripe, and cryptography correctly absent from the base since it is the [proxy] extra), twine check
PASSED on both artifacts, sdist carries no .env/db/.claude. 1184 tests pass.
2026-08-07 17:10:22 +08:00
..

treg proxy demo

A tiny web app that calls a real API it has no key for. Click a button, see who answers.

The point of the demo is that the code does not change between the two runs. server.js never mentions treg, never reads a secret, and has no dependencies. The credential appears only because treg is the parent process.

Run it

node server.js          # plain: the call goes out as-is
treg node server.js     # the same code, credentialed by your team

Open http://localhost:3000 and click Call api.openai.com.

Run What OpenAI answers
node server.js 401 — Missing bearer authentication in header. No key, no call.
treg node server.js 200 and the real model list. treg injected your team's key on the server.

The second button calls example.com, which is not a registered tool. It returns 200 either way: an address treg does not know is tunnelled without being read. That is the other half of the promise.

Requires the api.openai.com tool to be registered in your active team (treg tool ls). Any registered host works — edit TARGETS at the top of server.js.

One honest wrinkle: Node and proxies

Node's built-in fetch ignores HTTPS_PROXY until Node 24, where NODE_USE_ENV_PROXY=1 (which treg sets) turns it on. On Node 23 or older, a plain fetch() walks straight past the proxy and you get the same 401 under treg as without it.

So this demo speaks to the proxy explicitly — CONNECT, then TLS over the tunnel — in throughProxy(). About 30 lines, written out only so the demo runs on any Node version.

Real apps do not need that. Every common HTTP client already reads the environment: axios, got, undici's ProxyAgent, python-requests, httpx, curl, git. On Node 24+, so does fetch. Check with:

node --version          # 24 or newer → plain fetch() is captured