One endpoint, unchanged SDKs
Claude and OpenAI behind a single base URL. Your existing clients work as they are — switch which subscription serves a request without switching libraries.
Bring your own subscriptions
Your team already pays for Claude, ChatGPT, and OpenAI. When an agent fleet runs hard enough, a single plan stalls — and the work stops mid-flight. Penstock keeps those subscriptions in a vault you hold, and routes across them from one endpoint.
That claim above is the Private Vault grade — credentials on hardware you control. It is the strongest rung of a three-rung custody ladder, and it is the only rung where "never left my machine" is literally true. The other two say so plainly.
Private, invite-gated beta.
SUBSCRIPTION STATES
Every state names its remedy inline. A state with no next action is a bug.
How it works
Penstock does not sell tokens and does not run provider accounts on your behalf. The capacity is yours; the control plane is what you are buying.
01
Install the local helper and pair it. Penstock walks a Commissioning Record — helper installed, lamp test, node paired, custody line verified, subscription connected, provider loop closed, tool loop closed — and each line stamps as it completes. Grades that use a home device add an egress linked stamp after custody verification. You confirm the redaction bars in the console match your own machine's output, so the custody claim is something you check rather than something we assert.
02
Sign in to Claude, ChatGPT, or an OpenAI API key through the helper, on your side of the line. The credential is written into your vault. Penstock receives the fact that a subscription exists and is usable — never the credential itself.
03
Set base_url to
api.penstock.run. Your existing OpenAI and Anthropic
SDKs work unchanged. Penstock picks a subscription with headroom, shapes and
retries the request, fails over to a sibling subscription when one is rate
limited, and writes a trace you can read.
Custody
Where your credential is allowed to live is a real trade-off, so Penstock detects what your hardware can do, defaults you to the strongest rung it supports, and states the trade-off plainly. It is not a topology quiz, and the honest answer is never buried.
Credential lives on hardware you control
Credential never leaves macbook-pro.local. Penstock
cannot read or refresh it remotely.
The only rung where "it never left my machine" is literally true.
Credential lives in a Penstock-operated cloud vault
Default when your hardware has no secure element
Credential is held in Penstock-operated cloud vault
vault-sfo12-b, not on hardware you control.
No custody proof is claimed for this rung, because there is none to show.
Credential lives in a cloud vault process
Explicit downgrade — gives up residential egress
Convenience mode — gives up residential egress. Credential is isolated in a cloud vault process, not on hardware you control.
Offered because it is sometimes the right call. It is the one rung that trades something away, so the console carries that trade-off as a standing marker for as long as this grade is in effect.
Penstock's own console draws the same three variants for your own vaults. If a claim on this page and a claim in the product ever disagree, the product is the one telling the truth.
Platform
Claude and OpenAI behind a single base URL. Your existing clients work as they are — switch which subscription serves a request without switching libraries.
Penstock tracks headroom per subscription and picks one that can serve. When a provider rate-limits, it fails over to a sibling subscription you connected — and demotes the limited one rather than dropping it.
Rolling 5-hour and weekly window meters per subscription, with reset countdowns, so an exhausted plan reads as capacity rather than as an error. Idle reads as zeroed meters — itself a signal.
Per-request traces with model, duration, outcome, and the subscription that served it. Drill into a live session to see its entries, the tools it invoked, and the context it matched.
Credentials and provider sessions stay behind your custody line. Penstock's control plane receives routing state and traces, never credential material — and its own surfaces show you where its visibility stops.
An opt-in memory layer that enriches a request with your team's own knowledge, so you can write shorter prompts and get project-aware answers. Off unless you turn it on, per org.
Zero data retention on the proxy path: your prompts are not used to train models and are not shared between customers.
Pricing
Penstock is not a token reseller — there is no Penstock inventory to buy. You keep paying your providers directly for the subscriptions you already have, and you pay Penstock to route, meter, trace, and govern across them. Tiers below describe structure; we set real numbers with you during beta.
For a small team pointing its first agents at a shared endpoint.
Most popular
For teams running agent fleets, where one plan stalls under load.
For organizations that have to answer for where credentials live.
Reliability target: 99.5% uptime on the control plane, designed to fail over across your connected subscriptions. Tier capabilities describe structure; final pricing is set with you during beta.
Penstock is in private, invite-gated beta. Tell us what you're running and we'll get you an endpoint, a key, and a vault to commission.