LightNow Local Proxy
The LightNow Local Proxy lets local MCP clients use one LightNow-managed MCP entry instead of storing every MCP server configuration and secret in every client.
It runs on your machine, uses your LightNow CLI login session, resolves the MCP
servers enabled for your selected LightNow profile, and forwards tool/resource
requests to local stdio or reachable Streamable HTTP MCP servers.
Install
Requirements:
- Python 3.11 or higher
pipx- a LightNow account
- the LightNow CLI
pipx install lightnow-cli
lightnow login
Install the proxy with Homebrew:
brew tap lightnow-ai/tap
brew install lightnow-proxy
Or install it with pipx:
pipx install lightnow-proxy
Or install it with uv:
uv tool install lightnow-proxy
The Python package installs the lightnow-proxy command used by MCP clients.
For repository-local development:
uv tool install --from . lightnow-proxy
Configure a Client
Use the LightNow CLI. It writes the client MCP entry and the per-client Local Proxy config.
lightnow sync --client codex --local-proxy
lightnow sync --client claude-desktop --local-proxy
lightnow sync --client cursor --local-proxy
lightnow sync --client vscode --local-proxy
lightnow sync --client antigravity --local-proxy
Restart the MCP client after syncing.
Multiple accounts and organizations
Use a distinct --connection alias for every account, organization or profile
that should appear in the same MCP client:
lightnow login
lightnow sync --client codex --local-proxy \
--connection lightnow-personal --profile default
# Sign in with the organization account before creating this connection.
lightnow login
lightnow sync --client codex --local-proxy \
--connection lightnow-acme --tenant <tenant-id> --profile engineering
Each generated proxy config has a stable connection ID and points to one named
CLI session under ~/.lightnow/sessions/. It also records the expected issuer
and subject. The proxy refuses Registry requests when those values do not
match, so a later CLI login cannot silently switch an existing connection. No
access or refresh token is written to the proxy YAML.
Check the local setup:
lightnow config-status --client codex
Check whether the proxy can resolve the selected profile and reach its upstream MCP servers:
lightnow-proxy --health
lightnow-proxy --health --json
By default this reads ~/.lightnow/lightnow-proxy/default.yaml, which is written
when the default profile is synced into Local Proxy mode. For a client-specific
config, pass the generated path explicitly:
lightnow-proxy --config ~/.lightnow/lightnow-proxy/codex.yaml --health
lightnow-proxy --config ~/.lightnow/lightnow-proxy/codex.yaml --health --json
Named connections use separate files such as
~/.lightnow/lightnow-proxy/codex-lightnow-acme.yaml. The JSON health report
shows their non-secret connection alias, ID, account label, scope, profile and
identity-binding status. Legacy configs that use cli_config_path remain
readable, but are restricted to the configured authentication issuer.
When telemetry is enabled, active health checks are sent to the LightNow Control Plane as metadata-only proxy health events. The proxy also sends device presence immediately at startup and every two minutes. The Control Plane can then show which devices, clients and profiles are active, healthy, degraded, or failing without storing secrets, tool arguments, response bodies, network addresses, hardware identifiers, or local paths.
Vault providers configured for runtime resolution are resolved on this host,
after Registry API has returned a provider reference without credentials or a
secret value. HashiCorp Vault Proxy auto-auth on 127.0.0.1:8200 is the
default. Provider-specific loopback listeners can be mapped under
runtime_secrets.providers in the generated YAML; LightNow CLI preserves these
non-secret mappings on subsequent syncs. The optional OS-keyring path is
available with lightnow-proxy[keyring]. Resolution failures are fail-closed
and plaintext values are never added to the tool-schema cache.
More Documentation
Detailed setup guides, examples, diagrams, supported client paths, telemetry behavior and troubleshooting live in the LightNow docs:
Local Development
For contributors working on this repository:
uv venv
uv pip install -e .[dev]
make test
Run the proxy with the example config:
uv run lightnow-proxy --config config.example.yaml
Run the proxy as a stdio MCP server:
uv run lightnow-proxy --config config.example.yaml --transport stdio
Run a local health check against the example config:
uv run lightnow-proxy --config config.example.yaml --health
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file lightnow_proxy-1.4.0.tar.gz.
File metadata
- Download URL: lightnow_proxy-1.4.0.tar.gz
- Upload date:
- Size: 52.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8006224b07df3baeb5bd1a4fcd58087460f325226b6cb4985f0db9334cb54eaf
|
|
| MD5 |
37d10802cf7c4f7a5fc9115f14b0a22c
|
|
| BLAKE2b-256 |
c1e1fb8e74e8b2d4e268b9075e1a5222a6a56cc8c39b226b914a200387d1a675
|
Provenance
The following attestation bundles were made for lightnow_proxy-1.4.0.tar.gz:
Publisher:
release.yml on lightnow-ai/lightnow-proxy
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
lightnow_proxy-1.4.0.tar.gz -
Subject digest:
8006224b07df3baeb5bd1a4fcd58087460f325226b6cb4985f0db9334cb54eaf - Sigstore transparency entry: 2189604544
- Sigstore integration time:
-
Permalink:
lightnow-ai/lightnow-proxy@7b063b19ddf860b198b74df86857df0902e22b4d -
Branch / Tag:
refs/tags/v1.4.0 - Owner: https://github.com/lightnow-ai
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@7b063b19ddf860b198b74df86857df0902e22b4d -
Trigger Event:
push
-
Statement type:
File details
Details for the file lightnow_proxy-1.4.0-py3-none-any.whl.
File metadata
- Download URL: lightnow_proxy-1.4.0-py3-none-any.whl
- Upload date:
- Size: 38.5 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b4ac6a2ad19d2b8c25ead55e5d7b2273c4f1990a9995e2673c1cf70c481db871
|
|
| MD5 |
4e6f08408b96f00b66147caa9ab9ff56
|
|
| BLAKE2b-256 |
9bbc0dc8b1f6ba90971081abd03adbfd9a20315d266e61deb5399e0b996bcf72
|
Provenance
The following attestation bundles were made for lightnow_proxy-1.4.0-py3-none-any.whl:
Publisher:
release.yml on lightnow-ai/lightnow-proxy
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
lightnow_proxy-1.4.0-py3-none-any.whl -
Subject digest:
b4ac6a2ad19d2b8c25ead55e5d7b2273c4f1990a9995e2673c1cf70c481db871 - Sigstore transparency entry: 2189604552
- Sigstore integration time:
-
Permalink:
lightnow-ai/lightnow-proxy@7b063b19ddf860b198b74df86857df0902e22b4d -
Branch / Tag:
refs/tags/v1.4.0 - Owner: https://github.com/lightnow-ai
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@7b063b19ddf860b198b74df86857df0902e22b4d -
Trigger Event:
push
-
Statement type: