Docs · Security & data

Security & data

What Frontier Proxy runs, what it stores, what it never does — and the boundaries you should know before pointing an agent at a folder.

No API keys for coding agents

Frontier does not call model APIs on an agent's behalf and holds no model-execution keys of its own. There are no key or token fields on any coding-agent provider, by design. Every agent authenticates through its own CLI's login session, which stays where that CLI put it. If a provider cannot authenticate, log in with that CLI — copilot login, for example.

The one narrow exception: auxiliary services

A service that never runs a coding agent — never generates text, never edits a file, never runs on your behalf — may hold an opt-in credential. Today that is the Jev routing advisor; a forge API to open pull requests through your own gh/glab login is planned under the same rule. See ADR 0002.

  • Off by default. Routing works exactly as it always has until you turn an advisor on.
  • Encrypted, main-process only. The key is encrypted with Electron's safeStorage — backed by Keychain on macOS, DPAPI on Windows, and the OS keyring on Linux — and never reaches the renderer, frontier-state.json, a log, or an error message. The renderer only ever learns hasKey.
  • What leaves the machine when it's on: the prompt text, trimmed to fit the advisor's budget, and attachment names only — never attachment contents. When "share repo facts" is enabled (the default), it also sends lightweight repository metadata: top languages, file count, manifest names, and top-level folder names. Frontier never reads a file to send it.
  • Split & delegate sends the plan too. With the advisor on, a split run makes one extra call after planning. It sends each subtask's title, type, and prompt, so every subtask can get its own model. The planner is an agent that has read your repository, so its subtask prompts can quote code or file names. If that matters for a repository, keep the advisor off, or in Shadow, where the call still happens but changes nothing, for that work.
  • Advisory, never authoritative. Its answers only ever become bounded, labelled routing factors next to every other factor — they can never override an eligibility rule, an explicit provider pick, or a user-picked model. Losing the advisor (off, offline, invalid key, rate limited, slow) leaves routing behaving exactly as it does without it.

The privacy chip at the right of the header row is derived from your actual settings and never says "local" while an advisor is active — it names Jev, the mode, and what is sent. It is on every screen.

How processes are launched

  • Never through a shell. Providers are spawned with a cross-platform argument-safe wrapper (including Windows .cmd shims) with shell execution disabled.
  • Prompts go over stdin. The prompt is never interpolated into a command line, so nothing in a prompt can be read as an argument or shell metacharacter.
  • Custom CLIs get the same treatment. The {prompt} placeholder exists only for tools that require the prompt as an argv value.

Permission modes

AgentMode
Codex--sandbox workspace-write
Claude Code--permission-mode acceptEdits
Copilot Non-interactive silent mode with an explicit allow list for file writes and common Git, package, and build commands — not --allow-all.
OpenCode No permission flag and not --auto: it follows your own opencode.json permissions, whose defaults let a headless run edit files and run shell commands. Context & Tools allow/deny rules are layered on top for that run only; anything left at ask is auto-rejected.

The desktop app itself

  • Renderer code has no Node.js access; a small context-isolated preload bridge exposes only task and settings operations.
  • MCP OAuth tokens are encrypted with Electron's safeStorage, stay in the main process, and reach agents only as environment-backed header placeholders.
  • No telemetry is included.

What is stored, and where

State lives in a single frontier-state.json file in Electron's per-user application-data directory: tasks and their conversations, provider configuration, settings, and usage counters. Daily usage totals are discarded at the next local-date rollover. Delete the file to reset the app completely.

macOS permissions

The normal folder chooser and projects under your home directory do not require Full Disk Access. Choose Add project… in the header's project switcher and pick the folder in the system dialog. Full Disk Access is only relevant for protected locations such as Mail, Messages, some system folders, or another user's data.

If a provider shows CLI found but later hits an operating-system permission error, grant access to Frontier Proxy and the relevant CLI host in System Settings → Privacy & Security, then restart the app. A provider that says CLI not detected is a PATH problem, not a filesystem permission problem.

Honest limits

  • Frontier proxies CLI processes, not the private internals of the Codex or Claude desktop apps.
  • Subscription tools expose no reliable universal "tokens remaining" interface, so Frontier combines what each CLI reports with conservative local estimates and optional daily budgets.
  • Direct Ollama output is not an agent. Use Codex + Ollama when a local model needs filesystem and shell tools.