You choose the endpoint
Connect a self-hosted model service, compatible gateway, or internal API instead of hard-coding one provider into the client.
When code cannot casually enter a third-party SaaS, Cocode provides a client entry point for self-hosted endpoints, private gateways, and controlled workspaces.
Capabilities and limits follow the current release
A self-hosted AI coding agent runs the Host, model endpoint, or gateway in an environment controlled by your team. It increases infrastructure and data-path control but does not automatically provide encryption, access control, audit, backup, isolation, or security updates.
Connect a self-hosted model service, compatible gateway, or internal API instead of hard-coding one provider into the client.
Files, commands, network actions, and model requests have visible boundaries that are easier to review in a team environment.
A private endpoint does not mean falling back to scripts. GUI, TUI, sessions, diffs, and tests remain one workflow.
Cocode treats self-hosting as an engineering boundary: know where files live, where requests go, which actions need confirmation, and how results are recorded.
Clear boundaries make real development work easier to trust.
Choose an internal service, private gateway, or compatible API based on security and cost requirements. The client connects it to the same task context.

A developer can review task context, files, and diffs in the GUI, then continue execution from a controlled server through TUI or SSH.

This is an executable, reviewable path through a real repository—not an abstract feature list.
Run the client, Host, and compatible model endpoint on one controlled machine for experiments or personal use.
Connect developer clients to one gateway that centralizes models, credentials, quota, and audit controls.
Keep workspace, runtime, and model service inside a restricted network with explicit dependency and release paths.
Test identity, Chat/Responses, streaming, tool use, timeouts, and error semantics independently.
Centralize providers, routing, credentials, and policy while clients connect to one approved endpoint.
Place workspace, network, and model access inside a defined trust domain and audit scope.
Switch model services within a verified compatibility boundary and reduce client lock-in.
A successful diagnostic only proves the client environment; endpoint protocol, security, and capacity need separate verification.
cocode doctor
cocodeA running deployment proves availability at one moment, not security, resilience, or compliance.
| Capability | Status | Conditions and evidence scope |
|---|---|---|
| Infrastructure control | Team-owned | The deployer manages compute, network, storage, images, and runtime configuration. |
| Model location | Architecture-dependent | A self-hosted Host can still call an external model API; inference must be controlled separately. |
| Security controls | Must be configured | TLS, authentication, least privilege, audit, and isolation do not appear automatically. |
| Recovery | Must be verified | Backups, upgrades, rollback, health checks, and recovery exercises are operational responsibilities. |
Cocode evaluates identity, secrets, network, logs, backup, upgrades, and rollback separately. Deployment control becomes a security benefit only after those controls are configured and verified.
No. Cocode is the client and workflow layer. It supports self-hosted model endpoints and private gateways; whether the model service is self-hosted depends on your deployment.
It fits developers, platform teams, and engineering organizations that need control over code boundaries, model request paths, network permissions, and task context.
If the model endpoint matches the protocol and capabilities supported by the current client, a local or internal model can be used as the entry point.
Not necessarily. A controlled Host can still call a cloud model API, so inference location must be checked separately.
Cover TLS, authentication, secret storage, least privilege, network restrictions, logs, backups, upgrades, and a verified rollback path.