Stoke / Security

Security

Stoke is designed to keep the gateway on the request path and Ollama on loopback. The source is open so the security boundary can be inspected.

Report a vulnerability

Please use GitHub's private vulnerability reporting flow rather than posting credentials, exploit details, or sensitive configuration in a public issue.

Report privately on GitHub

Security properties

For a reproducible setup that keeps native Codex Responses separate from Ollama Chat Completions, read the Codex + Ollama guide. Stoke does not claim Responses caching, subscription dollar caps, or provider credential isolation beyond the configured boundary.

Read the architecture and the repository's security invariants.