MaskCode AI Quickstart
MaskCode AI equips developers to safely harness the reasoning power of Anthropic's Claude 5.5 Sonnet and Claude 5.5 Haiku without leaking proprietary code, secrets, API tokens, or customer PII.
3-Minute Setup:
- Install the MaskCode CLI via npm or Homebrew.
- Run
maskcode initinside your repository root. - Export your Anthropic API Key or bind your Claude Enterprise team license.
- Launch the proxy daemon with
maskcode proxy.
Zero-Trust AST Architecture
MaskCode AI operates on a simple principle: Code semantics belong to Claude; plaintext secrets belong to you. Our local WebAssembly Tree-Sitter compiler traverses the source file syntax tree, identifying literals, strings, variable bindings, and function bodies.
Identifies syntax boundaries without string truncation.
Substitutes variables with typed synthetic tokens.
Holds unmasking tables in ephemeral RAM only.
Supported Languages & Dialects
MaskCode AI compiles Tree-Sitter grammars for the most demanding enterprise engineering tech stacks:
1. Installing MaskCode CLI
The CLI includes our native Tree-Sitter WebAssembly parsers, enabling sub-2ms AST analysis directly on your local workstation.
# Install via npm
npm install -g @maskcode/cli
# Alternatively, install via Homebrew (macOS / Linux)
brew install maskcode/tap/maskcode
# Verify installation
maskcode --version
# Output: MaskCode AI v1.4.2 (Zero-Trust AST Engine)
2. Anthropic Claude 5.5 Integration
Configure your Anthropic API credentials. MaskCode forwards sanitized prompts directly to Anthropic's endpoints (https://api.anthropic.com/v1/messages) while guaranteeing strict zero retention.
# Set your Anthropic API Key
export ANTHROPIC_API_KEY="sk-ant-api03-..."
# Configure target model (Claude 5.5 Sonnet recommended for SWE-bench reasoning)
export MASKCODE_UPSTREAM_MODEL="claude-5-5-sonnet-2026"
# Enforce zero retention headers
export MASKCODE_ENFORCE_ZERO_RETENTION="true"
# Initialize project configuration
maskcode init --provider anthropic
Zero-Retention Verification Invariant:
Every request dispatched by the MaskCode proxy automatically injects the cryptographic header X-Anthropic-Data-Retention: zero. This ensures that Anthropic does not retain customer prompts or completions in persistent storage.
Claude Prompt Caching Compatibility
MaskCode’s deterministic tokenization maintains identical AST token values across sequential prompts within the same repository session. This enables Anthropic's Prompt Caching mechanism, yielding up to 90% cost savings on repeated context blocks.
3. VS Code & JetBrains IDE Integration
MaskCode provides official extensions for Visual Studio Code, Cursor, and JetBrains IDEs.
Install directly from the Visual Studio Marketplace. Provides in-editor secret warnings and real-time diff preview.
Available on the JetBrains Plugin Marketplace. Supports Java, Kotlin, Python, Go, and Rust.
Docker & Dedicated Local Daemon
For isolated CI/CD runners or air-gapped developer environments, MaskCode can be deployed as an immutable container:
docker run -d -p 4040:4040 \
--name maskcode-daemon \
-e ANTHROPIC_API_KEY=$ANTHROPIC_API_KEY \
-e MASKCODE_ENFORCE_ZERO_RETENTION=true \
ghcr.io/maskcode/proxy:latest
4. Code Example: Python SDK Integration
Here is a complete end-to-end example showing how to send proprietary code through the MaskCode client to Claude 5.5 Sonnet:
from maskcode import MaskCodeClient
# Initialize zero-trust client connected to local AST engine
client = MaskCodeClient(
upstream="anthropic",
model="claude-5-5-sonnet-2026",
enable_cache=True
)
proprietary_code = """
# Internal Payment Processor
STRIPE_LIVE_KEY = "sk_live_51M0x92JkL9920194882194829"
INTERNAL_DB = "postgres://root:password123@10.0.1.2:5432/core"
def process_refund(tx_id, customer_ssn):
# Sensitive payment reconciliation logic
return execute_refund(STRIPE_LIVE_KEY, customer_ssn, tx_id)
"""
# 1. Local AST Masking
# 2. Forwarding to Claude 5.5 Sonnet
# 3. Local In-Memory Rehydration
result = client.audit_and_refactor(
code=proprietary_code,
instruction="Refactor for idempotency and connection pooling."
)
print("[INFO] Secrets Shielded:", result.secrets_masked_count)
print("[INFO] Claude 5.5 Reasoning:\n", result.claude_reasoning)
print("[SUCCESS] Rehydrated Patch:\n", result.rehydrated_code)
5. REST & WebSocket Proxy API Reference
The local MaskCode daemon exposes a drop-in replacement endpoint for the Anthropic Messages API.
Drop-in compatible with Anthropic's standard Messages API. Automatically parses incoming code blocks, tokenizes secrets, and forwards sanitized requests upstream to Anthropic.
x-api-key: [ANTHROPIC_KEY], anthropic-version: 2023-06-01
Local-only AST evaluation endpoint. Accepts raw code and returns the tokenized AST with cryptographic replacement maps.
AST Sanitization Payload Schema
The intermediate representation consumed by the MaskCode proxy and Anthropic dispatch layer:
{
"version": "1.4.2",
"language": "python",
"sanitized_content": "STRIPE_KEY = ''",
"entities_detected": [
{
"token_id": "",
"category": "SECRET_CREDENTIAL",
"heuristic": "STRIPE_LIVE_KEY_FORMAT",
"line_range": [3, 4]
}
],
"zero_retention_enforced": true
}
Deterministic Local Rehydration Engine
When Claude 5.5 Sonnet returns refactored code or vulnerability mitigations, the response contains synthetic placeholder tokens. MaskCode executes an in-memory inverse AST transformation, replacing tokens with the developer's original secrets without persisting unmasked data to disk.
6. Cloudflare Deployment Architecture
The public portal (www.maskcode.qd.je) is built for zero-dependency static delivery on Cloudflare Pages. For enterprise gateways, MaskCode also compiles to a WebAssembly Cloudflare Worker running on edge servers in 300+ cities worldwide.
Cloudflare Pages Invariant:
All documentation, interactive playground scripts, and assets are hosted via high-security Cloudflare Pages with edge caching, automated SSL, and strict Content-Security-Policy (CSP) headers.
7. Cryptographic Audit Ledger
For SOC 2 Type II and HIPAA compliance audits, MaskCode writes a cryptographically signed SHA-256 digest of every sanitization transaction to ~/.maskcode/audit.log. Auditors can verify that zero private keys crossed outbound network sockets.