0.11.0 — Private inference in the tools you already use
v0.11 is a milestone for Trace Commons and NEAR AI. For the first time, you can send calls from Claude Code and Codex to NEAR AI's private inference, from a screen that shows you whether it is actually happening. More harnesses are coming.
This brings together two choices that should belong to you: keeping your AI interactions private, and deciding which traces to share. Private inference does not mean automatically contributing your conversations. Sharing is a separate, deliberate decision, session by session.
Where we're going
We're building toward a world where you can pay for private inference by selectively sharing data. You might choose to contribute traces from gig-work tasks or open-source contributions, helping fund private AI for personal conversations about therapy, legal questions, or medical advice that you do not want to share.
That is the direction, not a payment feature shipping in v0.11. The goal is not to make you trade away all your privacy to afford AI. It's to let you choose what to contribute while keeping your personal AI interactions private.
Two things people ask for are next, in v0.12, and are not in this release: contributing without an invite, and opencode support.
Private AI, in the tools you already use
v0.11 gives private inference a place of its own: Private AI, a top-level screen on macOS, Windows, and Linux. Your tools can route calls through a local component on your computer to NEAR AI, so you can see whether calls are actually flowing and choose who answers.
The local record and routing choice are yours. The confidentiality of inference comes from the destination you choose — specifically, NEAR AI's private inference infrastructure — not from routing through your computer alone.
What makes inference private
One of the destinations registered by default is NEAR AI's Private Inference, which runs models inside hardware trusted execution environments: Intel TDX for the virtual machine, NVIDIA's GPU TEE for the model and its computation, and the TLS connection terminated inside the enclave rather than at a load balancer. In their words, it "ensures that AI computations happen in a completely isolated environment where no one—not the cloud provider, not the model provider, not even NEAR AI can access your data," verifiable "through cryptographic attestation." That's their claim about their hardware, and their page explains how to check it yourself.
Note where that property lives. It belongs to the destination, not to this screen. A call answered by NEAR AI gets it; a call your tool sends straight to Anthropic or OpenAI gets whatever those services offer. The screen adds no confidentiality to anything. It's where you see your calls and pick somewhere that has some.
And one distinction worth keeping straight, because the two ideas sit close together: a session you contribute to Trace Commons is shared with Trace Commons. That's the whole product, and it's your call, session by session. TEE confidentiality is about who can read a call while it's being answered. It says nothing about what you later decide to share.
What you'll find there
The screen lists the coding tools on your computer — Claude Code and Codex today — and tells you, for each one, whether it is connected, whether anything has arrived from it, or whether it is genuinely answering.
That distinction is the point of the release. A settings file with the right value in it proves only that a file has a value in it. It is not evidence that one call was ever answered. Now you can tell the difference at a glance.
Connecting a tool happens one decision at a time, behind a preview. The app shows you the exact change it would make to that tool's own settings file and writes nothing until you say so. If you'd already put something in that setting yourself, it says so and leaves it alone. It won't overwrite your choices.
The screen also says what the calls answered on this computer have cost. Only calls answered here are in that figure — calls answered on another machine or in a browser are not, and neither is work a monthly plan has already paid for. A spend number that quietly means something narrower than "what I spent" is worse than no number.
The switch is also in the tray — the menu bar on macOS — and on a keyboard shortcut, with one deliberate asymmetry. Turning it off acts immediately, because that only ever reduces what your computer will answer. Turning it on opens the screen first. While it's on, anything else running on your computer can send calls through it, charged to the accounts you've set up. That's worth deciding with the consequence in front of you rather than from a menu.
The limits, plainly
Claude Code and Codex today. opencode is next, and the reason it is not here is worth saying. opencode takes a base URL under a provider block, and the presence of that block is itself a statement: it promotes that provider into opencode's configured set and reorders which model it picks by default. A user with an OpenAI key and no Anthropic one would go from a working model to a broken one before any request left their machine. The fix — letting an entry say "write this only where the file already shows the tool using this provider" — is merged upstream and ships in this release's routing component. Using it is v0.12.
Contributing still requires an invite. Open contribution is v0.12.
It does nothing until you connect something. Turning the switch on, by itself, changes where no tool sends its calls.
Private inference depends on the destination. NEAR AI's private inference provides the TEE confidentiality described above. Routing to another provider does not give that provider the same guarantees. The Private AI screen makes routing visible; it does not itself add confidentiality.
Contributing a trace shares it. Traces you choose to contribute are shared with Trace Commons. Keep sessions you want to remain private out of your contributions.
Along the way
Building this meant depending on IronWire, the local component that does the answering, and depending on something closely is how you find out what's wrong with it. We found and fixed eight defects there, all merged upstream (#33, #34, #37, #39, #40, #42, #45, #47).
Three are worth naming. Connecting a tool could move a setting you had already chosen. A preview showing you additions could commit a removal. And the last is the precondition that makes opencode safe to add at all. The first two reach you whether or not you ever open this screen.
Getting it
The desktop app updates itself. The CLI is on Homebrew.
Connect Claude Code or Codex to NEAR AI private inference, then choose which traces, if any, you want to contribute. Sharing remains your choice.