pikopod up serves the observing agent on :4700. Point your app’s provider base URL at http://127.0.0.1:4700/<upstream> and the agent forwards everything to the real provider, unmodified, and observes afterwards.
What it watches
Two different things, on two different clocks. Incidents. The upstream answered 5xx, throttled you with a 429, or could not be reached at all. These are facts about one request, so they need no baseline and fire from the very first one. See Incidents. Drift. The shape of a successful response changed: a field vanished, a type changed, a status value you had never seen arrived. This needs a baseline, so it stays quiet for the first 50 samples and 48 hours on purpose. A reference built from five responses has not seen your optional fields yet. See Drift and Warmup and baselines. Both produce an event with a stable fingerprint, and the fingerprint is the handle you feed back in:What it never does
- It never slows your traffic. It serves first and observes afterwards, through bounded, panic-isolated capture stages. Measured, not asserted: see Data plane safety.
- It never retries. An automatic retry in front of a payments API is a double-charge window. An unreachable upstream gets an honest 502.
- It never writes a raw payload. Credentials become placeholders, identifiers become format-preserving tokens, and strings it cannot classify are dropped, before anything touches disk. See Redaction.
- It never alerts on latency. Latency is noisy and rarely provable from the bytes. Duration is recorded, never a finding.
- It never initiates network traffic of its own. Slack, your forge, and your model provider are all things you configured.