NitroIDE's AI Pair Programmer: Bring Your Own Key, Surgical Edits, Zero Surprises
The most useful bug report I got this year was one sentence long: "AI always add and change things in script." Not a stack trace, not a repro — just the lived experience of every developer who has watched an AI assistant confidently rewrite the wrong file, touch code it wasn't asked about, and leave no way back.
So for v30 I rebuilt NitroIDE's AI pair programmer from the ground up around a single design rule: the AI never touches what you didn't ask for, and everything it does touch is reviewable and reversible. Here's how it works — the privacy architecture, the surgical edit system, and the trust controls that refuse to guess.
The privacy architecture: your key, your provider, our servers see nothing
NitroIDE has no AI backend. There is no proxy, no relay, no "AI service" of ours sitting in the middle. When you paste an API key, your browser talks directly to the provider you chose:
you → NitroIDE (browser) → Groq / Gemini / OpenRouter / OpenAI
Keys live in your browser's own localStorage, namespaced per provider, and are never sent to NitroIDE servers — there is simply no code path that does it. Groq, OpenRouter, and OpenAI go out as Bearer headers; Gemini uses the ?key= query parameter because that's what Google's API requires (and the setup UI says so openly).
Bring your own key also means bring your own billing: Groq, Gemini, and OpenRouter all have free tiers, so the AI pair programmer costs nothing to try. The setup modal auto-detects the provider from your key and lists that key's actual models — no typed model IDs to get wrong.
Surgical edits, not full-file rewrites
The old pattern — AI dumps an entire rewritten file, you squint at it, you accept, something subtle breaks — is gone. The v30 AI is taught to respond with FIND/REPLACE edit blocks: small, anchored changes that get parsed into reviewable edit cards, each with a side-by-side diff.
Matching is whitespace-tolerant (fuzzy), so the AI doesn't fail because your indentation differs by a space. And auto-apply only kicks in when every proposed edit matches cleanly — one ambiguous block and the whole batch waits for your eyes. You Apply per card, or all at once, after reading the diffs.
Trust controls: checkpoints, refusal, and no wrong-file edits
This is the part the one-sentence bug report paid for:
- Auto-apply is off by default. It's an opt-in wand toggle, not a default. Nothing changes in your files until you say so.
- Every apply takes a checkpoint. An in-memory snapshot of all attached files is taken before any edit lands, with a one-click Restore. Experiment freely; undo is always one tap away.
- Ambiguous edits are refused, not guessed. If an edit target can't be matched, manual Apply refuses it with a validation warning instead of applying something half-right.
- No wrong-file edits. The AI sees all attached files and picks the right one from your request — styling goes to
style.css, structure toindex.html, logic toscript.js. There is no "active editor" fallback that can silently dump a change into whatever file you last clicked. - Edit-intent gating. The AI doesn't get file context or edit powers until your message actually asks for a code change. Questions get answers, not diffs.
The engine behind this passed 70+ adversarial tests: ambiguous matches blocked, malicious output validated, XSS escaped, checkpoints covering all files. The full hardening notes are in the v30 changelog entry.
The details that make it feel instant
- Provider fallback: when one provider hits a rate limit, the AI silently switches to your next saved key. No dead ends mid-thought.
- 30-second timeouts with a real Stop button: the send button becomes Stop during generation, and cancelling never triggers a pointless fallback retry.
- Removable context chips: you see exactly which files the AI can see, and you can detach any of them.
- Resizable sidebar: drag it from 260 to 600px; your width is remembered.
Try it
Open the workspace, hit the AI button in the sidebar, paste a Groq, Gemini, OpenRouter, or OpenAI key, and ask it to change something small — a button color, a layout tweak. Watch it pick the right file, show you the diff, and wait for your approval. That pause, that diff, that Restore button: that's the whole design.
NitroIDE is free, no signup, and your code never leaves your machine: nitroide.com
⭐ If you enjoyed this, star NitroIDE on GitHub: github.com/nitroideofficial/nitroide