Guide
Private Vibe Coding With Mistral: What Actually Stays Private
Mistral's current lineup makes some private vibe coding setups possible and quietly retires others. Here is what you can actually run privately today, checked against Mistral's own pages.
Private vibe coding with Mistral means picking between three different things that all get called private: running a Mistral model entirely on your own hardware, using Mistral's self-hosted enterprise deployment of its coding tool, or keeping your API key out of reach even though the model itself runs on Mistral's servers. As of today, Mistral's only actively supported dedicated code model is Codestral, version 25.08, and it is API only. The entire Devstral line, the open-weight models Mistral built for agentic coding, is marked deprecated or already past its retirement date on Mistral's own model lifecycle page. The one way to run a Mistral coding model fully offline today is the older, general purpose Mistral 7B, released under the Apache 2.0 license and available through Ollama. For a company that wants Mistral specifically and cannot send code to a shared cloud, Mistral's Vibe Code product can be self-hosted on your own infrastructure or VPC, which is a different kind of private than running a 7B model on a laptop.
Three things people mean by private vibe coding
Private gets used for at least three different setups, and each one protects against a different problem. Local inference means the model runs on hardware you control, so nothing leaves the machine at all. Self-hosted deployment means the tool runs on infrastructure you control, but it is still a vendor's licensed software calling a model you may not own the weights to. Secret handling is a separate question again: where your API key or credential lives, independent of where the model itself runs.
Most people typing private vibe coding mistral into a search bar are conflating these. Someone worried about a key leaking into a transcript has a different problem from someone whose company policy forbids sending source code to a third party's servers at all.
This page keeps the three separate, because the honest answer to how do I keep my Mistral workflow private depends entirely on which one you actually need.
- Local inference: the model runs on your hardware, nothing leaves the machine.
- Self-hosted deployment: the tool runs on your infrastructure, but is still vendor-licensed software.
- Secret handling: where credentials live, independent of where the model runs.
Mistral's coding lineup, checked against its own lifecycle page
Mistral's model lifecycle page lists Codestral, version 25.08, as the current coding model, released end of July 2025 and categorized Premier, which on Mistral's own documentation means commercial API access rather than a weight file you download.
The Devstral line is a different story. Devstral Small 1.0 (v25.05) already retired on 11/30/2025. Devstral Small 1.1 and Devstral Medium 1.0, both v25.07, carry a retirement date of 5/31/2026. Even the newest release, Devstral 2 (v25.12), has a retirement date of 7/31/2026, which has already passed as of this writing. Every version of Devstral is now in Mistral's own deprecated and retired models table, with no active replacement in that category.
Mistral also sells Mistral Medium 3.5, a generalist model it describes on the same page as optimized for agentic and coding use cases, which is the closest thing to a current coding recommendation outside the dedicated Codestral line. One discrepancy worth knowing: Mistral's marketing page for its Vibe Code product still lists Devstral 2 among the models powering it, even though the lifecycle page shows that exact model past its own retirement date. Treat the lifecycle page as the source of truth until the product page catches up.
- Codestral v25.08: current code model, Premier license, API access.
- Devstral 1.0, 1.1, Medium, Small 2, and Devstral 2: all past deprecation or retirement.
- Mistral Medium 3.5: a generalist model marketed as optimized for coding and agentic tasks.
The one fully local option: Mistral 7B through Ollama
Ollama's mistral library model pulls Mistral 7B, currently at v0.3, distributed under the Apache 2.0 license with a 32K context window and function calling support. Run ollama run mistral once, and every exchange after that stays on your machine, because there is no server to call.
What this is not: Mistral 7B is a smaller, older generalist model, not Codestral and not a purpose-built coding model. It is noticeably weaker at code completion than the hosted Codestral or Mistral Medium 3.5. There is also an old Codestral listed on Ollama, around 13GB with a 32K context window and last updated roughly two years ago, but that release shipped under Mistral's Non-Production License, meaning research and testing only, not production use, and it is not the Codestral Mistral sells today.
A fully local Mistral setup trades capability for privacy. That trade is not specific to Mistral; it is the same one every local-inference setup makes, and it is worth knowing before you plan a workflow around it.
- ollama run mistral pulls Mistral 7B, Apache 2.0, nothing sent off your machine.
- The old Codestral on Ollama is non-production licensed: fine for testing, not for shipping code.
- Current Codestral v25.08 is not offered this way; it is API only.
Mistral's own private option: self-hosting Vibe Code
Mistral's coding product, now called Vibe Code and formerly Mistral Code, can be self-hosted on your own infrastructure or VPC, or deployed through Mistral Compute or a major cloud provider, according to Mistral's own product page. That is a different kind of private than running weights on a laptop: your code does not cross into Mistral's shared cloud, but you are still running Mistral's licensed software against a commercial model.
The access tiers listed on Mistral's site are Pro, Team, API, and Enterprise, with Enterprise covering custom deployments, model training, and dedicated support. The product ships native IDE extensions for VS Code, JetBrains, and Zed, plus a terminal and a web app, so the actual day-to-day interface looks similar regardless of which tier you're on.
This is the realistic path for the enterprise query in this cluster: a company that wants Mistral specifically and needs the code to stay inside its own network boundary, as opposed to one developer who just wants nothing to leave a laptop.
- Vibe Code can be self-hosted on-prem or in your own VPC, per Mistral's own product page.
- Native IDE extensions ship for VS Code, JetBrains, and Zed, plus terminal and web access.
- Enterprise tier adds custom deployments and dedicated support; pricing is not published.
Free versus private: not the same axis
Mistral's consumer app, Vibe, has a Free plan described on Mistral's pricing page as offering limited messages, web search, coding sessions, and image generation. Pro is $14.99 a month, or $5.99 for verified students, and mostly raises those limits while adding $15 a month in API credits. Team is $24.99 per user per month.
None of those tiers change where the computation happens. Free and Pro both run on Mistral's shared cloud under Mistral's terms. Paying more buys higher limits, not a change in where your code goes.
So if the real requirement is my code should not leave my network, moving from Free to Pro does not get you there. Either run a model locally, as in the section above, or move to the self-hosted Enterprise deployment.
- Free Vibe plan: limited coding sessions, still on Mistral's shared infrastructure.
- Pro at $14.99 a month: more usage, same infrastructure.
- Privacy comes from where it runs, not from which plan you're paying for.
What a vault still has to do, regardless of where the model runs
Whichever option you pick, you likely still need an API key or an enterprise credential somewhere, and that is a separate problem from the model's own privacy. Keep it out of .env files and shell profiles either way.
Forkbench is a desktop app that runs your coding tools in a real terminal on your Mac. Its Vault keeps keys in the macOS Keychain and lets a command use one by name, so a Mistral API key does not have to sit in a plaintext file or print to the terminal. The same limit applies here as everywhere else: an unpinned Vault key can still be read by the program it was handed to, so scope the key narrowly rather than relying on the Vault alone to contain it. Forkbench has no integration with Mistral specifically; it is a terminal, so whatever tool you point at Mistral's API, or at a local model, runs inside it the same way any other command does.
That is the honest limit of what any desktop vault buys you. It keeps the key out of a readable file. It does not decide what the program does with the key once the command is running.
- Store the key in the Keychain or a secrets manager, not a .env file.
- An unpinned key can still be read by the program it is handed to.
- Forkbench does not integrate with Mistral; it is a terminal that runs whatever tool you choose.
A setup you can build today
Decide which kind of private you actually need before picking a tool, because the three options in this page solve different problems and cost different amounts of capability or money.
For solo experiments where nothing can leave the machine, pull Mistral 7B with Ollama and skip the API key entirely. For a solo coding assistant you plan to ship from, use Codestral v25.08 through the API and keep that key in a vault, not a file. For a team that needs Mistral specifically and cannot send code to a shared cloud, ask Mistral about Vibe Code's self-hosted or VPC deployment rather than assuming the Pro plan covers it.
Whatever you build, do not plan around Devstral. It is retired on Mistral's own lifecycle page, even though some of Mistral's own marketing still names it.
- Solo and fully offline: Ollama plus Mistral 7B, no key needed.
- Solo and shipping production code: Codestral v25.08 via the API, key in a vault.
- Team that cannot leave its network: ask about Vibe Code's self-hosted or VPC deployment.
- Do not plan around Devstral. Every version is past its retirement date.
Related: Mistral and the limits of supervising a vibe coding session, Running coding models fully locally, Evaluating vault systems for AI agent secrets, Download Forkbench
Frequently asked
Is Devstral still available from Mistral?
No. Every version, Devstral Small 1.0, Small 1.1, Medium 1.0, Small 2, and Devstral 2, is marked deprecated or already past its retirement date on Mistral's own model lifecycle page, even though some of Mistral's product marketing still lists Devstral 2 as one of the models behind its coding tool.
Can I run a Mistral coding model completely offline?
Only an older, general purpose one. Mistral 7B is Apache 2.0 licensed and runs locally through Ollama. The current Codestral, v25.08, is API only, and the older Codestral available on Ollama is licensed for research and testing, not production.
Does paying for Mistral's Pro plan keep my code private?
No. Free and Pro both run on Mistral's shared cloud infrastructure. Paying for Pro raises your usage limits and adds API credits; it does not change where the computation happens.
Does Forkbench work with Mistral's coding tools?
Forkbench has no built-in integration with Mistral. It is a terminal app for your Mac, so any tool you point at Mistral's API, or at a local model through Ollama, runs inside it the same way any other command does.