macOS 11+ · MIT · no account, no telemetry

Agentic coding,
on your machine.

ACSA Code is a local-first engineering workbench: a Monaco editor, a map of your codebase, git with a real commit graph, and an agent you can watch, steer, approve and undo. Bring your own model — local, free tier, or frontier.

0.2.19 · about 111 MB, signed and notarised · the engine and the agent runtime are inside the app

11providers built in, plus a local one
0accounts, sign-ins or sessions
0analytics or crash-reporting SDKs
1download — Python and the agent are bundled

What you get

Everything the work needs, in one window

Not a chat box bolted to a text area. The editor, the map, git and the agent share one project on disk — so navigation, review and the agent never disagree about what the code says.

See the shape of a codebase before you touch it

The code map indexes the project in the background and draws what depends on what, with a plain-language summary of each file's job. It is built locally — no service, no upload.

  • Symbol search stays current: create, delete and agent writes refresh both the tree and the index.
  • Ask what reads a file and get the answer from the graph, not a guess.

An agent that shows its work — and gives it back

Put the chat in Agent mode and hand it a task. Every tool call is a step you can read as it happens. A turn that changed files reports “Edited N files +X −Y”, one row per file, and Undo this turn restores exactly what it touched.

  • Four approval modes — Read only, Approve for me, Ask me, Full access.
  • Steer mid-run: a message goes into the turn that is running, not the next one.
  • Ask me genuinely stops and asks, in the chat, when only you can decide.

A real editor, and Cmd-K for the change you did not want to type

Monaco — the editor underneath VS Code — with tabs, real paths and real saves. Select code, press ⌘K, describe the change, and accept or reject a diff in place. A whole-file review lands as comments anchored to the lines they are about.

  • Undo, redo, select, move: the keys you already press.
  • Reviews are one thread per line, so clustered findings stay readable.

Commit, review and read your CI without opening a browser

Stage a whole file or one hunk at a time, read the commit graph, open any commit's files and diff, and compare any commit against your working tree. On a repository it recognises, the page also shows the latest CI run and a failed run's log in place.

  • Renames, quoted paths, merge conflicts and both sides of a diff read correctly.
  • The page hears about checkouts and agent writes it did not make.

The terminal, with links you can actually click

A real shell in the bottom dock. When something prints an address — npm run dev, a preview URL, a docs link — it is clickable, and it opens in your browser instead of asking you to select text out of a canvas.

  • Move through your last commands, and resize the dock without losing the session.
  • Real OSC 8 hyperlinks route exactly the same way.

Install tools and skills the agent will actually use

The marketplace installs real MCP servers and skills into your project. Installed skills are mirrored into the agent runtime's own home, so they reach the prompt — and your host's ~/.agents/skills keep working alongside them.

  • Every entry shows the command it will run before you install it.
  • Trust is on the card: built-in, official, or community.

Any model. And the numbers to prove what it cost.

Eleven providers ship in the picker, and any OpenAI-compatible endpoint can be added with a base URL and a key. Run a local model and nothing leaves the machine at all. The performance page keeps tokens and cost per provider — including what a local model saved you.

  • Keys go to the OS keychain and are write-only: a page can set or clear one, never read it back.
  • Small local models often cannot drive tools — the app says so instead of pretending a run worked.

How it goes

From an empty window to a reviewed change

  1. 1

    Open the folder

    Projects are folders on disk — no import, no workspace file, no account. New projects can be scaffolded from a template.

  2. 2

    Say what you want

    Chat to think it through, or switch to Agent and give it the task. Pick how much it may do: read, approve, ask, or full.

  3. 3

    Read the diff, then keep it

    Steps scroll by as they happen. Review the change, stage it by hunk or whole file, commit — or undo the whole turn.

Bring your own model

Use the model you already pay for

The app speaks the OpenAI API shapes. OpenAI and DeepSeek serve the agent runtime directly; every other chat-completions provider is reached through a bundled tool adapter, so it works the same way from your side.

  • OpenAI
  • DeepSeek
  • NVIDIA NIM
  • Groq
  • Google Gemini
  • xAI
  • Moonshot
  • Cohere
  • Together
  • OpenRouter
  • Ollama, locally
  • + any OpenAI-compatible endpoint

Ways to start without a bill

Free tiers are rate-limited and shared. A run that keeps failing stops and tells you why, rather than waiting out its time limit.

Yours, by default

Nothing here is ours to collect

Keys in the keychain

Credentials live in the OS keychain and are write-only across the app's own API — a page can set or clear one and ask whether it exists, never read the value back. If a keychain is not usable, the app says so and keeps it in a 0600 file instead.

Projects on your disk

History, settings, usage and per-turn snapshots live in a local SQLite database in the app's data directory. Open a folder; that is the whole import step.

No telemetry at all

There is no analytics or crash-reporting SDK in the app or the engine, and the crash log stays local. Nothing is sent anywhere except the model calls you configure.

Work offline

With a local model the whole loop — index, edit, map, agent — runs without a network. That is the point of bundling the engine and the runtime.

Before you download

What it does not do, yet

A page that only lists wins is worth less than the five minutes it takes to find the caveats. These are the real ones.

macOS 11 or newer only

Releases are built, signed and notarised for macOS today. The code is written for all three platforms, but Windows and Linux are not shipped.

Local models often cannot run the agent

A model that chats but cannot call tools will read and reply without changing a file. Small local models frequently cannot drive the tool protocol — use a hosted provider for agent runs.

Anthropic's API is not supported in agent mode

It is a different protocol, so the adapter cannot front it. OpenAI and DeepSeek serve the runtime directly; the rest go through the adapter.

Free tiers throttle, and a wrapped URL is left as text

Rate limits belong to the provider, not the app. And a link the terminal wraps onto a second line stays text, because the visible half is not the address.

Questions

The short answers

What does it cost?

The app is MIT licensed and free. You pay only for the model calls you make, to whichever provider you configure — and nothing at all with a local model. Free tiers at Groq, Google and NVIDIA get you started without a card.

Do I need to install Python, Node or Codex?

No. The Python engine and the agent runtime are inside the app bundle; there is nothing else to install. Node and Python are only needed if you build from source.

Where do my API keys go?

The operating system keychain — macOS Keychain, Windows Credential Manager, Linux Secret Service. They are handed to child processes in their environment, never over IPC, and the page can never read one back.

Does my code get sent anywhere?

Only to the model provider you configure, as part of the prompts you send. Nothing else leaves the machine. With a local model, nothing leaves at all. There is no analytics SDK to opt out of, because there is none.

Can I use it at work?

It is a normal local application: no account, no server of ours, and MIT licensing. Your organisation's rules about which providers may see code still apply — point it at an approved endpoint, or at a local model.

Is this a wrapper around Codex?

The agent runtime is the open-source Codex CLI (Apache-2.0), bundled with its own home directory so it never touches a Codex install you configured yourself. The workbench around it — editor, code map, git, marketplace, provider management — is this project.

How do updates work?

The app checks on launch and offers an Update button in the title bar when one is available; it can also update itself from Settings → About. Each release's notes are in the changelog.

Get it running in about a minute

Download, drag to Applications, open a folder. Pick a model — a free tier will do — and ask for something small.

Signed with a Developer ID, notarised and stapled — it opens without a Gatekeeper detour.