MIT · macOS 11+ · no account

The open-source workbench
for coding agents

Your model; Your workbench. Steer the Codex CLI agent with any model of your choice — local, free tier, or frontier.

The editor with the agent's model picker open over it: 29 models listed across the configured providers, from gpt-5.4-pro down to a local one.
11providers built in, plus a local one
0accounts, sign-ins or sessions
0analytics or crash-reporting SDKs
1download — Python and the agent are bundled

What you get

An agent that has your files, your build and your git

So it stops guessing at your setup. The map tells it what depends on what, the terminal runs your tests, and git shows you what it changed. The editor, the map, the repository and the marketplace below are the app itself, on a real project — not mockups.

Understand code you didn't write

The code map indexes the project as you open it and draws what depends on what, with a plain sentence about what each file is for. Ask what reads a file, and the answer comes from the graph rather than from a guess.

  • Search never lies to you: creating, deleting and the agent's own writes all refresh the index.
  • All of it is computed on your machine — no service, and nothing uploaded.
The code map in ACSA Code: 35 files, 30 symbols and 32 dependency edges in one TypeScript project, grouped into communities.

See everything it did. Undo any of it.

Hand it a task and watch the steps go by. When a turn ends it reports what changed, file by file — and Undo this turn puts those files back exactly as they were.

  • Four approval modes — Read only, Approve for me, Ask me, Full access.
  • Steer mid-run: a message goes into the turn that is running, not the next one.
  • Ask me genuinely stops and asks, in the chat, when only you can decide.

Drawn, not captured — the step list and the change log as the app shows them after a real turn.

Change the code where the code is

The editor is Monaco, with tabs and real saves — the floor, not the pitch. The part worth your time is ⌘K: select a block, describe the change, and accept or reject the diff without leaving the file.

  • Undo, redo, select, move: the keys you already press.
  • Reviews are one thread per line, so clustered findings stay readable.
The editor with store.ts open, the file tree beside it, and a real git log in the terminal below.

Read the change, then commit it

The diff, the commit graph and the commit box are one screen. Stage a file or a single hunk, compare any commit against your working tree, and on a repository it recognises a failed CI run opens beside the change that caused it.

  • Stage one hunk, so a stray debug line does not have to ride along with the fix.
  • It stays in step with checkouts and the agent's own writes, so it never misreports what is uncommitted.
The Repository screen: a clean working tree, the commit box, thirteen commits in the graph, and the latest CI run with its duration, trigger and the three-run history.

It checks its own work with your project's tests

The agent is told to verify with what the project already has — your build, your test command, your dev server — instead of inventing a harness for the occasion. It is an expectation rather than a guarantee, and it is the difference between “done” and done.

  • A run that changed no files says so, rather than being presented as a finished task.
  • The bottom dock is a real shell, so you can watch the verification go by — or take over.
The app's own terminal running the project's test command: six test files and seven tests passed in 95 milliseconds.

Give it your tools and your conventions

Skills and MCP servers install into the project and are handed to the agent — including the skills already on your machine. It can follow the way your team works instead of a generic one.

  • Every entry shows the command it will run before you install it.
  • Trust is on the card: built-in, official, or community.
The Marketplace: 19 skills and MCP servers, grouped by category, each showing whether it is built-in, official or community.

Pay for the model, not for the app

Eleven providers ship in the picker, and any OpenAI-compatible endpoint can be added with a base URL and a key. Point it at a free tier — or at a local model, and nothing is metered at all. The ledger keeps tokens and cost per provider, including what a local model saved you.

  • Your keys go to the OS keychain: the app can set or clear one and ask whether it exists, never read it back.
  • Small local models often cannot drive tools — the app says so instead of pretending a run worked.
AI Models & Providers: Ollama connected on this machine, the cloud APIs listed beside it, and the installed local models with their sizes.

How it goes

From an empty window to a reviewed change

  1. 1

    Open the folder

    Projects are folders on disk — no import, no workspace file, no account. New projects can be scaffolded from a template.

  2. 2

    Say what you want

    Chat to think it through, or switch to Agent and give it the task. Pick how much it may do: read, approve, ask, or full.

  3. 3

    Read the diff, then keep it

    Steps scroll by as they happen. Review the change, stage it by hunk or whole file, commit — or undo the whole turn.

Bring your own model

Use the model you already pay for

The app speaks the OpenAI API shapes. OpenAI and DeepSeek serve the agent runtime directly; every other chat-completions provider is reached through a bundled tool adapter, so it works the same way from your side.

  • OpenAI
  • DeepSeek
  • NVIDIA NIM
  • Groq
  • Google Gemini
  • xAI
  • Moonshot
  • Cohere
  • Together
  • OpenRouter
  • Ollama, locally
  • + any OpenAI-compatible endpoint

Start for free!

Free tiers are rate-limited and shared. A run that keeps failing stops and tells you why, rather than waiting out its time limit.

Yours, by default

100% Data Ownership & Privacy

Keys in the keychain

Credentials live in the OS keychain and are write-only across the app's own API — a page can set or clear one and ask whether it exists, never read the value back. If a keychain is not usable, the app says so and keeps it in a 0600 file instead.

Projects on your disk

History, settings, usage and per-turn snapshots live in a local SQLite database in the app's data directory. Open a folder; that is the whole import step.

No telemetry at all

There is no analytics or crash-reporting SDK in the app or the engine, and the crash log stays local. Nothing is sent anywhere except the model calls you configure.

Work offline

With a local model the whole loop — index, edit, map, agent — runs without a network. That is the point of bundling the engine and the runtime.

Before you download

What it does not do, yet

A page that only lists wins is worth less than the five minutes it takes to find the caveats. These are the real ones.

macOS 11 or newer only

Releases are built, signed and notarised for macOS today. The code is written for all three platforms, but Windows and Linux are not shipped.

Local models often cannot run the agent

A model that chats but cannot call tools will read and reply without changing a file. Small local models frequently cannot drive the tool protocol — use a hosted provider for agent runs.

Anthropic's API is not supported in agent mode

It is a different protocol, so the adapter cannot front it. OpenAI and DeepSeek serve the runtime directly; the rest go through the adapter.

Free tiers throttle

Rate limits belong to the provider, not the app. And a link the terminal wraps onto a second line stays text, because the visible half is not the address.

Questions

The short answers

What does it cost?

The app is MIT licensed and free. You pay only for the model calls you make, to whichever provider you configure — and nothing at all with a local model. Free tiers at Groq, Google and NVIDIA get you started without a card.

Do I need to install Python, Node or Codex?

No. The Python engine and the agent runtime are inside the app bundle; there is nothing else to install. Node and Python are only needed if you build from source.

Where do my API keys go?

The operating system keychain — macOS Keychain, Windows Credential Manager, Linux Secret Service. They are handed to child processes in their environment, never over IPC, and the page can never read one back.

Does my code get sent anywhere?

Only to the model provider you configure, as part of the prompts you send. Nothing else leaves the machine. With a local model, nothing leaves at all. There is no analytics SDK to opt out of, because there is none.

Can I use it at work?

It is a normal local application: no account, no server of ours, and MIT licensing. Your organisation's rules about which providers may see code still apply — point it at an approved endpoint, or at a local model.

Is this a wrapper around Codex?

The agent runtime is the open-source Codex CLI (Apache-2.0), bundled with its own home directory so it never touches a Codex install you configured yourself. The workbench around it — editor, code map, git, marketplace, provider management — is this project.

How do updates work?

The app checks on launch and offers an Update button in the title bar when one is available; it can also update itself from Settings → About. Each release's notes are in the changelog.

Get it running in about a minute

Download, drag to Applications, open a folder. Pick a model — a free tier will do — and ask for something small.

Signed with a Developer ID, notarised and stapled — it opens without a Gatekeeper detour.