The local-first AI workspace.
Chat, a coding agent, agent teams and five more workspaces in one desktop app.
Your keys, your models, your machine. No backend, no telemetry, no account.
- Nothing phones home. No analytics, no crash reports, no update checks. Every connection is for work you asked for, and SECURITY.md lists each address.
- Any model, all at once. Eleven cloud providers, Ollama, and any other model app on your computer that serves the common chat format, side by side, with your own keys. Run fully local when you want to.
- An agent that asks first. Commands, deletions, web pages it picks and anything outside your project need your approval. Every file change is a diff you can keep or undo.
- Readable to the last line. MIT licensed. Vanilla JavaScript and Rust, no bundler, no minified app code.
This page describes
main. Changes made since v2.6.0 reach the download with the next release; the changelog lists them.
| Workspace | What it does |
|---|---|
| Chats | Multi-provider chat with projects, attachments, memory and a local knowledge base |
| HashCoder | A coding agent on your real project: file tree, edits as diffs, terminal, Undo |
| 3D Forge | Describe a part, get a dimensioned solid. Exports STL, OBJ, 3MF and STEP in millimetres |
| Finance | Statements, CSV, PDF and XLSX, or the records of a system you connect, read into a list of figures, with every total, card and chart worked out by the app from that list, and updated when you edit it |
| Sandbox | Agents that inspect untrusted code for malware, prompt injection and suspicious logic |
| ERP | Tell its agent about your business; it builds a working app with linked records and books, then changes it, updates its records and answers questions about them when you ask. It can also answer from a system you connect and bring its records in. Exported as one HTML file |
| Agent Swarm | Teams of agents in chain or vote, on any mix of models, with past runs to reopen. Agents can look things up in a system you connect, never change it |
| Virtual OS | A simulated project desktop an agent builds inside |
Plus Agents, nine built-in specialists and a builder for your own, and Split, one prompt answered by two models side by side.
Agents can also work with a business system you connect in Settings → Connections, such as an ERP that offers its records over MCP. A system signs in with a key or through your browser, and the key or the sign-in stays with the app and is never shown to a page or a model; records go only to models on your computer unless you allow otherwise, and every change to a record asks you first, showing exactly what will be sent. In the ERP, the agent only reads a connected system: it answers from its records, and brings records into a table only after showing you each one. Odoo, GitHub, Stripe and Supabase are ready-made choices, and GitHub and Supabase connect reading-only unless you say otherwise. HashCoder uses a connected system when a task is about one, such as opening a pull request, with each change asked first. See SECURITY.md.
The agent works on your real files. Inside the project it moves freely; every edit appears as a diff with Keep and Undo, and tests run in the built-in terminal. Attach a screenshot, a picture, a PDF or a text file to a request by the paperclip, by pasting or by dropping it in. For a website it finds real, openly licensed photos of the subject and credits them on the page, under the same setting as the Agent Swarm. It works with cloud models and with models on your own computer: a local model is given instructions and tools sized to it, and one under 15 billion parameters, such as a 7B, checks its work against your request before it finishes; one under 5 billion that does not run your tests after a change has them run for it. After a larger change, a larger model takes a second look at its own work with a clean slate, and fixes what that finds. A larger model is also given a map of the project's code as each conversation begins: which files define what, the most used first. A model on your computer is shown a small project whole instead. A request of several asks is listed ask by ask, and the agent goes back through the list before it finishes; whatever is left of its plan is said under the answer. An edit that takes away something your request does not name, a function, a section of a page or a heading, is flagged to the agent to put back, and what your request says to leave alone, such as the tests, is left alone. Before it calls a website done, its pages, stylesheets and scripts are read the way a browser would, and what will not work, or lets the page down, is sent back to be fixed: content hidden until a script runs, an animation that never ends, a blur behind a bar that stays on screen, no rule for reduced motion, pictures with no size. An answer that names a file your project does not have is sent back to find it. Switch on lessons in Settings and it keeps short notes on how each project is built and tested for the next conversation on it.
Build a team on a canvas, start from a template, or describe the task and have one designed. A team is sized to its task: a short piece of writing or a question goes to one writer, and a team on your computer's own models is a few agents that take turns. Watch each agent work in the live trace, then open the result: every agent's part, the files it made and every version of them. When some agents did not finish, the result offers to run just those, and the ones that depend on them, keeping what the rest wrote. A website the team builds can show real, openly licensed photographs found on Openverse, credited on the page; this sends a few search words about the site's subject and can be turned off in Settings (see SECURITY.md).
- You approve what matters. Commands, deletions, web pages the model picks and anything outside the open project raise this bar. Every decision is written to
~/.hashcortx/audit.log. - A blocklist compiled into Rust refuses keys, credentials and system folders, whether they are asked for as a file or named in a command.
- On macOS, agent commands run in the system sandbox, which keeps them out of your keys, keychains, shell start-up files and the app's own data however a command is written. On every system they start without environment settings named like secrets.
- A task on a local model stays local, and cloud AI requests are capped at 30 a minute and 6 at once.
- Stated plainly: API keys are stored on disk unencrypted, protected by your user account; the build is not code-signed.
Everything the app does, and what it does not, is in SECURITY.md.
macOS (Apple Silicon). Download the DMG from the latest release and drag HashCortx to Applications. The build is not notarised: on first launch, right-click the app, choose Open, then Open again. If macOS still refuses:
xattr -dr com.apple.quarantine /Applications/HashCortx.appWindows. Run the installer from the latest release. It is built without the embedding model, so it starts on any 64-bit PC and searches the knowledge base by keyword.
Linux and Intel Macs. Build from source (below).
Then open Settings → API keys, add a key and press Test. Or skip keys and run a model on your own machine: Settings → Local model walks you through it.
Build from source
cd ~
git clone https://github.com/Hash-7777/HashCortX.git
cd HashCortX
npm install
npm run tauri dev # develop
npm run tauri build # packageNeeds Node 18+ and Rust via rustup, plus macOS: Xcode Command Line Tools · Linux: Ubuntu 24.04+ with the Tauri v2 system libraries · Windows: MSVC build tools and WebView2.
On Windows, run cd ~ first. An administrator PowerShell starts in C:\Windows\System32, and a checkout there fails to bundle with a misleading "file not found".
On Windows, allow the app in Ollama. The app's page comes from http://tauri.localhost, which Ollama refuses until it is allowed. Run setx OLLAMA_ORIGINS "http://tauri.localhost" and reopen Ollama; until then the app says that the local model app refused it.
Older x86-64 processors (without AVX2). The default build links an ONNX Runtime that needs AVX2 and BMI2 (Intel Haswell, AMD Excavator and newer); on an older processor the app exits before a window appears. Build without the embedding model instead, and search falls back to keywords:
npx tauri build -- --no-default-featuresBefore a pull request, run what CI runs on Linux, macOS and Windows:
npm run check # 8,494 source checks
cargo test --manifest-path src-tauri/Cargo.toml # 206 Rust testsTauri v2 · Rust · vanilla JavaScript with no bundler, about 3.7 MB of interface source that ships as written. Architecture · Security · Contributing · Changelog
Is it free? Yes. MIT, no paid tier. You pay your AI providers directly, or nothing with a local model.
Does it work offline? Yes, with Ollama or another local model app. Web search, cloud models and the Python sandbox's first start need the internet.
Which systems? macOS on Apple Silicon, built and used daily. Windows 10, tested. Linux builds and passes CI, but has not been run by anyone yet.
Does my code leave my machine? Only inside a request to the model you chose. There is no HashCortx server.
Are my API keys encrypted? No. They sit in the app's own folder, protected by your user account. Why.
Was it built with AI? Yes, with AI coding models under human architecture, review and correction. Every product and security decision is the author's.
More in the Wiki.
| Shortcut | Action |
|---|---|
Cmd/Ctrl + Shift + C |
Open or leave HashCoder |
Cmd/Ctrl + Shift + N |
New chat |
Cmd/Ctrl + K |
Model picker |
| App | What it is | Licence |
|---|---|---|
| HashCortx (you are here) | The local-first AI workspace | MIT |
| HashCerebrum | Medical research workbench with a 3D brain interface | AGPL-3.0 |
| HashMeterAi | An honest local meter for your AI usage | Apache-2.0 |
| HashNotch | Turns the MacBook notch into a live activity island | GPL-3.0 |
They connect through files on your disk, not a service. HashCortx records token counts in ~/.hashcortx/usage.jsonl for HashMeterAi, and posts a short "finished" notice for HashNotch: a title, never a prompt or an answer.
HashCortx · by Seif Hashish · MIT
Download · Website · Wiki · Discussions





