Open source desktop harnessv0.7.1

Your agents.One workspace.

Bring your coding agents, terminal, browser, diffs, and source control together in one local-first desktop workspace — then hand a live thread from one agent to the next, or name a team and let the lead hand the work around.

  • Local execution
  • Bring your own CLI
  • MIT licensed
Ronin desktop workspace showing its project rail, composer, and source control actions
Connect your CLI
CodexClaude CodeCursorGrok BuildOpenCodeAntigravityDroidKiloPi
01

Why Ronin

The control layer between a prompt and a pull request.

Coding agents are powerful in a terminal. They become practical when you can see the work, set the limits, compare the changes, and ship with intent. Ronin gives that loop a focused interface.

09
agent adapters
04
permission modes
14
browser tools
01
local execution layer
02

Core system

01

Connected CLIs

Use the agents you already trust.

Connect the CLIs already installed on your machine. Switch provider, account, model, and reasoning effort without changing the shape of your workflow.

busCodexcodexClaude CodeclaudeCursorcursor-agentGrok BuildgrokOpenCodeopencode+4 more adapters
02

Permission boundary

Set the boundary per thread.

Choose Supervised, Auto-accept edits, Auto, or Full access before the work begins. Approvals appear inline when the agent reaches a boundary.

SUPERVISEDEDITSAUTOFULLboundaryeditsrc/router.tsranrunpnpm testranrunrm -rf distwaiting on you
03

Source control

Treat git as part of the conversation.

Review diffs, restore a checkpoint, isolate work in a worktree, commit, push, and open the pull request without losing the thread.

src/router.ts41−return routes.filter(Boolean)41+return routes.filter(isRoutable)2 files changedCommit & push
04

Local execution

Keep the execution layer local.

Provider processes, terminals, filesystem reads, and git operations run on the server you control. Connect over LAN, Tailscale, or SSH when you need distance.

hardware you ownRONINclienttyped websocketLOCAL SERVERone processagentsgitPTY
03

The product

Built around the work,
not the chat bubble.

The primary object is a thread with a repository behind it. Everything else— terminal, browser, usage, diff, and source control—stays close enough to act on.

Workspace

The thread is the workspace.

Compose with any connected agent, choose its model and autonomy, then keep the terminal, preview, diff, and git state in the same working context.

Ronin workspace with project rail, agent composer, and git actions
ronin / workspacelocal

Stats that count everything

Ronin reads each provider's own session transcripts — including turns you ran in a bare terminal — and prices them at the full API rate. A real month from the maintainer's machine, not a claim about yours:

$1,571.42
Raw token cost

if billed at full API rate

2.39B
Processed tokens

398M per active day

99.5%
Cached input

2.34B of observed input

$9,744.50
Cache savings

6.2× the raw token cost

04

Inside a thread

A thread is not
a chat log.

The conversation is the working surface. Hand it to another agent, fork it for a second opinion, question one paragraph on the side, or play the whole turn back — without leaving the repository it belongs to.

01

Provider hand-off

Switch provider mid-thread.

Start with Codex, hit a wall, hand the thread to Claude. Same history, same checkpoints, same working directory. An agent that has been here before resumes its own session; a newcomer gets a brief built from the thread.

Documentation

A thread hands off from codex to claude, carrying its history, checkpoints, and working directory. The session resumes at turn 24.

02

Second opinion

Ask two models the same thing.

Press Compare, pick who should answer, and the same prompt runs on each model in its own worktree. They read as ordinary threads with chips to jump between. Keep the one you like; delete the rest.

Documentation

One prompt runs twice: claude-opus-5 in worktree A, kept, and gpt-5.6-sol in worktree B, discarded.

03

Side chats

Ask on the side.

Select the passage you are stuck on and a chip appears. It opens a fresh thread on exactly that text, same project, same checkout. The main thread never learns you asked.

Documentation

A sentence in the transcript is selected, and an “Ask on the side” chip opens a separate thread on just that passage. The main thread is untouched.

04

Captured tasks

Capture work as you read it.

Agents leave work behind in the transcript. Select it, press Capture, and Ronin files a draft thread that is ready on every device — while you stay exactly where you were reading.

Documentation

A line in the transcript is selected and filed as a draft thread titled “Drop dead helper”, already synced.

05

Turn replay

Replay a twenty-minute turn.

The prompt, each tool call, and the reply play back in order, with the pauses compressed, so you see the rhythm of the work without sitting through the dead air.

Documentation

A twenty-one minute turn replays on a scrubber holding twelve tool calls, paused at 7 minutes 42, with the dead air between calls compressed.

Build systems

A team,
not just a model.

Claude leads, Codex implements, Grok reviews — or any roster you name. You define the roles; the lead hands work around in one shared worktree until the task is done. Gate a role if you want to see it coming. Not the default; you build the team.

Documentation

Run a build system

Split the auth guard
one shared worktreewaiting on you
lead · claudeimplement · codexreview · grok
  1. 01
    orchestratorclaude

    does not edit · handed work to implement

    done
  2. 02
    implementcodex

    wrote src/server/auth.ts

    done
  3. 03
    reviewgrok

    paused until you approve

    ask first

The lead

The orchestrator does not edit.

It decides what happens next, hands a piece of work to a teammate, reads what came back, and either delegates again, asks you a question, or finishes.

Shared checkout

One worktree. One agent at a time.

Each teammate gets its own thread the first time it is asked to work, in the same worktree as the lead. A file one of them writes is a file the next one sees.

Ask first

Gate a role if you want to see it coming.

A gated role pauses the run until you approve or decline the task. Decline with a note the lead will read. The lead thread also lands in Needs you.

Board & queue

A board,
not just a list.

Six lanes — Draft, Up Next, Working, Needs You, Snoozed, Done. Drag to settle something, snooze it, or pick the next thing up. The sidebar and the board never disagree, because they read the same threads.

Documentation
Draft2

Split the router

Drop dead helper

Up Next1

Port tests to Vitest

Working2

Refactor auth guard

Audit bundle size

Needs You1

Approve rm -rf dist

Snoozed1

Bump deps

Done2

Fix flaky preview test

Ship v0.6 notes

Quota resume

Hit a limit? Ronin waits.

A spent five-hour window is not a failure you can act on. Ronin parks the message, counts down above the composer, and sends it the moment the window resets. Cancel it, fire it early, or walk away.

A queued message, “rerun the migration”, waits on a spent quota window. The window resets in 41 minutes 12 seconds.

Documentation

Needs you

Nothing stalls silently.

Anything that stopped until you answer collects in a sidebar queue and a dock badge. A system notification fires when a turn finishes, fails, or waits for approval.

Two things are waiting on you: three approvals for the command rm -rf dist, and a question asking which router to use.

Since you last looked

Come back to a summary.

What finished, what is still running, and what is waiting on you — gathered for the moment you sit back down.

Four turns finished, one is still running, and two are waiting on you.

Documentation
05

Working loop

From intent to merge

Four steps. One working context.

Every turn has a visible state. Every change can be inspected. Every branch can stay isolated. You decide when the result is ready to leave the machine.

  1. 01

    Prompt

    Give the agent the repo, model, effort, and permission boundary.

  2. 02

    Execute

    Watch commands, edits, terminal output, and browser actions arrive in context.

  3. 03

    Inspect

    Read the latest-turn diff, leave line comments, or restore a checkpoint.

  4. 04

    Ship

    Commit, push, and open the pull request from the workspace header.

Browser preview / MCP

Let the agent verify what it built.

Ronin exposes fourteen focused browser tools to the active agent—navigation, interaction, snapshots, appearance control, and recording—against your real dev server.

preview_openpreview_clickpreview_typepreview_snapshotpreview_recording_start

A preview session against localhost:3000: preview_open returned 200, preview_snapshot is ready, a preview_click on Deploy is done, and preview_wait_for is still running against the text "Success". Four actions, no failures, 42.8 seconds.

06

Make it yours

The harness
keeps going.

Everything past the conversation: skills every provider can read, work that runs while you sleep, the same threads on your phone, and a surface you can actually stand to look at all day.

Portable skills

Write a skill once, every agent gets it.

Drop a SKILL.md in ~/.ronin/skills and every connected provider can use it. Slash commands work the same way, next to each CLI's native ones.

~/.ronin/skills/review-pr/SKILL.md
/clear/compact/model/review/fork
Documentation

Automations

Work that runs without you.

Save a prompt, pick a schedule, walk away. Each run is a real thread you can read afterwards, defaulting to its own worktree so unattended edits never land in your checkout.

nightly 02:00sweep the flaky testsworktree
mon 09:00summarise last weekworktree
Documentation

Remote access

Drive the same threads from your phone.

Pair over your tailnet and scan the QR. LAN and SSH work too. The work still happens on hardware you own.

$npx t3 pair --tailscale
QRtailnetLANSSH
Documentation

Inline previews

HTML renders in the transcript.

When an agent writes a coverage report, a chart, or a mockup, Ronin renders it in place — sandboxed, with relative assets loading. No open-this-link step.

A sandboxed coverage report renders inside the transcript, in a frame labelled coverage.html.

Documentation

Appearance

Themes that go deep.

Eight OKLCH palettes ship, including the pure-black OLED Void. Search Open VSX to pull almost any VS Code theme straight in, or import your own. Light and dark both stay intact.

Eight palettes ship: Paper, Tsukimi, Graphite, Aizome, Urushi, Obsidian, Carbon, OLED Void.

Source control

Git is a first-class citizen.

A checkpoint after every turn to diff or restore; commit, branch, discard, and worktrees in the topbar; pull requests across every connected server — review, react, and edit in place.

CommitCommit & pushCommit, push & Pull requestPush
07

Straight answers

Product details.
Plainly stated.

01What is Ronin?

Ronin is an open-source desktop harness for coding agents. It runs the provider CLIs already installed on your machine and gives their threads a shared interface for prompts, permissions, terminal output, browser previews, diffs, usage, and source control.

02Is Ronin a code editor?

No. Ronin is an agent harness, not a text editor. The primary object is the thread and its repository context. It opens files and shows diffs when useful, then hands focused editing back to the editor you already use.

03Can one thread use more than one agent?

Yes. A thread can be handed from one provider to another mid-conversation and keeps its history, checkpoints, and working directory. An agent that has worked in that thread before resumes its own session; a new one receives a brief built from the thread. You can also run the same prompt on several models at once — each answer gets its own git worktree, so the attempts never collide.

04What is a build system?

A team you define for a project: one model leads, the others take roles. The orchestrator does not edit files; it hands work to teammates in one shared worktree, one agent at a time. Gate a role if you want to approve it first. You create a team in Settings → Build systems, then launch it on a task — it is not the default way a thread works.

05What happens when a provider rate limit is hit?

Ronin parks the message instead of failing it, counts down to the reset above the composer, and sends it the moment the window reopens. You can cancel the queued message or send it early. The usage view also shows when each provider's window resets.

06How much does Ronin cost?

Ronin is free and MIT-licensed. It does not resell models, tokens, or subscriptions. You install and authenticate the supported provider CLIs yourself.

07Does my code stay local?

Ronin's execution layer is local: provider processes, terminal sessions, filesystem reads, and git operations run on the server you control. The provider CLI you choose may still send prompts and code context to that provider under its own terms.

08Which systems are supported?

Linux, macOS, and Windows. Linux remains the primary target and ships as an x86_64 AppImage; macOS ships as a disk image and Windows as an installer in the same release. Windows support is native — Ronin launches the same CLIs you run in PowerShell, including npm's .cmd shims, so there is no WSL step and no distro to pick.

09Is Ronin stable?

Not yet. Ronin is currently at version 0.7.1. It is pre-1.0 software and the project explicitly asks users to expect bugs.

Pre-1.0 software

Run the harness
on your machine.

Install and authenticate at least one provider CLI, then take the build for your platform—Linux, macOS, or Windows—or launch Ronin from source. Early software—expect rough edges.

Build from source
  1. 01git clone https://github.com/0veek/Ronin.git
  2. 02cd Ronin
  3. 03vp i
  4. 04vp run dev:desktop
License
MIT
01
Primary target
Linux
02
Also supported
macOS · Windows
03
Current release
v0.7.1
04