Skip to main content
Local first · your data never leaves the machine

Run the agent on your own desktop not in another browser tab

Kova is a native desktop app: a streaming conversation surface driven by an independent local agent runtime that handles model turns, tool execution, and session persistence. What it may change, and whether it has to ask first, is decided by you — not by the model.

Tauri v2 native windowLocal sidecar runtimeMulti-server MCPExpo mobile app
Kova · Living-room lights
+ 新对话
自动化
插件 / 专家 / 技能
我的文件
任务 / 项目
Lighting scene debug 2h
Weekend cleaning script 1d
Monthly report template 3d
Dim the living-room lights to 30% and pull together an energy report.
Ran light-scene write · living room → 30%
Done — both living-room groups are at 30%. The energy report is in the right panel, and I added a 7am schedule for tomorrow.
Describe a task, @mention an agent, /open the command menu
Living room30%
Balcony0%
Sensors3 在线
Schedules2 条
Why local

Three different bets

Most AI assistants are either a browser tab or a chat box with everything pushed through someone else’s cloud. Kova takes another road: the app is local, the model is swappable, the agent is constrainable.

01 / Local first

Data and credentials bypass the middleman

Sessions, memory, subagent definitions, and MCP configuration live in ~/.kova/ and your workspace’s .kova/. API keys go to the system keychain — on macOS, service name com.kova.assistant. You can open the directory and see exactly what it stores.

~/.kova/Keychainrusqlite
02 / Swappable

Changing models is a dropdown

Configure several providers in the model picker. Tool execution, session persistence, context compaction, and permission checks all run in the local sidecar, independent of the model — switching models bypasses no approval.

Multi-providerPer-turn switch
03 / Constrainable

”Stop and ask” is local logic, not model manners

Suspending, approving, denying, and rolling back happen in deterministic code. When the model says “done”, that alone does not count — exit tools carry an objective id check, and a stale completion signal is rejected.

stale-turn guardprefix rules
The loop

What actually happens in a conversation

You see a streaming thread. Behind it runs a deterministic loop — and only one of its steps belongs to the model. The rest is local code.

Assemble context

Pull session history, inject long-term memory and loaded skills, attach the content of @-mentioned files and any attachments. If the context is filling up, compact first, preserving key decisions and produced files.

Call the model

Hand it to the currently selected model; receive incremental text or a set of tool calls. Switching models affects only this step.

Adjudicate each tool call

Every call passes the session mode (may this tier write?) and then the approval level (must this tier ask?). Both must allow it.

Stop and ask when required

An approval suspends the turn with state preserved; when your answer arrives it resumes from exactly that step. A denied call returns to the model as a blocked result so it can take another route instead of deadlocking.

Execute, feed back, checkpoint

The tool runs inside the sidecar, its result is appended to the context, and the loop returns to step two. Every call and file change becomes a checkpoint you can return to.

Permission model

It does not quietly decide for you

In the UI these are two separate dropdowns, and the combination is the actual behaviour. Collapsing them is the most common misunderstanding about Kova.

agentSession mode

The full toolset. The default — reads, writes, runs commands, dispatches subagents.

planSession mode

Structurally read-only. It can read and plan, then uses plan_exit to get approval before handing back to agent to implement. Planning and implementation are separated by permission, so the reading phase never holds write rights.

askSession mode

A read-only subset with no bash. For “just tell me, don’t touch anything”.

goalSession mode

Full toolset plus cross-turn autonomy. Your first message is the objective; the model works to completion without you pressing continue. See goal mode.

workspace-writeApproval level

Inside the workspace and the writable-root list, writes are auto-approved; bash still asks, with “remember this class of command” generating prefix rules.

The approval cardThree buttons only

Deny, just this once, allow and remember. “Remember” stores a command word prefix, never a blanket: interpreter and destructive commands get no such button, matches are checked segment by segment, and redirects or command substitution are rejected the way the shell would read them. The writable-root list keeps it from ever granting write access to a directory you did not approve.

Said plainly
The workspace-write level does not contain bash — a command can reach any path outside the workspace through the shell. That is a deliberate trade-off, covered in its own section of docs/permission-modes.md. When you need real isolation, use a sandbox or a container.
Capabilities

Core capabilities

Conversation

Multi-threaded sessions, attachments, and the prompt queue

Session management, attachments and @-mentions, slash commands, a model picker, voice input, and AI-summarised titles. The prompt queue keeps the composer usable while the agent is still working, and its entries persist into the session transcript — refresh, restart, and thread switches lose nothing.

prompt queue v2checkpointsstreamdown
Agent runtime

A separate sidecar process

Long jobs never block the interface, a frontend crash never kills work in progress, and every surface reuses the same runtime. Coding, browser, HTTP, and screenshot tools ship in the box, with context compaction and long-term memory.

NDJSON over stdio
Subagents

Task / TaskWait / TaskList / TaskStop

Independent contexts and toolsets, three-layer discovery (built-in / user / plugin), and an activity trail written as it runs — replayable after a restart.

activity replay
MCP

Multi-server connection pool

Two-layer config merging, output guards, OAuth, and calls that pass through the same approval flow with an audit trail.

Interface

From setup to stats, all on your own machine

New chat
+ New chat
Automations
Plugins / Experts / Skills
My files

Pick a direction, or just say what you need.

InspirationWritingCodeAnalysisPlugins
Describe a task, @mention an agent, /open the command menu
Settings · Usage
Models
Credentials
MCP servers
Usage
Observability
Backup
Total tokens1.28M
Cache hit rate86%
Feature tour

The feature tour

Ten topics, each with a full design write-up — from the conversation workspace to prompt caching. Click through.

01

Conversation workspace

Multi-threaded sessions, attachments and @-mentions, checkpoint rollback, slash commands and voice input.

02

Prompt queue v2

QueueEngine snapshot persistence, three idempotent sync rules — queue entries keep even their images.

03

Modes overview

Five things called “mode”, fully separated: session mode, approval level, work mode, automation tier.

04

Goal mode

An explicit state machine, two stop valves, the stale-turn guard, and why there is deliberately no token budget.

05

Subagent design

The Task quartet, three-layer discovery, persistent activity replay, and token settlement.

06

Prompt caching

prompt_cache_key shard routing, shaped-alike summary requests, two miss-accounting standards.

07

Plugins & workspaces

The office / canvas / ui-design workspaces and the local plugin marketplace.

08

Automation

Scheduled tasks, merged catch-up runs, the unattended approval tier, and webhook notifications.

09

Remote & mobile

Pairing codes for tokens, three network paths, the Expo app, and the security boundary.

10

Agent engine

The turn lifecycle, built-in toolset, context compaction, and long-term memory.

Workspaces

Workspaces you actually open

A plugin is not a paragraph of prompt text — it is an interface you operate. The key is that its output is structured data, so the agent edits the same document instead of handing you a picture.

office

Slides & spreadsheets

Slide decks with per-slide editing, presentation mode, and .pptx export; a spreadsheet powered by the Univer engine with formulas, styles, merges, and frozen panes.

Univerpptxgenjs
canvas

Infinite canvas

Text, shapes, images, Mermaid, tables, charts, and embedded web pages placed freely, exportable as a single SVG.

*.canvas.json
ui-design

A Figma-style design workspace

Pages, artboards, a layer tree, and a full property inspector. It ships its own MCP server, so the agent drives canvas nodes directly — add, edit, delete, align, distribute, stack, and group.

Direct MCP control
Architecture

Four layers

Splitting the agent into its own process is deliberate: long jobs never block the interface, a frontend crash never kills work in progress, and every surface reuses the same runtime. See Architecture.

repo map
Get started

Running in five minutes

You need Bun, a Rust toolchain, and Node.js. Full details in the Quickstart.

Terminal
Who it’s for

Who it is for

People who want to work locallyData

Code, data, and files stay on your own machine, and you would rather not upload a workspace to somebody’s server just to use an assistant.

People wiring up lots of toolsIntegration

You already run several MCP servers and want one place that manages them and records every call.

People who need real documentsOutput

What you need is a .pptx and .xlsx you can actually open — not a preview image in a chat box.

Teams who want to build on itEngineering

A template you can build on: a clear monorepo, the cross-surface contract concentrated in packages/pi-protocol, and rebranding in one command.

Install it, or read two lines of code

Grab a build, configure a model, and start a conversation. To change it, every directory in the monorepo maps to one clear responsibility.

Kova — released under the Apache License 2.0. If you redistribute a derivative, keep the LICENSE file and the license notices of the upstream dependencies.