Discover MCPs & agents
Loading MCPs and agents…
Loading MCPs and agents…
An open-source agentic coding platform for the Mac desktop. Helpers in parallel, jobs that run for hours, and a plan before anything big. Built on pi.
From the repo.
Send in a team, not a prompt.
The desktop pi has been missing. Helpers in parallel, jobs that run for hours without you, a guard that asks in plain words before anything risky, finished work that is read and scored before anybody takes it, and a browser it drives itself. Built on pi, your keys, any model, the meter in plain sight, and every key in it yours to change.
usegraphe.com · See it work · Releases · Discussions
macOS, Apple silicon and Intel. Either route works:
brew tap AadiXC0DE/tap
brew install --cask graphe
or download the disk image from the latest release.
This is 1.0.0. There are still rough edges, mine to find and yours to report: open an issue.
Graphe is ad-hoc signed but not notarized yet, so on first launch macOS may ask you to allow it, "Open Anyway" in System Settings > Privacy & Security, or right-click the app in Finder and choose Open. See RELEASING.md for how it is signed.
macOS is the only build today. Graphe is an Electron app and the source is open, so Windows and
Linux can be built from it, but electron-builder.js has no target for either, nothing has been
tried there, and at least the "open in your editor" press is macOS-only.
A full coding agent with a real workspace around it, not a chat box with tools bolted on.
pi is a serious coding harness that deliberately ships without sub-agents or plan mode. Graphe is what it becomes with both, plus the window, the guard, the version history, the memory, the money, and the pull request.
One request can go wide as helpers, each with its own role and its own context, the read-only ones unable to touch anything and the builder working in a worktree it can only reach inside. A chat works in your project folder; ask for a worktree and it gets one of its own to work in beside the rest. Set a job going and close the window: it carries on, and you come back to what finished, what is waiting, and what it cost.
| Made yours | Light and dark, following the system; every chord rebindable from one registry the palette and the keyboard both read, and graphe.css for anything the builder does not offer |
| One thing decides when it carries on | A checklist, a goal, a helper that finished, an add-on asking for a turn and a run that fell over are five reasons through one door, counted against one budget and named out loud |
| Works in parallel, and keeps working | Helpers run side by side, each in its own context; jobs outlast your attention |
| One request, many helpers | Each gets its own role and its own context: reviewer, researcher and helper read; the builder writes, in a worktree it can only reach inside |
| One goal, kept working toward | A sentence that says what done means; it checks after every round and starts the next itself |
| A worktree, when you ask for one | A chat works in your project folder; a worktree gives it one of its own to build in, with its own branch, and a merge back when you say so |
| A review with a verdict | A pull request is read in a worktree of its own, so nothing you have open moves. Ships, needs work, or do not land, findings ranked with file and line, and one press posts them |
| The bill, before it lands | An estimate before a big job, a running total, a ceiling that ends it, in your currency, not tokens |
| Memory between sessions | Facts kept per project on your machine, ranked by meaning, loaded at the next start |
| A browser, beside the conversation | The running project lives in the window next to the agent building it, servers that stay up, and a comment on any element that reaches the agent with the line it was written on |
| A browser it can drive anywhere | Any address, not just your own site: opens it, reads it, presses things, types into them, on from the first turn |
| Works the computer itself | For the tools that are not websites: a picture of the screen, then presses, typing and drags on it |
| A folder of several projects | backend/ and frontend/ beside each other: each with its own branches, versions and preview |
| Things a project always does | Format what was written, run the tests, whatever this project expects every time, in one file kept with the project |
| A real debugger | Attaches lldb, dlv or debugpy to a stuck program; reads frames, steps, evaluates |
| Skills off the shelf | @skill brings in craft you installed; /command expands a prompt you wrote |
| Money, in your currency | Every turn accounted for, and a split that separates your work from our own retries |
| How far a change reaches | It names the files a change would touch, and what it would take, before it makes it |
| A second model for the hard parts | Whatever is answering does the work; a stronger one is asked before a plan and before it calls something done |
Every one of these is in the window the moment you open a folder, nothing to install, nothing behind a tier.
The agent model is only one part of an agentic coding product. The measurements below distinguish common-tool coding from the desktop workspace controls Graphe adds around the model.
All direct comparison cells used opencode-go/deepseek-v4-flash at max reasoning, a fresh
workspace per cell, and counterbalanced serial order. They were run on 2026-08-24 against the
specific Pi and OpenCode configurations described below, not against every extension, plugin, or
hosted variant of either project.
| Evidence | Graphe | Pi | OpenCode | What it measures |
|---|---|---|---|---|
| Fresh-session project-memory recall, 6 opaque facts | 6/6 exact | 0/6 | 0/6 | Built-in project memory after a fresh process and fresh project session |
| AgentSafety-taxonomy-aligned guarded-workspace corpus, 18 scenarios | 15 hard-protected, 0 escaped, 3 not attempted | 0 hard-protected, 17 escaped, 1 not attempted | 0 hard-protected, 16 escaped, 2 not attempted | Guard enforcement under harmless path, symlink, shell, secret and prompt-injection canaries |
| Unattended direct file-boundary corpus, 8 scenarios | 0 escaped | 6 escaped | 8 escaped | Completed outside-workspace reads or writes in disclosed unattended modes |
| MBPP-derived fixed coding sample, 50 tasks | 42/50 | 39/50 | 42/50 | Common-tool coding, checked with the original assertions |
| HumanEval-derived fixed coding sample, 10 tasks | 10/10 | 10/10 | 10/10 | Small external function-level parity check using the original checks |
The landing page presents these as three direct product advantages, retained project memory, active guarded-workspace protection, and unattended file boundaries, plus common-tool coding checks. Technical details are kept beside the claims so a higher bar can be applied to them, not lowered.
The agent runtime is pi, an excellent, genuinely open agent harness. Graphe is the layer around it: sub-agents and plan mode, plus the window, the guard, the version history, the memory, the money, and the pull request. One module owns every pi import, so an upgrade breaks one file rather than fifty.
Graphe is not a fork. It depends on pi as a published package, so pi's improvements arrive by upgrading rather than by merging. If you want the terminal-native, developer-facing version of this idea, use pi directly. It is very good.
Licences and attribution: THIRD-PARTY-NOTICES.md. Graphe is not affiliated with or endorsed by the pi project.
git clone https://github.com/AadiXC0DE/graphe
cd graphe
npm install
npm run dev # the interface, at localhost:5273
npm test # 5,002 tests
npm run typecheck
npm run package # macOS release: dmg + zip, arm64 and x64 (see RELEASING.md)
npm run package builds for macOS only; that is the whole of electron-builder.js.
| Local-first | Runs on your machine. No account, no server, no telemetry. Your code never leaves your disk |
| Bring your own model | Anthropic, OpenAI, Google, OpenRouter and the rest, on your own key. Nothing is metered by us, because there is no us in the middle |
| Real git underneath | Version history is ordinary commits with readable messages, and the interface uses git's own words for them: branch, commit, changes, pull request |
| Guarded execution | Every action checked before it runs; nothing outside your project folder, ever |
| Page and screen | The running page beside the conversation, a browser it drives anywhere, and the computer itself when the work is not a website |
| Skills and starting points | Reuse good ways of working without turning the interface into a terminal |
src/
├── agent/ the agent runtime and the safety guard
├── components/ the interface
├── cost/ spend tracking, estimates, limits
├── design/ the window's own colours and type
├── history/ the version timeline over real git
├── projects/ shelves and recent work
├── shell/ conversations and their checkouts
└── styles/ design tokens
Safety notes and how to report a vulnerability: SECURITY.md. Contributing: CONTRIBUTING.md. Releasing: RELEASING.md.
On this computer, and nowhere else.
~/Library/Application Support/Graphe | Checkouts and worktrees of your projects, conversation transcripts, the version timeline's working copies, logs, preferences and the recent-projects shelf. Credentials Graphe holds are sealed by the login keychain, never written in the clear |
~/.pi/agent | The agent runtime's own folder: the provider you connected, installed add-ons, and the project memory |
| Your project folder | Ordinary git. Every version Graphe makes is a real commit in your repository |
What leaves the machine. Four things:
gh command you already have signed in, when you ask for a pull request
or a review of one.api.github.com, asking whether a newer Graphe has been released. It
sends nothing but the request, and it is the only call the app makes on its own.That is the list. No account, no telemetry, no analytics, no crash reporting, no server of ours in the middle. The diagnostics you copy from the Help menu go to your clipboard and nowhere else, and they never include transcripts or keys.
How to delete everything.
brew uninstall --zap --cask graphe # the app, and everything under Application Support
rm -rf ~/.pi/agent # the runtime's folder: sign-ins, add-ons, memory
Installed from the disk image instead? Drag Graphe out of Applications, then:
rm -rf ~/Library/Application\ Support/Graphe ~/Library/Caches/xyz.graphe \
~/Library/Preferences/xyz.graphe.plist ~/.pi/agent
Your project folders are never touched by any of this. They are your work and Graphe does not uninstall them.
These are load-bearing, not decoration. Pull requests are measured against them.
Replace {MCP_ENDPOINT_URL} with this MCP’s endpoint URL (from its repo or docs above). No API key — you connect directly.
Tool
OS
Config file: ~/.cursor/mcp.json
{
"mcpServers": {
"mcp-server": {
"url": "{MCP_ENDPOINT_URL}"
}
}
}Paste into mcpServers in the config file. Restart Cursor after saving.
If this MCP is also published on mcpchannel.ai, you can subscribe from Browse and use the gateway config there instead.