Documentation

Getting started

Conduit is a desktop application. There is no hosted version to sign into — you run it on your own machine, with your own provider key.

Installing

Installers are on the GitHub Releases page — v1.0.0-rc.7 is the current tagged build for Windows, macOS, and Linux. You can also build from source, which takes about five minutes on a machine that already has the toolchain.

Prerequisites

RequirementVersionNotes
Node.js20What CI builds against
pnpm10.34.4Pinned; corepack enable is the easiest route
RuststableVia rustup, with rustfmt and clippy
Visual Studio 2022 Build Tools—Windows only, for native compilation

On Windows, the repository includes check-setup.ps1, which verifies all four and tells you what's missing.

Build and run

terminal
git clone REPO_URL conduit
cd conduit
pnpm install
pnpm dev

pnpm dev starts the Vite dev server and then the desktop shell. The first Rust build takes a while; subsequent ones are incremental.

CommandWhat it does
pnpm devRun the app in development mode
pnpm buildProduce a native installer for your platform
pnpm checkTypecheck the TypeScript workspace

Supported platforms

Binaries aren't OS code-signed yet. macOS Gatekeeper and Windows SmartScreen will warn on first launch because the bundles have no OS-level signature. Auto-update payloads are separately signed and verified. Building from source sidesteps the warning entirely.

Your first conversation

Conduit won't let you chat until it has a way to reach a model. On first launch, onboarding asks you to pick a provider and supply a credential.

Using a hosted provider

  1. Open Settings → Providers & Keys (⌘,).
  2. Choose your provider and paste its API key.
  3. Pick a model from the list Conduit fetches from that provider.

The key goes into your operating system's credential store — Windows Credential Manager, macOS Keychain, or Linux Secret Service. Settings hold only a reference to it, never the value. On machines without a keychain, an encrypted file-backed store is available as an explicit opt-in.

Using a local model, with no key

Install Ollama or LM Studio, pull a model, and select that provider in settings. No credential is needed and nothing leaves your machine. Combined with local-only mode, which refuses cloud providers outright, Conduit makes no internet requests at all.

Attach images when the model supports vision. Edit any message and resend: editing your latest message rewrites it in place, while editing an earlier one forks a new conversation from that point, keeping the original intact. Export a conversation as Markdown or JSON.

Supported providers

Seventeen providers ship built in — the OpenAI-compatible endpoint is the seventeenth, not an addition on top.

ProviderCredentialBase URL
AnthropicAPI keyEditable
OpenAIAPI keyEditable
Google GeminiAPI keyFixed
xAIAPI keyEditable
Z.aiAPI keyEditable
Moonshot AIAPI keyEditable
QwenAPI keyEditable
DeepSeekAPI keyFixed
MistralAPI keyFixed
GroqAPI keyFixed
Together AIAPI keyEditable
Fireworks AIAPI keyEditable
OpenRouterAPI keyFixed
OpenCode ZenAPI keyFixed
OllamaNone — localEditable
LM StudioNone — localEditable
Any OpenAI-compatible endpointOptionalEditable

The last row covers self-hosted gateways such as vLLM and LiteLLM, and any vendor with no dedicated adapter yet: give Conduit a base URL and, if the endpoint requires one, a key.

Adding GPT, Claude, Grok, GLM, Kimi, and the rest

Conduit talks to the model families people actually run in 2026 — GPT, Claude, Gemini, Grok, GLM, DeepSeek, Kimi, Qwen, and MiniMax — through whichever of these three paths fits the model you want.

  1. Built-in adapter. Anthropic, OpenAI, Gemini, xAI, Z.ai, Moonshot AI, Qwen, DeepSeek, Mistral, Groq, Together AI, and Fireworks AI each have a dedicated provider: pick it, paste the key, and load the model list. That covers Claude, GPT, Gemini, Grok, GLM, Kimi, Qwen, and DeepSeek directly — each ships with its own default endpoint, so there's no base URL to look up.
  2. A gateway. OpenCode Zen or OpenRouter catalogue the rest behind one key, including MiniMax and whatever else those services are currently serving — Conduit fetches the live list rather than a fixed catalog.
  3. Any OpenAI-compatible endpoint. For a vendor with no dedicated adapter, or a self-hosted proxy such as vLLM or SGLang, point the OpenAI-compatible provider at that endpoint's base URL and supply a key if it needs one.

Qwen's built-in adapter defaults to DashScope's international endpoint, and Moonshot's defaults to api.moonshot.ai — both fields stay editable if you need a different region.

Keyboard shortcuts

Use Ctrl in place of ⌘ on Windows and Linux.

ShortcutAction
⌘KCommand palette — search, commands, models, artifacts
⌘1–⌘9Go to Home, Chats, Apps, Slides, Documents, Library, Workflows, Connectors, Memory
⌘NNew conversation
⌘,Settings
⌘/Open this shortcuts sheet
⌘\Toggle the sidebar
⌘JToggle the document panel
⌘⇧EExpand the artifact panel, or restore the layout
⌘⇧PCycle provider
⌘⇧WToggle web search for this turn
⌘⇧FFork the conversation here
⌘⇧CCopy the last assistant message
EscClose a panel, or stop a running response

The command palette is modal: type > for commands, @ for artifacts, / for models, or plain text to search every message you've ever sent. Settings has its own search box at the top of the sheet, so you can jump straight to a setting by name instead of hunting through sections.

Tools and connectors

Built-in tools

These need no configuration:

A tool asks before it runs unless it is marked read-only. Built-in read-only tools run automatically, and a connector's tool does only when its server marks it read-only; every other tool prompts you before it runs. Web search is off by default and asks for consent the first time; hosted search only runs through the official Anthropic, OpenAI, or Gemini endpoint, and falls back to the local backends above once you point a provider at a custom base URL. Queries to a local search backend go to that service; Exa, the default, may keep them under its terms.

The model's page fetch reaches public https sites only: never localhost or an address on your own network, and every redirect is checked. It returns a page's title and readable text rather than raw HTML, and reads PDFs up to 20 MB. A scanned PDF with no text counts as a page with nothing to read.

MCP connectors

Conduit runs Model Context Protocol servers as supervised connectors. Add a local process on the Connectors page with the command and arguments that start it, or point at a remote MCP endpoint that speaks streamable HTTP.

A connector's tool runs without asking only when its server marks it read-only (the standard readOnlyHint, or Conduit's own permissionLevel field). Every other tool asks first, and you can remember an approval for one chat or always. Before 1.0.0-rc.6, tools on most third-party servers ran without asking, so connectors you already use may now prompt for tools that ran silently before.

The runtime restarts crashed local servers with backoff, capped at three restarts in five minutes, limits concurrency, and times out individual calls at thirty seconds. Tool output is size-capped and redacted before it reaches the model, and a structural guard prevents that output from being replayed as though it were an instruction — the standard prompt-injection route through tool results.

Transports: local stdio and remote streamable HTTP ship today. Legacy HTTP+SSE is not supported.

The composer can also pull in a connector's prompts and resources, not just its tools: a prompt picker fills in the arguments a prompt declares before it lands in the composer for you to edit, and a resource picker attaches content to the next message only. Consent is asked once per connector, and a resource that tries to slip in instructions is refused and named rather than silently followed.

Connecting a server on your own machine is the docs problem. Putting that server in front of a customer — without a JSON config and without appearing inside Claude Desktop — is a different one. How to demo an MCP server to a customer compares a hosted chat, Claude Desktop plus config, and shipping a desktop client.

Naming the command on Windows

Connectors are started directly, never through a shell. That is a deliberate guard — connector configuration would otherwise be a route to arbitrary command execution — and it has two consequences on Windows that most published MCP instructions do not account for, because they are written for clients that do use a shell.

Give the executable its real filename, extension included. A bare npx fails with the system cannot find the file specified: without a shell there is nothing to try the entries in PATHEXT on your behalf. Use npx.cmd. The same applies to any tool whose Windows form is a .cmd or .bat shim; node and other real .exe programs resolve normally.

The cmd /c recipe from other clients' documentation will be refused. Configurations in the shape "command": "cmd", "args": ["/c", "npx", …] — the usual Windows advice for Claude Desktop and others — fail with refusing to spawn connector through a shell interpreter. sh, bash, powershell and pwsh are rejected the same way. Point the command at the program itself and pass its arguments in args.

The agent loop

When a model calls a tool, Conduit runs it and feeds the result back for another round within the same turn. You control the bounds under Settings → Agent: a maximum step count from 1 to 50, and a wall-clock budget from 30 seconds to 30 minutes. The chat UI shows a live progress timeline — thinking, tool calls, and text, in the order they actually happen across rounds, with elapsed time and a note when a round stalls — rather than a single spinner.

Artifacts

Longer outputs — documents, scripts, small web pages — open in a panel beside the conversation rather than filling the message scroll. Conduit renders text, code with syntax highlighting, JSON as a collapsible tree, Markdown (including Mermaid diagrams and KaTeX math), and interactive HTML.

Interactive HTML runs inside a sandboxed frame that allows scripts and nothing else: no same-origin access, no popups, no top-level navigation. Forms still work — Conduit hands the page its submit event, and nothing is sent anywhere by submitting. An injected content policy sets connect-src 'none', so the page cannot fetch or open sockets of its own, and Conduit serves it from a sandboxed address of its own. The page can't call the application's own commands. One exception, a known issue on macOS: a page's script can still open a WebRTC connection, which the content policy doesn't cover; Windows and Linux block it in the webview. If you need an artifact to load images or fonts from a specific host, you can widen that yourself in the Artifact Security part of Settings → Privacy & data.

A page that needs live data — an exchange rate, the weather — can still ask for it. Its fetch() calls go to Conduit, which holds the first request to each new site and shows a banner naming it. You can allow that site once, always for that page, or not at all, or let the page reach any public site. Conduit then makes the request itself: https only, no cookies or credentials, no local or private addresses, with a 20-second timeout, a 5 MB response limit, and 120 requests a minute per page. The globe button on the page lists every site it has asked for and every request it made. Permissions belong to that one page and are deleted with it. Local-only mode refuses all of this, and Pages can connect to the internet in the same Artifact Security settings turns it off.

Paste a fenced code block into a conversation and Conduit will offer to promote it to an artifact. Artifacts export to disk, optionally with a metadata sidecar.

Each artifact holds one current payload. There is no version history — editing replaces the contents in place, so export anything you want to keep a copy of.

Documents

Create a collection under Documents in the sidebar, then add files — plain text, Markdown, CSV, Word (.docx), or PDF. Drop a file anywhere on the window to add it, or attach a whole collection from the composer for a single chat. A reply shows the files it drew on as clickable chips; click one to see the exact passage.

Each collection is embedded by one provider — OpenAI, Gemini, OpenRouter, or Ollama (Anthropic can't embed). Indexing sends a document's full text to that provider, so Conduit asks for consent the first time, remembers your answer per provider, and you can withdraw it later from the Documents page. Pick Ollama and nothing leaves your machine — local-only mode forces this choice. Retrieval itself is hybrid: vector similarity plus keyword search over the same local SQLite database, and the retrieved passages still go to whichever provider answers the chat.

Parsing happens on-device, with no OCR step, so a scanned PDF with no text layer yields nothing — Conduit tells you when that happens rather than importing an empty document.

Image generation

OpenAI, Gemini, and OpenRouter can generate images inline in a conversation. Conduit asks once, before the first image, since each one is billed by the provider — asking about image generation doesn't itself trigger the prompt. The result is saved locally as an artifact rather than linked from the provider, so it doesn't expire.

Personal apps

A page worth keeping can be saved as a personal app: Save as app in the page's ⋯ menu makes a copy you open from Apps on the rail, or from Your apps on the new-chat screen. The copy keeps working after you delete the chat. Saving asks which of the page's site permissions to keep, one by one, and keeps none you don't tick. When the chat's page changes later, the app offers Update. Eight starter apps come built in; add one from the Apps page, or press Open app on an idea that has one.

A page (an app, or one in a chat) can declare three more things, each checked by Conduit. It can keep data between launches — up to 5 MB per page, stored with the rest of your data and encrypted when encryption at rest is on; Clear data removes it. It can take a few settings, such as a city, which Conduit asks for in a form of its own and passes to the running page without reloading it. And it can ask your AI model, after you allow it for that page: the prompt names the provider and says when text would leave your device, and the page gets text in and text out — no tools, chat history, memory, or documents.

Every personal app has its own Settings page (the gear in the app's header, or ⋯ → Settings): which model answers it, tokens per day with a daily limit for cloud models (100,000 by default; models on your computer are never limited), its saved data key by key with Export and Clear, the sites and providers it may use, and a week of one-line activity records — never prompts, replies, or saved values.

Slides

Describe the story, or ask for a deck in any chat, and Conduit drafts a storyline for you to approve, then builds one live deck: every change edits that deck instead of producing another copy. The deck opens in a studio with the slide large in the middle and the chat beside it. Ask for a change and the assistant edits one slide, or swaps a word across the whole deck.

Script shows every word of the deck as one document; type there, or double-click text on a slide. Text you write is kept when the assistant rewrites a slide, unless you ask it to change that text. History keeps a version for every change, labelled by your request, to restore at any time. Two themes are built in, plus any theme the assistant designs for you.

Present opens the deck full screen, with a separate presenter view — current and next slide, speaker notes, and a timer — to keep private while you share the slides. Export saves a single HTML file that presents itself in any browser, or a PDF on Windows only. Slides adds to your local database: going back to a release from before Slides shipped starts with an empty database (the old file is kept as a backup).

Research

For a question that needs more than a quick search, turn on Research in the composer's + menu, or pick it on Home, and ask. It needs web search turned on and is not available in local-only mode. Research uses a local search backend (Exa, Tavily, Brave, your own SearXNG, or DuckDuckGo), never hosted search, so search queries go to that service and the page text goes to the chat provider you picked.

The brief. Before anything runs, Research proposes a brief: one to six sub-questions it will answer, an optional scope, and a depth. You edit it and approve it. Each depth sets how far it may go:

What it reads. It reads pages in full, three at a time: web pages and PDFs up to 20 MB, parsed on your device. A scanned PDF has no text to read and counts as a page with nothing on it. On a long page or PDF the model sees the opening plus the parts that match your questions, not the whole thing.

The quote check. The model pulls out claims, each with the exact words from the page that support it. A claim counts only if its quote (at least 20 characters) is found in the stored text of that page, and that check is done by the app, not the model. Research then searches again for whatever is still unanswered, and a writer turns the checked claims into the report. The numbered citations and the Sources list are produced by the app, not the model.

The report. The result is a Markdown document in the chat's documents: a summary, findings for each sub-question, open questions, and numbered sources, with every finding cited. The chat card shows the summary and how many sources were cited and read, and has an Open report button. Stop ends the run and keeps what was found so far.

Pages can't give it orders. Page text only ever reaches a model call that has no tools, so a page that tries to give instructions can't make it search, fetch or save anything. Research's model calls run in a hidden conversation of their own.

Limits: the model sees an excerpt of a long page, not all of it. A scanned PDF has no text. Your own Documents are not a source yet. A thinking model is slow, and Deep can hit its time limit before it finishes.

Workflows

The Workflows page runs routines for you: fetch pages, search the web, have the model summarise, ask you a question, and save the result as a document. Start from a ready-made workflow — a morning briefing, a page summary, a topic watch — or build your own in the step editor, then run it now or on a schedule (daily, on weekdays at a set time, or every few hours). Open any run to see what each step did; if you fix a step, rerun from it without repeating the steps before it.

Turning a schedule on first lists everything the workflow will be allowed to do on its own — the sites it reads, web search, which model, saving documents — for you to approve. A scheduled run that needs more, after an edit for example, pauses and asks: allow once, always allow, or don't allow. Each run has a time and token limit, and you can stop a run in progress. A run missed while Conduit was closed happens once when you open it.

To keep schedules running with the window closed, Conduit can stay in the tray and start there when you sign in; both are off by default, and the tray option is offered once, the first time you switch a schedule on.

Home

Conduit opens on Home, first on the rail. One ask box starts anything: ask for a deck and Slides opens with a storyline; anything else starts a chat. Below it, Needs you lists workflow approvals, workflow questions, and memory suggestions waiting on you (hidden when nothing is), Pick up where you left off shows your latest chats, decks, and apps, and every area of the app sits in a tile with a live count — or an example to try while it is empty.

Ctrl+1 to Ctrl+9 (⌘ on macOS) open Home, Chats, Apps, Slides, Documents, Library, Workflows, Connectors, and Memory, and the command palette has a "Go to" entry for each.

Appearance and language

Conduit has one design in two modes. Under Settings → Appearance, choose dark, light, or following your system, and pick the main colour — the accent on buttons, selection, and the active item — separately for each mode; a colour that would be hard to read is refused. The same page sets the interface font size, density, and diagram size.

The same settings page sets the interface language, across all eight locales Conduit ships in. It changes menus, buttons, dates, and numbers — it does not change the language the assistant replies in.

Where your data lives

Conduit stores everything in your platform's application data directory: a SQLite database for conversations, messages, prompts, and usage, plus a content-addressed blob store for attachments and artifacts, deduplicated by hash.

Messages are written as an append-only event log with a materialised view over it, which is what lets a conversation survive the app being killed mid-response. On startup, Conduit reconciles the two.

Optional AES-256-GCM encryption at rest is available under Settings → Privacy & Data, with the master key wrapped by your OS keychain. It is off by default and does not yet cover message text — see the privacy page for the current scope.

Troubleshooting

The build fails on Windows

Almost always a missing C++ toolchain. Install the Visual Studio 2022 Build Tools with the "Desktop development with C++" workload, then run check-setup.ps1 to confirm.

My provider key isn't being saved

Conduit needs a working OS credential store. On headless or minimal Linux systems there may be no Secret Service running. Either start a keyring daemon or enable the encrypted file-backed credential store, which requires supplying a key through the environment.

Ollama models don't appear

Confirm Ollama is running and has at least one model pulled, and that Conduit's base URL for it matches the port Ollama is listening on.

An MCP connector won't start on Windows

Two causes cover nearly all of it, both from connectors being started without a shell. If the log says the system cannot find the file specified, the command needs its extension — npx.cmd rather than npx. If it says refusing to spawn connector through a shell interpreter, the configuration is routing through cmd, sh or powershell, which is refused by design; name the program directly instead. See Naming the command on Windows.

Something else is broken

Export a diagnostics bundle from Settings → Diagnostics and attach it to an issue. It excludes secrets, base URLs, allowlists, and conversation content by design, and requires you to acknowledge what it contains before it's generated.

Read the source