Features
Every feature, with its limits
What Conduit does today, area by area — and, next to each item, the default or the limit that applies to it. Nothing below is on a roadmap; the last section lists what is deliberately not built. Current release: v1.0.0-rc.7.
Personal apps
Ask for a tool and get a working page — a dashboard, a converter, a tracker, a game — then keep it. See personal apps in the docs, or the product tour for a screenshot.
- Save a page as an app. Save as app in a page's ⋯ menu makes a copy you open from Apps on the rail, and it keeps working after you delete the chat. Saving asks which of the page's site permissions to keep, one by one, and keeps none you don't tick.
- Eight starter apps built in. A Pomodoro timer, unit converter, Snake, a memory game, a world-capitals quiz, a budget tracker, and a weather dashboard and currency converter that use live data and ask before they connect.
- Data that stays between launches. A page or app can keep up to 5 MB of its own data, stored with the rest of yours and encrypted only when encryption at rest is on. Clear data removes it.
- Settings and your model. A page can declare a few inputs, such as a city, and Conduit draws the form. After you allow it for that page, it can also ask your AI model: the prompt names the provider and says when text would leave your device, and the page gets text back — no tools, chat history, memory, or documents.
- Per-app controls. Every personal app has its own Settings page: which model answers it, a daily token limit for cloud models (100,000 by default; models on your computer are never limited), its saved data with Export and Clear, the sites and providers it may use, and a week of activity records that never include prompts, replies, or saved values.
- Known issue on macOS. A page's script can still open a WebRTC connection there; Windows and Linux block it in the webview. Open pages and apps you got from someone else with care on macOS.
Slides
Presentations you build by asking. Describe the story, or ask for a deck in any chat. See the Slides docs.
- One live deck, edited in place. The assistant drafts a storyline for you to approve, then builds the slides into a single deck — each change edits that deck rather than producing another copy. The deck opens in a studio with the slide large in the middle and the chat beside it.
- Targeted edits. Ask for a change and the assistant edits one slide, or swaps a word across the whole deck.
- Script. Every word of the deck as one document. Type there, or double-click text on a slide; text you write is kept when the assistant rewrites a slide, unless you ask it to change that text.
- History. A version is kept for every change, labelled by your request, and you can restore any of them.
- Two built-in themes, plus any theme the assistant designs for you.
- Present with a presenter view. Present full screen, with a separate presenter window — current and next slide, speaker notes, and a timer — to keep private while you share the slides.
- Export. As a single HTML file that presents itself in any browser on every platform, or as a PDF on Windows only.
- One thing to know. Slides adds to your local database, so going back to a release from before Slides shipped starts with an empty database (the old file is kept as a backup).
Research
A research report whose every finding is checked against its source. See the Research docs.
- A brief you approve first. Turn on Research in the composer's + menu, or pick it on Home. It proposes the sub-questions it will answer, a scope and a depth, which you edit and approve before anything runs. Quick is 8 searches, 15 pages and 10 minutes; Standard is 20, 40 and 20; Deep is 50, 100 and 40.
- Every finding checked against its page. It reads pages in full, web pages and PDFs alike, and pulls out facts with the exact words that support them. A fact counts only if those words are really on the page; the app checks that, not the model. It searches again for whatever is still unanswered.
- A report you keep. The result is a document in your chat: a summary, findings per sub-question, open questions, and numbered sources, with every finding cited. The chat card shows how many sources were cited and read. Stop keeps what was found so far.
- Pages can't give it orders. Page text only ever reaches a model call that has no tools, so a page that tries to give instructions can't make it search, fetch or save anything.
- Limits. It needs web search turned on and isn't available in local-only mode. A long page or PDF is read as an excerpt, the opening plus the parts that match the questions. A scanned PDF has no text to read. Your own Documents are not a source yet. A thinking model is slow, and Deep can hit its time limit.
Workflows
Routines that run for you and stop to ask. See the Workflows docs.
- Steps you can read. Fetch pages, search the web, have the model summarise, ask you a question, and save the result as a document. Start from a ready-made workflow — a morning briefing, a page summary, a topic watch — or build your own in the step editor, with problems shown before you save.
- Run now or on a schedule. Daily, on weekdays at a set time, or every few hours, with a notification when it finishes. A run missed while Conduit was closed happens once when you open it.
- Asks before acting. Turning a schedule on first lists everything the workflow will be allowed to do on its own — the sites it reads, web search, which model, saving documents — for you to approve. A scheduled run that needs more, after an edit or a settings change, pauses and asks: allow once, always allow, or don't allow.
- Tools, with limits. A "Let the model use tools" step can search the web, read pages, check the time, or do arithmetic, and a scheduled run asks you to approve those tools first. The summarise step gets no tools. Each run has a time and token limit.
- Tray is opt-in. To keep schedules running with the window closed, Conduit can stay in the tray and start there when you sign in; both are off by default.
Home
The app opens on Home. See the Home docs.
- One ask box. Ask for a deck and Slides opens with a storyline; anything else starts a chat. Quick starts sit underneath.
- Needs you. Workflow approvals, workflow questions, and memory suggestions waiting on you in one list — hidden when nothing is.
- Pick up where you left off. Your latest chats, decks, and apps.
- A tile per area, with a live count. An empty area shows an example to try instead.
- Go anywhere from the keyboard. Ctrl+1 to Ctrl+9 (⌘ on macOS) open Home, Chats, Apps, Slides, Documents, Library, Workflows, Connectors, and Memory; the command palette has a "Go to" entry for each.
Models & providers
Conduit talks to a model provider directly with your own key — there is no Conduit account and no Conduit-hosted model. See adding a provider for setup.
- Seventeen built-in providers. Anthropic, OpenAI, Google Gemini, xAI, Z.ai, Moonshot AI, Qwen, DeepSeek, Mistral, Groq, Together AI, Fireworks AI, OpenRouter, OpenCode Zen, Ollama, LM Studio, and any OpenAI-compatible endpoint.
- Custom base URL on eleven of them. Anthropic, OpenAI, Ollama, LM Studio, OpenAI-compatible, xAI, Z.ai, Moonshot, Qwen, Together AI, and Fireworks AI take an editable endpoint, so a LiteLLM proxy or compatible API works too. Gemini, OpenRouter, OpenCode Zen, Groq, DeepSeek, and Mistral use a fixed endpoint.
- Model families beyond the dedicated adapters. Grok, GLM, Kimi, and Qwen each have a first-class provider (xAI, Z.ai, Moonshot, Qwen). MiniMax does not — it's reachable only through OpenRouter, OpenCode Zen, an OpenAI-compatible endpoint, or Ollama and LM Studio.
- Local models with no key. Ollama and LM Studio are supported directly, plus any OpenAI-compatible server you run yourself, such as vLLM or SGLang.
- Bring your own key. Credentials live in the OS keychain and requests go straight from your machine to the provider — Conduit never proxies a request or resells a token.
- Local-only mode. One toggle refuses every cloud provider — only a local model such as Ollama or LM Studio can answer — and turns off web search, cloud document indexing, and page network access. It's on by default for a fresh install; choosing a cloud provider during setup switches it off.
- Switch mid-conversation. ⌘⇧P cycles the active provider without starting a new chat.
- Vision. Image attachments go to models that accept them. A text-only model — DeepSeek, for instance — gets the image dropped with a note rather than a faked answer.
- Extended reasoning display. Anthropic's thinking output renders in the conversation.
Documents
Collections of your own files, searchable from the chat. See the documents page for a screenshot of how sourced passages appear.
- Five file types, parsed on-device. Plain text, Markdown, CSV, Word (
.docx), and PDF. There is no OCR step — a scanned PDF with no text layer yields nothing. - Hybrid search. Vector similarity plus SQLite full-text search, merged by reciprocal rank fusion, both running against the same local database as your chats.
- Sourced answers. The files an answer drew on appear as chips on your message; click one to read the exact passage that was used.
- Four embedding providers. OpenAI, Gemini, OpenRouter, or Ollama — Anthropic cannot embed. A document's full text is sent once to whichever provider you pick; consent is asked per provider, remembered, and can be withdrawn.
- Local-only mode forces Ollama. With it on, cloud embedding is refused outright, so a collection stays entirely on your machine. Retrieved passages still go to whichever chat provider answers.
Images & artifacts
- Image generation on three providers. OpenAI, Gemini, and OpenRouter only. The finished image is saved locally as an artifact rather than left as a link that expires. Images are billed by the provider, and Conduit asks once before the first one.
- Artifacts render beside the chat. Text, code, JSON, Markdown, Mermaid diagrams, KaTeX maths, generated images, and sandboxed HTML all open in a side panel, kept out of the message scroll.
- Interactive HTML is sandboxed, not just warned about. A frame with scripts allowed and everything else forbidden — no same-origin access, a content policy that blocks the page's own network requests,
srcdocdelivery so it has no origin to trade on, and no bridge back into the app. Forms and buttons work. - Pages can fetch live data, from sites you allow. A page that wants a currency rate or a weather feed asks first: a banner names the site, and you allow it once, always for that page, or not at all — or let that page reach any public site. Conduit makes the request itself, over https only, with no cookies or credentials and no access to local or private addresses, and every request is logged. Permissions belong to one page, not the app. Refused entirely in local-only mode, and one switch in Settings → Privacy & data turns it off.
- Export to disk, with an optional metadata sidecar. There is no version history — see Not built.
Agents & tools
Run control, transparency, and consent for what the model does on its own.
- Run control. Queue a follow-up while a turn is still running, or interrupt it mid-loop and redirect it — the run doesn't have to finish before you can act.
ask_userforms. When the model needs a detail from you, it can put a real form in front of you — text fields, dropdowns — instead of guessing.- Live progress. A segment timeline shows thinking, each tool call, and the answer in the order they actually happened across rounds, with elapsed time and stall detection. A document being written shows its line count, size, and a "still working" note.
- An inspector for what happened. Once a reply is done, its steps fold into one line — "2 steps · 1 site" — that opens the inspector beside the chat. Its Activity tab lists every tool call, search, and site contacted, with timing and status; Sources lists the search results and document passages the answer used. Anything that needs you — an approval or a question — still appears in the chat.
- Chats that say when they need you. A chat you've left shows "Running" or "Needs you" in the chat list, so a turn waiting on an approval doesn't sit unnoticed.
- Remembered tool approvals. Approve a tool for this chat or for good. Sensitive tools are the exception — never remembered, always asked.
- Skills (
SKILL.md), enabled per conversation. Metadata is read first and the full instructions load only when you switch a skill on. Conduit does not execute a skill'sscripts/— they are listed as documentation, never run. - User-approved memory. The model can propose a fact through a tool, but it lands as pending — reaching no future prompt until you save it. Everything kept is a plain list on the Memory page you can read, edit, or delete. Memory is on by default, and stored items are encrypted only once encryption at rest is switched on.
- Context gauge and automatic compaction. The gauge estimates how full the next request will be, not summed turn totals. Compaction is on by default at 90% full: older turns are journaled into a summary while the most recent ones stay verbatim, and raw messages are never deleted.
- Built-in tools, no setup. Web search and fetch, document write and edit, clipboard, calculator, time, UUID, and random values — available without adding a connector. The page fetch reads public https sites only, never your own network, and reads PDFs up to 20 MB.
- Web search, off by default. Hosted search runs on the official Anthropic, OpenAI, or Gemini endpoint, or through OpenRouter's built-in search — a custom base URL strips it. Every other model searches through a local backend: Exa (the default; free and rate-limited without a key, and queries go to Exa under its terms), Tavily, Brave, your own SearXNG, or DuckDuckGo, with a link in Settings → Web search to get a key. It's disabled entirely in local-only mode.
- Workspace folder tools, opt-in. Off by default and gated behind an explicit acknowledgement, they give the model read, write, edit, glob, and grep inside one folder you choose — path-sandboxed, with no shell execution.
Connectors
MCP — the Model Context Protocol — for bringing your own tools in on your own terms.
- Local stdio servers. Supervised child processes with restart, backoff, concurrency limits, and per-call timeouts.
- Remote MCP over streamable HTTP. The current spec, with a fallback to older ones. The deprecated SSE-only shape is deliberately rejected rather than silently accepted.
- OAuth, with tokens in the keychain. Sign in to a remote server that uses OAuth; Conduit identifies itself with a published client metadata document, and tokens are stored in the OS keychain, never held by the interface.
- Official registry search. Search
registry.modelcontextprotocol.ioand install a remote server in one click. - Prompts and resources in the composer. A prompt picker fills in the arguments a server prompt declares and puts the result in the composer to edit before you send it. A resource picker attaches a resource to the next message only. A resource that tries to issue instructions is refused and named, not silently followed.
- A tool asks before it runs unless its server marks it read-only. Read-only tools run without interrupting you; every other tool stops and asks first, and you can remember an approval for one chat or always. Tool output is size-capped and redacted, with a structural guard against it being replayed as an instruction.
Conversations
- A side rail for everything else. Home, Chats, Apps, Slides, Documents, Library, Workflows, Connectors, Memory, and Settings sit on a labeled rail at the edge of the window, and each opens as a full page — a reply keeps running while you're on another one.
- Ideas to start from. Twenty-one hand-written, tested starting points — a pomodoro timer, a budget tracker, flashcards, a game of Snake — in seven groups, under the message box in a new chat. Picking one fills in a prompt you can edit before sending. Ideas that need something you haven't set up say so. Which ones you've tried is remembered on your device only.
- One + menu in the composer. Attach files, web search, a workspace folder, documents, skills, and connector prompts and resources from one button; whatever is switched on shows as a chip you can remove.
- Full-text search across every conversation, surfaced in the ⌘K command palette alongside model and artifact switching.
- Edit any message and resend. Editing the latest message rewrites it in place. Editing an earlier one always forks a new conversation that branches before that message — there is no in-thread branch switcher, and the original is kept.
- Pin, archive, and folders. Every conversation has a menu for renaming, pinning, and archiving; folders are one level, with no nesting.
- Export a conversation as Markdown or JSON.
- Saved prompt library. Folders, tags, and
{{variable}}templating for prompts you reuse. - Usage and cost tracking — estimates. Per-day cost and token charts computed locally from your own usage, from a small hand-maintained price table. Unknown or local models price at zero; actual billing may differ.
Privacy & security
The full statement, including every network flow and its default, is on the privacy page. The highlights:
- The trust boundary. The interface sends a typed request and receives typed events — it never holds a key or opens a socket. Keys, the database, and the HTTP client live only in the Rust core.
- Keys in the OS keychain. Windows Credential Manager, macOS Keychain, or Linux Secret Service, referenced by name and never held in Settings as a value.
- Local SQLite storage. Conversations, attachments, documents, and artifacts live in a database and content-addressed blob store on your machine — no Conduit server to upload them to.
- Local-only mode. One toggle refuses cloud providers on every path, and switches off web search, cloud document indexing, and page network access. Use it with Ollama or LM Studio and switch off update checks, and the app makes no internet request at all.
- Optional encryption at rest — off by default. AES-256, keyed from the OS keychain, covering attachment blobs, artifact content, document chunks, memory items, saved prompts, per-chat custom instructions, and tool results. It does not cover message text, the event log, compaction summaries, or the search index. If the key goes missing while encrypted data exists, the app refuses to start rather than fall back to plaintext.
- No telemetry. No background analytics or usage reporting. Diagnostics exports are manual, redacted, and local files — nothing is sent anywhere on its own.
- Signed update payloads. Every update is Ed25519-signed and verified before it's applied. The installers themselves are not OS code-signed, so Windows SmartScreen and macOS Gatekeeper still warn on first launch — see the changelog.
- Optional automatic updates. The default policy is manual — nothing is checked until you press Check now. Automatic checking and installing are opt-in; an automatic install is staged and applied on quit, never by restarting the app on its own, and isn't offered for the Linux
.debbuild.
Personalisation
- One design, dark and light. Choose dark, light, or following your system. A labeled rail gives every feature one place.
- Your main colour. Pick the accent for each mode in Settings → Appearance; a colour that would be hard to read is refused.
- Interface in eight languages. English, German, Spanish, French, Japanese, Korean, Brazilian Portuguese, and Simplified Chinese, with dates, numbers, and file sizes to match. Changing it doesn't change the language the assistant replies in.
- Text size. Compact, default, or comfortable, applied across the interface.
Keyboard
- Command palette (⌘K), modal. Type
>for commands,@for artifacts,/for models, or plain text to search every message you've sent. - Shortcuts sheet opens with Ctrl+/ on Windows and Linux, ⌘/ on macOS, listing the full set: ⌘N new chat, ⌘, settings, ⌘\ sidebar, ⌘J document panel, ⌘⇧E widen the artifact panel, ⌘⇧P cycle provider, ⌘⇧W web search, ⌘⇧F fork, ⌘⇧C copy the last reply, Esc to close a panel or stop a response.
- Settings search. Every setting is findable by name, not just by which section it's filed under.
Platforms
- Windows 10 and 11 — x86_64 installer.
- macOS 11 (Big Sur) and later — separate builds for Apple silicon and Intel.
- Linux — x86_64, as a
.debpackage or an AppImage. - No feature differences between platforms. Every capability above works the same on all three, except that automatic update installs aren't offered for the Linux
.deb.
White-label
Full status table and details on the white-label page.
- Runtime branding ships today. From Settings → Branding, a stock install can change its product name, tagline, in-app logo, window title, and around eighteen accent and surface colours — reversibly, in minutes.
- Build-time branding is early access. Producing your own installer — with your own app icon, installer name, bundle identifier, bundled fonts, and update channel — is built from source today and open to design partners; there is no pre-built branded installer to download yet.
- Not yet built: shipping a build pre-wired to your own connectors, and OS-signed and notarized branded builds — both are in development, not shipping.
Not built
Said plainly, so nothing above is mistaken for a promise about these:
- No cloud sync or multi-device access — every install is its own, independent database.
- No account, login, or hosted service of any kind.
- No artifact version history — it was built, then deliberately removed. An artifact is a single payload by design.
- No Azure OpenAI or AWS Bedrock provider.
- No dedicated MiniMax provider — reach it through OpenRouter, OpenCode Zen, or an OpenAI-compatible endpoint instead.
- Installers are not OS code-signed or notarized, so Windows and macOS both warn on first launch.
- The assistant does not switch its reply language automatically — picking an interface language changes the UI, not the language the model replies in.
Every claim above is checked against the release it describes. See what changed release by release, what stays on your machine, or the full documentation.