Pinvou Agent: a desktop AI workspace built around deliverables, not chat replies
Open-source desktop AI agent for tools, files, knowledge, workflows, and real deliverables.
At a glance
- What is it?
- Pinvou Agent is an MIT-licensed Tauri and Rust desktop agent that bundles work, design and coding modes, a local knowledge base, and MCP tool connectors into one app. It is a preview release, and its update path is still manual.
- Who is it for?
- Pinvou Agent suits engineers and analysts who want a local-first desktop agent with a knowledge base, an artifact panel and MCP connectors, and who are willing to run preview builds from GitHub Releases. Skip it if you need a stable, auto-updating product, a headless server deployment, or a coding agent that is not already installed on your machine.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 1 day ago.
- What is it written in?
- Mainly Rust, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The problem Pinvou Agent is aimed at
Most desktop chat clients end a task with text. You paste a document, ask for a summary, and copy the answer somewhere else. Pinvou Agent is built on the opposite assumption: a session should end with a file, a plan, or an edited project. The README frames this directly, describing a workspace "designed for tasks that should end with a result, not just another chat response."
The target user is someone who juggles three kinds of work in one day. In Work mode you attach PDFs, Office documents and images, pull in a local knowledge collection, and ask for a written deliverable. In Design mode you describe a poster or a data visualization and then edit the result by selecting elements and changing copy, fonts, colors and layout. In Code mode you hand a real repository to Codex, Claude Code or Kimi over ACP. The pitch is that these are not three products but three modes over one session store, one knowledge base and one tool registry.
That framing also sets the bar. If your work is a single question with a single answer, the app's structure (sessions, collections, personas, skills, workflows) is overhead you will notice and not use.
How the pieces fit: Tauri shell, Rust core, ACP for coding
The repository layout tells most of the architecture story. The top level contains pinvou3-app, pinvou-cli, pinvou-knowledge, remote-control-relay, private-runtimes and CodeWhale alongside docs and scripts. The app directory is named pinvou3-app and holds a src-tauri subdirectory, so the desktop shell is Tauri with a Rust backend, and the topics list confirms React on the front end. That means the UI is a web view and the privileged work (files, processes, local model calls) happens in Rust.
State is file-based rather than database-server-based. The README states that sessions, settings, knowledge and runtime extensions all live under ~/.pinvou3/. That single directory is the unit of backup, migration and inspection. A knowledge collection is a directory the app indexes for full-text and vector retrieval; multiple collections can be attached to one chat, toggled independently, and answers retain collection and file provenance.
Tools arrive through a unified store covering local MCP servers, remote MCP servers, CLI tools and API connectors, with OAuth or SSO where the provider supports it. Coding is different: instead of wrapping a model, the app drives an external agent process over ACP, and the README notes sessions stay bound to their workspace and can be continued after restarting the app. The remote-control-relay directory suggests the phone QR-code steering path runs through a separate relay component rather than peer-to-peer.
Installing a preview build and pointing it at a model
There is no package-manager install documented. The README links Download Preview to the GitHub Releases page, so the supported path today is downloading a build for Windows, macOS or Linux from there. The badge line lists those three platforms. In-app update checks are explicitly not enabled yet, which means you re-download a release to move versions.
Model configuration happens in application settings, but the README also gives an environment-variable form for a local vLLM server. These three variables set the endpoint, a placeholder key and the model name:
export DEEPSEEK_BASE_URL="http://127.0.0.1:8000/v1"
export DEEPSEEK_API_KEY="local-no-auth"
export DEEPSEEK_MODEL="your-model-name"If vLLM is serving on port 8000 with an OpenAI-compatible route, the app should reach it at that base URL. The key value is a stub because a local server typically does not check it; the model name must match what your server actually serves, since the README uses a placeholder rather than a real identifier.
For a first real task, the sequence the README describes is: start a session, attach a PDF or Office document, attach one or more knowledge collections, and ask for a deliverable. Files the agent creates or edits are collected automatically in the artifact panel, where you can preview, locate and open them. Markdown artifacts are editable in place, and you can select a passage and ask the agent to revise just that passage. If the task is complex, Plan mode shows the plan for review before execution; YOLO mode executes directly. Choose Plan the first time you run a workflow you have not seen before.
Where the local-first claim stops
The README's own note is the most important paragraph in the document: whether data leaves your machine depends on the model and tools you enable. A local model with local tools stays fully local. Cloud models, remote MCP servers and third-party connectors send the relevant requests to their respective services.
That is a narrower guarantee than the local-first topic tag suggests, and it is worth reading literally. The knowledge base is on disk, sessions are on disk, but retrieval results and file contents are placed into prompts, and prompts go wherever the configured endpoint points. Attach a cloud model and a remote MCP server to the same session and the boundary moves without any warning dialog that the README documents.
The connector list sharpens this. Ready-made connectors cover Feishu (Lark), DingTalk, WeCom, Tencent Meeting, Tencent ima, Obsidian, enterprise knowledge bases, and legal and enterprise data services. Several of those are hosted services that will receive whatever the tool call carries. If your constraint is that no document text may leave a controlled network, your only safe configuration is a local model plus local MCP servers, and you have to verify that per session rather than per installation.
The second limitation is maturity. The three listed releases are all labelled preview (预览版), the most recent being v0.9.3. Preview labels plus a manual update path mean you should not treat this as a set-and-forget tool on a machine you depend on.
How it differs from a coding agent CLI or a chat client
The closest comparison is a terminal coding agent such as Claude Code or Codex CLI. Those are single-purpose: they read and edit a repository, run commands, and print results in a terminal. Pinvou Agent does not replace them, it hosts them. Code mode drives Codex, Claude Code or Kimi through ACP inside the desktop app, so the coding agent's plans, tool steps, permission requests and file changes surface in a GUI, and the session survives an app restart.
That is a real difference in approach, not a cosmetic one. A CLI agent has no knowledge base, no artifact panel and no design mode; it also has no GUI permission prompt, which some engineers prefer because it keeps the loop in one window. Conversely, Pinvou Agent cannot run headless on a server, because it is a desktop application with a Tauri shell and a web view.
The other comparison is a general chat client with file upload. Those send your document to a model and return text. Pinvou Agent's difference is the artifact panel and the editable Markdown artifacts: the output is a file you keep editing, and the knowledge collections persist between sessions with provenance attached to answers. If you never reuse a document and never want the output as a file, the chat client is lighter and you already have it.
Maintenance, licensing and what upgrading costs
The repository is not archived and the last push was on 2026-09-10, which is recent. The release cadence visible in the list is fast: v0.9.1 on 2026-09-02, v0.9.2 on 2026-09-07 and v0.9.3 on 2026-09-09. Fast preview cadence cuts both ways. Fixes arrive quickly, and so do behaviour changes in a 0.x line.
Upgrading is manual. The README states updates come via GitHub Releases and that in-app update checks are not enabled yet, so an upgrade means downloading a new build and replacing the old one. Because sessions, settings, knowledge and runtime extensions live under ~/.pinvou3/, that directory is what you back up before replacing a build, and it is also what carries your configuration forward. Whether a given upgrade migrates that directory's contents is not documented in the README.
The licence is MIT, which permits commercial and private use, modification and redistribution provided the copyright notice and permission notice are preserved. THIRD_PARTY_NOTICES.md and TRADEMARKS.md exist at the repository root, and the app bundles third-party runtimes under private-runtimes, so a redistribution of a modified build carries notice obligations that go beyond the project's own MIT text. Trademark rights are addressed separately in TRADEMARKS.md; the MIT grant does not cover the project name or logo. None of this is legal advice, and if you plan to ship a fork you should read those three files yourself.
Editorial conclusion
Pinvou Agent suits engineers and analysts who want a local-first desktop agent with a knowledge base, an artifact panel and MCP connectors, and who are willing to run preview builds from GitHub Releases. Skip it if you need a stable, auto-updating product, a headless server deployment, or a coding agent that is not already installed on your machine. Before adopting it, check the releases page for the current build, confirm that a local vLLM or OpenAI-compatible endpoint answers at your configured base URL, and read docs/multi-agent-acp.md to see which coding agents the ACP integration expects.
Frequently asked questions
Does Pinvou Agent send my files to the cloud?
It depends on the model and tools you enable. The README states that a local model with local tools stays fully local, while cloud models, remote MCP servers and third-party connectors send the relevant requests to their respective services.
Is there an installer or an auto-update for Pinvou Agent?
Builds are distributed through GitHub Releases for Windows, macOS and Linux, and the README states that in-app update checks are not enabled yet, so moving to a new version means downloading it from the releases page.
Where does Pinvou Agent store sessions and knowledge?
The README states that sessions, settings, knowledge and runtime extensions all live under ~/.pinvou3/, which makes that directory the thing to back up before replacing a build.
Which coding agents can Pinvou Agent drive?
The README names Codex, Claude Code and Kimi, connected through ACP, with sessions bound to their workspace and continuable after restarting the app. The repository also links docs/multi-agent-acp.md for details.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/pinvou-pinvou-agent)