Local-first agent control plane
Your agents can move fast.
You can still see everything.
Not Codex brings Codex, Claude Code, Cursor, Grok Build, OpenCode, and Pi into one governed workspace for interactive sessions, repository workflows, scheduled Automations, and bounded agent loops.
Public source today. Signed packages and a hosted app are not available yet.
- 6agent harnesses
- Codex, Claude Code, Cursor, Grok, OpenCode, and Pi
- 1governed workspace
- Sessions, worktrees, approvals, and review
- 3ways to run
- Interactive, scheduled, and bounded loops
- 0hosted lock-in
- Local-first and MIT licensed
Six first-class harnesses
Bring the agent. Keep one workspace.
Choose a provider instance and model for each task. Not Codex translates their different session and event protocols into one durable timeline without pretending every provider has the same capabilities.
- Codex
- Claude Code
- Cursor
- Grok Build
- OpenCode
- Pi
New / Pi native RPC
Pi is more than a name in a picker.
Not Codex discovers Pi models, skills, and slash commands dynamically, keeps a persistent Pi process per thread, and stores a restart-safe session cursor.
- Permission bridge
- Pi tool calls follow the same approval-required, edit-safe, and full-access modes.
- Provider-aware controls
- The interface exposes only the modes and actions a selected harness can actually support.
- Multiple instances
- Keep separate provider installations or identities explicit where the harness supports them.
Repository workflow
Work in parallel without making a mess.
Give each task an isolated lane. Keep branches, checkpoints, diffs, and stacked changes close to the conversation that produced them.
- Separate worktrees
- Concurrent agents do not silently overwrite each other.
- Reviewable checkpoints
- Inspect what changed before you commit, push, or open a pull request.
- Stack-aware handoff
- Keep dependent branches legible while work moves toward main.
The rest of the workspace
Agent work needs more than a chat box.
The everyday controls around a task matter just as much as model output. Not Codex keeps review, navigation, media, usage, and personalization in the same product surface.
- 01Pull requests in context
- Browse pull requests across connected repositories, open a read-only review workspace, and keep branch context beside the task.
- 02Images in the prompt
- Paste screenshots and local images into a task. Compatible agents receive the real local paths instead of a flattened description.
- 03Terminals and previews
- Keep long-running commands, development servers, and preview surfaces attached to the repository and session that started them.
- 04A calmer task list
- Pin, snooze, archive, search, and regenerate thread titles while project grouping keeps related repositories together.
- 05Usage you can inspect
- See provider limits and a rolling 24-hour usage view without leaving the workspace where the work is happening.
- 06Make it your workspace
- Choose project defaults, customize keybindings, and browse Open VSX themes with predictable light and dark palettes.
One execution model
Different agents. The same clear path to review.
Interactive sessions, Automations, Loopy specifications, and accepted LoopAny deliveries all enter the ordinary Not Codex harness. That keeps approvals and repository safeguards in the path regardless of how work begins.
- 01Ask in a real repository
- Start with the project, branch, and agent you want. Every task gets an explicit context instead of an anonymous terminal tab.
- 02Run inside a governed lane
- Worktrees isolate concurrent changes while approvals, questions, tool calls, failures, and reconnects remain visible in one timeline.
- 03Review before it lands
- Inspect checkpoints and diffs, prepare stacked work, and decide what becomes a commit or pull request. Keep the final decision with the operator.
Automations
Schedule outcomes, not blind scripts.
Turn a well-scoped task into a recurring agent workflow while retaining the same project checks, isolation, notifications, and review surface as an interactive session.
- 01Flexible schedules
- Run immediately, once, on an interval, or on a weekly schedule.
- 02Bounded follow-through
- Continue until complete within explicit time and attempt limits.
- 03Repository-aware
- Run project checks, isolate work in a worktree, and optionally prepare a branch or pull request.
- 04Observable by default
- See history, next run, current state, notifications, and the resulting agent session.
Monkey D. Loopy
When a prompt needs a bounded, verifiable loop.
Author and inspect a structured loop, validate its control flow, then execute every agent step through a normal Not Codex thread. Verification checks the specification and mocked effects; it does not certify model quality.
Durable run receipt
Follow the loop without losing the thread.
Each run has an environment-scoped receipt with status, bounded progress, timestamps, the underlying session, and explicit cancel, resume, or retry controls.
Optional LoopAny connector
Accept scheduled work without moving execution to the cloud.
A compatible LoopAny server can schedule and deliver work. Not Codex root-jails accepted paths and routes the work through its local harness instead of evaluating remote workflow source on your machine.
Cross-device control
Keep an eye on the work when you leave the desk.
Responsive web and mobile clients control a paired Not Codex environment. Review sessions, answer questions, inspect changes and pull requests, and manage safe connector settings from the same server-authoritative model.
- Paired, not duplicated
- The phone is a client. Provider sessions and integrations keep running in the paired environment.
- One recovery story
- Web and mobile read the server-authoritative state after reconnects or restarts.
Trust boundary
Fast agents still need visible limits.
Not Codex is designed around ownership and recovery rather than invisible autonomy. It is early software, so you should still use recoverable repositories and inspect agent actions.
- 01Credentials
- Use the provider CLIs and credentials already managed on your machine.
- 02Execution
- Keep the server local and bind it to a trusted network only.
- 03Changes
- Isolate concurrent work and use supervised mode when destructive or consequential actions should require approval.
- 04Recovery
- Persist session and integration state so restarts do not erase the audit trail.
- 05Source
- Inspect the implementation and build it yourself under the MIT license.
Available now
Open source and ready to inspect.
The repository, architecture, security guidance, integration docs, and this public site are available today. Build locally if you want to explore the work in progress.
Read the build guideWhat comes next
Packaging, hardening, and proof.
Signed desktop packages, broader installation paths, continued security review, and more production evidence are the next milestones. They are planned, not promised.
Follow the roadmapNot another agent







