Your projects, secrets, and agents stay connected—so every session builds on the last.
Zero-leak vault, local notes, and native MCP bridge for Cursor and Claude Code.
Open source · Self-hostable · Local-first · Argon2id + AES-256-GCM
AGPL-3.0-or-later · Architecture · kylrix.space · API Docs
- Kylrix — open-source, local-first workspace for notes, goals, workspaces, chat, vault, and agents.
- CLI & MCP Bridge —
npm i -g @kylrix/cli· CLI Docs - Use the cloud — kylrix.space
- Self-host —
curl -fsSL https://raw.githubusercontent.com/Kylrix/kylrix/master/selfhost.sh | bash→ app on:5003 - Wire an agent — mint a PAT (your workspace) or agent key (the agent's own workspace), then
npx skills add kylrix/kylrix --skill mcp --skill api --skill agents
Kylrix is an independently bootstrapped, open-source engineering ecosystem built for decade-scale durability. Maintaining core runtimes, offline-first sync engines, zero-knowledge vault primitives, and sovereign agent toolchains requires continuous development and dedicated engineering bandwidth.
If Kylrix powers your daily workflow or team infrastructure, consider sponsoring development to accelerate roadmap velocity and sustain active maintenance.
You can build custom mobile apps (iOS/Android), desktop wrappers (Tauri/Electron), or menu bar companions for Kylrix.
- Personal Tools & Wrappers: Mint a Personal Access Token (PAT) to connect directly to the HTTP REST API (
/api/v1) or isomorphic SDK. - Distributed / Third-Party Apps: Register an OAuth 2.1 Client with PKCE flow so users can authorize your app securely without exposing private credentials.
Caution
Strict Branding Policy & Termination Warning: The primary requirement for building on Kylrix infrastructure is to never use the name "Kylrix" or any confusingly similar branding in your application name, domain, package, or public listing. Failure to adhere will result in immediate termination of the OAuth2 client and suspension of associated developer accounts.
Notice to Users: The only official clients provided and maintained by the Kylrix team are the web app (kylrix.space) and the official CLI (@kylrix/cli). Consciously using third-party clients that mimic the Kylrix brand risks credential theft and account suspension.
Install once for sovereign offline local-first execution (powered by embedded SQLite):
npm install -g @kylrix/cli(or via pnpm)
pnpm add -g @kylrix/cli1-Click Web Login (Cloud or Custom Base URI):
# Connect to Kylrix Cloud (default)
kylrix login
# Connect to self-hosted instance or custom backend base URI
kylrix login --url http://localhost:3005Multi-Account Profiles & Base URI Silos:
# List accounts partitioned under the active base URI
kylrix accounts list
# Switch active account profile seamlessly
kylrix accounts switch user@example.com
# Manage backend base URIs and partitions
kylrix server list
kylrix server switch http://localhost:3005Manage Sovereign Ideas & Notes:
kylrix ideas listUnlock Encrypted Vault:
kylrix vault unlockStart MCP Server for Cursor, Claude Code, Windsurf:
kylrix mcp(Zero-install alternative: run with npx @kylrix/cli <command>)
📖 See
docs/cli.mdfor the complete command reference and SDK documentation.
Agent skill:
npx skills add kylrix/kylrix --skill selfhostConfigure (optional — omit to auto-mint admin credentials into .env):
export SELFHOST_ADMIN_EMAIL=you@example.com
export SELFHOST_ADMIN_PASSWORD='your-secure-password'Install (bundled Appwrite + Kylrix, no cloud backend):
curl -fsSL https://raw.githubusercontent.com/Kylrix/kylrix/master/selfhost.sh | bash| Default | |
|---|---|
| App | http://localhost:5003 |
| Appwrite API | http://localhost:8080/v1 |
More: SELFHOST.md · re-run ./selfhost.sh anytime (detects drift, skips healthy steps).
git clone https://github.com/Kylrix/kylrix.git
cd kylrix
cp env.sample .envInstall Ota (execution contract for this repo):
curl -fsSL https://dist.ota.run/install.sh | shRun:
ota doctor
ota up --workflow dev # local app → http://localhost:3005
ota up --workflow verify # lint + test + buildContract: ota.yaml · schema: appwrite.config.json
Humans and agents share the same workspace. MCP for IDE tool loops; REST for scripts, mobile, and CI.
Choose auth
| Token | Use when |
|---|---|
PAT (kyl_pat_…) |
The agent acts in your workspace (IDE tools, scripts, MCP on your behalf). Settings → Developers |
Agent key (kyl_apk_…) |
The agent gets its own workspace — it provisions itself and mints its own PAT. Settings → Smart Agents |
| Surface | Use when |
|---|---|
WebMCP (navigator.modelContext) |
In-browser agents (Chrome, ChatGPT browser) with zero-config live session tools |
| MCP | IDE agents (Cursor, Claude, Windsurf, Codex, …) |
REST API (/api/v1) |
Scripts, mobile apps, CI, custom backends |
Steps
- Mint a token — PAT (your workspace) or agent key (agent workspace)
- Install skills
npx skills add kylrix/kylrix --skill mcp --skill api --skill agents
- Connect MCP (IDE only — uses your PAT; Smithery wires the official endpoint)
npx -y @smithery/cli install kylrix/kylrix --client cursor
- Browser Agents (WebMCP) — Auto-exposed via
navigator.modelContextwith zero config in your live session:Test: Enableawait navigator.modelContext.executeTool('kylrix_create_note', { title: 'Agent Note', content: 'Created via in-browser modelContext', tags: ['webmcp'] });
chrome://flags/#enable-webmcp-testingin Chrome, browse via ChatGPT, or click the WebMCP badge in Settings → Developers.
Wiring reference: docs/integrations.md · docs/webmcp.md
| Link | |
|---|---|
| WebMCP (W3C in-browser) | docs/webmcp.md · navigator.modelContext |
| MCP | Humans & agents above · docs/mcp.md |
| REST API | docs/api.md · https://www.kylrix.space/api/v1 |
| Sign in with Kylrix (OAuth 2.1) | docs/oauth2.md |
| SDK | sdk/ in this repo |
| Flows | Extensible layers inside Kylrix — kylrix.space/flows |
| Area | What |
|---|---|
| Notes & ideas | Linked notes, tags, sharing |
| Goals | Goal tracking and focus sessions |
| Events | Calendar and scheduling |
| Forms | Build forms and collect responses |
| Flows | Installable workflow plugins (kylrix.space/flows) |
| Workspaces | Projects, collaborators, permissions |
| Connect | Chats, moments, group hangouts |
| Vault | Client-encrypted credentials (optional) |
| Agents | In-workspace sessions with tool parity to users |
Local copy is the default source of truth; sync confirms in the background.