trinity
A personal AI agent that runs on your own machine and keeps receipts.
Trinity remembers you, learns procedures, acts through tools under a permission gate, reaches you on whatever surface you are using, and does not lose your work when something crashes. Built on the BEAM so those properties are structural rather than aspirational.
What it does.
- Talks. Streaming chat with any model provider, switched by configuration. The reply is saved as a draft while it streams, so a crash loses at most a moment of it. Long conversations are compacted with their lineage kept.
- Acts. Filesystem, web and shell tools behind a permission gate with fingerprint-bound approvals. Every effect leaves an Ed25519-signed, hash-chained receipt you can verify offline with
mix trinity.receipts.verify. - Remembers. A persona, a small always-on memory, full-text search over every past conversation, and a semantic tier recalled by meaning with local embeddings. Encrypted at rest, and exportable as one archive.
- Learns. Skills in the agentskills.io SKILL.md format. The agent can propose new skills; each proposal is staged with a diff, scanned, and applied only when you approve it.
- Connects. An MCP client (stdio and Streamable HTTP) for any server you add, and an MCP server with OAuth 2.1, so Claude Code, VS Code, Codex or goose can connect to Trinity through the same gate and receipts.
- Reachable from elsewhere. Gateways let Trinity answer from other channels, with pairing for unknown senders and approvals capped below what the desktop may grant.
- Delegates. Bounded child sessions with their own context and budgets in turns, tokens and time; their approvals surface on the same permissions page.
- Shows what it costs. One telemetry catalogue for every model call, tool call and approval, with credentials redacted by shape, and a cost ledger by day, model, session and persona against budgets that warn or refuse.
- Computes, rather than estimates. A Lua sandbox inside the process with a heap ceiling and a wall clock; anything a script wants done goes through the same permission gate.
- Runs on a schedule. Tasks on a cron, a one-shot time, or a phrase like "every weekday at 9am", as durable jobs that survive a restart.
Supply chain.
OpenSSF Best Practices silver, awarded 23 September 2026. CycloneDX SBOM, Developer Certificate of Origin on every commit, build provenance attestations, a Scorecard workflow, and a FIPS CI leg.
Run it.
Elixir/OTP and Phoenix LiveView, packaged as a desktop application with a Tauri shell. The pinned toolchain is in .tool-versions, installed with asdf install; Rust is pinned separately in rust-toolchain.toml and is only needed for the desktop shell. From the README:
git config core.hooksPath .githooks # once, before your first commit
cp .env.example .env # then put a provider key in it
mix setup # dependencies, database, assets
mix phx.server # or: iex -S mix phx.server
Then open localhost:4000. The README's running-from-source section has the rest.
Standalone, or governed.
Trinity.Authority is a public behaviour with one in-tree implementation. Under Requisition, Trinity can only propose, and every proposal is a governed act with a receipt; Requisition plugs in through an adapter without Trinity depending on it. Ultraviolet connects as an MCP server like any other. Both are optional. Trinity depends on beam_mcp.
Apache-2.0, open source from the first commit.