egzos
v0.1.1. The core's first source-available release (PolyForm Strict 1.0.0): the CLI, the MCP server, the browser approval tap, the audit chain and the lifeboat UI run end to end. Install it from the release tag below.
egzos is an MCP-first, CLI-first personal context layer. Your container is the home; platforms are clients. The security model is the product.
What egzos is
Your container, your rules. egzos stores your personal context — notes, decisions, threads, artifacts — in a container you run and own. Platforms (the egzos.io flagship, your own forks, Claude Code, any MCP client) connect to the container as clients. They do not hold your data; they access it under capabilities you grant.
Push-first. Platforms never pull from your container live. You push what you choose, to whom you choose; nothing is revealed by default, and every read is a capability check.
Emergent hierarchy. Thread, project, team, org, exo, global — these are container types you instantiate at will, not a fixed chain you have to fill in. Rings of trust and parent pointers do the rest.
Agents propose, humans dispose. Agent output (summaries, suggestions, auto-titles) is a proposal in your inbox. You approve it; the ledger records what happened. No agent acts on your behalf without your disposition.
The security model is the product. The authorization server lives inside your container. Browsers authenticate via auth-code + PKCE; the CLI uses device-code; MCP clients follow the MCP authorization spec — all against your container's own AS. The egzos.io session proves your subscription; the container token proves your authorization. Those are two separate authorities, deliberately.
Signed .xmb export. Leaving is easy. One command exports your container as a signed, portable archive you can import anywhere.
Quickstart
pipx install "git+https://github.com/Egzos/egzos@v0.1.1"
egzos init # your container at ~/.egzos, and your owner token
egzos add "Prefer imperative commit messages" --kind preference --key commit.style
egzos add ./notes.md # files work too; everything lands unverified
egzos find commit # numbered results; act on them with %1, %2 …
egzos connect # mints a token for Claude Code, prints the line to run
egzos connect --apply # …or registers it with Claude Code for you
Then, in Claude Code, ask it to use the egzos tools: egzos_fetch reads your context for a scope,
egzos_remember writes (it lands unverified in your inbox), egzos_inbox lists the queue.
- Agents propose, you dispose. Anything an agent writes waits in
egzos trust pendinguntil you approve it:egzos trust approve <id>opens a one-shot approval page in your browser. A move that would widen who can read something is parked until you say yes. - Every read and every yes is on the record.
egzos audit tail/egzos audit verify— a hash chain that verifies end to end. - Structure as you go.
egzos mk project health,egzos mv %1 project:health,egzos fetch project:health.
The core and the flagship
What is in this repository (public, source-available under the PolyForm Strict License 1.0.0):
- The container: context store, trust engine, audit ledger
- The CLI (
egzos) and MCP server - The lifeboat UI (server-rendered, in-process, no JS toolchain)
- The authorization server surface
- Spec and contracts (
spec/)
What is in Egzos/egzos-platform (proprietary; private from its first product-code commit):
- The egzos.io flagship web UI
- Hosted containers, previews, relay
- Server-side intelligence (scheduling, continuous baselining, nightly suggest)
- Billing and sessions
The core is free for noncommercial use under its licence (PolyForm Strict 1.0.0); commercial use needs a separate licence from the copyright holder. The flagship's hosted experiences and infrastructure are the paid product, over there.
How the build works
This repo is built by an agent roster running in GitHub Actions under the Chief's gate.
Agents propose; the Chief disposes; GitHub enforces. Everything visible to an agent is data, not instructions. The build behaves like the product.
Agents open PRs on branches named agent/<name>/<slug>. The Chief approves each PR by SHA. GitHub's branch protection executes the merge. No agent has merge rights. The build dogfoods the product's own trust posture.
- Agent definitions:
.claude/agents/ - Agent routing:
.claude/agents/README.md - Trust posture and rules:
CLAUDE.md - Spec and contracts:
spec/
Security
See SECURITY.md. Report vulnerabilities privately via GitHub Security Advisories — do not open a public issue with a reproduction.
Status
MVP preview. The CLI, MCP stdio server, browser approval tap and audit chain run end to end on the
walking skeleton's modules (Phase 0.1) plus the MVP additions (egzos connect, the step-up tap). The
lifeboat (egzos web, FastAPI + Jinja + htmx per spec/design/lifeboat.md) lands next, in its own PR. The frozen-contract
build (spec/contracts/) replaces them module by module. Not yet included: the container's OAuth
authorization server and remote MCP (Phase 5), embeddings, and the egzos.io flagship.
License
Source-available under the PolyForm Strict License 1.0.0: you may use egzos for any noncommercial purpose (personal use, research, hobby projects, noncommercial organizations), but not distribute it, change it or build on it, and not use it commercially without a separate license from the copyright holder. Versions up to and including 0.1.0 were released under Apache-2.0. The egzos name and mark are not part of any licence grant — see TRADEMARKS.md.
Metadata
Release files for egzos 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| egzos-0.1.1.tar.gz | 745.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| egzos-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 893.6 kB
Release files / egzos-0.1.1.tar.gz
| Download URL | egzos-0.1.1.tar.gz |
|---|---|
| Size | 745.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
cc32d3ae903720df17ad15325744934351b98b27df3f79828f05ef997e7b640e
|
|
BLAKE2b-256 checksum How to use checksums |
8a1f6521e50c9cf58a7535a8c50a64f663f659fba822cc40e0817e523c9ef3d7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.
Transparency logRelease files / egzos-0.1.1-py3-none-any.whl
| Download URL | egzos-0.1.1-py3-none-any.whl |
|---|---|
| Size | 147.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e96b16164e7631e8e305de80a1230f6802676753a8997e0f88ea71c55d6a7501
|
|
BLAKE2b-256 checksum How to use checksums |
e2a0cbfacb33b4cadfba64146cf38e3f5b9e6c2f322b176011f2c79fa47a5000
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.
Transparency log