PipkinPad: a local, AI-assisted file manager and terminal workspace.
Project description
PipkinPad
PipkinPad is a locally-run Python workbench: manage files in the current directory, use a persistent terminal, and let an OpenAI API-compatible AI assist with processing work tasks.
Installation & Startup
pip install pipkinpad
cd your-project
pipkinpad start
The app listens on 127.0.0.1:8765 by default. Use --port 9000 to change the port. By default the browser is not opened automatically; add --browser to open it on start. The startup directory is the workspace root — the service and AI cannot access paths outside it.
To use the same workbench from another device on a trusted network, start it on the host machine with:
pipkinpad start --host 0.0.0.0
Then visit http://HOST_IP:8765 from the other device. Do not expose this service to an untrusted network or the public internet.
Configure the model (keys are never echoed):
pipkinpad config --base-url https://api.openai.com/v1 --model gpt-4.1-mini --api-key YOUR_KEY
pipkinpad config
pipkinpad clear-config
Password protection
Set a password before starting the server to require login in the browser:
pipkinpad config --password YOUR_PASSWORD
After a successful login, PipkinPad remembers that browser for 30 days using an HTTP-only signed cookie. Changing the password invalidates previous logins. To return to password-free local access:
pipkinpad config --clear-password
The password is never stored directly. Its salted PBKDF2 hash and the cookie signing secret are kept inside PipkinPad's encrypted local settings file.
You can also fill in the "Configure API" panel on the app's right sidebar. Connection parameters and API keys are encrypted and saved to a local config file; the master encryption key is stored in the operating system credential store.
Security Model
- A random local session token is generated on every startup; the file API and terminal WebSocket require this token.
- File operations are path-normalized and restricted to the startup directory; hidden files are not shown in the tree.
- The AI only sees chat history and files or terminal output you explicitly attach.
- The AI can only propose commands. The page provides a confirmation button for each Bash command; once confirmed, the command runs in the workspace's isolated Bash process, and output is handed back to the AI for further processing. The AI never writes to the human-facing Terminal; when leveraging Terminal context, it can only read its output.
- UI state is saved in
.pipkinpad-ui-state.jsonin the workspace, so devices connected to the same PipkinPad service share layout, tabs, context settings, and a Terminal-output snapshot. - Audit events are saved to
.pipkinpad-audit.jsonlin the workspace; API keys and terminal input are never logged.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file pipkinpad-0.1.6.tar.gz.
File metadata
- Download URL: pipkinpad-0.1.6.tar.gz
- Upload date:
- Size: 33.5 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ef759b5e977ef3adc6387ee9f5911eae02f7ae72ee07066754b372c5f22f36c7
|
|
| MD5 |
6a667ad22e88611271c7078cf1aebcaa
|
|
| BLAKE2b-256 |
c67ef7e7fb639ea355f746d969b90c9c01583e4b1b9063175608e3bc3d4eba1f
|
Provenance
The following attestation bundles were made for pipkinpad-0.1.6.tar.gz:
Publisher:
publish.yml on hzq1995/pipkinpad
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
pipkinpad-0.1.6.tar.gz -
Subject digest:
ef759b5e977ef3adc6387ee9f5911eae02f7ae72ee07066754b372c5f22f36c7 - Sigstore transparency entry: 2161814130
- Sigstore integration time:
-
Permalink:
hzq1995/pipkinpad@7927b3aa5bb68218c14b23a5ccea073adbc53bb1 -
Branch / Tag:
refs/tags/v0.1.6 - Owner: https://github.com/hzq1995
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@7927b3aa5bb68218c14b23a5ccea073adbc53bb1 -
Trigger Event:
push
-
Statement type:
File details
Details for the file pipkinpad-0.1.6-py3-none-any.whl.
File metadata
- Download URL: pipkinpad-0.1.6-py3-none-any.whl
- Upload date:
- Size: 37.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
e61aa86253ec340ec8e2fb644f97b4c18fe4734e8b777e3b8d744686264df035
|
|
| MD5 |
0e7f513d97bcc425b240b7cac948c0cc
|
|
| BLAKE2b-256 |
05ede269538230150b96456666f1c2628c833ec2522f9e3b92fe5a2746b5cac5
|
Provenance
The following attestation bundles were made for pipkinpad-0.1.6-py3-none-any.whl:
Publisher:
publish.yml on hzq1995/pipkinpad
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
pipkinpad-0.1.6-py3-none-any.whl -
Subject digest:
e61aa86253ec340ec8e2fb644f97b4c18fe4734e8b777e3b8d744686264df035 - Sigstore transparency entry: 2161814757
- Sigstore integration time:
-
Permalink:
hzq1995/pipkinpad@7927b3aa5bb68218c14b23a5ccea073adbc53bb1 -
Branch / Tag:
refs/tags/v0.1.6 - Owner: https://github.com/hzq1995
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@7927b3aa5bb68218c14b23a5ccea073adbc53bb1 -
Trigger Event:
push
-
Statement type: