A personal agent with a spine

Make room for an intelligence that remembers.

A local-first personal AI agent runtime with durable memory, model freedom, real-world tools, and explicit safety boundaries. Ódinn turns the messy middle of real work into a local, inspectable workspace—one that can act without becoming unknowable.

01 State stays local02 Models stay yours03 Actions leave a trail
THE SIGNAL
Local-first by designThe control plane, memory, and evidence begin on your machine.
Open model surfaceBring a provider, a local server, or a model you trust.
Nothing consequential is invisibleApprovals, runs, and policy decisions stay reviewable.
02THE SYSTEM
A workspace, not a chat skin

Intelligence is only useful when it can keep the thread.

Ódinn binds the conversation to the things real work needs: durable context, real tools, bounded authority, and a record you can return to later.

01

Memory that stays yours

Keep durable personal and project context locally, review what is remembered, and correct it without erasing history.

ODINN / FORGE
02

Bring your own model

Use browser sign-in, API keys, local OpenAI-compatible servers, Ollama, or supported command-line adapters.

ODINN / FORGE
03

Tools with a safety boundary

Search the web, use an isolated browser, and run tools through the same policy-gated, audited kernel path.

ODINN / FORGE
04

Work you can inspect

See sessions, projects, goals, schedules, approvals, runs, and audit history in a chat-first local console.

ODINN / FORGE
03THE PROTOCOL

Power should leave a trace.

Every tool boundary travels through the same policy-gated kernel. Ódinn can move quickly, but the important choices remain legible.

  1. 01
    Start with the outcome

    Chat naturally or define a bounded task.

  2. 02
    Make authority explicit

    External or risky actions pause before they cross the line.

  3. 03
    Keep the evidence

    Runs, decisions, and results stay attached to the work.

Walk through the operator console
04THE BOUNDARY
Safety without theater

Useful force. Visible limits.

Ódinn defaults to a loopback-only, single-user gateway. Browser mutations are approval-gated, credentials stay out of normal evidence, and unknown tools are treated conservatively.

Study the security model
Three things it will not pretend

01Forked workers provide crash containment, not a security sandbox.

02Remote hosting provides application-level tenant isolation, not hostile-user operating-system isolation.

03External effects and nondeterministic provider behavior remain outside full replay and rollback guarantees.

05THE LABS
Seven experiments / zero silent switches

Where the forge gets strange.

Experimental capabilities are individually gated. Each has a name, a boundary, and a page that tells you exactly what enabling it means.

Separate from Labs / on by default

Automatic Improvements

Watches for repeated audited failures and applies only reversible, allowlisted reliability tuning through a bounded controller. It cannot disable safeguards, grant permissions, or invent arbitrary actions.

See the boundaries
v0.4.0-beta.3
OPEN SOURCE
Public beta / built in the open

Bring your work. Keep your authority.

Ódinn is a real workspace for conversations, memory, tools, and the decisions that connect them. Start local, choose your model, and keep the system close enough to understand.

YOUR MACHINE / YOUR MODELS / YOUR AUTHORITY

Give your AI a workspace with a line it cannot quietly cross.