siddsachar/row-bot
Row-Bot - Personal AI Sovereignty. A local-first AI assistant with integrated tools, a personal knowledge graph, voice, vision, shell, browser automation, scheduled tasks, health tracking
About siddsachar/row-bot
siddsachar/row-bot is an open-source project on GitHub, mainly written in Python. Row-Bot - Personal AI Sovereignty. A local-first AI assistant with integrated tools, a personal knowledge graph, voice, vision, shell, browser automation It currently holds 1,507 stars and 173 forks with 0 open issues, and was last pushed on an unknown date (repository created unknown).
Project Overview
AI Homed tracks it on the Local & On-Device AI board.
GitHub Repository Details
README
Row-Bot
(formerly Thoth)
Row-Bot is a local-first desktop AI assistant for doing real work with models, memory, and tools. Its name is the operating model: Reason through messy context, Orchestrate tools and model providers, and Work inside the files, repos, workflows, and channels you choose.
It combines chat, durable memory, tool use, Agent Profiles, Goal Mode, automatic parent-led agent orchestration, profile-first workflows, Developer Studio, Designer Studio, Smart Skills, Skills Hub, Custom Tools, Plugin System v2, progressive external-tool and skill discovery, context metering and rolling compaction, provider-aware reasoning controls, messaging channels, authenticated multi-device owner access with durable trusted addresses, a native Buddy desktop overlay, managed visible-browser automation, opt-in native Computer Use, centralized conversation cleanup, realtime voice, and provider-aware model routing. Durable app data stays local by default.
For larger tasks, Row-Bot can keep a visible goal, run the thread through a focused Agent Profile, and orchestrate scoped child agents for research, review, implementation, or follow-up work. The original parent remains responsible for joining required results and answering, while durable checkpoints preserve approvals, steering, retries, stops, and recovery. Checkpoint-safe work budgets and application-wide delegation limits keep long or repetitive runs bounded and visible. Parallel writers can be assigned to distinct existing local folders as separate Developer workspaces; folder-scoped locks let those children work concurrently while preserving one writer at a time inside any shared folder. If an app restart interrupts delegation or owned shell work, Row-Bot closes unanswered tool calls without replaying them and resumes the saved parent when its required child results are ready.
Recommended Auto capability loading keeps permitted core tools directly available and searches enabled MCP, plugin, Custom Tool, and channel capabilities only when a request needs them. Enabled manual and plugin skills can be selected for the current parent or child task under the same profile, approval, workspace, and execution-budget boundaries. For long conversations, the responsive desktop composer meters the complete next model input and Row-Bot can compact complete older turns into durable untrusted reference context while preserving the newest turn and atomic tool-call/result groups. It validates the rebuilt prompt before saving and fails with an exact capacity message when the fixed prompt and tool schemas cannot fit the selected window.
Choose the model path that fits the task: local models through Ollama; provider keys for OpenAI, Anthropic, Google AI, xAI, MiniMax, OpenRouter, Atlas Cloud, Requesty, Ollama Cloud, OpenCode Zen, and OpenCode Go; subscription or OAuth sign-in for ChatGPT / Codex, Claude Subscription, and xAI Grok; or custom OpenAI-compatible endpoints such as oMLX, LM Studio, vLLM, llama.cpp, LocalAI, LiteLLM, and SGLang. Row-Bot keeps provider identity, capability labels, reasoning choices, context limits, media surfaces, and chat-only fallbacks explicit so local, hosted, subscription, and self-hosted models can sit side by side.
Row-Bot itself has no account system, no Row-Bot-hosted inference server, and no first-party telemetry pipeline. Provider calls go to the provider or endpoint you choose, and provider keys, OAuth tokens, and subscription tokens are stored in the OS credential store when available. Official Docker deployments use a separate persistent encryption-key volume and encrypted credential records instead. The optional Computer Use beta depends on Cua Driver, whose separately disclosed upstream telemetry must be accepted before Row-Bot installs or invokes it.
Download the latest installer from GitHub Releases. Windows and macOS use one-click installers. Linux has a one-line user installer.
What You Get
| Area | Details |
|------|---------|
| Agent orchestration | LangGraph ReAct agent, Goal Mode, Agent Profiles, Profile Library, automatic parent-led child-agent orchestration, required and detached work, dependency ordering, multi-wave live joins, ordered steering and approvals, transient retry, folder-scoped parallel writers, orphan-only checkpoint repair, explicit parent restart recovery, compact Agent groups and cards, exactly-once completion, checkpoint-safe work budgets, repeated-action protection, configurable nesting/concurrency/active-time limits, profile/tool allowlists, promoted Agent-run workflows, generation-scoped cancellation, complete-input context metering, fixed-envelope preflight, recoverable capacity-aware rolling compaction, and per-thread, per-workflow, per-profile, and per-Developer model overrides. |
| Models and providers | Provider-qualified model selection, exact per-thread/per-model reasoning effort, toggle, and budget controls, readiness routing, chat-only fallback for non-tool models, chat/agent/vision/image/video capability labels, native Ollama tool-capability detection with maintained-family fallback, model-scoped custom endpoint profiles and probes, detected/manual/custom context caps, provider-scoped credential-backed live catalog discovery with last-known-good preservation, xAI Grok OAuth and live image-generation quality/resolution metadata, ChatGPT / Codex and Claude Subscription providers, native OpenCode gateway discovery and per-model transport routing, provider-scoped tool-schema compatibility, phased OpenAI-compatible timeouts with safe pre-stream retry, prompt-cache diagnostics, and background model cache. |
| Memory and knowledge | Personal knowledge graph, 10 entity types, 67 typed relations, bounded semantic/lexical/graph recall, a disclosed checked-by-default local embedding setup download, cache-only normal recall, explicit repair, fast lexical/graph fallback, durable bounded document batches, streamed upload hashing and deduplication, atomic sharded vectors, resumable extraction, queue controls and health repair, audit and review states, recall traces, graph visualization, Obsidian-compatible wiki export with source provenance, Dream Cycle refinement, duplicate merging, stale-confidence decay, relationship inference, self-knowledge, insights, and conversation search. |
| Tools | 30+ core tool modules for web search, DuckDuckGo, Wikipedia, arXiv, YouTube transcripts, URL reading, documents, wiki vault, Gmail, Google Calendar, filesystem, shell, managed visible-browser automation, opt-in native Computer Use, workflows, Goal Mode, child-agent delegation, tracker, channels, X, image generation/editing, video generation, MCP, Developer Studio, Designer Studio, Custom Tool Builder, status, calculator, Wolfram Alpha, weather, vision, memory, system info, and charts. Browser and Computer Use keep separate targets and runtimes but share bounded observation, receipt, error, activity, approval, and cancellation contracts. Recommended Auto loading keeps core profile tools direct and searches enabled external MCP, plugin, Custom Tool, and channel schemas on demand; eager compatibility mode remains available. File tools read PDF, CSV, Excel, JSON, JSONL, TSV, and image files, with schema, stats, previews, and PDF export where supported. |
| Developer Studio | Local Git workspace linking and cloning, code threads, explicit existing-folder assignment for child Agents, folder-scoped writer locks, per-thread and child-agent worktrees, repo inspector, file tree, diffs, todos, tests, branch, commit, push and PR prep, approval modes, and optional Docker Sandbox with a shadow workspace and explicit import back into the real repo. Docker Sandbox intentionally fails closed inside the official Row-Bot server container instead of nesting or falling back silently. |
| Designer Studio | Decks, documents, landing pages, app mockups, and storyboards with a sandboxed interactive runtime, templates, brand controls, critique and repair, AI image and video generation, chart insertion, Mermaid and Plotly rendering, shareable HTML, and export to PDF, HTML, PNG, and PPTX. |
| Workflows | Scheduled runs, webhook triggers, task-completion triggers, step pipelines, conditions, approvals, subtasks, notification-only runs, concurrency groups, delivery defaults, profile-first workflow agents, promoted Agent-run workflows, per-workflow model/tool/skill/profile overrides, safety modes, run status, run history, upcoming runs, and a Workflow Console. |
| Controlled self-evolution | Structured self-reflection, bounded change proposals, reviewable execution boundaries, persistence, Dream Cycle and memory integration, and Command Center/status visibility for improvement work that stays explicit and auditable. |
| Channels and voice | Telegram, WhatsApp, Discord, Slack, SMS, and plugin-owned channels with platform-aware live streaming, typing and edit fallbacks, interactive approvals, durable child-agent and Goal Mode notices, media intake, voice transcription, document extraction, health checks, auto-generated send/photo/document tools, and optional tunnel support. SMS remains final-text-only. Realtime voice adds provider-backed voice sessions, action handling, speech/cue policy, and local faster-whisper or FunASR/SenseVoice STT plus Kokoro TTS options. |
| Platform and app | Native desktop app plus authenticated single-owner desktop and compact browser access; one-time invitations, durable revocable sessions, exact trusted-address add/remove controls, assigned-interface route discovery, route and device management, Tailscale Serve, browser-local voice, and strict HTTP/WebSocket origin gates; authenticated headless serve mode; official hardened Docker/VPS deployment and multi-architecture GHCR images; a native Windows/macOS Buddy desktop overlay with drag-to-undock placement, selected-thread messaging, shared drafts, progress, Stop, approvals, focus hand-back, docking, collapse, hide, and tray recovery; an exact Playwright-matched managed Chromium runtime with explicit install/repair and bounded installed-browser fallback; opt-in Computer Use setup, live takeover, and permission recovery on Windows and macOS; a race-safe conversation cleanup service with retained Designer/Developer ownership rules; installable PWA support; local browser-first Linux launch; Home status surfaces; recovery tools; verified auto-updates; and a searchable public user guide. |
| Extensibility | Smart Skills, pinned skills, slash commands, Skills Hub browsing/import/search, automatic per-task discovery of enabled manual and plugin skills, Plugin System v2 for native tools, MCP-backed tools, bundled skills, and channels, sandboxed Plugin Center and marketplace, bundled skills and tool guides, Agent Profiles, child-agent tools, Goal Mode tools, external MCP clients over stdio, Streamable HTTP, and SSE, Custom Tools from repos or folders, hardened Custom Tool Builder setup, Claude Code Delegation through an approval-gated CLI worker, migration from selected Hermes/OpenClaw data, setup center, identity settings, and stability diagnostics. |
See docs/ARCHITECTURE.md for the full subsystem reference.
Install
Windows
1. Download the latest Windows installer. 2. Run it. The installer bundles the embedded Python runtime, app source, and Python dependencies. Ollama is optional and only needed for local models. 3. Launch Row-Bot from the Start Menu or desktop shortcut.
User data lives in %USERPROFILE%\.row-bot. Repairing or upgrading replaces the bundled runtime and preserves your data. Startup logs are written to %USERPROFILE%\.row-bot\row_bot_app.log, including recovery hints for known optional audio package issues such as TorchCodec.
macOS
1. Download the latest macOS DMG.
2. Drag Row-Bot.app into Applications.
3. Launch Row-Bot from Applications or Launchpad.
The first run may ask you to confirm that the app was downloaded from the internet. The packaged app uses its bundled Python runtime and dependencies, and it starts Ollama if Ollama is already installed. Apple Silicon and Intel Macs are supported on macOS 12+.
If you only want provider models or a custom endpoint, you can skip model downloads during setup.
Linux
Run:
curl -fsSL https://raw.githubusercontent.com/siddsachar/row-bot/main/installer/install-linux.sh | bash
To install a specific version:
curl -fsSL https://raw.githubusercontent.com/siddsachar/row-bot/main/installer/install-linux.sh | bash -s -- 4.9.1
The installer downloads the release tarball, verifies its SHA256 from the GitHub release manifest, installs under ~/.local/share/row-bot, creates ~/.local/bin/row-bot, and stores user data in ~/.row-bot. The default Linux build opens in your system browser. Native window and tray support are available when the required GTK, Qt, and AppIndicator libraries are installed.
Manual tarball install:
tar -xzf Row-Bot-X.Y.Z-Linux-x86_64.tar.gz
cd Row-Bot-X.Y.Z-Linux-x86_64
./install.sh
row-bot
If ~/.local/bin is not on PATH, run ~/.local/bin/row-bot or add it to your shell profile. On Linux, provider secrets use Secret Service or KWallet when available. WSL and headless systems can run without a keyring, but new secrets are session-only until secure storage is configured. For persistence in headless Linux, run Row-Bot inside a D-Bus session with a Secret Service backend such as gnome-keyring-daemon, or explicitly configure another secure Python keyring backend such as an encrypted file keyring.
Browser Automation installs its Playwright-matched managed Chromium only after you choose the explicit install or repair action in Settings. Linux may still need distribution packages that the tarball cannot install; if Playwright reports a missing operating-system dependency, install that dependency and run the Browser repair action again. Normal startup and readiness checks never download a browser.
Docker / Headless Server
The official image is a complete single-owner server deployment for amd64 and arm64. From the repository root, pin the release and start the hardened loopback-only Compose profile:
export ROW_BOT_IMAGE=ghcr.io/siddsachar/row-bot:4.9.1
docker compose -f deploy/docker/compose.yaml up --detach
docker compose -f deploy/docker/compose.yaml ps
After the service is healthy, create the first one-time owner invitation from a trusted terminal:
docker compose -f deploy/docker/compose.yaml exec row-bot \
row-bot access invite --layout desktop --origin http://127.0.0.1:8080
Compose persists app data and a separately mounted encryption key in two named volumes. Back up both together. The container does not grant owner access from a Docker bridge address, and every browser must authenticate. Read Docker And VPS Operations before adding LAN, Tailscale, SSH, reverse-proxy, or public VPS reachability.
Upgrading from Thoth 3.x
Row-Bot v4 is the renamed successor to Thoth. Current Row-Bot releases no longer run the old automatic Thoth-to-Row-Bot rebrand migration during startup. That migration shipped for multiple Row-Bot releases after the v4 rename and has now been removed from the hot startup path.
Users still on Thoth or an early Row-Bot build should first install and launch a previous migration-capable Row-Bot release, then upgrade to the current release. The current Migration Wizard remains focused on selected Hermes/OpenClaw data and is separate from the removed Thoth rebrand bridge.
Quick Start
On first launch, Row-Bot opens a setup wizard. Pick one of three paths:
| Mode | Use it when | Setup |
|------|-------------|-------|
| Local | You want inference and embeddings on your machine. | Choose a local runtime, download a recommended model such as qwen3:14b or a smaller model such as qwen3:8b, then start chatting. Ollama is the supported local runtime today. |
| Providers | You want hosted models, frontier reasoning, media generation, or no local model download. | Add an OpenAI, Anthropic, Google AI, xAI, MiniMax, OpenRouter, Atlas Cloud, Requesty, Ollama Cloud, OpenCode Zen, or OpenCode Go key, refresh live catalogs where available, pick a default model, and save Quick Choices. ChatGPT / Codex, Claude Subscription, and xAI Grok OAuth sign-in are available in Settings after launch. |
| Custom/Self-hosted | You run oMLX, LM Studio, vLLM, llama.cpp, LocalAI, LiteLLM, SGLang, or a private gateway. | Enter an OpenAI-compatible base URL such as http://127.0.0.1:1234/v1, choose the closest compatibility profile, add a key if your server requires one, fetch models, probe the exact model, verify or declare its server context, and choose a default. |
For routine chats, use Row-Bot normally. For longer work, create a Goal so progress and blockers stay visible, choose an Agent Profile for the role you want, and let the parent orchestrate child agents when subtasks can run separately under tighter tool and approval boundaries. Required children join the same live parent turn; detached children can continue without blocking it. When independent children need to write in parallel, give each one a distinct existing local folder as its Developer workspace. Changing only a shell working directory does not partition writer ownership, and children assigned to the same folder still serialize. Use child worktrees when the task instead needs Git-backed branch isolation.
Capability loading defaults to the recommended Auto mode. Core tools permitted
by the active Agent Profile stay directly available; enabled external tools and
skills are searched locally and loaded for the current task as needed. Use
Settings -> Tools -> Capability loading to select eager compatibility mode
for an older provider or integration that requires every external schema.
Supported models expose a Thinking control beside the desktop model picker
and inside compact mobile Chat controls. The available effort, On/Off, and
token-budget choices come from the exact provider-qualified model and persist
only for that model in that chat. Use /reasoning in Chat or a connected
messaging channel to inspect or change the same setting; Provider default sends
no per-thread override and remains the compatibility choice.
To use the same running Row-Bot from another computer, phone, or tablet, open
Settings -> System -> Remote Access on an authorized owner device. Select a
current route or add one exact trusted HTTP or HTTPS address, create a one-time
invitation with either desktop or compact presentation, then open or scan it on
the new device. Both layouts receive the complete owner product, including
Settings. The host must remain running, every resulting device session can be
revoked independently, and a saved trusted address can be removed when the
route is no longer used.
For website navigation, Browser Automation uses a visible task-owned page with opaque snapshot-bound controls. Open `Settings -> System -> Browser & Computer Use` to install or repair the exact Chromium revision matched to Row-Bot's Playwright package. A supported installed Chrome or Edge channel can be used without a probe launch; a real channel launch failure falls back at most once to an already-ready matching managed Chromium.
To let an interactive local task operate a native Windows or macOS app, use the same Settings section. Review the Cua Driver 0.20.0 telemetry notice, explicitly install the checksum-verified private runtime, grant the requested operating-system permissions, and complete the Calculator test. Computer Use is off by default and unavailable to channels, schedules, background workflows, child agents, plugins, mobile clients, and headless/server callers. Browser Automation remains the preferred tool for websites, and the two engines never silently substitute for one another after a structured refusal.
Common first prompts:
Remember that my mom's birthday is March 15Search for recent papers on transformer architecturesRead report.pdf in my workspaceRun git status on my projectOpen Calculator and work out the total from these figuresCreate a goal to update the release docs and track blockersDelegate competitor research to a focused child agent and summarize the risksCreate a six-slide pitch deck for my startupShow my headache trends this monthRemind me to call the dentist tomorrow at 9amReview this repo and suggest the highest-risk issuesTurn this GitHub repo into a Custom ToolWhat did I ask about taxes last week?
--ctx-size or the equivalent server option separately. The desktop meter
shows the estimated next input and automatic rolling compaction begins at 75
percent of the effective window when capacity is known. Models that are useful
for normal conversation but not reliable with tools can still run through
chat-only mode.



