Intelligence should not be temporary.
1Helm gives every job a permanent AI resident with its own private computer, durable memory,
and real skills — so the agent you train today is better at the job tomorrow.
Download for Mac · for Windows · for Linux · The story · Ship's manual · Vision · Security
AGPL-3.0-only
Self-hosted
Model-agnostic
Signed + notarized
macOS · Windows · Linux
Every AI chat you've ever had ends the same way: the context window fills, the session dies, and everything the model learned fits on a sticky note addressed to its replacement. One tab, one session, one race against the token timer.
That isn't a law of nature. It's a product decision — and 1Helm makes the opposite one. Instead of renting intelligence by the session, you give each ongoing job a resident: an agent with a stable identity, a persistent private Linux computer, curated memory, and scheduled obligations that survive restarts, model swaps, and closed laptops.
The whole story, as told at 1helm.com — click to scroll it yourself.
Create a channel for product, finance, research, home, support, or anything else that deserves an owner. 1Helm provisions a complete world around it:
| Every ordinary channel receives | What that changes |
|---|---|
| One permanent resident | Threads are sessions; the employee identity survives them. |
| One private Linux computer | Chat tools and Terminal use the same persistent /workspace. |
| Memory with provenance | Decisions, corrections, preferences, files, and outcomes become continuity. |
| A serious skill arsenal | The agent sees what exists and loads a full procedure only when it chooses one. |
| Durable obligations | Follow-ups, timers, workflows, and services can wake the computer back up. |
| Skipper at the boundary | Host work, credentials, fleet operations, and cross-channel work route themselves. |
The human sets the outcome and brings judgment, taste, credentials, and real authority. The resident inspects, installs, edits, runs, retries, waits, and verifies inside its own world. When it needs something outside that world, it calls Skipper directly. Skipper acts and returns the exact thread to the same resident automatically.
The Captain is the leader—not the package manager, retry loop, permission dialogue, or message bus between agents.
Captain 1Helm
│
│ “Own the launch and ship the fix.”
▼
Resident ─── routine execution ───► private channel computer
│ │
│ needs host, credential, │ files · tools · services
│ or another resident │ memory · obligations
▼ │
Skipper ─── crosses the boundary ─────────┘
│
└──────── automatic return ─────► Resident verifies and finishes
- Captain is the first user, workspace owner, and final human authority.
- Skipper is the one workspace-wide chief of staff and host/fleet operator.
- Residents are permanent specialists, one per ordinary channel.
- Threads are durable sessions—not the agent's entire identity.
- The computer, memory, skills, and obligations belong to the channel and survive model changes and application restarts.
On Apple Silicon:
- Download the current signed DMG.
- Open it and drag 1Helm to Applications.
- Launch 1Helm. Gatekeeper verifies its Developer ID signature and Apple notarization ticket.
- Complete Captain → Providers → Workspace. If required, approve Apple's signed container runtime once during workspace creation.
Application state lives under ~/Library/Application Support/1Helm and every
update preserves it — credentials, databases, resident state, files, and
workspaces. Profile → Check for updates asks the Mac running 1Helm—not the
device displaying the web UI—to download and verify the signed update.
Windows 11 x64 gets a signed Setup executable that provisions one private WSL 2 world per channel. Linux hosts use a verified installer that provisions a durable systemd service with an atomic, digest-verified, health-checked updater — see the Linux install guide. Whichever platform, it works best on a dedicated machine: your crew works around the clock, and your everyday computer takes naps.
Every resident starts with a seven-skill operational core plus the focused playbooks selected by its channel template. The shared workspace catalog still contains 34 complete procedures covering outcome ownership, Skipper handoff, obligations, skill discovery, memory, research, email, calendar, contacts, messaging, documents, spreadsheets, PDFs, meetings, projects, personal operations, travel, finance, support, software delivery, data, media, infrastructure, security, and more.
The model receives a compact inventory of its assigned skills—not all 34 procedures in every prompt. It loads one complete skill when useful and can ask Skipper for another catalog skill when the job expands. A resident can also:
- search the open SkillsMD registry directly, then inspect and install a selected GitHub-backed skill — only after immutable revision pinning, bounds, scanning, hashing, provenance storage, and runtime-authority wrapping;
- learn a workspace-specific procedure from your local sources, URLs, and notes through the visible Learn a new skill workflow;
- crystallize a successful real workflow into a complete reusable procedure — activation cues, authority boundaries, recovery, retained state, verification, and concrete completion evidence.
That last one is the point: work through your invoices together once, and the resident doesn't just remember the fact — it writes itself the procedure. Train it once. It's trained.
Built-in split-pane terminals: one workspace, four panes, four different AI CLIs running side by side.
Connect multiple ChatGPT, Claude, Gemini/Antigravity, and xAI OAuth accounts; OpenRouter, NVIDIA NIM, Cloudflare, GLM, and custom API keys; then enable exact models and assemble fallback or round-robin routes. Model choice cascades — Global → Channel → Session → Message — so you can swap engines mid-thread.
Changing a route never replaces the resident or discards its computer, memory, skills, files, obligations, or thread history. You're changing the engine, not replacing the employee.
Each signed-in workspace member connects their own OAuth accounts and API keys.
New accounts and routes are private to that member unless their owner explicitly
shares them with the workspace; shared accounts are usable but remain editable
only by their owner. The same fabric also exposes an authenticated OpenAI- and
Anthropic-compatible /v1 endpoint for external tools, with separate revocable
keys per member.
Connections are host-owned brokers, not secrets copied into every resident's shell. Gmail exposes scoped account listing, search, read, and draft creation; sending remains disabled by default. Photon maps allowlisted inbound iMessage threads to a resident and permits narrow replies in an already-authorized conversation. Provider, Gmail, and Photon credentials stay on the host.
New connection types have to earn their place with least-privilege scoping, secret isolation, reconnect and recovery, deduplication, deterministic tests, and an audit trail. A prompt saying “use this service” is not a connector.
- Captain → Providers → Workspace onboarding in the signed Mac app.
- Exactly one resident for every ordinary channel and one Skipper in
#main. - A persistent, fully isolated Linux computer per ordinary channel on every supported platform (exact contracts in the table below).
- Shared channel
/workspacefor the agent command surface and human Terminal, with automatic terminal heartbeat and silent same-session reconnection. - Durable files, threads, curated memory, Mnemosyne long-term recall, corrections, follow-ups, and recurring workflows.
- Direct resident → Skipper escalation and automatic Skipper → resident return.
- Outcome-first Activity with expandable work evidence and a tamper-evident SHA-256 chain for new operational events.
- Local-first collaboration through an optional workspace domain routed to the Captain's Mac; workspace state and provider credentials remain on that Mac.
- Host-owned updates: a signed native Mac updater plus an atomic, digest-verified Linux system service with health-check rollback.
- Signed, Apple-notarized, stapled Apple Silicon DMG releases.
| Platform | Current contract |
|---|---|
| Apple Silicon macOS 26 | Native desktop product and real isolated Linux computer per resident (Apple container machine, home-mount=none). |
| Linux / CI | Supported headless systemd host with one unprivileged LXC per resident (subordinate UID/GID mapping, exact ownership checks); CI may select an explicit test backend. |
| Windows 11 x64 | Native desktop product with one private WSL 2 world per resident (Windows-drive mounts and interop disabled); the signed Setup executable ships with every release. |
Not yet shipped: a native Linux desktop shell, mobile clients, a hosted control plane, rich Photon attachment fidelity, or blind execution of community skills.
For development or a source deployment outside the verified platform installers, use Node 22:
PUPPETEER_SKIP_DOWNLOAD=1 npm install
npm run build
npm start # http://127.0.0.1:8123A fresh data directory opens first-run setup. The source runtime defaults to
./data; do not point development at an existing production data directory.
| Environment variable | Default | Meaning |
|---|---|---|
PORT |
8123 |
HTTP/WebSocket control-plane port. |
CTRL_DATA_DIR |
./data |
Databases, routing state, uploads, and narrow workspace mirrors. |
HELM_CHANNEL_COMPUTER_BACKEND |
apple on macOS, lxc on Linux, wsl on Windows |
Host isolation backend; native and mock are explicit development/test overrides. |
HELM_CHANNEL_MACHINE_IMAGE |
local/1helm-channel-machine:0.0.10 |
Versioned channel-machine image contract. |
export HELM_URL=http://127.0.0.1:8123
export HELM_TOKEN='a 1Helm session token'
npm run helm -- channels
printf '%s\n' '{"channel_id":2,"body":"Own this outcome and verify it."}' \
| npm run helm -- message
printf '%s\n' '{"channel_id":2,"name":"Weekly evidence","prompt":"Audit the launch and publish a verified status.","interval_seconds":604800}' \
| npm run helm -- workflow-create
npm run helm -- audit-verify1Helm is a compact Node/TypeScript control plane hosted by Electron on macOS and in the accepted Windows implementation, or by systemd on Linux. It does not need an external database or a server transpilation step.
| Layer | Implementation |
|---|---|
| Runtime | Official Node 22 with native TypeScript stripping. |
| Control plane | node:http, WebSocket, additive SQLite migrations. |
| Client | Vanilla TypeScript bundled with esbuild and Tailwind CSS. |
| Model routing | Embedded ReRouted headless engine, private internal gateway, account pools, retries, routes, quotas, and logs. |
| Computers | Defensive argv-only Apple container machine, narrow root-owned unprivileged LXC, and private WSL 2 backends; explicit native/mock test seams. |
| Terminal | node-pty; ordinary terminals enter their channel VM while Skipper remains native. |
| Memory | Curated records with provenance plus an isolated Mnemosyne SQLite store per identity. |
| Scheduling | Durable obligations, wake reconciliation, lifecycle safety, repair, update, and pressure-aware sizing. |
| Desktop | Sandboxed Electron renderer, ephemeral loopback server, persistent host data, and native wake/update integration on supported desktop hosts. |
Start with docs/VISION.md for the product record and
docs/architecture for the readable
system tour. SPEC.md is the detailed behavioral contract.
Agent turns follow a documented durability and reliability contract: per-thread concurrency, generation-fenced single-writer responses, restart-safe queues, durable connector delivery, narrow human blockers, and adversarial release acceptance tests.
npm run typecheck
npm run build
npm test
npm run test:onboarding-browser
npm run benchmark:autonomyThe autonomy benchmark emits deterministic machine-readable JSON covering the shipped skill arsenal, compact capability map, narrow human-blocker boundary, resident autonomy tools, wakeable recurring work, and audit-chain invariants for its fixture. It is deliberately not presented as a live-model success rate or a complete security score.
Every pull request and push to main runs typecheck, a production build, and
the complete npm test contract.
- Residents use separate Linux worlds: Apple machines with no Mac home mount, unprivileged LXC with subordinate host IDs, or private WSL 2 distributions with Windows-drive mounts and interop disabled.
- Skipper's host tools require Captain-authorized provenance.
- Workspace file mirrors are channel-scoped, size-bounded, and symlink-contained.
- Provider and connection credentials stay in host-owned storage.
- Registration, sessions, JSON bodies, uploads, collaboration access, and gateway keys are bounded and independently controlled.
- New operational events enter an append-only hash chain. This is tamper-evident retained history, not a remotely witnessed transparency log.
See SECURITY.md and the
security model for the full boundary and current
dependency debt.
- Product direction:
docs/VISION.md - Complete user guide:
docs/USER_GUIDE.md - Changelog:
CHANGELOG.md - Release lifecycle:
docs/release-lifecycle.md - Release checklist:
docs/release-checklist.md - Governance:
docs/GOVERNANCE.md - Terms & privacy: 1helm.com/terms · 1helm.com/privacy
- Company contact:
build@1helm.com

Let them cook. Keep the helm.
1Helm · AGPL-3.0-only · Copyright © 2026 Joseph Yaksich


