Tool-calling agent loop
A Codex-style agent loop that plans, calls tools, reads results and iterates until the task is verified done.
Velox is a native desktop coding agent — no web UI, everything runs in one window. Multi-provider LLMs, a tool-calling agent loop, diff-approved file edits, an embedded terminal, git, browser-use and computer use. End-to-end software development in a single app.
Velox combines the editor, terminal, git client and agent into one native desktop app — so the agent can actually finish the job.
A Codex-style agent loop that plans, calls tools, reads results and iterates until the task is verified done.
OpenAI, Anthropic or any OpenAI-compatible endpoint. Per-chat API & model, connection test, thinking-level control.
Every file write shows a diff you approve. One-click undo restores the agent's last change instantly.
A real shell inside the app — local tabs and remote SSH tabs side by side. Run builds and tests, let the agent verify its own work.
Stage, commit (with AI-suggested messages), branch and browse history. VSCode-style tree with M/A/D/? badges and project-wide search.
Drive a real browser via CDP and control the whole desktop — click, drag, type, clipboard, window management.
Connect Model Context Protocol servers (stdio or HTTP) to extend the toolset, and run commands on remote machines over SSH profiles.
.velox/memory.md is loaded every run — the agent remembers your build commands, conventions and bans.
Group chats by project, pin and rename sessions, attach images, dictate with Whisper, and get Windows notifications when a task finishes.
From read-only brainstorming to full autonomy — switch anytime from the mode selector.
Answers and explains. Reads your code, never writes. Perfect for planning and code review chats.
Edits files with diff approval. The sweet spot: fast iteration while you stay in control of every write.
Runs commands and writes files without asking. For trusted tasks and long autonomous runs.
Researches and produces a step-by-step plan — with numbered survey cards when a decision is yours to make.
| Tool | Ask | Auto-Edit | Full Access | Plan |
|---|---|---|---|---|
read / glob / grep |
auto | auto | auto | auto |
write / edit / patch |
ask | auto (workspace) | auto (sandbox) | deny |
run_command |
ask | ask | auto | deny |
ssh_command |
ask | ask | ask | deny |
web_* |
auto* | auto* | auto* | auto* |
* Web tools require “Allow network tools” in Settings → Permissions. Denylisted commands are rejected in every mode — even Full Access can't bypass them.
Every tool call goes through a policy engine first — the verdict is allow, ask or deny. Sandboxing is enforced at the policy level, not by convention.
Writes outside the session's working folder are rejected in every mode. Attempts like C:\Windows\... are blocked by the policy engine itself.
An editable regex list blocks destructive commands — rm -rf /, mkfs, dd if=, fork bombs, shutdown, root deletes. No mode can bypass it.
Remote machines are outside the sandbox, so ssh_command always shows an approval card unless you add a rule yourself.
“Remember for this session” grants a tool permanently for that mode — and every grant is revocable from Settings → Permissions.
API keys live only in %APPDATA%/velox-data on your disk. Nothing is synced to any cloud service.
Every file write the agent makes is snapshotted. One action restores the last change — no reflog archaeology needed.
Velox speaks Model Context Protocol and SSH — plug in tools and reach remote boxes without leaving the window.
Add stdio or streamable-HTTP servers from Settings → MCP Servers. Their tools join the agent's toolset automatically as mcp_<server>_<tool> — e.g. filesystem, GitHub or PostgreSQL.
# e.g. filesystem server
npx -y @modelcontextprotocol/server-filesystem C:\data
Save host/port/user with password or key auth, test the connection, then open remote terminal tabs next to local ones — or let the agent run commands remotely (always with approval).
# agent-side remote control ssh_command → systemctl restart api ✓ asked first
Type / in the composer to steer the agent mid-conversation.
/planProduce a step-by-step plan before touching code/reviewReview the current diff or a file/readRead a file or folder into context/runRun a shell command in the embedded terminal/searchSearch the project and jump to hits/compactSummarize and shrink the conversation context/verifyRun the test loop until everything is green/btwAsk something unrelated without polluting context/helpList all commands and shortcutsLive in the shell? The CLI runs the very same agent engine as the desktop app — same approval model, same project memory, same providers. No desktop install required: it opens (or creates) the shared velox-data folder on its own.
ask, auto-edit, full-auto, plan/sohbetler# install globally npm install -g @veloxy/velox-cli # run interactively (TUI) velox # or one-shot velox "fix the flaky test in cart.spec.ts" -m auto-edit
Kullanım: velox interactive TUI velox "task" one-shot task, print & exit -m, --mode <mod> ask | auto-edit | full-auto | plan --model <id> model id (stored on the session) --provider <id> provider id --session <id> continue an existing session --data <dir> data dir (default: %APPDATA%/Velox/velox-data) -v, --version -h, --help
/yardım this screen /model provider + model /mod approval mode /hedef session goal /sıkıştır compact context /sohbetler pick a session /yeni new session /çıkış quit ↑↓ input history PgUp/PgDn scroll Ctrl+C cancel/clear Ctrl+D exit
Open a folder, drop a .velox/memory.md with your conventions, and pick a provider & model per chat.
In Plan mode it asks clarifying questions with numbered option cards. In Auto-Edit it proposes diffs you approve.
It runs your tests in the embedded terminal until green, then hands you a clean diff in the git panel.
$ npm run ship ✓ typecheck passed ✓ 42 tests passed ✓ build complete → release/Velox Setup 0.12.23.exe (single file)
Shipped versions so far, and what's cooking next.
Agent loop with multi-provider LLMs, diff-approved edits, embedded terminal, sessions, git panel, browser & computer use, voice input, TR/EN.
Survey cards (ask_user), live context meter with /compact, instant undo, chat forking, project memory, publish script.
MCP client, SSH profiles & remote terminal, per-mode permission grants, command denylist, canvas view, AI-suggested commit messages.
Plugin hooks, richer test-verification loops, more languages in the UI, and deeper CLI ↔ desktop integration.
Runs entirely on your machine — your keys never leave %APPDATA%/velox-data.
Windows · Linux (AppImage) · deb · rpm · Linux install guide
Windows 10/11 · single-file installer · no account required
No. Velox is fully local — the app, files and terminal run on your machine. Only the prompts you send to your chosen LLM provider go over the network, and API keys are stored locally in %APPDATA%/velox-data.
OpenAI and Anthropic out of the box, plus any OpenAI-compatible endpoint — including local servers like Ollama or LM Studio. You can set a different API and model per chat.
Yes — that's what the modes are for. Ask mode never writes, Auto-Edit requires diff approval for every file change, and Full Access is opt-in. Undo restores the agent's last write at any time.
Yes. The app ships with native TR/EN, and this website automatically switches to Turkish for visitors from Türkiye — you can override it with the EN/TR toggle in the header.
The terminal is pipe-based, so full-screen programs like vim or top won't render. Undo covers the agent's file writes only — side effects from shell commands aren't rolled back.
Model Context Protocol is an open standard for connecting tools to AI agents. Add a server (stdio or HTTP) in Settings → MCP Servers and its tools become available to the agent automatically — filesystem access, GitHub operations, database queries and more.
Yes — install it with npm install -g @veloxy/velox-cli, then run velox for the interactive TUI or velox "task" for a one-shot run. It shares sessions and settings with the desktop app — see the CLI section above.
Yes — computer use lets the agent see the screen (with a coordinate grid), click, drag, type, use the clipboard and manage windows. But it's gated behind the approval model like any other powerful tool.