A hotkey-summoned AI panel that appears over whatever you're doing, already knowing what you were doing. Pure Rust, iced 0.14, macOS first (Windows builds in CI).
Press the hotkey and the panel opens over your work carrying the frontmost app's context — selection, caret, or a screenshot crop — asks a model, and can paste the answer straight back where your caret was. It is designed to be measured in milliseconds: no dock icon, no browser tab, no context switch.
- Context capture — the panel opens knowing the frontmost app and your selection (accessibility tree on macOS, opt-in for Electron/Chrome apps), or a screenshot crop for anything visual.
- Multi-provider — OpenAI (Responses and Chat Completions), Anthropic, Gemini, Azure OpenAI, Cerebras, SambaNova, Groq, xAI, OpenRouter, Ollama/llama.cpp, and any OpenAI-compatible custom endpoint. Roles route each kind of request (fast/smart/vision/…) through a fallback chain.
- ChatGPT plan (Codex) sign-in — device-code auth uses a ChatGPT subscription directly, no API key. These models handle images too.
- Model quick-pick —
⌘Kopens a floating picker with per-provider icons;⌘Dpins favourites, and pins persist. - Dictation —
⌘Lstreams the microphone through OpenAI realtime transcription (gpt-live-transcribe) into the composer. Works in Japanese. @file attach — type@in the composer to fuzzy-find a file by name and attach its text. Matching is yuru, so romaji finds kanji and kana filenames:toukei→統計資料.pdf.- Agent runs — toggle agent mode with
⌘J(or prefix one request with/agent) and submissions run a minimal coding agent (pi's harness:read,bash,edit,write) in a task window, scoped to the folders from Settings → Files. The toggle is per-session; a new chat returns to plain asks. Commands and writes run without prompts (diffs shown as they land, scoped to your folders); destructive commands — therm -rf/ force-push class — are refused once and run only after the agent restates its intent and confirms, with the exchange visible in the task window. - Budget — an optional monthly spend ceiling with warnings, priced from a user-correctable TOML table.
- English and Japanese UI, following the system language.
| Key | Action |
|---|---|
⌥Space |
Summon / dismiss the panel (Windows: Ctrl+Shift+Space) |
⌥⇧Space |
Crop a screen region and open it as an attachment (macOS) |
⏎ / ⇧⏎ |
Send / newline |
⌘⏎ |
Paste the latest answer back into the app you came from |
⌘⇧⏎ |
Escalate the last question to the smart model |
⌘C |
Copy the answer (when not editing text) |
⌘V |
Attach the clipboard image |
⌘N |
New chat |
⌘K / ⌘D |
Model picker / pin the current model |
⌘L |
Start or stop dictation |
⌘R / ⌘. |
Retry / cancel |
@ |
File finder |
⌘J |
Toggle agent mode for this session |
/agent … |
Run the coding agent once, on what follows |
⇥ |
Cycle lanes |
↑ / ↓ |
Prompt history |
⌘T |
Task window (agent runs) |
⌘, |
Settings |
esc |
Dismiss |
macOS asks for permissions as features are first used: Accessibility for
reading the frontmost app's selection, Microphone for dictation, and Screen
Recording for region capture. Each is optional — the panel works without it,
minus that feature. Electron and Chrome apps expose no selection until
allow_ax_tree_activation is enabled in settings; it is off by default
because that flag can degrade window behaviour in those apps.
Everything lives under one directory — ~/Library/Application Support/aibo
on macOS, %APPDATA%\aibo on Windows. Credentials are stored there in
owner-only files, never in config.toml; environment variables
(AIBO_<PROVIDER>_API_KEY, e.g. AIBO_OPENAI_API_KEY — dictation uses the
OpenAI one) work as a fallback. Everything below is editable in the settings
window — providers, pins, the panel hotkey, @ finder roots, the monthly
budget, the accessibility opt-in, language — and config.toml remains the
hand-editable equivalent (plus advanced knobs like role chains and request
deadlines that have no UI yet):
[ui]
language = "ja" # optional; defaults to the system language
panel_hotkey = "control+alt+Space" # optional; rebind if the default is taken
[pins]
models = ["openai/gpt-5.6", "anthropic/claude-fable-5"]
[files]
roots = ["~/Documents", "~/dev"] # @ finder roots; defaults to
# Documents, Desktop and Downloads
[[providers]]
backend = "anthropic" # key goes in settings, not here
[budget]
limit_micros = 20000000 # $20/month soft ceilingcargo build --release
./target/release/aiboQuality gates, all enforced in CI:
cargo test --workspace --all-targets
cargo clippy --workspace --all-targets -- -D warnings
cargo fmt --all -- --checkRun them before pushing by installing the repository's hooks once:
git config core.hooksPath .githookspre-commit runs fmt and clippy with CI's exact flags — a bare
cargo clippy leaves missing_docs a warning and exits 0, which is how a
green local check becomes a red build — and pre-push runs the tests.
--no-verify skips either when a work-in-progress commit needs to exist.
vendor/ carries temporary patches to cosmic-text and cryoglyph
(overflow fixes for CJK fallback shaping) applied via [patch.crates-io];
they retire with the next iced upgrade.
| Crate | Owns |
|---|---|
src/ (root) |
The runtime: process supervision, provider routing, file walk, dictation |
crates/aibo-ui |
The iced shell: panel, settings, picker, finder, i18n |
crates/aibo-platform |
OS integration: context capture, screenshots, paste-back |
crates/aibo-provider |
Provider protocol adapters |
crates/aibo-session |
Configuration and session state |
crates/aibo-core |
Roles, routing, shared types |
crates/aibo-agent / aibo-tools |
Agent loop and tiered tool execution |
crates/aibo-store |
Local-only encrypted persistence (SQLCipher) |
docs/plan.md is the product spec (§-references in code comments point into
it) and docs/design.md the visual spec.