Private memory, documents, voice and a local LLM for your agents, served by a Mac app on-device.
Everything above runs on the device. M1K3 uses the network for two things: the one-time download of a bigger brain when you ask for one, and web search, which is on by default so answers can be current, with one switch in Settings to turn it off. The 1.0 build has no cloud path at all. A later release adds an opt-in Private Cloud Compute rung — off by default, one message at a time, every PCC answer labelled — see SECURITY.md.
| Surface | Where | Stack | Status |
|---|---|---|---|
| macOS native | macos/ | Swift 6.2, SwiftUI, MLX-Swift | The product — on-device knowledge · RAG · agent · voice · calls. Build it: macos/README.md. |
| iOS + visionOS | macos/M1K3iOSApp/ | Swift 6.2, SwiftUI | Native SwiftUI shell on the same macos/Sources/ package graph — chat · RAG · memories · docs. Ladder tops out at Lil on-device. See macos/docs/IOS_VISIONOS_PORT.md. |
| 間 AI mobile | app/ | Kotlin Multiplatform | Slow burn — the Android surface (KMP), pre-release. See app/README.md. |
| The attic | git history before 7545b4a4 | Python, THREE.js, Tauri | Where M1K3 grew up — the original CLI, avatar experiments, and ideas. Cleared from the tree 2026-08-13; see The attic. |
macos/README.md: clone → xcodegen generate → ⌘R.M1K3 ships a command-line client, m1k3, inside the app bundle. It's a thin
client — the running app is the daemon (one MLX slot on the machine, and it
belongs to M1K3.app).
brew trust round-tower/tap # Homebrew 6: trust the tap once
brew install --cask round-tower/tap/m1k3 # the cask symlinks Contents/Helpers/m1k3
# Open M1K3 ▸ Settings ▸ Privacy ▸ MCP server: switch it on, then Copy the token
m1k3 login # paste the token (echo off; kept in your keychain)
m1k3 connect claude # also: codex · cursor · vscode · zed
The MCP server is off until you switch it on, and every request carries its
access token: m1k3 login stores it, and connect writes it into your agent's
config as an Authorization: Bearer header. Without it the server answers 401.
Then m1k3 status, m1k3 ask "what did I decide about the pin?",
m1k3 remember "…", m1k3 search "…", m1k3 speak "build's green".
Prefer clicking? M1K3 ▸ Settings ▸ Privacy ▸ MCP server has the same thing:
pick your agent, copy the snippet (the token is already in it). Already have M1K3 installed? The binary is
at /Applications/M1K3.app/Contents/Helpers/m1k3.
m1k3 agent-notes --write folds this into a project's AGENTS.md (or any path
you name). It's marker-fenced, so re-running it replaces the block rather than
stacking copies:
## M1K3 is the resident
M1K3 is a local, private assistant running on this Mac, reachable over MCP. It
holds the user's own documents and memories — so before you search the web, ask
it: `ask_m1k3` for a grounded answer, `search_knowledge` for the sources behind
one. Persist a durable fact with `remember` and it is there next session too.
`speak` narrates aloud, which is often kinder than a wall of text.
M1K3 can be down — a "disconnected" MCP server just means the app is closed.
Never block on it; carry on without it.
One honest caveat: the App Store build's helper (TestFlight today) is sandboxed, so it
can't write another app's config file or run claude for you. There, m1k3 connect prints the config to paste instead — and says so. The Developer ID
build (the DMG and the Homebrew cask) does the write.
The running Mac app serves MCP over HTTP at http://127.0.0.1:4242/mcp —
knowledge search, documents, voice, and ask_m1k3 (ask the resident AI).
Every request carries the server's access token (Settings ▸ Privacy ▸ MCP
server); m1k3 login && m1k3 connect claude wires Claude Code in. Setup for any
client: macos/docs/MCP_SETUP.md.
18 tools (generated live from the running server).
| Tool | Required args | What it does |
|---|---|---|
ask_m1k3 | — | Ask M1K3's local brain a question |
forget_memory | query | Permanently forget a fact M1K3 remembers — the consent primitive, the counterpart to remember |
get_answer | job_id | Fetch the result of an ask_m1k3 call that returned a job id because it was taking a while |
get_document | id | Fetch the text of one indexed item by its id (from list_documents) |
get_status | — | M1K3's overall status: active brain tier, TTS provider, voice tier, and the busy flags — whether M1K3 is speaking, in a conversation, using its mic, or already answering an ask_m1k3 call |
list_documents | — | List the items M1K3 has indexed, with their ids, kinds, and titles. |
list_jobs | — | List recent ask_m1k3 jobs — id, state (running/done/error), and age in seconds |
list_todos | — | The user's todo list as M1K3 holds it |
listen | — | Listen on M1K3's microphone and return the transcript once the speaker pauses (or the timeout passes) |
memory_stats | — | How many atomic facts M1K3 currently remembers (the live, non-superseded count) |
open_link | url | Open a web link in M1K3's review panel on the user's screen, beside the conversation, so they can see the page |
propose_todo | title | PROPOSE a todo for the user |
recall_memory | query | Recall atomic facts M1K3 remembers about the user — the temporal memory GRAPH, separate from the document corpus search_knowledge reads |
related_memory | query | Recall the single best matching fact for the query, then walk M1K3's memory GRAPH one step out to its neighbours (linked or superseded facts) |
remember | title, text | Store text in M1K3's memory — it becomes part of what M1K3 knows, searchable in every future conversation (the same store search_knowledge reads) |
search_knowledge | query | Search M1K3's stored knowledge (documents, calls, notes; hybrid retrieval when available) |
speak | text | Speak text aloud through M1K3's voice (and animate the avatar) |
stop_speaking | — | Stop any in-progress speech immediately. |
The table above is generated live from the running app — never hand-edit it. Refresh with
mcp-inventory --inject README.md --server m1k3(needs the M1K3 app running).
M1K3 didn't start as a Mac app. It started in August 2025 as a Python CLI with
a synthesized voice, grew a THREE.js avatar, a PWA, a Tauri popover, a RAG
engine, and an MCP server — and then everything it learned was rebuilt native.
That history is signed and permanent in this repo's git history — a project
about provenance should keep its own. The attic/ tree was cleared from the
working copy on 2026-08-13; to walk through it, check out any commit before
7545b4a4 (or resurrect it with git checkout 7545b4a4 -- attic).
Start with CONTRIBUTING.md. Architecture and current
state: CLAUDE.md. Security reports: SECURITY.md.
Inference, retrieval, and voice run on-device; M1K3 itself has no servers and never sees or stores your conversations, and the 1.0 build has no cloud path at all. A later release adds an opt-in Private Cloud Compute rung (off by default): the one message you choose to send will go to Apple's Private Cloud Compute — see SECURITY.md for what will and will not be sent and Apple's own guarantees, quoted and linked.
Functional Source License, FSL-1.1-ALv2. M1K3 is
source-available and free for humans, forever: read every line, build it,
modify it, run it for yourself, use it inside your organisation, teach with
it, research with it. What the licence does not permit is a competing use —
offering M1K3, a fork of it, or a substantially similar product to others as a
commercial product or service. Each version converts to Apache-2.0 two years
after release. It is not an OSI open-source licence and we don't call it one.
Attribution and third-party notices are in NOTICE; the decision
and its reasons are in
ADR 0005.
Revisions before 2026-09-09 were published under Apache-2.0 and stay that way;
the boundary is recorded in NOTICE.
The source is public; the name is not. M1K3, the M mark, the pixel face
and CRT look, the icon, and the voice are trademarks and brand assets, all
rights reserved and outside the licence grant. See
TRADEMARKS.md. The companion creatures are not ours: the
Fox is the Khronos glTF sample by PixelMannen (CC0) and tomkranis (CC-BY 4.0);
Colobus, Gecko, Inkfish and Sparrow are by Quaternius
(CC0) — credited in NOTICE and in the app's Third-party licenses screen. The only official builds are Round Tower's
(app.m1k3 on TestFlight, and on the Mac App Store once it is live; and the DMGs on m1k3.app).
Organisations: M1K3 for Teams — the same on-device brains, institutional memory, and a tuned persona served on your own Apple Silicon hardware, under your own domain — is licensed separately. See m1k3.app/teams or write to hello@round-tower.ie.
Contributions are by invitation under a short CLA (Apache-2.0 inbound, FSL outbound). M1K3 is built in the open with MurphySig provenance — the git history is signed, human-and-AI collaboration on the record.
This listing does not have a supported local package template. Use the maintainer’s documentation for its hosted endpoint, authentication, and client-specific setup. No install command has been inferred.