AGPL licensed one self-contained binary macOS · Linux · WSL no Node · no Bun · no npm

Your terminal, with a coding agent inside.

Describe what you want in plain language. moh reads your code, edits files, runs commands — showing you every step and asking permission before anything risky.

curl -fsSL https://raw.githubusercontent.com/Marco-Cricchio/moh/main/scripts/install.sh | sh
or with Homebrew brew install Marco-Cricchio/moh/moh

The installer verifies the sha256, installs to ~/.local/bin and upgrades in place. The Homebrew formula installs the same checksummed release binary from Marco-Cricchio/homebrew-moh. Then just run moh.

moh — Tokyo Night
◈ session started prompt a1d3dd1c
◈ permission mode normal
· jev: inactive (no api key)
› you
the session log must stay append-only, fix the writer
◆ moh
Let me read the session store before changing anything.
⌨ preview src/session/store.ts
14│export function record(file: string, event: unknown): void {
15│ appendFileSync(file, JSON.stringify(event) + "\n");
16│}
✓ read src/session/store.ts · 0s
✓ edit src/session/store.ts · 0s
edited src/session/store.ts
◌ permission bash · requested
✓ bash npm test · 8s
42 passing (0.8s)
✓ permission bash · allowed (user)
◆ moh
The writer was already append-only; the missing flag is what made a re-open truncate. Suite is green.
─ model anthropic/claude-sonnet-4
› type… (shift+enter newline · ctrl+a/e line start/end)
✓ done ↻ 1  ◆ anthropic/claude-sonnet-4
▣ ~/projects/app ◉ dev
( ⏎ send ) ( esc stop ) ( ^m model ) ( ^o mode ) ( ^k commands ) ( ^s settings ) ( ^w workflow )

An illustrative session. The layout, glyphs, block grammar and colours are moh's real TUI (Tokyo Night theme), captured from the running binary.

Scroll to explore

01 Three things make it different

Not a fork. Not a wrapper. Yours.

moh is an independent, AGPL-licensed agent you own end to end — no vendor account in the middle, no telemetry, no lock-in.

01 / 03

The provider you choose

Anthropic, OpenAI, Google, GitHub Copilot, OpenRouter, Kimi, xAI — plus OpenAI-compatible endpoints and local models. All through one config.

If one provider goes down, moh falls back to the next on your list. Your setup is never tied to a single vendor.

02 / 03

Your data stays yours

Sessions, memory and notes live as a plain append-only log under ~/.moh/ — on your machine. Nothing is silently rewritten, and nothing about your usage is sent anywhere.

Resume, fork, rename, export, or move a session to another machine.

03 / 03

It asks before it acts

Layered permission rules gate every file write and every shell command: y once, a always, e edit the call, n deny.

Writes outside the project root are approved one at a time, every time. Extensions can veto a call — they can never grant more than you allowed.

02 What is in the box

Small enough to read, complete enough to live in

A headless core with a thin terminal client on top: the same engine drives the interactive TUI, scripts and CI.

01 / 18

Keyboard-driven TUI

Subagents, chips, live tool output, themes, thinking levels. Steer a running turn simply by typing.

02 / 18

Parallel lanes

Give a task its own git worktree and moh works there while your main checkout stays yours. One lane per task, integrated when you are ready — and a conflict resolves as a resumable step, not a surprise.

03 / 18

A browser it drives itself

The native browser tool opens pages, reads the accessibility tree, clicks and fills forms — with permissions scoped to the URL and SSRF protection on by default. One row in Settings enables it and installs its own toolchain: no npm, no sudo.

04 / 18

Headless for CI

moh run executes a turn with no prompts and fails fast: a permission prompt that cannot be raised denies the call instead of hanging.

05 / 18

Sessions that survive

Resume, fork, rename, and a trash that keeps deleted sessions recoverable. Handoff moves a session to another machine in one command.

06 / 18

Secrets never reach the log

Every event passes a redaction pass at the single write seam: secret-shaped keys and high-confidence patterns become [redacted] before anything is persisted. No flag, config key or consent turns it off.

07 / 18

Memory and compaction

Durable per-project facts written after each turn, and compaction that keeps long sessions usable without rewriting history.

08 / 18

Subagents and MCP

In-process subagents with strict tool inheritance, plus Model Context Protocol servers configured per project and loaded lazily.

09 / 18

Skills and workflow mode

Author your own skills, or turn on the bundled workflow: /workflow on adds a port of the Matt Pocock agent workflow — plan, spec, tickets, implement, review.

10 / 18

File and image mentions

Type @ for a fuzzy path picker; files, directories and images ride along with the turn. Images preview inline where the terminal supports it.

11 / 18

Usage you can audit

moh usage reports calls, tokens, estimated cost, tool statistics and route health — computed locally from your own logs, with no phone-home.

12 / 18

Extensible by design

An extension is a directory with a manifest: what it declares is what it gets. One consent names its capabilities, and an edit or a widened capability asks again. Panels, overlays, slash commands — and scoped powers, never a wider permission than you allowed.

13 / 18

Jev, an optional second opinion

moh can consult Jev — a TypeSafe service that answers with typed judgments, one probability or one choice per question, never text. It backs small decisions: the per-turn router, a prompt-injection check, prompt classification.

What leaves your machine

It is off unless you add a key, and every use case is a separate switch you own. The anti-injection check is the only one that sends the text you typed, so it is never on by default; /jev controls the use cases live, and the panel states exactly what leaves your machine.

14 / 18

Model fallback, with or without Jev

When a model call fails — quota exhausted, rate limited, overloaded, network — moh moves to the next stop you configured instead of quietly swapping vendor.

How the chain is chosen
without Jev

The chain is derived automatically from your configured, fallback-eligible endpoints, starting from the active one. Stops are concrete endpoint/model-id references, never substitutions moh invents; fallbackEligible: false excludes an endpoint, and a single provider is simply a chain of one.

with Jev routing on

The per-turn router also chooses which of your models serves each turn. Jev answers with a tier — economico, bilanciato, potente — never a model id, and moh maps it to a model you actually have. Nothing is invented, and if fewer than two tiers can be filled the router stays inert. It is off by default; a manual /model pick pauses it and auto hands it back.

Either way the switch is visible rather than silent: a toast names the stop, and the session log keeps the event, so a resumed session still shows what happened.

15 / 18

Project map (MPM)

The optional Moh Project Map builds a local, rebuildable structural view of your project — paths, symbols and provable relations, never copies of your source. moh uses it to orient a codebase task and to answer a model's focused query.

How it decides what to say

Advice is source-cited, and only ever at three confidence tiers: files the task names, symbols it mentions, and (advisory, deliberately quiet) identifiers from the model's own recent reasoning. An ambiguous match produces no advice at all. It is opt-in, its background maintenance is built not to block a turn, and you can inspect exactly what is mapped with /mpm or moh mpm.

16 / 18

Retro: what to fix next time

As a session closes, deterministic checks over its log — no model call — note what a reviewer would: a lint or test script nothing runs, the same expensive command issued again and again. Judgement findings (navigation, coding standards) are read in batches of ten sessions, never after every one.

Nothing changes without you

/retro (or moh retro) lists the findings by confidence. a shows the exact change — a rule for CODING_STANDARDS.md, a pointer in AGENTS.md — and writes it only after you confirm, appended under a ## Retro findings heading; existing prose is never edited, and a hook or CI job is proposed for you to make. d dismisses for good, and each dismissal raises the bar for that category. Findings never reach the system prompt, and one setting turns the whole thing off.

17 / 18

Bang commands

Type !git status in the composer and it runs — no prompt to phrase, no waiting for the model to decide. !!npm test runs it and hands the output to the model when it finishes; \! keeps a literal !.

Same gate, same log

It is a real bash tool call: the same permission rules, extension veto and path scopes — if bash is denied, ! is denied. The prompt shrinks to y/n because you typed the command yourself, and it never records an "always" rule a later model call could ride on. The call lands in the session log like any tool result, redacted at the same seam. It waits for the running turn to end, and stops after 120 seconds.

18 / 18

Custom themes

Eighteen built-in palettes — Tokyo Night, Catppuccin, Gruvbox, green and amber phosphor, Commodore 64, Amiga Workbench and more — a keypress apart with ctrl+t. Or open the theme studio and make your own.

How the studio works

Five sliders — hue, brightness, contrast, saturation, warmth — and per-element colours picked by name (amber, teal, violet…), never hex codes. Everything repaints live, and nothing is saved until you name the theme. It lands as a small JSON file in ~/.moh/themes/: colours over a built-in base, no code. A broken file falls back to Tokyo Night with a visible error, and low-contrast roles get a warning.

01 / 18

The animations illustrate real behaviour; the model names, file names and numbers inside them are examples.

03 Bring your own model

One agent, every backend

Built-in providers and OpenAI-compatible endpoints, plus local runtimes — switch with /model, chain fallbacks per model, and set the thinking level per endpoint (where available).

  • Anthropic
  • OpenAI
  • Google
  • GitHub Copilot
  • OpenRouter
  • Kimi
  • xAI
  • OpenCode
  • DeepSeek
  • Groq
  • Cerebras
  • Mistral
  • Moonshot
  • Together AI
  • Fireworks AI
  • Hugging Face
  • NVIDIA NIM
  • Z.ai
  • Qwen
  • MiniMax
  • Vercel AI Gateway
  • Cloudflare AI Gateway
  • Baseten
  • + any OpenAI-compatible endpoint
  • Ollama · local
  • LM Studio · local

Vendor names are trademarks of their respective owners; listed for compatibility only. On the first run moh opens with a zero-credential mock provider, so you can look around before configuring anything.

04 How it compares

Independent, and honest about it

moh is not a fork or a clone — it is its own codebase, AGPL-3.0-or-later licensed. Compared with the well-known terminal agents:

Aspect moh Claude Code OpenAI Codex OpenCode Pi
Providers Any: Anthropic, OpenAI, Google, Copilot, OpenRouter, xAI, local — with per-model fallback chains Claude models only — via Anthropic, Amazon Bedrock, Google Cloud, Microsoft Foundry or a gateway OpenAI by default; custom providers and local models (Ollama, LM Studio) 75+ providers and local models Many providers, subscriptions, custom and local models
License AGPL-3.0 Proprietary Apache-2.0 MIT MIT
Your data Append-only log in ~/.moh/ — resume, fork, rename, trash, export Local transcripts, cleaned up after 30 days by default Local history, can be turned off Local; uploaded only when you share a session Local session trees, all branches in one file
Permissions Layered allow/ask/deny rules per tool and argument; out-of-root writes always re-ask; extension veto Allow/ask/deny rules per tool and argument, permission modes, OS-level sandbox Sandbox modes, approval policies and command rules Allow/ask/deny rules per tool and pattern None built in, by design: run it in a container or add a confirmation extension
Headless moh run — fail-fast, no prompts, CI-ready Yes (claude -p) Yes (codex exec) Yes Yes (pi -p, JSON, RPC, SDK)
Extensibility Manifest extensions with per-capability consent and scoped powers, skills, custom providers, embeddable core Plugins from marketplaces (skills, subagents, hooks, MCP servers) and mods: JS/TS hooks that can redraw the interface and step into tool calls Plugins from marketplaces (skills, apps, MCP servers) and lifecycle hooks JS/TS plugins with event hooks and custom tools, MCP servers, custom agents and skills TypeScript extensions, skills, prompt templates, themes and packages; MCP

Vendor names are trademarks of their respective owners; the comparison is informational, based on each project's official documentation as of October 2026.

05 Quick start

Running in about a minute

Install

macOS arm64/x64, Linux x64/arm64 and Windows through WSL. Self-contained: nothing else to install first — or use Homebrew if you already live there.

curl -fsSL https://raw.githubusercontent.com/Marco-Cricchio/moh/main/scripts/install.sh | sh
brew install Marco-Cricchio/moh/moh

Start it

The first run needs no accounts and no API keys — it opens with the mock provider.

moh

Connect a real model

A guided wizard: API key, or a subscription you already pay for (Claude Pro/Max, ChatGPT Plus/Pro, a personal Google account).

moh provider add

06 Questions

Answered straight

Still curious? The user manual walks through every step in plain language.

Is this a fork of something else?

No. moh is an independent codebase, licensed AGPL-3.0-or-later, written from scratch — not a fork, a clone, or a thin wrapper around another agent.

Do I need Node, Bun or npm?

No. The binary is self-contained (the Bun runtime is embedded), verified by sha256 at install time, and upgrades in place when you re-run the installer.

Where does my data actually live?

Under ~/.moh/: one append-only event log per session, per-project memory, and your configuration. The log is the session, so resume, fork and replay are all projections of the same file — nothing is silently rewritten.

What is Jev, and is it required?

Jev is an optional second account moh can consult for small decisions — it returns typed judgments, never prose, so nothing about it can end up in what you read. moh works exactly as described without it: no key, no Jev. If you do enable it, each use case is a separate opt-in you can flip, and only the anti-injection check sends anything you typed — which is why it starts off.

Does it phone home?

No telemetry: nothing about your usage, prompts or code is sent to the project. Usage reports are computed locally from your own logs. The one thing that does reach the network on its own is the update check for new releases, and that is fully disableable.

What does it cost?

moh itself is free software, AGPL-3.0-or-later. You pay whoever serves your model — or use a subscription you already have, or run local models through Ollama or LM Studio and pay nothing per token.

Which platforms are supported?

macOS arm64 and x64, Linux x64 and arm64, and Windows through WSL — inside WSL the installer installs the Linux binary, because moh ships no native Windows build. The installer refuses to guess on anything else.

Can I extend it?

Yes. An extension ships as a directory with a manifest that declares what it needs; enabling it runs one consent naming those capabilities, and an edit or a widened capability asks again. It can contribute commands, panels and overlays, and be granted scoped powers — a path, a host, a credential, a tool, an endpoint — never more than you allowed. Declared dependencies install pinned and digest-verified, with no lifecycle scripts. You can also write your own skills, register custom providers, or embed the headless core as a library in your own application.

Install it and try to break it

One command, no dependencies, nothing to sign up for. If it does not convince you in ten minutes, that is useful feedback too.

curl -fsSL https://raw.githubusercontent.com/Marco-Cricchio/moh/main/scripts/install.sh | sh