A desktop hub for apps that respect you.
Apps provide capabilities through services. Iro owns credentials, permissions and routing — so a stranger's app is safe to install.
One way in for every app
Every app — ours included — installs from a catalog through Iro's consent sheet. Signed packages, pinned publisher keys, no silent installs.
Credentials never leave Iro
Tokens and API keys stay in the kernel vault. Services get proxied HTTP to their own origins only, with known secrets scrubbed from responses.
Revoke anything, keep your data
Per-capability grants, per-app storage, Activity for every call. Revoking breaks only that feature; uninstalling clears the code, not your files.
Your models, your choice
API keys, local Ollama, or your own subscription. Per-app budgets, tiers and pins — switching models never changes the app.
Onboarding installs the Store and opens it. Each app is one consent sheet.
Accounts live on the app's page. Sign in or pick a folder in Iro's trusted window.
One app, four presentations: in-app, separate window, compact widget, or its own desktop app.
Starter apps
Iro ships with no apps. Everything comes from the official catalog, independently of Iro releases. Start with the Store, then GitHub, Markdown Notes, Daily Briefing, the Assistant, and the model apps.
Pre-release: Iro builds run locally and are ad-hoc signed. Download, signing and auto-update arrive with the release phase. For now, build from source.