TensorCode documentation.
TensorCode is a planned harness for the coding agents you already run, not an editor and not a fork of one. There is no installable TensorCode release. This page documents what exists today in the Closed beta — specifications, three Rust libraries, and a founder-smoke tool — and what is planned under ADR 0003 / 0003a, with the open follow-ons that still gate each capability. TensorCode is in Closed beta.
What TensorCode is today.
There is no installable TensorCode release. TensorCode is in Closed beta. What exists today is a set of specifications and architecture decisions, three Rust libraries you can build and test, and a founder-smoke tool that exercises the one runnable path. Everything this page calls planned is governed by ADR 0003 (agent-harness product direction) and ADR 0003a (adapter and authentication authority), and is still gated by the open follow-ons A–D.
ADR 0003 is accepted for planning; it is not a blanket authorization to implement, and it is amended by ADR 0003a. Nothing here carries a release date, and none of the planned surfaces are generally available.
What TensorCode is (planned).
TensorCode is planned as an agent harness for existing coding agents (Codex / Pi class). It is not an IDE and not a VS Code fork. The product surfaces are a CLI and a Desktop application that share one harness. The Desktop build is planned on Tauri v2 with the system webview, with an idle memory target below 350 MB for the desktop and worker together.
Where a session runs, and what gates it.
A run is classified into one of three session classes. Each names where the tools execute, the credential path it would use, and the follow-on it is blocked on today.
| Session class | Where tools run | Credential path | Status today |
|---|---|---|---|
Cloud Agent | A TensorBoot microVM on TensorPlane infrastructure, one microVM per agent. | Per-job TensorGate credential (tg-job + jwt) issued for the run. | Planned (ADR 0003 §8, Phase B). Not gated by Follow-on A–D, but not available in the Closed beta. |
Enterprise-managed local | The customer's own machine under central management. | Managed run credential (Follow-on A). | Blocked on Follow-on A — MUST NOT be implemented until A lands. |
Personal-local interactive | A single developer's machine, interactive session. | Depends on the sub-route below. | Only the unbound scratch + harness-opened local-model route runs today (see below). |
The Personal-local interactive class has three sub-routes, each with its own gate (ADR 0003 §4):
| Sub-route | Gate |
|---|---|
| (i) Consumer-login carve-out | Bound: Follow-on A + Follow-on D. Unbound: Follow-on D. Blocked today. |
| (ii) Harness-opened TensorGate keys | Follow-on A (bound and unbound). Blocked today. |
| (iii) Local OpenAI-compatible servers via tensorcode-openai-compat | Bound: Follow-on A. Unbound scratch: not blocked — this is the one runnable route. |
How model calls leave the device.
Hosted model calls leave the device through TensorGate only. Local models run through an OpenAI-compatible server you already run (LM Studio, llama.cpp, or an Ollama-class server) via the tensorcode-openai-compat client. In that mode the client is harness-opened only: the adapter binary must never own the provider socket. The consumer-login carve-out is blocked on Follow-on D.
Default EU-resident inference is not guaranteed. Sovereignty modes for inference and telemetry residency are Follow-on C; a procurement pack (DPA / AI-Act material, audit export) is in scope but not delivered here.
The v1 adapter allowlist.
| Adapter | v1 | Notes |
|---|---|---|
Codex | In v1 | On the v1 allowlist. Installed only from an allowlisted official vendor channel. |
Pi | In v1 | On the v1 allowlist. Consent-based download from the official channel — it is not bundled with TensorCode. |
Hermes / other harnesses | Out | Not in the first release. |
Claude Code is not on the v1 adapter allowlist — discovery may surface it as unsupported or not qualified, and it must never be a runnable default.
Install sources are allowlisted to official vendor channels, and a version is trusted only while it is on the qualified list. An unqualified update demotes the adapter to non-runnable. Discovery is read-only: discovery is not authorization.
What you can run today.
The one runnable path today is the founder-smoke tool on Linux x86_64 only (macOS ARM64, RHEL, and Windows 11 + WSL2 are deferred pilot platforms; there is no production service-level or uptime commitment). Repository access is granted to Closed beta participants. Run the commands from the repository root.
Discover the installed Codex / Pi harnesses (read-only):
Create an unbound scratch worktree:
Run one local chat completion against your own OpenAI-compatible server (placeholders only — supply your own host, port, and model):
The consumer-login route refuses by design. It prints label=unsupported and label=dev-evaluation-scaffold to stderr and exits 2:
Run the hermetic tests:
Passing --bound refuses while Follow-on A is open: Tensorplane-bound local runs are not implemented yet.
Libraries you can build today.
tensorcode-redaction
- fail-closed by construction.
#![forbid(unsafe_code)].- Linear-time regex enforced by
cargo deny. - Milestone M01 is in review; M02–M07 are pending.
tensorcode-token-accounting
The crate and its README exist on the pinned branch pin/m01-13b650a, which is what tensorcode-openai-compat pins.
- Pure library: no network, no persistence, no floating-point money.
- Money is
Money { micros: i64, currency }. BTreeMapfor deterministic ordering.#![forbid(unsafe_code)]and#[non_exhaustive]error types.
tensorcode-openai-compat
- fail-closed OpenAI-compatible protocol client and normalization library.
#![forbid(unsafe_code)]and#![deny(missing_docs)].- Public surface:
Client::new(endpoint, cfg)andClient::chat(req). - Features:
default = []andtestkit.
tensorcode-mcp, tensorcode-computer-use, tensorcode-skills-sdk and tensorcode-workspace-index are specification only; no tensorcode-core repository has been created yet. There is nothing to build in them yet.
Multiple workers on one Project.
Workers on a single Project coordinate only through TensorLine — there is no peer IPC. Offline operation is single-worker per Project. Running a second worker on the same Project is blocked on Follow-on B (Project ↔ TensorLine binding).
What is not available in the Closed beta.
- Cloud Agents (planned, ADR 0003 §8 Phase B).
- Enterprise-managed / headless local runs (Follow-on A).
- Any Tensorplane-bound local class (Follow-on A).
- The consumer-login carve-out (Follow-on D).
- Harness-opened TensorGate keys for Personal-local (Follow-on A).
- A runnable harness adapter beyond Codex and Pi — the deferred adapter stays off the v1 allowlist.
- A second worker on one Project (Follow-on B).
- A guarantee that inference and telemetry remain in the EU (Follow-on C / sovereignty modes).
- On-prem TensorGate.
- A native TensorCode coding engine.
- Generic OAuth proxying.
- macOS, RHEL, and Windows pilot platforms.
How to get into the Closed beta.
TensorCode is invite-only. Request early access; Closed beta participants receive access to the TensorCode repositories.
How TensorCode is priced.
TensorCode is part of the single platform plan — €35 per contributing developer, billed on unique non-bot git authors whose work the platform touched, trailing 90 days. There is no separate TensorCode price. See billing for the full model.
Get early access to the platform.
Every product is included in one platform subscription. Request early access and we'll onboard your team hands-on — free while we build toward launch.