Your keys. Your machine. Your crypto agent.

A self-custodial desktop crypto agent. Research markets, quote swaps and run missions while your keys stay on your machine.

Restricted by default: mutating calls wait for approval. Full access is an explicit grant that skips the generic per-call gate. Understand permissions

Product previewView full screenshot
Original Project VEX desktop screenshot showing a mission conversation and the local wallet sidebar.
Cropped screenshot · Source: Project VEX · Preview only; the screenshot controls are not interactive.
02A more open internetSource-available · macOS / Windows / Linux · Economic model: planned

03 FROM THE LIVE APP

See it work. Then read the log.

Real screenshots of the desktop app, and the mission film underneath. No mockups, no staged terminals.

Browse the docs
Mission session with the contract being drafted and the Book rail

Screenshot from the live app

This is Vex.

A mission session in the chronos theme: the chat thinks in the open, the mission contract fills in field by field, and the Book rail keeps your wallets and balances beside the conversation.

  1. 1Visible reasoning: the plan is on the record before any call runs
  2. 2The mission contract: on-chain actions stay blocked until every field is filled and the contract is accepted
  3. 3The Book rail: live balances and positions, per wallet and per chain
How missions run
Agent Scan: the full-history ledger of every on-chain action, with filters and per-row transaction links

Screenshot from the live app

Every action, on the record.

Agent Scan is the in-app ledger of everything Vex has executed on-chain, newest first, with day dividers. It is the log you read after the fact, and it never renders a timeout as an empty history.

  1. 1Every on-chain action Vex executed, newest first
  2. 2Each row links to its transaction on a block explorer
  3. 3Filters by kind, status, protocol and chain
Where the record lives
The Launch a token dialog with the Trench and pools.fun lanes on Robinhood Chain

Screenshot from the live app

Launches, gated like everything else.

The Launch a token dialog runs on Robinhood Chain through two lanes, Trench and pools.fun. You fill the figures, Vex prepares and checks them, and only then can anything deploy.

  1. 1Two lanes: Trench and pools.fun, both on Robinhood Chain
  2. 2pools.fun locks the whole supply into a pool, so the token trades from its first block
  3. 3“Nothing is authorized until this launch has been prepared and checked.”
How launches work

The mission film · 49s · plays while in view

Watch the original launch film

Original film · Source: Project VEX.

04 HOW IT RUNS

Two modes. Two permission levels.

Choose how Vex works, then choose what it may execute. These are independent choices made when a session is created.

01 · RUNNING MODE
02 · PERMISSION LEVEL
Agent + Restricted

A one-shot conversation. Mutating calls wait for your approval in the app. Restricted is the default permission level.

This comparison explains behavior; it does not start an agent or grant access.

Compare all four combinations
ModePermissionBehavior
AgentRestricted · defaultOne-shot conversation; mutating calls wait for your approval.
AgentFull accessOne-shot conversation; generic per-call approval is skipped.
MissionRestricted · defaultGoal-driven loop; pauses for approval of mutating calls.
MissionFull accessGoal-driven loop; can execute permitted calls without generic per-call prompts.

Both permission levels retain tool policies and the Safety Contract. Full access removes your opportunity to catch a bad idea at the generic approval gate. Mission setup keeps on-chain mutations locked regardless of permission. Session settings are fixed at creation; Studio project scope has a documented exception.

The New Session dialog: mode, permission and wallet pickers

Screenshot from the live app

The Vex home screen in the dark chronos theme
The Vex home screen in the light celeris theme

Chronos and Celeris. Dark and light, same rules.

05 BIOLOGICAL MEMORY

Memory that earns its keep.

Vex proposes its own lessons, but nothing is remembered on its own say-so. Every candidate passes deterministic fail-closed filters, then a five-axis judge, before it becomes long-term knowledge.

How memory works
01Lessons, not balancesSecrets are hard-redacted and live state (balances, prices, gas, open quotes) is rejected at the write door. Only the durable lesson is ever stored.
02A judge, not a diaryPromotion requires a verdict on five axes: grounding, durability, novelty, generalizability, process over outcome. The judge runs on your own provider account and sees only redacted, bounded context. A broken verdict promotes nothing, ever.
03Forgetting is a featureInfluence decays on a 30-day half-life, stretched to 60 days when the current market regime matches the lesson and cut to 15 when it does not. Faded lessons are never deleted; a fresh confirmation revives them.
04Advisory onlyA remembered lesson can never authorize an action, size a trade, approve an intent or sign a transaction. The database itself enforces it. Restricted approvals stay with you.

06 THE SECURITY MODEL

Built to be distrusted.

Don’t take the claims. Take the code. Every card below ends in the doc that proves it.

“In Restricted: the agent proposes. You approve.”

01Sandboxed rendererStrict CSP, deny-all Electron permission handlers, privileged code behind typed IPC.
02Signed buildsmacOS: Developer ID + notarization. Windows: Azure Trusted Signing. Linux: unsigned, so download only from the official GitHub Releases. Updates are user-triggered and come only from published releases.
03Prompt-injection doctrineTool output is data, not instruction; destination addresses come only from you or your own wallets.
04Disclosuresecurity@projectvex.ai · three-business-day acknowledgment · safe harbor for good-faith research.

What Vex can’t protect.

A lost master password. A trade you approve yourself. Builds that don’t come from GitHub Releases. We will never DM you first, and we will never ask for your seed phrase or master password.

07 COUNTED FROM SOURCE

Counted from source, not marketing.

The numbers below come from the code you can read and the public GitHub release counters.

2,000+
Downloads
226
Tools in the app
12
Protocol integrations
15
Coding agents in Studio

How we count →

KyberSwapUniswapJupiterMorphoPendleRelayKhalaniDexScreenerVirtualspools.funLighter

08 GET IT

Put it on your machine.

Free to use. Source-available. Signed and notarized on macOS, signed on Windows; Linux builds are unsigned, so download them only from the official GitHub Releases.

ApplemacOSApple Silicon.dmg arm64ApplemacOSIntel.dmg x64Windowsx64.exe x64LinuxLinuxUniversal.AppImageLinuxLinuxDebian / Ubuntu.deb

Latest installer: loading from GitHub… · · All builds and checksums ↗

Choose the build for your operating system and processor.

Before first run.

DockerDocker Desktop or Engine with Compose ≥ 2.23.1; Windows needs the WSL2 backend.
OpenRouterAn OpenRouter API key: inference runs on your own account, at your own cost.
A one-time ~333 MB local model download on first run (5-15 minutes on slow links).

Source-available license: free to read, audit and run for personal self-custody. Not an OSI open-source license: redistribution and forks aren’t licensed. Read it ↗

09 FOR DEVELOPERS

Give your coding agent Vex’s hands.

Studio connects coding agents to Vex’s local tools and wallets. In a default Restricted project, fund-moving calls wait for an approval card in the app. Full access is an explicit project grant that skips that generic gate; project scope and tool policies still apply.

Studio docs
The Studio workspace in the desktop app: the projects rail and explorer, a terminal running in the rh-desk project, and the project's portfolio panel

Screenshot from the live app · a project open in Studio: rail, terminal, portfolio

  • Flip the Agent | Studio toggle and a project opens into a terminal with real shells, a file explorer and viewer, and one search across projects and files. Up to four projects stay alive at once, and a relaunch brings you back to the same tab.
  • The server exports 213 tools over MCP: 29 load instantly and 184 protocol tools are found through the read-only vex_ToolSearch, identical for every project, client and machine.
  • It serves calls only while Vex is open and unlocked. There is no always-on door into a self-custodial wallet.
  • In a restricted project, mutating calls route through the same in-app approval broker; a Studio approval waits up to 1 hour for you.
  • Projects live in ~/Vex/projects. Vex writes each client’s MCP config and four project files itself, verifies every write against a fingerprint, and never deletes a file.
Claude CodeClaude CodeCodex (OpenAI)CodexGemini CLIopencodeopencodeGrok (xAI)Grok BuildKimiQwenQwen CodeGitHub CopilotCopilot CLICursorCursorAMPAmpKiroMistralMistral VibeClineClineDroidWarpWarp

The 15-agent roster · 13 wired today

10 $VEX · ROBINHOOD CHAIN · VIA VIRTUALS

The app is the product. The token is its meter.

ECONOMIC MODEL v1.0 · PLANNED / NOT LIVE

The published fee policy charges 25 bps on successful swaps, bridges and launches. Quotes, reads and research are free. The proposed economic model directs fees toward $VEX buyback and burn; that mechanism is planned, not live.

$VEX……FDV …LIQ …Chart ↗Buy ↗Explorer ↗
Loading market data… · Source: DexScreener ↗ ·
0x8Ff92566f2e81BDd68EDfAa8cde73942A723796b

11 FAQ

The questions that decide trust.

Can Vex move funds without me?

Not by default. In restricted mode every fund-moving action creates an approval you must click, fail-closed: an error means no trade, not a silent one. Full mode skips the generic gate for a session you configure; the Safety Contract still applies, and you choose per session.

How approvals work →
Where do my keys live?

On your machine. Wallets are generated locally and sealed in AES-256-GCM keystores under a scrypt-derived master key. No custodian, no server-side signing, no cloud backup. Deleting the config directory deletes your keys, so export backups first.

Where keys live →
Does it depend on the cloud?

Inference runs through your own OpenRouter key, on your own account. Your wallet, approvals and signing stay inside the app on your machine; memory, embeddings and the database run in local Docker containers whose ports bind to 127.0.0.1, never the LAN. Crash reporting is strictly opt-in and off by default.

The privacy model →
Is it open source?

Source-available: free to read, audit and run for personal self-custody. Redistribution, forks and commercial use aren't licensed, so no, not OSI open source, and we won't call it that. The code is public because trust should be checkable.

Read the license ↗
What does it cost?

The app is free to use. You pay your own inference (OpenRouter) and gas. Vex takes a 25 bps fee on successful swaps, bridges and launches, charged only when the action succeeds and never on one that reverts or fails. Quotes, reads and research are free.

How the fee works →
What do I need to run it?

macOS 13+, Windows 10/11 x64, or Ubuntu 22.04/24.04; Docker with Compose 2.23.1 or newer (Windows needs the WSL2 backend); an OpenRouter API key; and a one-time ~333 MB model download on first run.

Full requirements →
Where do I buy $VEX, and what is it for?

Through Virtuals Protocol on Robinhood Chain. The Buy link goes to the official listing. The app does not require the token. The proposed buyback-and-burn model is planned, not live; see the Token page for its status. Verify the contract address against @ProjectVEXai before trading.

The economic model →

Your keys. Your machine. Your agent.

The app is out. The docs are open. Verify everything.