Gripi is a desktop and web interface for Pi, served by a self-hosted gateway. Run the gateway on a development machine or home server with Pi CLI installed, then use Pi from the desktop app or a web browser, on the same machine or over an encrypted private network.
Pi stays Pi. Gripi does not alter Pi’s system prompt, patch Pi, install extensions, rewrite sessions, or change Pi-owned configuration. It works with the Pi setup you already have. The only addition is a small Gripi extension, loaded into each Pi process with --extension, that gives the browser access to Pi’s session tree.
Try the live interactive demo →
No installation required. Responses and backend actions are simulated.
The project is a fully vibe-coded alpha version at the moment. Initially, it was supposed to be a quick proof of concept, but I ended up using it for my daily work and I actually like it. So please, feel free to try it; but expect some rough edges, missing features, and behavior that may change. Happy to look at any feedback (use GitHub issues)!
- All Pi sessions on the gateway machine in one sidebar, with search, project and tag filters, pinning, and unread markers.
- A Pi-style composer with slash commands,
@file completion,!shell commands, and image attachments. - Steer Pi or queue follow-ups while it is running.
- A Brief view that collapses tool calls, results, and thinking into summaries.
- Find in conversation, model and thinking settings, and context usage.
- Notifications when replies finish, including Web Push on phones.
Requirements:
- A Linux or macOS machine for the gateway, with
curland Git. - Pi CLI on
PATH, already working, authenticated, and configured for the OS user that runs the gateway. Gripi does not install or configure Pi.
bash -o pipefail -c 'curl -fsSL https://raw.githubusercontent.com/melounvitek/gripi/master/bin/install | bash -s -- gateway'What it does
- Downloads and runs Gripi’s current installer from the
masterbranch. - Checks that Git is available.
- Installs Mise to
~/.local/bin/misefrom its official installer ifmiseis not already available. - Clones Gripi into a temporary directory.
- Uses Mise to install Gripi’s pinned Go and Node.js versions.
- Installs Node dependencies, builds the Go gateway, and ensures an admin password exists in
~/.config/gripi/env. A newly generated password is printed. - Moves the completed checkout to
~/.local/share/gripi. It refuses to overwrite an existing installation.
It does not install or configure Pi, and it does not start the gateway.
Start the gateway:
~/.local/share/gripi/bin/startThe gateway listens only on 127.0.0.1:4567 by default. Open http://localhost:4567 and approve the browser with the admin password printed by the installer. It is saved as GRIPI_ADMIN_PASSWORD in ~/.config/gripi/env.
To use the gateway from other devices, or keep it running with systemd, see local and remote setups.
The desktop app is installed separately from the gateway and supports macOS and Linux. It requires curl and Git; on Linux, it also requires FUSE 2 (fuse2 on Arch Linux).
bash -o pipefail -c 'curl -fsSL https://raw.githubusercontent.com/melounvitek/gripi/master/bin/install | bash -s -- desktop'What it does
- Downloads and runs Gripi’s current installer from the
masterbranch. - Checks that Git is available.
- Installs Mise to
~/.local/bin/misefrom its official installer ifmiseis not already available. - Clones Gripi into a temporary directory.
- Uses Mise to install the pinned Node.js version and build the Electron desktop app.
- Installs or replaces
Gripi.appunder~/Applicationson macOS, or installs and registers the AppImage under the user’s XDG data directories on Linux. - Removes the temporary checkout. It does not install the gateway.
The app connects to http://localhost:4567 by default. Use File → Add Server… to add other gateways and File → Next Server (Ctrl+Tab) to switch between them. Pi always runs on the selected gateway machine.
There is no mobile app. On iPhone, open the gateway in Safari, tap Share, choose Add to Home Screen, turn on Open as Web App, and tap Add (Apple’s guide). On iOS/iPadOS 16.4 or newer, the Home Screen app can receive Web Push notifications for finished replies, even while it is closed. Notifications require HTTPS, such as Tailscale Serve.
The gateway shows an update control in the sidebar when a new version is available. It tests the update before installing it, then restarts. See self-updates for the requirements.
To update manually, stop the gateway and run:
cd ~/.local/share/gripi && git pull --ff-only && mise run setupThen start it again. mise run setup rebuilds the gateway; without it, bin/start keeps running the old build.
To update the desktop app, run its installer again.
Stop the gateway and remove any systemd unit or tailscale serve configuration you added. Then delete:
~/.local/share/gripi: the gateway.~/.config/gripi: settings, including the admin password.~/.pi/gripi: Gripi’s own data, such as approvals, tags, pins, and uploaded attachments.
Pi’s sessions and settings in ~/.pi/agent are not affected. If the installer installed Mise and you no longer need it, also delete ~/.local/bin/mise.
To remove the desktop app, delete ~/Applications/Gripi.app on macOS. On Linux, delete ~/.local/share/gripi-desktop and ~/.local/share/applications/gripi.desktop.
Anyone who can use Gripi can run shell commands as the gateway’s OS user, with that user’s files, credentials, environment, and network access. Therefore:
- Do not expose the gateway directly to the public internet.
- For remote access, use HTTPS or an encrypted VPN such as Tailscale. Plain HTTP over a LAN or Wi-Fi can expose passwords and access cookies, so Gripi rejects remote plain HTTP unless you explicitly allow it for a VPN.
- Keep access approval enabled for any gateway reachable from another device. Only disable it when the network already limits access to trusted devices and users.
- Only open projects you trust. Gripi loads project resources automatically.
In the default single-user mode, every new browser must be approved once, either with the admin password or from a browser that is already approved. See access approval to change the password or remove a browser.
Optional multi-user mode gives each user a private token and shows them only their own sessions. It is intended for users who trust each other: all users still run commands as the same OS user, and they share model and thinking settings.
Gripi uses Pi’s own runtime, sessions, tools, models, and configuration. The composer works like Pi CLI’s editor: while Pi is running, Enter steers and Alt+Enter queues a follow-up. It differs from Pi CLI in these ways:
- Project resources load automatically. Gripi starts Pi with
--approve, so project settings, extensions, skills, prompts, themes, system prompts, and packages work without first trusting the directory in Pi CLI. As a result, opening a project can run its extensions or package installation scripts. Only open projects you trust, or turn this off. - The send button steers by default. Use its menu to queue a follow-up instead. Prompt templates and skills use the selected mode, extension commands run immediately, and built-in commands sent in Steer mode run as controls rather than messages.
- Shell output appears when the command finishes.
!commandadds its output to the model context, and!!commanddoes not. Output is not streamed. If a shell command and Pi are both running, Stop cancels the shell command first; press it again to stop Pi. - Extension UI is partial. Select, confirm, input, editor, notify, title, and editor-prefill requests work. Extension status text is not shown in the footer, which shows only the model, thinking level, and context usage.
- There is no terminal UI. For custom TUI components, terminal keybindings, or code that checks
ctx.mode === "tui", use Pi CLI.
The gateway is written in Go. The browser UI and demo use plain JavaScript with no build step, and the desktop app uses Electron. Pi CLI must be on PATH; setup does not install it.
git clone https://github.com/melounvitek/gripi.git
cd gripi
mise install
mise run setup
mise run devmise run dev serves the gateway in development mode on http://localhost:4567. It uses the same port, settings, and Gripi data as an installed gateway, so stop that one first. Run the main checks with mise run test. See testing for the other checks and the browser suite, frontend architecture for how the UI is organized, and configuration for all settings.

