Privacy-first desktop AI engine that runs LLMs, image generation, RAG, and agentic tools locally on your own GPU — powered by llama.cpp, with optional cloud providers.
C#
3
3,613 commits
updated Oct 3, 2026
XE Local AI Engine runs AI workloads locally on one machine. A single ASP.NET Core process serves the React management
UI, exposes loopback-only endpoints under /api/local/v1 plus SignalR hubs, persists to SQLite with per-column
encryption, and supervises the llama-server, sd-server, and whisper-server child processes that do the inference.
The current source version is
1.0.0-rc.2, composed in eng/ReleaseVersion.props.
Just want to install and use the app? Start with the User Guide — download, install (Windows & Linux), first run, troubleshooting, and privacy, all in plain language. App downloads are on the Releases page.
Official binaries are portable-only: Windows ships a Velopack Portable.zip with no Setup.exe, and Linux ships a
Velopack AppImage. Both formats self-update. Release assets are unsigned because no signing certificate exists — verify
CHECKSUMS.sha256 and review RELEASE-MANIFEST.json / RELEASE.spdx.json before running them.
Installing on behalf of an AI agent? An external agent (Claude Code, Codex CLI, Cursor, and others) can install, set up, start, and connect to this engine with no human in the browser:
curl -fsSL https://raw.githubusercontent.com/w0rldx/XE-Local-AI-Engine.Source/main/install.sh | \ bash -s -- --setup --start --install-skill # PowerShell: set XE_ADMIN_EMAIL/XE_ADMIN_PASSWORD plus XE_SETUP=1, XE_START=1, XE_INSTALL_SKILL=1, then: # irm https://raw.githubusercontent.com/w0rldx/XE-Local-AI-Engine.Source/main/install.ps1 | iexA piped install has no usable prompt input, so set
XE_ADMIN_EMAILandXE_ADMIN_PASSWORDbefore requesting setup. On success it prints the node's ready line and a one-timeXE_MCP_KEY=value, and--setupprints a one-timeXE_RECOVERY_CODE=for the vault — save both, neither is shown again. See the Agentic Support install guide, the MCP client runbook, and the shipped external-agent skill.
XE-Local-AI-Engine.Client) — the host process: FastEndpoints, the SignalR hubs, the
composition root and the SPA. See API & hubs.XE-Local-AI-Engine.Desktop) — the Avalonia native window; it uses the engine over REST and
SignalR only. See ADR 0013.XE-Local-AI-Engine.Client.React) — the node-local browser UI for every feature below.
See React client.llama-server children on a
loopback port range; Ollama is an opt-in secondary. The node can acquire prebuilt binaries, build llama.cpp and
stable-diffusion.cpp from source in-app, or route turns to a cloud provider. See
Local runtime & providers.sd-server daemon per model,
one job at a time, images encrypted at rest. See Image generation.Development:Sandbox:Provider=docker, which the shipped
configuration does not set. See ADR 0004 and
its status record.run_python tool with no network, host filesystem, or conversation access.
Off by default (Compute:Enabled) and profile-opt-in even when on. See Compute tools.uv-managed Python runtime holding an exclusive node-wide GPU admission gate. See
Training and ADR 0005./api/local/v1/mcp/server plus a shipped skill, so an external agent can drive this node
(Agentic Support).whisper-server child process
the way the other runtimes are. Audio is never persisted; transcript rows are encrypted. See
Audio transcription.web_search and web_fetch tools for agents, with a review gate against prompt
injection and an ask-before-send consent for each web request unless the conversation opted into auto mode. See ADR 0017
and Security and privacy.node.key is wrapped under the admin password and a one-time recovery code;
a locked node serves only an unlock page. See ADR 0018.Agentic Support lets a same-machine external agent install, configure, start and operate the node without a browser:
install.sh and install.ps1 resolve stable, prerelease, or pinned GitHub releases; verify the mandatory
CHECKSUMS.sha256; install atomically; and optionally run --setup, --start, --autostart, --install-skill;--setup, --mcp-key <delegate|agentic>, and --status --json are one-shot engine commands; --mcp-only serves
the normal local UI and API without opening a browser;<data-dir>/ready.json make the dynamic loopback port and PID discoverable
without scraping logs;/api/local/v1/mcp/server, never stdio. A delegate key sees the 8 shared
agent-run tools; an agentic key additionally sees the admin tools enumerated in
skills/xe-local-ai-engine/references/mcp-tools.md;agentic is trusted operator-equivalent only for that enumerated MCP surface. It grants no Operator role or JWT and
no arbitrary REST access. Approval-required root calls are strictly audited before auto-approval, while spawned
children keep their ordinary curated tools;The external-agent skill lives once at skills/xe-local-ai-engine/; --install-skill installs the version-matched
files to the user's agent skill roots rather than copying them into this repository. The trust decision is recorded in
ADR 0006. Autostart is never on by default: it is an
explicit --autostart/-Autostart opt-in registering a current-user systemd service or Scheduled Task.
Host/Origin, and secret-redacted.--autostart
(user-scope only); autostart is never the default.Home.md.Prerequisites: the .NET SDK pinned in global.json; Node.js matching
XE-Local-AI-Engine.Client.React/package.json; pnpm; Python 3 with uv; the Aspire CLI; and on Linux/WSL setsid. A
GPU is optional and Docker is not required by default — the app self-provisions llama.cpp and GGUF models on first run.
scripts/dev-start.sh # start the isolated Aspire AppHost for this checkout
scripts/dev-status.sh # resource states and endpoint URLs (--json); the port changes on every restart
scripts/dev-stop.sh # the only sanctioned stop path — never `aspire stop --all`
These wrappers keep parallel checkouts from killing each other's instances; the cleanup contract is in
scripts/README-dev-stop.md. dev-start.sh also mints and reuses a per-checkout,
never-tracked XE-Local-AI-Engine.AppHost/.data/node.key, so encrypted dev data stays readable. If it mints a key
next to data written under a different secret, it says so and names what to delete.
scripts/run-backend-tests.sh # the backend gate: one Release build, every enrolled test project
cd XE-Local-AI-Engine.Client.React
pnpm run acceptance # validate + coverage thresholds + tooling tests + production bundle
AGENTS.md §Validation is authoritative for the full gate set, including analyzer requirements,
pnpm run openapi:check after a backend contract change, the Python scope, and the opt-in live runners.
The desktop package is deliberately asymmetric: Linux ships a self-contained single-file AppImage, Windows a
framework-dependent Velopack Portable.zip needing the x64 ASP.NET Core Runtime 10.0.12 or a newer .NET 10 servicing
patch. Desktop mode is opt-in through the launcher (XE_LAUNCH_MODE=desktop or --desktop); headless, Aspire and CI
runs are unaffected. A console window opens with live logs, and closing it shuts the whole app down including the
supervised child processes. Run one instance per user-data directory — a second races on the SQLite database. The
tag-triggered release.yml is the only official release path.
Maintainer mechanics, artifact contracts and RC evidence live in publish/README.md; the
update-channel story in docs/velopack-release-install-guide.md; the
publication gate in docs/release-publication-checklist.md.
XE Local AI Engine is licensed under Apache-2.0. See LICENSE and NOTICE.
C#
76.7%
TypeScript
20.2%
Python
1.3%
Privacy-first desktop AI engine that runs LLMs, image generation, RAG, and agentic tools locally on your own GPU — powered by llama.cpp, with optional cloud providers.
C#
3
3,613 commits
updated Oct 3, 2026
XE Local AI Engine runs AI workloads locally on one machine. A single ASP.NET Core process serves the React management
UI, exposes loopback-only endpoints under /api/local/v1 plus SignalR hubs, persists to SQLite with per-column
encryption, and supervises the llama-server, sd-server, and whisper-server child processes that do the inference.
The current source version is
1.0.0-rc.2, composed in eng/ReleaseVersion.props.
Just want to install and use the app? Start with the User Guide — download, install (Windows & Linux), first run, troubleshooting, and privacy, all in plain language. App downloads are on the Releases page.
Official binaries are portable-only: Windows ships a Velopack Portable.zip with no Setup.exe, and Linux ships a
Velopack AppImage. Both formats self-update. Release assets are unsigned because no signing certificate exists — verify
CHECKSUMS.sha256 and review RELEASE-MANIFEST.json / RELEASE.spdx.json before running them.
Installing on behalf of an AI agent? An external agent (Claude Code, Codex CLI, Cursor, and others) can install, set up, start, and connect to this engine with no human in the browser:
curl -fsSL https://raw.githubusercontent.com/w0rldx/XE-Local-AI-Engine.Source/main/install.sh | \ bash -s -- --setup --start --install-skill # PowerShell: set XE_ADMIN_EMAIL/XE_ADMIN_PASSWORD plus XE_SETUP=1, XE_START=1, XE_INSTALL_SKILL=1, then: # irm https://raw.githubusercontent.com/w0rldx/XE-Local-AI-Engine.Source/main/install.ps1 | iexA piped install has no usable prompt input, so set
XE_ADMIN_EMAILandXE_ADMIN_PASSWORDbefore requesting setup. On success it prints the node's ready line and a one-timeXE_MCP_KEY=value, and--setupprints a one-timeXE_RECOVERY_CODE=for the vault — save both, neither is shown again. See the Agentic Support install guide, the MCP client runbook, and the shipped external-agent skill.
XE-Local-AI-Engine.Client) — the host process: FastEndpoints, the SignalR hubs, the
composition root and the SPA. See API & hubs.XE-Local-AI-Engine.Desktop) — the Avalonia native window; it uses the engine over REST and
SignalR only. See ADR 0013.XE-Local-AI-Engine.Client.React) — the node-local browser UI for every feature below.
See React client.llama-server children on a
loopback port range; Ollama is an opt-in secondary. The node can acquire prebuilt binaries, build llama.cpp and
stable-diffusion.cpp from source in-app, or route turns to a cloud provider. See
Local runtime & providers.sd-server daemon per model,
one job at a time, images encrypted at rest. See Image generation.Development:Sandbox:Provider=docker, which the shipped
configuration does not set. See ADR 0004 and
its status record.run_python tool with no network, host filesystem, or conversation access.
Off by default (Compute:Enabled) and profile-opt-in even when on. See Compute tools.uv-managed Python runtime holding an exclusive node-wide GPU admission gate. See
Training and ADR 0005./api/local/v1/mcp/server plus a shipped skill, so an external agent can drive this node
(Agentic Support).whisper-server child process
the way the other runtimes are. Audio is never persisted; transcript rows are encrypted. See
Audio transcription.web_search and web_fetch tools for agents, with a review gate against prompt
injection and an ask-before-send consent for each web request unless the conversation opted into auto mode. See ADR 0017
and Security and privacy.node.key is wrapped under the admin password and a one-time recovery code;
a locked node serves only an unlock page. See ADR 0018.Agentic Support lets a same-machine external agent install, configure, start and operate the node without a browser:
install.sh and install.ps1 resolve stable, prerelease, or pinned GitHub releases; verify the mandatory
CHECKSUMS.sha256; install atomically; and optionally run --setup, --start, --autostart, --install-skill;--setup, --mcp-key <delegate|agentic>, and --status --json are one-shot engine commands; --mcp-only serves
the normal local UI and API without opening a browser;<data-dir>/ready.json make the dynamic loopback port and PID discoverable
without scraping logs;/api/local/v1/mcp/server, never stdio. A delegate key sees the 8 shared
agent-run tools; an agentic key additionally sees the admin tools enumerated in
skills/xe-local-ai-engine/references/mcp-tools.md;agentic is trusted operator-equivalent only for that enumerated MCP surface. It grants no Operator role or JWT and
no arbitrary REST access. Approval-required root calls are strictly audited before auto-approval, while spawned
children keep their ordinary curated tools;The external-agent skill lives once at skills/xe-local-ai-engine/; --install-skill installs the version-matched
files to the user's agent skill roots rather than copying them into this repository. The trust decision is recorded in
ADR 0006. Autostart is never on by default: it is an
explicit --autostart/-Autostart opt-in registering a current-user systemd service or Scheduled Task.
Host/Origin, and secret-redacted.--autostart
(user-scope only); autostart is never the default.Home.md.Prerequisites: the .NET SDK pinned in global.json; Node.js matching
XE-Local-AI-Engine.Client.React/package.json; pnpm; Python 3 with uv; the Aspire CLI; and on Linux/WSL setsid. A
GPU is optional and Docker is not required by default — the app self-provisions llama.cpp and GGUF models on first run.
scripts/dev-start.sh # start the isolated Aspire AppHost for this checkout
scripts/dev-status.sh # resource states and endpoint URLs (--json); the port changes on every restart
scripts/dev-stop.sh # the only sanctioned stop path — never `aspire stop --all`
These wrappers keep parallel checkouts from killing each other's instances; the cleanup contract is in
scripts/README-dev-stop.md. dev-start.sh also mints and reuses a per-checkout,
never-tracked XE-Local-AI-Engine.AppHost/.data/node.key, so encrypted dev data stays readable. If it mints a key
next to data written under a different secret, it says so and names what to delete.
scripts/run-backend-tests.sh # the backend gate: one Release build, every enrolled test project
cd XE-Local-AI-Engine.Client.React
pnpm run acceptance # validate + coverage thresholds + tooling tests + production bundle
AGENTS.md §Validation is authoritative for the full gate set, including analyzer requirements,
pnpm run openapi:check after a backend contract change, the Python scope, and the opt-in live runners.
The desktop package is deliberately asymmetric: Linux ships a self-contained single-file AppImage, Windows a
framework-dependent Velopack Portable.zip needing the x64 ASP.NET Core Runtime 10.0.12 or a newer .NET 10 servicing
patch. Desktop mode is opt-in through the launcher (XE_LAUNCH_MODE=desktop or --desktop); headless, Aspire and CI
runs are unaffected. A console window opens with live logs, and closing it shuts the whole app down including the
supervised child processes. Run one instance per user-data directory — a second races on the SQLite database. The
tag-triggered release.yml is the only official release path.
Maintainer mechanics, artifact contracts and RC evidence live in publish/README.md; the
update-channel story in docs/velopack-release-install-guide.md; the
publication gate in docs/release-publication-checklist.md.
XE Local AI Engine is licensed under Apache-2.0. See LICENSE and NOTICE.
C#
76.7%
TypeScript
20.2%
Python
1.3%