Building / xNAUT

Trust leaves a trace.

A native terminal for running a fleet of coding agents — and a record of what they actually did. Hash-linked, arguments sealed under an HSM-held key, batches signed on the HSM, and an offline verifier a customer runs without you. 20 MB, macOS and Windows.

Receipt chain / Session 2026-08-19Each row hashes the last
  1. #041214:02:11claude-codewrote ledger/verify.rs +118 −69f3a…c1d2e71b…4830
  2. #041314:02:19codexcargo test · 64 passed, 0 failede71b…48303c0d…9a7e
  3. #041414:02:33claude-codefiled XNAUT-212 via MCP3c0d…9a7eb8e2…07f1
  4. #041514:03:02HEADhead signed · Securosys HSM · CHb8e2…07f1sig 3045…
$ openssl dgst -sha256 -verify xnaut.pub -signature head.sig head.jsonVerified OK

Check it at xnaut.dev/attest, or with stock OpenSSL against the published key. No account, no API, no xNAUT installed.

ILLUSTRATION / HASHES SHORTENED / NOT A LIVE LOG

01 / The build

One place. Your rules.

A native terminal built for running several coding agents at once. Claude Code, Codex, Gemini or any CLI agent, launched from one surface with live status, isolated git worktrees, and diffs the agents annotate themselves. Switch projects and your exact context comes back.

It also works the other way round: a built-in MCP server on localhost turns the terminal into a tool the agents call. They can list projects, file tickets and write docs into the vault — so the agents do not just run in xNAUT, they drive it.

NautFlow is the layer around them: something that plans, splits the work, checks it, and only then calls it done. Not a prompt that emits files and hopes.

Why I built it

I did not set out to build a product. I set out to stop being annoyed by my own desk. My day ran across Warp, Pieces OS, iTerm, Cursor and VS Code, and every one of them was good at something and wrong for me in some specific, grinding way. So I built a terminal to my own rules and used it every day, which is the only design process I actually trust.

Then the enterprise tools arrived — Devin and that class of product, around $500 a month, and what you get for it is a flow: stages that walk the work from idea to finished rather than just answering you. The flow was the good idea. The execution did not convince me, and it could not run several agents at once on the same project, which I already had working. So I built my own version of that flow. That is NautFlow.

The useful question is not “did it run?”
It is “what can I check?”

02 / Design decisions

The trade-offs are part of the story.

01

Proofs, not promises

Last year a client told me I had not worked the hours on my invoice. Neither side can prove anything in that conversation, so I built the proof into the tool — and then had to keep correcting it. A hash chain proves nobody edited a row. It cannot prove nobody rewrote the whole file from row one, because the database, the operator and the machine all sit inside the same trust boundary. So the head of the chain is signed on a Securosys HSM in Switzerland. To forge history you now need hardware you do not have to sign for you, and it will not, because the private key cannot leave it. Not policy. Physics.

02

A pile of signatures is not a chain

An engineer at Securosys read one sentence on the xNAUT site and asked two questions. One was a word — we wrote 'sealed' where we meant 'signed', and encryption was never in that path. The other was a hole: every attestation receipt was signed on its own, so you could delete the one you would rather nobody saw and every remaining signature still verified. The public verifier would have shown a clean green tick for a log with a hole in it. Receipts now carry a sequence and the hash of the previous one, and the HSM signs position and content together. We had published the correct argument two days earlier and still shipped the bug one directory over — which is the part worth saying out loud.

03

Verification that does not go through me

A proof you can only check through the party who made it is a promise wearing a costume. So a receipt verifies in your own browser at xnaut.dev/attest against the published public key — or, if you do not trust that page either, with one line of stock OpenSSL against the key and the signature. No account, no API, no xNAUT installed. The math answers.

04

Local models by default, cloud on request

Explain Screen, chat and theme generation run against Ollama or LM Studio on localhost unless you ask otherwise. Cloud providers sit behind a privacy monitor that flags keys and PII before a prompt leaves the app. The default matters more than the option.

05

Write down what done means, before starting

Hand a coding agent a one-line request and it produces something plausible. What it will not tell you is which parts of your request it quietly dropped or which assumptions it invented — because nobody wrote down what done meant, so there is nothing to check the result against except your memory of a sentence you typed an hour ago. NautFlow keeps your words verbatim as the contract, builds a document chain on top, and has a Validator attack it and write the acceptance gate before the build starts. A slice that promised an object and returned a string used to sail on and fail three steps later; now it stops at the boundary where the promise broke. Untested is not passed.

06

Most of it started as someone else's better answer

The manager watching the agents was blind: a gate that answered yes or no so four failing checks and forty looked identical, a timer that interrupted every agent every five minutes regardless of what it was doing, and a build slice that could never actually fail, so a dead build looked exactly like a slow one. Rather than invent a way out I went reading — research code, other tools, and what people said was not working. The gate reports a score now, agents are interrupted when they stall rather than on a clock, and a failing slice is allowed to fail. Almost none of that was my idea, which is the part of open source that matters most.