Problem
Some people will want a Dock icon, and Windows users have no path at all. Among comparable products, the ones that ship on Windows did so with a packaged app and a winget id, not a CLI. tldraw offline, the closest precedent (same canvas engine, same agent CLIs, loopback-only), ships a brew cask, a winget id, and dmg, exe and AppImage downloads.
Proposal
Only if the localhost app, the tap and Linux support leave people asking for it. Then:
- A Tauri or Electron shell that wraps the localhost app exactly. Nothing in
src/ changes.
- A
cask in the same tap, a winget manifest, and direct downloads attached to the release.
- Lift from OpenDesign:
packages/platform/src/command.ts (a .cmd shim goes through cmd.exe /d /s /c "..." with windowsVerbatimArguments, and %VAR% in a prompt is rewritten to "^%" so cmd.exe cannot expand it); wellKnownUserToolchainBins() to augment PATH on GUI launch, with the searched directories shown when an agent CLI is not found; per-user NSIS install with no elevation; --appimage-extract-and-run on Linux.
- Signing and notarisation with a retrying
notarytool hook; asar: true with asarUnpack for native modules if any remain.
Skip from OpenDesign: the custom od:// protocol, runtime-generated electron-builder config, R2 as the primary release store, the weekly release train.
Out of scope
A hosted authoring app. It is a different product with a different security model.
Context
Step 6 of the sequence in docs/2026-09-19-standalone-app-and-install.md. Ranked last: hard (signing, notarisation, Windows process handling), and Windows is its only unique value. Depends on the localhost app issue.
Sequence
#106 bundle → #114 curl installer → #108 localhost app → #109 Homebrew tap → #110 Linux → #111 desktop shell (only on demand). No PyPI: the toolkit installs from the release tag's tarball (#subdirectory=tools), so there is no second registry to maintain.
Problem
Some people will want a Dock icon, and Windows users have no path at all. Among comparable products, the ones that ship on Windows did so with a packaged app and a
wingetid, not a CLI. tldraw offline, the closest precedent (same canvas engine, same agent CLIs, loopback-only), ships a brew cask, a winget id, and dmg, exe and AppImage downloads.Proposal
Only if the localhost app, the tap and Linux support leave people asking for it. Then:
src/changes.caskin the same tap, awingetmanifest, and direct downloads attached to the release.packages/platform/src/command.ts(a.cmdshim goes throughcmd.exe /d /s /c "..."withwindowsVerbatimArguments, and%VAR%in a prompt is rewritten to"^%"socmd.execannot expand it);wellKnownUserToolchainBins()to augment PATH on GUI launch, with the searched directories shown when an agent CLI is not found; per-user NSIS install with no elevation;--appimage-extract-and-runon Linux.notarytoolhook;asar: truewithasarUnpackfor native modules if any remain.Skip from OpenDesign: the custom
od://protocol, runtime-generated electron-builder config, R2 as the primary release store, the weekly release train.Out of scope
A hosted authoring app. It is a different product with a different security model.
Context
Step 6 of the sequence in
docs/2026-09-19-standalone-app-and-install.md. Ranked last: hard (signing, notarisation, Windows process handling), and Windows is its only unique value. Depends on the localhost app issue.Sequence
#106 bundle → #114 curl installer → #108 localhost app → #109 Homebrew tap → #110 Linux → #111 desktop shell (only on demand). No PyPI: the toolkit installs from the release tag's tarball (
#subdirectory=tools), so there is no second registry to maintain.