* fix(terminal): one intentional-stop register and per-run spawn and input facts Main now keeps one register of PTY stops it made on purpose, with an owner count and a kind: reversible (sleep, hibernation) or replaced (a restart handing the pane to a new process). It replaces four separate markers, and every exit path reads it, so a hibernated or restarted pane keeps its tab and binding through the exit instead of being retired and grafted back. Main also records two facts per process run, keyed by incarnation: whether the run was a fresh spawn (from the spawn-commit origin, which now counts a cold restore as a reattach) and when a client first sent it input a person produced. Renderer keystroke, paste, drop and quick-command writes carry a userInput flag; terminal.send, stream input and dispatched agent prompts are recorded by the runtime, excluding terminal query replies. * test(terminal): a stopped process's synthetic and late provider exits keep its pane One process can reach the runtime's exit handler twice: main's synthetic exit when the kill reply overtakes the stream, then the provider's own exit, which certifies the death. Both must read the same stop, a later process on the same id must not, and the stop is forgotten when the duplicate-exit window closes. * test(terminal): a runtime worktree sleep keeps its tabs and wake bindings * fix(terminal): keep every overlapping stop kind on one exit A sleep and a restart that stop the same process now each keep their label: the exit carries both renderer flags, and a runtime kill during the sleep still records its SSH stop as reversible. A later stop of an already-stopped process joins its entry, so a failed repeat cannot erase the stop that landed. The cold-restore rule moves into the run facts, so the binding span keeps labelling a cold restore as a spawn. * test(terminal): IME and Hangul commits reach the PTY as user input Drives a real xterm through the pane's input handling: a macOS input-source substitution, an iPadOS Hangul syllable, and a composition the route delivers after a pane switch each reach onData flagged as user input, which is what tags the write main records. * test(terminal): state why the IME provenance test's canvas stub is safe * fix(terminal): a new process ends an unpinned stop, and focus reports are not input - A landed stop that no exit pinned to an incarnation now ends when a new process commits on the same id, so that process's exit is not read as the stop. Both spawn-commit funnels report through one runtime method. - A spawn commit with no incarnation starts its run facts clean, since it cannot be told from a new process. - Stream input that is only focus reports no longer counts as user input; the desktop renderer already excludes them through xterm's own signal. - The IME provenance test uses typed fakes: the pane input and composition route installers now take only the fields they read. * chore: restore pnpm-lock.yaml to the base revision * fix(terminal): typing in the dashboard preview is a run's user input The dashboard popout's terminal preview writes to the PTY through its own runtime path, which recorded no input, so a pane typed into only from the preview read as untyped. It now records before the write, after the mobile-driver check. One classifier, shared with terminal.send, decides which provenance-free bytes nobody typed: a whole terminal reply or only focus reports, which also covers the focus-in a desktop renderer sends when it reattaches a remote pane. * test(terminal): the IME provenance test removes the navigator stubs it adds happy-dom serves navigator.userAgent from the prototype, so the test found no own descriptor to restore and left the iPad user agent in place. The pane-switch case then ran as a Mac pane only because it followed the Hangul case. Deleting the own-property stub restores the default platform for every case. * fix(terminal): every PTY write names its input kind, and one record point reads it A run's first input was recorded by opposite defaults: the renderer's pty:write recorded nothing unless a writer opted in, terminal.send recorded everything that was not a reply, and main's own controller writes recorded nothing. Each unclassified producer silently took its transport's default, so the worktree-create draft counted from the renderer and not from main, and mailbox pointers never counted. Every host write entry point now takes a required kind: driving, launch or query-reply. That covers the runtime controller's write and settled write, the terminal writer, sendTerminal, sendTerminalAgentPrompt, pty:write and pty:writeAccepted, the renderer transport and the runtime input helpers. The fact is recorded once, just before the provider write, in the controller funnel and the pty:write funnel: only driving bytes count, and a payload that is only a reply or focus reports never does. The per-producer records are gone. Launch writes (create-time drafts and follow-ups, the agent launch prompt, restored and cold-restore startup commands, the SSH background launch) do not count. Mailbox pointers, dispatch, plugins and agent-team sends do. The runtime mixins are unchecked by the compiler, and the pane session is an any bag, so two source scans fail on any write there that leaves out its kind. * fix(terminal): type the pane session's transport so the compiler checks every write's kind The pane-connection session is an `any` bag, so a transport write there that left out its input kind compiled, and only a text scan over the renderer caught it. Declaring `transport: PtyTransport` on the session puts those writes under the compiler, so the scan is gone. One hidden-delivery guard now narrows a null PTY id itself instead of relying on an untyped predicate. The main-process scan over `@ts-nocheck` runtime files missed five files whose directive sits on the second line, below a lint directive, and missed a write through a local alias of the PTY controller. It now finds both. * fix(terminal): record a runtime spawn's run facts only after its binding save succeeds The runtime spawn funnel reported the commit before its host-session binding save, so a spawn discarded for a failed save still recorded run facts and cleared a landed stop. Report it after the save, and separately on the adopted return, which makes no save. Also align tests and fixtures with main: the removed stop-owner map, required write input kinds, SQLite-backed stores and async binding saves. * test(terminal): pin where the renderer spawn funnel records its commit The merge moved the renderer funnel's spawn-commit report into the publish step, after the binding save, but no test covered it: deleting the call or moving it back before the save left every suite green. Cover both: a committed spawn records its run facts and supersedes an unpinned landed stop, and a spawn discarded for a failed binding save records nothing and leaves the stop. * fix(terminal): record a runtime spawn's commit only once its registration succeeds The runtime funnel reported each commit before registering the process, so a spawn that exited during start still recorded run facts and could end a landed stop, while the renderer funnel reports only after registration. Report after registration on both the ordinary and the adopted branch, so only a committed, registered run has facts and an unknown run keeps reading as not fresh. * test(terminal): pin that a runtime adoption supersedes a landed stop no exit pinned * fix(terminal): read an unconfirmed explicit stop's reversibility from the intentional-stop registry
Orca
中文 · 日本語 · 한국어 · Español · Français · Português
The AI Orchestrator for 100x builders.
Run Codex, ClaudeCode, OpenCode or Pi side-by-side — each in its own worktree, tracked in one place.
Download Orca
Features
Also in the box:
- Quick open — Search across worktrees, files, agents, commands, and repo context without leaving your flow.
- Account switcher & usage tracking — See Claude and Codex usage and rate-limit resets, and hot-swap accounts without re-logging in.
- Rich repo previews — Preview Markdown, images, PDFs, and repo docs in the workspace.
- Computer Use — Let agents operate desktop apps and visible UI when a workflow needs real interaction.
- Notifications and unread state — Know when an agent finishes or needs attention, then mark threads unread to come back later.
- And many, many more — we ship daily, so this list is perpetually behind. The changelog is the real feature list.
Supported Agents
Works with any CLI agent — if it runs in a terminal, it runs in Orca.
Claude Code
Codex
Grok
Cursor
GitHub Copilot
Muse
DeepSeek Harness
ZCode
OpenCode
MiMo Code
Amp
OpenClaude
Antigravity
Pi
oh-my-pi
Hermes Agent
Devin
Goose
Auggie
Autohand Code
Charm
Cline
Codebuff
Command Code
Continue
Droid
Kilocode
Kimi
Kiro
Mistral Vibe
Qwen Code
Rovo Dev
+ any CLI agent
Install
Desktop — macOS, Windows, Linux
- Download from onOrca.dev
- Or grab a build directly: macOS Apple Silicon · macOS Intel · Windows (.exe) · Linux AppImage · All builds
- Running
orca serveon a headless Linux server? See the headless Linux server guide.
Or via a package manager:
# macOS (Homebrew)
brew install --cask stablyai/orca/orca
# Arch Linux (AUR) — or stably-orca-git to build from source
yay -S stably-orca-bin
Mobile Companion — iOS, Android
Pair with your desktop app to monitor and steer your agents from your phone.
- iOS: Download on the App Store or join TestFlight
- Android: Download APK 0.0.50 · Install guide
Community & Support
-
Discord: Join the community on Discord.
-
Twitter / X: Follow @orca_build for updates and announcements.
-
WeChat: Scan to join the Orca community WeChat group 10.
-
Feedback & Ideas: We ship fast. Missing something? Request a new feature.
-
Privacy: See the privacy & telemetry docs for what anonymous usage data Orca collects and how to opt out.
-
Show Support: Star this repo to follow along with our daily ships.
Developing
Want to contribute or run locally? See our CONTRIBUTING.md guide.
The relay that pairs the mobile app with a desktop host is also in this repository under
cloud/, with a separate pnpm workspace and setup guide.
Signed Builds
Windows code signing sponored/provided by SignPath.io, certificate by SignPath Foundation.
License
Orca is free and open source under the MIT License.










