A focused AI workspace
Give your chosen development tool a clear brief, selected files and the permissions needed to build or repair the missing pieces.
Your coding agent works best with the right skills, instructions, tools and plugins in its working folder. Baltor finds them, vets them and puts each file where your harness reads it, so nobody has to search, sort or copy them by hand.
Get started creates your account. Get set up connects your harness.
What your agent gets at one step
Recorded from this release's library
search: split address lines in a customer file
download split_Bytes match the digest
Placed where the harness reads it
Example layout
working-folder/ ├── AGENTS.md ├── CLAUDE.md imports @AGENTS.md ├── .agents/skills/split-address-lines-into-components/ │ ├── SKILL.md │ └── scripts/split_address_lines.py ├── .mcp.json this step's tools only └── .baltor/step.lock.json item, version, digest
The library
Skills with their scripts, instruction files, tools and code, subagents and commands, hooks and protocol server settings. Your agent searches it from inside its harness, and new vetted additions keep arriving.
SKILL.md · scripts/ · assets/
AGENTS.md · CLAUDE.md
tested scripts and packages
agent and command definitions
checks your harness runs itself
the tools a step may call
What it makes possible
Hand a big job to a small or local model before you log off. The Baltor Harness breaks it into small steps and gives each one only the files it needs, so the work keeps moving while you sleep.
How overnight work runsBuilt so each step carries only the context it needs, reuses proven code instead of writing it again, and runs on the smallest model that does the job well.
Where the savings come fromEvery run leaves a record of what worked, what failed and which setup was fastest. Baltor is designed to use those records to set up the next task better.
How it keeps improvingHow it works
Your harness asks for what a step needs. Baltor answers with the exact files and puts them where the harness reads them.
Your agent searches the library from inside Claude Code, Codex, OpenCode, Pi or the Baltor Harness.
Baltor returns the exact version, checked against its digest and counted in your usage.
Each file lands where your harness reads it: skills, instructions, tools and settings.
Your harness gets the service address and the name of the environment variable that holds your key. The key itself never goes into a file.
Claude Code, in .mcp.json
For long jobs, the Baltor Harness can start a fresh harness for every small step, so each step holds only its own files. Turn it on for long runs and off for quick ones.
{
"mcpServers": {
"baltor": {
"type": "http",
"url": "https://baltor.ai/mcp",
"headers": {
"Authorization": "Bearer ${BALTOR_SERVICE_TOKEN}"
}
}
}
}Baltor never asks for a model key. Your harness calls your models through the connection you control.
Every download names its version and digest, and your access is checked again before the bytes are read.
Connecting gives Baltor no permission to run commands on your computer. Your harness decides what runs, with the permissions you set.
Anything else, write to the operator at the contact address in the privacy notice.
Claude Code, Codex, OpenCode, Pi and the Baltor Harness. Get set up shows the exact steps for each. Another client can connect when it speaks the Model Context Protocol version this service accepts and sends the key in a header.
No. Bring the model access you already have: a provider key, a model on your own computer, Ollama Cloud, or a machine on your network. Baltor never asks for a model key.
One item at the version you selected counts once. A search, a second look at the same reference and a refused download are not downloads.
For each item your agent downloads, one usage record: the item's name, its digest and the time. Your tasks, files, prompts and model keys stay on your computer. The privacy notice lists everything the service stores and for how long.
Create your account and connect your harness in a few minutes.
Savings depend on the task, the model and the setup. No percentage reduction or guaranteed gain is claimed.
Use cases
Three ways the right files, in the right place, change what your agents can finish.
A small or local model carries a long job to the end while you are away, one small step at a time.
How overnight work runsLess context per step, more reuse and the smallest model that does the job well.
Where the savings come fromEvery run leaves a record, and the next task is set up with what the last ones learned.
How it keeps improvingUse case
Hand a big job to a small or local model before you log off, and come back to checked work and a record of every step.
Starting a fresh harness for every step keeps each step small and focused, which is what lets a small model go the distance. For a quick task, turn it off and run in one session.
Use case
Spend less on each task by giving every step exactly what it needs, and nothing it does not.
Search returns short references. Your agent downloads only the item it chose, so a small step never carries the whole history.
With the right material in front of it, a smaller or local model can take on work that would otherwise need a large one, and the large model is kept for the steps that need it.
Every item carries its source, licence and exact version, so proven scripts and tools are reused instead of generated again at every run.
A step sees only the tools and protocol servers it asked for, so its instructions stay short and its choices stay clear.
Use case
Every run teaches the next one. Baltor is designed to learn from what worked and set up the next task better.
What the step asked for, which files it used, which model ran it, how long it took and whether the result was accepted.
Records of what worked shape the next setup: the files a step is offered, the model it runs on and how the task is broken down.
When two ways of doing a step compete, the choice follows recorded results, and a change waits until there is enough evidence to trust it.
New vetted skills, tools and plugins keep arriving, items that stop working are withdrawn, and what customers never find is reworked.
Pricing
Baltor Pro is for one person and the devices that person connects. You bring your own harness and your own model access.
One plan
$29 a month
Subscribe from your account page once your account is ready.
No. A Baltor key gives access to the library. The model calls happen in your own tools, with your own provider account or your own models.
It stays where you saved it. Revoking a key or cancelling stops new requests; it does not recall files that were already delivered.
The Baltor Harness you install is free and open source. The library is Baltor Pro, $29 a month, and the measured unit is one downloaded item.
Not today. One account holds one person's keys. Shared accounts and team billing are later work.
Create your account, subscribe to Baltor Pro for $29 a month and connect your harness.
Step 1 of 5
Your email address is all we need. We send you a link to confirm it.
Already have an account? Sign in
Step 3 of 5
Your email address is confirmed when you set it. Then you are signed in.
It has expired, it was used already, or a newer message replaced it. Nothing was changed.
Ask for a new linkYour workspace
Connect with the service access token that was issued for your account.
Your model provider key is different. Keep it in your own tool, not in this form.
No account yet? Get started.Email sign-in is not enabled yet. This form checks real service access; it does not create an account or a subscription.
Accounts
It takes a minute: your email address, a link to confirm it and a password you choose.
Get started walks you through creating your account, subscribing and connecting your harness.
Enter your email address. We send you a link, and you choose your password on the page it opens. Creating an account does not start a subscription or give access to your local files.
Get started
Leave your email address, and we send your link to finish setting up.
Accounts cannot be created on this service right now, so no form is shown and nothing you type here is recorded. To ask for an account, write to the operator at the contact address in the privacy notice.
Your first subscription may come with a discount code, and checkout takes that code.
We keep your address and note only to send your link, as the privacy notice says, and an operator can erase both on request. We will not add you to a mailing list.
Already have an account? Sign in
Intelligence workspace
Inspect an exact reference before fetching its body. Your own tools run in your environment.
Selected material
Search returns references. Fetching a body requires a separate access check and may record usage.
Connect, describe the material you need, then inspect the returned source and permissions before downloading.
Browse what you have
Search answers a question. Browsing shows what is there, grouped by where the material comes from. Open an item to read its details before you fetch the file.
Material that names no development tool suits every tool, so a tool filter keeps it. Material that declares an effect, such as running a command, is not offered here, because this page holds no permission to run anything.
Sign in to browse the material published for your account.
Your account
Sign in to see your service identity, usage and available subscription settings.
Your account includes Baltor Pro.
Sign in with your verified account to manage client tokens.
Choose what this connection may do and when it expires. It cannot manage accounts, billing or other credentials.
Shown once. Closing or reloading the page clears this copy. The service cannot recover it.
Signing out of this website does not revoke these tokens. Revoke them here when a device no longer needs access.
Open the connection settingsService usage is separate from the model calls your own tools make.
Sign in to see the downloads recorded for your account.
Only configured plans are shown. A completed checkout does not itself confirm that access is active.
Administration
Sign in with an administrator service token. Email is not required.
Tokens share the selected tenant's material and usage. A token is not a separate private account.
Shown once. It cannot be recovered from the service. Store it in your secret manager.
Revocation takes effect on the next service request. It does not recall material already downloaded. Bootstrap administrator keys are managed separately.
How it works
Start with what you want to achieve. Break the work into steps, give each step relevant expertise and tools, then check the result before moving on.
The plan can change as you learn more. A step can ask for missing information, try another approach or send unfinished work back for improvement, within the limits you set.
See what each step needs
Choose a step to see its information, tools and expected result. The person inspecting the data needs different material from the person checking the finished import.
This is an illustration, not a recorded customer result. Selecting a step does not access your files or call a model.
Useful information, when it is needed
A useful briefing is not always the shortest one. Start with relevant information and add more when the work reveals a gap.
It can search for additional material or ask a question. Your permissions and remaining budget still apply. New instructions cannot grant access to private files or allow spending by themselves.
If an action times out, first check whether it happened. Trying again must not send a second email or repeat another change by mistake.
Use what suits the work
The goal and quality checks stay the same. The way a step does the work can vary.
Give your chosen development tool a clear brief, selected files and the permissions needed to build or repair the missing pieces.
A decision may need one model request rather than a complete development session. Use a compatible model service you have already configured.
Use reviewed code when it meets the requirements. That step may need no model call and no newly generated code.
Models may run on your machine or through a provider you choose. You supply access; Baltor does not need to install or host the models for you.
Make the effort count
These are the questions Baltor is designed to address at each step of the work.
Match information to the task. Bring in more when it helps, without making every step carry the whole history.
Relevant information, less repetitionCompare suitable models and reusable code for each step, against your quality and spending requirements.
An approach that fits the workBring relevant methods, examples and checks into the work, with sources and applicability kept visible.
Specific guidance, not generic guessesFind an eligible implementation first. Generate new code for the gaps instead of reproducing a known solution as more output tokens.
Reuse what is already qualifiedKeep useful results and corrections. Compare proposed improvements on real tasks before making them the default.
Measured improvement, not blind repetitionBuilding blocks for better solutions
Useful intelligence includes how to approach the work, code that can do it, what happened before, and what you want done differently.
Methods, questions, constraints, examples and output contracts that guide the work.
A field-definition guide and a checklist for missing values.
Reusable functions, tools, packages and workflows with declared inputs, outputs and effects.
A qualified normalizer with its dependency and verification records.
Saved outcomes, failures, repairs, measurements and solution information that can inform a new task.
A previous import's failed assumptions and the checks that detected them.
Scoped corrections, priorities and instructions supplied by a person.
“Keep uncertain matches for review. Never overwrite the original file.”
The four layers describe the broader product. The hosted service currently provides a small Context Intelligence example; it does not yet offer a populated catalogue across every layer.
Your tools, with help from Baltor
A person with an account can sign in with a service token, search the small example library, download permitted files and view usage. Administrators can create and revoke test tokens.
The complete example above is still being tested from start to finish. Public account creation, paid subscriptions and automatic setup of every step are not open yet. We have not established token savings or overnight task completion for this release.
Get set up
Create your account, connect the harness you already use, and let your agent ask for what each step needs.
Step 1 / Get access
Leave your email address on Get started, and we send your link to finish setting up.
Get startedConfirm your email address, choose a password, then connect your tools. Creating an account does not start a subscription.
Get startedThe person who runs this service creates each account and issues its first key. To ask for one, write to the operator at the contact address in the privacy notice.
Already have an account? Sign in
Step 2 / Connect your harness
Your harness connects to this service with the Model Context Protocol. Pick it below and copy one reviewed entry. It holds this service's address and the name of the environment variable with your key, never the key.
Loading the reviewed connection settings Merge this entry into your existing configuration. Do not replace your other settings.
Loading the secret-free configuration.
Source: Client documentation
Loading documented compatibility information.
Set BALTOR_SERVICE_TOKEN in your environment. The file holds the variable's name, never the key, so it is safe to keep in version control. Then check the entry with Choose a client above.
This prompt hides the value while you enter it. The value is not part of the command history. The client process inherits the environment variable.
read -rsp "Baltor service token: " BALTOR_SERVICE_TOKEN export BALTOR_SERVICE_TOKEN
After closing the client, clear the terminal variable with unset BALTOR_SERVICE_TOKEN. Do not run environment dumps or record the terminal while handling secrets.
This browser check initializes the protocol and lists the available operations with your current connection. It does not run any work, fetch file bodies or spend model credits.
Sign in with your service token to run the connection check.
Not tested. No model calls are made by this check.
Configuration, connection, retrieval, native loading and useful task completion are separate checks. A green connection does not qualify all five. This service does not offer a browser-based authorization flow for native clients yet. Read the access and data boundaries.
If you created this token on your Account page, open Account, find it under Your client tokens and select Revoke. If your operator gave you the token, ask your operator to revoke it. The service refuses a revoked token on its next request. Revoking a token does not recall files that were already downloaded.
Choose a client above to see how to remove its entry.
Open your accountStep 3 / Search and download
Ask your agent to search Baltor for what the current step needs. It gets short references with source, licence and digest, downloads only the one it chooses, and every download appears in your usage.
Connecting needs nothing installed beside your harness. The engine that runs on your machine is free and open source under the MIT licence; the documentation has its installation steps.
First-use example
Practice the real retrieval path with the small input-review procedure in the library. No model call is needed for this browser exercise.
Sign in with your service token, then search for review inputs. The query returns metadata and exact references, not file bodies.
This prepares a query in the workspace. You choose when to search.
Open Source, integrity and access. Check the identity, source, license, digest and qualification basis. The current example is host-attested diagnostic material, not independently qualified commercial intelligence.
Access is tenant-specific. An empty result can mean your account lacks the grant; it does not mean the item is available to everyone.
Select Fetch exact revision only if body access is permitted. The service checks your current grant again. The browser verifies the downloaded bytes against the selected digest before saving them. A download can record usage.
A downloaded file is still material to inspect. This page does not execute it, install a plugin or confirm that your client loaded it.
Open your account and refresh usage. Keep the exact reference with any later task result. If a download times out, retry the same selection in the same page session to reconcile its request identity; do not assume the first request did nothing.
You can exercise tenant-scoped search, deliberate selection and integrity-checked delivery. It does not prove model quality, lower token cost, a complete task inside a native client or automatic improvement.
Access and data
Connecting to the intelligence service grants access to permitted material. It does not give the service permission to run commands on your computer.
A service token identifies a scoped tenant connection. The service stores token digests, checks scope and expiry, and can revoke access. Your model provider keys belong with your local client or approved credential broker. Do not enter them into the website.
The browser holds its service token in page memory only. Closing or reloading the page clears that connection. Avoid shared devices, untrusted extensions and screenshots of credentials.
Search returns permitted metadata. Fetching a body rechecks access and its exact identity. A digest proves that bytes match the selected reference; it does not prove that the material is safe, correct or useful.
Inspect unfamiliar code and plugins. Use a confined workspace and a sandbox appropriate to the work, with explicit file, command and network permissions. A shared container does not isolate one process from every other process inside it.
Search text, requested references and service authentication reach the server when you use the workspace. The service records access and usage metadata. The website does not automatically upload your project files, model keys or complete execution traces.
Do not send private customer content yet. The final retention policy, deletion workflow and consent controls remain launch work, and we would rather say that than let you assume otherwise. Embeddings and derived features must not be treated as anonymous data.
The service runs on one Fly machine in one region with an attached persistent volume. A local backup-and-restore exercise has passed. This is not a multi-region service, an availability guarantee, an independent security audit or a compliance certification.
Public account creation is not open. Access comes from your operator, who can issue and revoke test tokens. A test token cannot delegate administration.
Agree on the data policy and task permissions with your operator. Keep provider credentials out of prompts and retrieved files. Do not repeat an external action after an uncertain outcome until its state has been reconciled.
Privacy
Kind: published notice. The owner approved it on September 22, 2026, with Baltor.AI as the operator and the postal contact address below. It states what the hosted Baltor service stores today, taken from the source and the deployment. Planned behaviour is marked as planned.
Operator: Baltor.AI, 1428 Bryn Mawr St, Saxton, PA 16678, United States.
Baltor serves reviewed material, such as guidance, skills and reusable code, to the tools that you run on your own computer. Your tasks, your files, your prompts and your model keys stay on your computer. The service never receives them and has no way to ask for them.
| Data | Why | Where |
|---|---|---|
| Your email address and password | To sign you in. The password is kept only by the identity provider, in hashed form. Baltor never stores or sees it after sign-up. | Supabase, United States |
| An account record that links your sign-in to your account | To know which material you may read | The service database on Fly, United States (iad) |
| A digest of each access key | To check a key without being able to show it again. The key itself is shown once and never stored. | The service database |
| One usage record for each downloaded item: the item name, its digest and the time | To show you your usage and, when billing opens, to reconcile it | The service database |
| A digest of a browser session that you signed out of, until it would have expired | To refuse that session afterwards | The service database |
| A waiting list entry, if you ask to join the list: your email address, an optional note of at most 280 characters, the state of the entry and its dates | To invite people in small groups | The service database |
| A record of each refused request: a random reference, the address path, the reason code, the account when one is known, the time and the service version | To find and fix problems. The last 500 are kept and older ones are removed. A record never holds a password, a key, a promotion code, a request body or your network address. | The service database |
| Your payment details | Planned, when billing opens. Stripe collects and keeps them. Baltor receives only a customer identifier and the state of your subscription. | Stripe |
The service keeps a count of refused sign-in attempts for each network address in memory for a short time, to slow down guessing. It is not written to disk. To stop one machine from flooding the waiting list, the service also keeps the times of recent waiting list requests under a keyed one-way digest of the sending network address, never the address itself, and removes them once the one-hour counting window has passed.
The hosting provider keeps daily snapshots of the service database for five days. To delete your account and its records, write to the contact address below. Deletion removes the account record, the key digests and the usage records; snapshots expire within five days. To leave the waiting list, ask in the same way: the entry keeps only a one-way digest of the address and the history of decisions, so the address itself is gone. Self-service deletion is planned.
Baltor.AI, 1428 Bryn Mawr St, Saxton, PA 16678, United States.
Questions that contain no personal data can also go to the public issue tracker of the repository. Do not post personal data in a public issue.
This notice changes when the service changes what it stores. The history of this file is the record of those changes.
Terms
Operator: Baltor.AI, 1428 Bryn Mawr St, Saxton, PA 16678, United States.
Last changed:
The privacy notice says what the service stores about you.
Documentation
Connect your own tools, find material for each task and check your downloads.
Loading the documentation list.
The local engine is free and open source under the MIT licence. Its quickstart uses Python 3.10 or newer and Docker for code execution. Connecting your existing harness to the hosted library does not require this installation.
python3 -m venv .venv source .venv/bin/activate python -m pip install "https://github.com/alisonjieli-png/loop-engine/archive/refs/heads/main.zip" loop-engine doctor
The engine calls the model you choose, such as a local Ollama, Ollama Cloud or a model server on your own network, with your own key. The repository README has the full steps, including Windows and macOS.
The public website calls a unit of work a step. The implementation uses the canonical Loop runtime described here and in the repository.
A discrete cognitive or act step Loop node is an independently governed instance of the Loop runtime responsible for one clearly defined cognitive step or action. A cognitive step might interpret information, identify a missing requirement, compare alternatives, or evaluate a result. An action might inspect a directory, build software, execute a test, create an artifact, or send an authorized email.
Each discrete cognitive or act step Loop node receives the context, instructions, skills, plugins, tools, and working files relevant to its assignment. Essential information can be supplied directly, while additional information can remain in centralized storage behind authorized, versioned references. It does not automatically need the entire task history or every available tool.
A separately initialized harness process, such as OpenCode, Pi, Codex, or a custom implementation, can perform the assignment. When explicitly permitted, another harness can attempt the same assignment after a failure. The assignment's contracts, permissions, history, and remaining authority persist across those attempts.
Discrete describes the scope of the assignment, not a restriction to one attempt, one model call, or one output. A discrete cognitive or act step Loop node can examine whether an observation matches its expectations, identify a problem, repair or change its approach, and repeat until its declared completion conditions are satisfied.
Alternatively, a discrete cognitive or act step Loop node can publish an initial candidate output and continue working while its continuation conditions and authority permit. It can produce additional alternatives over time, including alternatives that are better, worse, or useful under different circumstances. Consumers must identify exactly which output they used. Publishing an output does not necessarily mean that the producing assignment has finished.
For externally consequential actions, continued operation does not authorize repeated effects. For example, generating alternative email drafts can continue, but sending an email requires its own authorization and protection against duplicate delivery.
Harness Intelligence is a provisioning view over the four persistent layers. It is not a fifth persistent layer.
Runtime Memory is the temporary note board for one run. Saving a note does not promote it into reusable intelligence.
Through your signed-in connection
Model keys stay in your environment or its approved credential manager. A remote model may receive the information you allow your tools to send.
Every executable graph vertex is a Loop. A harness is an implementation adapter used by a Loop. Files, services, contracts and stores are not additional executable vertices.
Operational runtime type
└── Loop
├── Operational relationship
│ ├── Starting
│ ├── Spawned by
│ ├── Queried by
│ ├── Retrieved by
│ └── Connected from
├── Role
│ ├── Practitioner
│ ├── Intelligence
│ └── Solution
├── Versioned role profile
├── Purpose and domain categories
├── Run mode
│ ├── deterministic
│ ├── hybrid
│ └── non-deterministic, with model-led semantic work
├── Step profile
├── Typed input and output contract
├── Loop condition
├── Exit condition
├── Graph relationships
├── Budget, permissions, and effect policy
├── Model settings when the selected mode permits a model
└── Run History recordsLoop role profiles
├── Practitioner
│ ├── reference nine-step
│ ├── compact five-step
│ ├── research
│ ├── solver
│ ├── verifier
│ ├── code execution
│ └── self-improvement task
├── Intelligence
│ ├── cross-layer search and materialize
│ ├── Context Intelligence: serve, search, and frame
│ ├── Code Intelligence: resolve, invoke, and load
│ ├── Runtime History and Solution Intelligence: search, replay, and compare
│ └── User Feedback Intelligence: serve, scope, and interpret
└── Solution
├── atomic component
├── pipeline
├── router and fallback
├── ensemble
└── validator