Opens in the current directory. Approvals appear in the transcript where the call is; many sessions, one screen.
$ cd my-project && qqExplore the TUIA terminal UI, a headless runner, and a local server, sharing one runtime. Every action passes a policy you can read, and every event is kept, so sessions survive restarts and many agents can run at once.
--verbose and gate the write behind it.Your agent works. You stay in control.
FROM YOUR TERMINAL TO YOUR PIPELINE
Work interactively. Run unattended. Share a local server.
Opens in the current directory. Approvals appear in the transcript where the call is; many sessions, one screen.
$ cd my-project && qqExplore the TUIThe same agent in a script or CI job. Read-only unless you say otherwise; JSONL out, meaningful exit codes.
$ qq run --approval auto --format jsonlExit codes: 0 1 2 3 4 5 130
"Add a --dry-run flag and a test"
Several clients, one runtime, over HTTP and SSE. Random loopback port by default.
$ qq serve --bind 127.0.0.1:4711Run a server
Same tools. Same policy. Same SQLite store. Everywhere.
A POLICY, NOT A LEAP OF FAITH
A real bash parser grades every shell command: allow, prompt, or forbidden. A held call shows you what will run, where, and why it asked; answer once, or grant it for the session or the workspace.
Forbidden means forbidden. No mode, grant, or delegate overrides it.
Understand the policy| verdict | example | auto (TUI default) |
|---|---|---|
| ● allow | cargo test | runs |
| ◇ prompt | npm install x | asks |
| ✕ forbidden | sudo … · curl … | sh | refused |
KEEP THE WORK IN VIEW
The sidebar groups sessions by what you should do — NEEDS YOU, WORKING, IDLE, DONE — with unread counts, not by when you opened them. Ctrl+G jumps to the next one that needs you.
Alt+A / Alt+D approve or deny another session's oldest held call without leaving yours. Sub-agents appear under their parent, bounded by the roster and depth you configure.
Work with sessionsYOUR MODEL. YOUR CREDENTIALS.
Or any OpenAI-, Anthropic-, or Gemini-compatible endpoint: a gateway, LiteLLM, or a local model server.
Credentials live in your OS keyring, stored once with qq auth login. Config files hold names, never secrets; a repository’s config cannot reach a credential you did not register.
Layer your configuration: packs → global → trusted project → QQ_CONFIG and the environment.