# Local mode keeps the control plane out

[Journal](/journal/)

September 4, 2026 · Amended September 5, 2026 · [guides](/journal/#guides)



Muniment Desktop keeps account-free threads local by separating control-plane access, Pi provider credentials, process variables, and run records.

![An account-free thread connects to a local credential file and run journal behind a barrier from the control plane.](/_astro/local-mode-keeps-the-control-plane-out.K9GqhLjz_1CA77v.avif)

An account-free thread needs a local authority boundary, not just a signed-out screen. Our Muniment Desktop note draws that boundary through credentials, process variables, and records.

## The thread does not borrow cloud authority

The signed-out screen offers **Use local mode**. That choice opens the thread surface without a Muniment account.

Local mode does not contact the Muniment control plane for authentication or model access. Pi runs on the device, and the desktop passes no Muniment virtual key to it.

A separate **Sign in for cloud features** action leaves local mode. Features that need the control plane retain their sign-in boundary.

## Pi owns provider access

Open the sidebar’s **Local mode** section from the thread surface. Select **Anthropic**, **Google**, or **OpenAI**. Enter the key in **Provider API key**, then select **Save key**. The desktop writes the key to Pi’s `~/.pi/agent/auth.json` store with Pi’s file lock.

Pi can also use provider credentials that the Pi CLI saved in the same store.

Local mode removes inherited provider credential and endpoint variables from the Pi process environment.

## The run journal stays local

Local mode writes run input, model output, tool activity, and completion records to the local run journal. A completed local run records its elapsed time and no cloud receipt. These records use the same event shapes as cloud-backed runs.

The note establishes that record shape and local destination without claiming a public result.

No visitor can install Muniment Desktop today. This article therefore reports product behavior from our note, not a result that visitors can measure.

On 2026-09-05, the note moved provider access to the sidebar and added Anthropic and OpenAI.

The source is our Muniment Desktop `docs/public-evidence/local-mode.md` note pinned to commit `c4a94196e60aae669399a13c363c216a5ed438f8`.

Local mode earns its name when credentials, process inputs, and run records stay on the local side of the control-plane boundary.
