---
title: Desktop app
group: Apps
order: 1
summary: Run Escanor with your own computer as the server: install it on Linux, Windows or macOS, see what it includes, and how it protects your data.
updated: 2026-10-07
---
Escanor Desktop is the whole Escanor app running on your computer, with your computer's hardware doing the work: local models, Docker, an editor, files and background jobs, plus the same dashboard, assistant and integrations as the website.

## Install

Download it from the [home page](/#download). It is available for Linux, Windows and macOS. The builds are not yet code-signed, so your system asks you to confirm the first run; see [Updates](/docs/updates) for installation notes.

| System | Get | First run |
|---|---|---|
| **Linux** | `.AppImage` (compatible x86-64 Linux) or `.deb` (Debian and Ubuntu) | For the AppImage: `chmod +x Escanor-*.AppImage`, then run it. For the `.deb`: `sudo apt install ./Escanor-*.deb`. |
| **Windows** 10 and 11 | Installer (`.exe`) | If SmartScreen warns, choose **More info**, then **Run anyway**. |
| **macOS** | `.zip` or `.dmg` (Apple silicon or Intel) | Unzip (or open the disk image) and drag Escanor to Applications. Open it once; when macOS says it cannot verify the developer, go to **System Settings › Privacy & Security** and click **Open Anyway**. |

Sign in with the same account you use on the website. Sessions renew while permitted; revocation or service policy can still require sign-in. You can add more than one account and switch between them (desktop only).

## What is in it

The sidebar lists areas from most to least used.

| Area | What you get |
|---|---|
| **Escanor** | Home, and the round assistant button on every screen (or **Alt+J**): open sites and apps, search, volume and media, ask the assistant, hand it any task. Asks aloud before changes. |
| **AI** | The assistant, runs, a complete AI activity log (runs, chats and every MCP call, filterable and exportable), context, and **Local models**. |
| **Local models** | A library of models with what each is good for and whether it fits this computer's memory; downloads that keep running while you browse; an installed list with load and unload; a streaming chat playground. |
| **Work** | Integrations, projects from every connected platform, automations, auto-fix, MCP keys and activity. |
| **Observe** | Activity, deployments, repositories, incidents, monitoring, analytics. |
| **This computer** | Live resources, Docker, the **Editor** (VS Code in its own window with the Escanor theme and extension), background jobs, **Phone**, and an audit log. |
| **Settings** | Personal, workspace, developer (API and MCP keys, authorised apps, log ingest keys, endpoints) and computer settings (permissions, shared folders, voice, startup). |

When the app opens, it shows the last data you saw (cached on this computer, one cache per account) and refreshes it in the background.

## Pairing your phone

Open **Phone** to see the pairing code and QR. See [Computers and pairing](/docs/computers-pairing).

## Voice

Speech recognition uses a model on this computer after its required model files are downloaded. Assistant and integration requests can still require connectivity. See [Voice](/docs/voice).

## Security

- Session tokens stay in the main process and use OS-backed encryption when available, with an owner-only file fallback when it is unavailable. The window never sees them; calls to the Escanor API go through a proxy that only talks to that API.
- Phone pairing uses a one-time code. After that, every message between the phone and the computer is sealed end to end and protected against replay. The relay only ever sees ciphertext.
- Shell, file, app-install, background-job and OS-control capabilities are **off for phones by default**. Destructive operations require approval and can be denied when an approver is unavailable.
- The editor and its local API listen on `127.0.0.1` only, with credentials created at each launch.
- Everything is gated by one capability list with risk levels, and each use is written to the audit log.

## The companion

The window icon is the Escanor mark. Your companion (a dog by default) keeps you company on loading and empty screens: change it in **Settings > Companion**. See [Companions](/docs/companions).

## Known limits

- Builds are unsigned and there is no automatic update yet: install a newer build over the old one.
- Reading the screen and operating other applications on your computer is not built; opening, launching, searching, media and volume are.
- Phone to computer is Wi-Fi or the relay; direct peer-to-peer is not built.
