Mongrel AI

AI inside the workbench, on your terms.

Mongrel's assistant is opt-in, works with the providers you already trust, and keeps every proposed action behind your review. Your keys, your models, your call.

Bring your own provider

AI features are opt-in and work with any OpenAI API-compatible service, using the Responses API or the Chat Completions API, plus first-class Anthropic and Google Gemini support. Keys are optional for keyless local services.

Model discovery loads identifiers from the provider's model list; manual model entry always works.
API keys stay in the OS keychain only, never in plain settings files.
HTTPS is required for remote providers; plain HTTP is allowed only for loopback services.
Redact-before-send strips common secrets, tokens, and credentials from prompts by default.
Optional local usage budgets with soft warnings and hard limits, reconciled manually against your provider bill.

An assistant that knows the workbench

Chat about databases, SQL, terminals, containers, Kubernetes, and APIs with the context you choose: the active database and schema, the current query, or a bounded result sample. Responses stream as they arrive, and Stop cancels the active request.

Full thread management: rename, search, duplicate, pin, archive, and branch conversations.
Text and image attachments with provider-native vision, voice dictation, read-aloud, and optional OpenAI Realtime voice sessions.
Reviewed SQL and aggregation proposal tools insert into the active query editor only after you accept.
Connection diagnostics for SSH, TLS, DNS, PostgreSQL, and MySQL failures, plus terminal and container log triage.

Built-in MCP client

Mongrel is a Model Context Protocol host and client. Connect MCP servers over the standard transports, then browse their tools, resources, prompts, and tasks from the assistant. An active license or trial is required to connect.

Local stdio launches the program directly, without a shell, with per-process memory, CPU, and runtime limits, plus an optional bwrap or sandbox-exec OS sandbox on Linux and macOS.
Streamable HTTP with HTTPS required for public servers, static bearer or OAuth 2.1 with PKCE, and custom header, proxy, CA, and mTLS options.
Legacy HTTP + SSE compatibility for older servers.
Import and export the common mcpServers JSON shape; exported files never contain secrets.

Reviewed execution, not blind automation

MCP tools reach chat through provider-native function calling, but the provider never gets direct database, shell, or MCP execution access. Mongrel re-lists the server and revalidates the live tool schema before every call.

Proposals-only by default: every tool call pauses for your confirmation.
Automatic read-only runs only for individually granted tools on explicitly trusted servers, and only while the live schema and read-only, non-destructive, closed-world annotations hold.
Production connection profiles default to proposal-only behavior.
Mongrel is an MCP host and client; it does not act as an MCP server for other tools.

The assistant ships with every Mongrel install. Add a provider when you are ready, and leave it off when you are not.