Your Mac,
by voice.
Say jarhead, pass Touch ID, talk. It uses the computer for you. The brain is whatever you already have a login for.
v2.0.0MITmacOS 14+Apple silicon
Wake01O OListeningWakes on a word.
Touch ID opens it.
Asleep it listens on-device for one word. Nothing billed. Then Touch ID, Apple Watch, the Mac password or a passphrase.
- Three misses lock the gate for a minute.
- Speaker verification is not attempted.
- Say stop. It stops mid-sentence.

- . .gate
- O Oheard
- ^ ^granted
- > <denied
- - -locked
Threads03o oActingSeveral things at once.
Each with its own brain.
Each has its own brain, conversation, budget and blob. Up to three run beside the main one.
"Tell Ben on Slack I'm late and put on Focus on Spotify" - Slack asks before it sends.asks
- Spotify runs in the background by Apple events.done
- "Stop the Slack one" needs no model call.
JarheadWed 24 Sep 12:37 
Rails05^ ^SpeakingOne policy table.
Run, confirm or refuse.
Every call is run, confirm or refuse. The reason is spoken. No tool is special-cased.
- A spoken yes covers one action once.
- Your key or click holds it 1.5 s.
- On-screen text is never an instruction.
- mkfs
- diskutil erase
- dd onto a device
- shutdown
- rm -rf / or ~
- Other apps' TCC resets
- Every secret store
Sleep06- -AsleepSay good night.
Alarms still ring.
It says "night." and closes the session. Ten idle minutes do the same. Alarms, timers, watchers and routines fire while it sleeps.
- No session, no brain turn, nothing billed.$0
- Set-up asks once. Fire time never asks.
- Nothing fires while Jarhead is quit.
JarheadWed 24 Sep 12:37 
Numbersthe ledgerMeasured on one Mac.
Written down.
Measured on the author's Mac and written down. The harnesses are in the repo. Every latency carries its n and date.
- 126 msprefire partials, p95
- 457 mscareful partials, p95
- 1.11 sGPT-Live-1 reply, median
- 4.4 sdelegation to first visible action, median
- 8.9 sdelegation to verified completion, median
- 55 mstool round trip, median
- 48 to 75 msscreenshot, warm full display
- 10.7kinput tokens, cold Codex thread
- 71tools in ten families
- 3live threads beside the main one
- 1.5 syour key, click or scroll holds the hands
- 2 sliveness ping
- 90 sdaemon linger after a crash
- 10 minidle sleep
- Reflex rows ran on pnpm jarhead bench, 2026-09-11.
- Model rows ran real Codex, canned hands, 2026-09-12.
- The voice reply is Agora's measurement, 2026-07-09.
Costswhat it billsFive cents a minute.
Asleep costs nothing.
The voice bills $0.05 a minute. It counts per second. Pause and Stop close the session.
- Codex runs on your ChatGPT plan.
- A local brain bills nothing. The voice does.
- The Ledger tab totals each day.
- $0.05per minute of open session
- $3an hour of talking
- $0asleep
Madehow it is madeSwift in the app.
TypeScript in the daemon.
- Jarhead.app is Swift.
- The daemon jarheadd is TypeScript.
- Two Swift helpers act on the Mac.
- The ledger is append-only. Nothing is deleted.
- Its self-edits apply only on your yes.
- One 8×8 Bayer renderer dithers everything that shades.

Installsource onlyFour commands.
Then say jarhead.
One line clones the repo and runs four commands. Setup opens on first launch and writes your key.
It never writes your keys. Read it first at https://jarhead.kevinliu.studio/install.sh
- git clone https://github.com/Kevin-Liu-01/Jarhead.git && cd Jarhead
- pnpm install && pnpm build:handsNode ≥ 24, pnpm 10 (corepack enable), Xcode
- pnpm build:macbuilds, signs, installs /Applications/Jarhead.app
- open -a JarheadSetup opens: your OpenAI key, a brain, permissions
- Then say "jarhead", pass Touch ID, talk.
- Keys go into ~/.jarhead/env at mode 0600.
- Sixteen permissions in one sweep. Seven required.
- pnpm run doctor checks keys, brain and permissions.
Setup7
- Welcome
- Voice
- Brain
- Permissions
- Wake
- Agents
- Done
- macOS 14 or newer on Apple silicon
- Xcode 15.3 or newer
- Node 24 or newer and pnpm 10
- An OpenAI API key for the voice
- A brain you are already signed in to
- A Code Signing certificate in your keychainSelf-signed is enough. Without one every rebuild resets the permission grants.