Skip to content

Install

Tori is macOS only, and ships as an unsigned universal app (Apple Silicon and Intel). Unsigned means macOS will refuse to open it on the first try. That is expected, and getting past it takes about ten seconds.

Tori is unsigned because it has no Apple Developer certificate yet. Signing and notarization are planned; until then the steps below are the cost of installing it.

Terminal window
brew install --cask gettori/tap/tori

The cask clears the quarantine flag for you, so the Gatekeeper steps below are only for a DMG you downloaded yourself. The rest of this page is that route.

  1. Download Tori_<version>_universal.dmg from the Releases page.
  2. Open the DMG and drag Tori into Applications.
  3. Eject the DMG.

Double click Tori in Applications. macOS will block it with a message like “Apple could not verify ‘Tori’ is free of malware.” Dismiss that dialog, then:

  1. Open System Settings.
  2. Go to Privacy & Security.
  3. Scroll down to the Security section. You will see a line naming Tori, with an Open Anyway button next to it.
  4. Click Open Anyway, then confirm (Touch ID or your password).

Tori opens, and every later launch is a normal double click.

The “right click and choose Open” trick no longer works. It was the standard advice for years, and it was removed in macOS 15 (Sequoia). If you find that suggestion elsewhere, it is out of date, use Open Anyway above.

The Open Anyway button only appears after you have tried to open the app at least once. If you do not see it, go back and double click Tori first.

Removing the quarantine attribute does the same thing in one command:

Terminal window
xattr -cr /Applications/Tori.app

Then open Tori normally. This clears the flag macOS attaches to downloaded files; it is what the Open Anyway button does under the hood.

Tori_<version>.apk on the Releases page is Tori on Android. It pairs with a Mac running Tori rather than standing alone, so turn on Settings > Remote there first, pick an address the phone can reach (Tailscale works across networks, not only the same Wi-Fi), then scan the QR the Remote pane shows.

The APK is signed with Tori’s own key rather than distributed through the Play Store, so Android asks once whether to allow the install. Later releases carry the same key and install over the top.

An iOS app is planned.

  • macOS. Tori is developed and tested on macOS 15, and the bundle sets no minimum version, so older releases are untested rather than blocked. The Gatekeeper steps above are written for macOS 15 and later; on older versions the Open Anyway button lives in System Settings (or System Preferences) under Privacy & Security too, and the right click Open trick still works there.
  • Apple Silicon or Intel. The DMG carries a universal binary.
  • At least one agent CLI installed. Claude Code ships the deepest integration; Codex, Copilot, Gemini, Kimi, OpenCode and Pi are also supported out of the box. Tori drives the agents you already have; it does not bundle one. After first launch, Settings > Agents shows which ones it found.
  • Node.js, if you want the bundled TypeScript language server to run.

Tori checks for a newer release on launch (once a day at most) and shows a dismissible notice in the title bar when one exists. It never downloads or installs anything for you: run brew upgrade --cask tori, or click through to the Releases page and repeat the steps above. Replacing an unsigned app re-triggers quarantine anyway, so an in-place auto-update would not save you the Open Anyway step.

To stop the check entirely, use the app offline; a failed check is silent.

brew uninstall --cask tori, or drag /Applications/Tori.app to the Trash. Everything else Tori writes lives under a single directory, ~/.config/tori/:

  • settings.json, appearance, typography and layout preferences
  • tori.toml, your spaces, projects and folders
  • agents/, adapter overrides, if you added any
  • checkpoint-index/, per-turn checkpoint snapshots
  • state.json, hooks-status/, the first-run flag and live session status

That is not the complete list; see the files on disk reference for the rest. One cache lives outside it: ~/Library/Caches/tori/, holding the published model list the context meter reads, plus a data directory under ~/Library/Application Support/tori/ for per-account agent logins and usage snapshots. Deleting all three removes every trace. Tori never touches your agent CLIs’ own session data, so your agent transcripts are unaffected.