Skip to content
All projects

MYOCA

Private repo

Make your own chat agent.

A bring-your-own-key Android agent runtime with no backend and no login, where every agent is granted device capabilities one at a time.

FlutterDartMCPAndroid
lines of Dart
89k

lines of Dart

tests
677

tests

feature modules
11

feature modules

servers of mine
0

servers of mine

Why this exists

Every chat app that wraps a model puts a server between you and the provider you are already paying for. That server sees your prompts, holds your keys or rents you theirs, and requires an account before it will do anything useful.

MYOCA removes it. You bring your own credentials, every model and embedding call goes straight from the phone to the provider, and there is no login anywhere in the app, including for the paid tier.

Capability scoping is the actual product

An agent that can read your files is useful. An agent that can read your files because every agent can is a liability. So capabilities are granted per agent rather than per app: one agent may reach the filesystem, another only the network, a third nothing at all.

That turns a vague privacy promise into something the architecture has to earn. Keys, chats, documents, and configuration never leave the device, and there is no first-party server that could receive them even if the code tried.

What is built

Secure credential storage, three provider adapters with health checks, an MCP client so agents can reach external tools, per-agent permission scoping, and the chat runtime across eleven feature modules covering agents, chat, providers, MCP, privacy, security, history, activity, photo editing, and the dashboard.

An agent can remember something, and forget it too

Agent memory is not a bigger context window, it is a store an agent writes to and reads from deliberately: remember a fact, recall it later, forget it on request. The interesting failure mode was not storage, it was contamination. A note taken from a conversation later found to be compromised has to lose its text without losing its row, because deleting the row breaks every reference to it and keeping the text keeps the taint.

The dashboard makes a promise no other screen in the app makes so plainly: it tells you which MCP servers still need your attention. That claim is now guarded by a client that throws if it ever makes the network call the screen swears it does not make, so the promise cannot silently stop being true.

A reopened conversation now shows what its tools actually did, not a paraphrase of it. Token totals are counted per conversation and published as a floor rather than an exact figure, because a floor that undercounts is honest and an estimate that overcounts is not.

Screenshots

MYOCA dashboard showing zero providers, agents and MCP servers, with local device tools already available
Nothing configured yet, and the device tools already work: no account, no permission.
Add provider screen with Gemini, OpenAI, Anthropic and OpenAI-compatible options, and a note that the API key never leaves the device
Bring your own key. Stored on the device, never sent to MYOCA.

Interested in the rest?

The full history, the architecture decisions, and the code behind this are available on request.

{
  "created_at": "2026-09-14T20:07:33+05:30",
  "updated_at": "2026-09-21T18:10:53+05:30"
}