Getting Started with rho

rho is a fast, clean, local, private, and secure coding agent CLI built in Rust. It delivers native performance, strict in-process safety boundaries, session persistence, standard MCP tool servers, and lightweight lifecycle hooks.

rho startup screen with live quota in footer
🔥 π + ρ = pirho

The pirho Connection: For those who play with fire

In Greek, combining π (pi) and ρ (rho) spells πυρ (pyr) — fire. rho was built with deep appreciation for the minimalist terminal ergonomics of pi.dev, forging that same clean spirit into bare-metal Rust. Together, π + ρ makes pirho: designed for developers who love playing with fire, moving at blazing native speed, and keeping zero runtime bloat between them and their code.

  • Aligned ergonomics: Identical thinking levels, slash commands (/thinking, /skill:<name>, /new), and positional prompts.
  • Native Rust speed: Compiled binary with instant startup, zero node/python runtime prerequisites, and in-process tools.
  • Safe fire handling: Fail-closed lifecycle hooks, process group isolation, and direct provider connections.

Installation

Cargo (Recommended)
cargo install rho
Homebrew
brew install casonadams/tap/rho
GitHub Releases
gh release download -R casonadams/rho

CLI Commands & Options

rho provides a focused set of subcommands and flags for agent execution, MCP tool management, and configuration:

CLI Reference
# Start interactive multiline REPL
rho

# Execute a one-shot prompt
rho -p "Find and fix memory leaks in parser"

# Continue the last session in the current directory
rho -c

# Interactively browse and select from previous sessions to resume
rho -r

# Resume a specific session by ID (including budget checkpoint)
rho --resume <SESSION_ID>

# Export session to HTML or Markdown
rho --export session.html

# Authenticate an AI provider (OAuth subscription or API key verification)
rho login claude
rho login chatgpt
rho logout anthropic

# List live provider models and context windows
rho models

# Inspect or edit configuration
rho config
rho config model anthropic/claude-3-7-sonnet

# Model Context Protocol (MCP)
rho mcp list
rho mcp test filesystem
rho mcp add db "https://mcp.db.example.com/mcp"
rho mcp remove db

# Self-update to latest release
rho update
rho streaming assistant turn with collapsible reasoning block

8 Built-in Native Tools

rho includes 8 fast, native tools designed specifically for coding agents:

Providers, Authentication & Rolling Quotas

rho supports both API keys and subscription OAuth. Run rho login <provider> to authenticate:

rho login provider selector modal

Configure defaults globally in ~/.config/rho/config.toml or per-project in .rho/config.toml:

~/.config/rho/config.toml
# Role-based model configuration and thinking level
thinking_level = "high"

[models]
default = "anthropic/claude-3-7-sonnet"
guard = "local/qwen2.5-coder:7b"

# Execution limits & context window
max_turns = 1000
context_window_messages = 24
compaction_max_bytes = 8192

# Custom OpenAI-compatible endpoints
[providers.my-local-endpoint]
base_url = "http://127.0.0.1:8000/v1"
key_env = "LOCAL_API_KEY"

# UI block framing, output toggles, and border colors (persisted automatically via /settings)
[ui]
block_style = "border"           # "border" (outline, default) or "solid" (fill)
agent_block_output = false       # Box assistant responses in bordered frames
hide_thinking = false            # Hide thinking transcript blocks by default
tools_expanded = false           # Expand tool output cards by default
cursor = "hardware"              # "hardware" (default, native cursor) or "software" (block)
user_border = "blue"             # User prompt blocks
agent_border = "gray"            # Agent / sub-agent blocks
tool_border = "gray"             # Tool / command cards
bash_success_border = "gray"     # Successful bash commands
bash_error_border = "red"        # Failed bash commands

# Web tools and search provider configuration (persisted automatically via /settings -> Tools & Permissions)
[tools.web.search]
enabled = true                  # Enable or disable built-in web_search
default = "brave"                # "brave", "duckduckgo", "yahoo", "firecrawl", "exa", or "gemini"
fallback = ["duckduckgo", "yahoo"] # Fallback engines attempted only on failure/empty

[tools.web.fetch]
enabled = true                  # Enable or disable built-in web_fetch
multimodal = true               # Enable or disable Gemini multimodal analysis fallback
[mcp]
enabled = true                  # Enable or disable MCP subsystem

[permission]
enabled = true                  # Enable or disable mutation guardrails

Specialized Web Fetch Extractors

When fetching URLs, web_fetch automatically intercepts recognized GitHub and YouTube resources to deliver clean, token-efficient Markdown:

Pass format = "html" to bypass specialized extractors and retrieve raw HTML.

Safety Guardrails & Modal Controls

rho features an in-process safety and permission gatekeeper that evaluates tool executions and shell commands before they run. Non-mutating inspections run automatically, while potentially hazardous operations are presented in an interactive confirmation modal:

Automated Guard Model Classification

To eliminate confirmation fatigue while maintaining strict safety, rho can delegate unclassified shell command evaluation to a dedicated, low-latency Guard Model.

Recommended Local Model: qwen2.5-coder:7b

For fast, offline command inspection without cloud API costs or latency, ollama/qwen2.5-coder:7b is strongly recommended for the guard role:

Configuring Guard Model via CLI
# 1. Pull the model locally with Ollama
ollama pull qwen2.5-coder:7b

# 2. Configure guard model role in rho
rho config models.guard ollama/qwen2.5-coder:7b

# Or disable guard model evaluation (reverts to baseline prompt)
rho config models.guard none

Declarative Rules (permission.toml)

Rules can be explicitly authored in .rho/permission.toml (project) or ~/.config/rho/permission.toml (global). Explicit rules take priority over the guard model:

.rho/permission.toml
[permission.bash]
"cargo test *" = "allow"
"npm run build" = "allow"
"git push --force*" = { action = "deny", reason = "Force-pushing is strictly prohibited" }
"rm -rf *" = { action = "deny", reason = "Destructive deletion blocked by project policy" }

[permission.path]
"*.env*" = { action = "deny", reason = "Do not read secret environment files" }

Use rho --no-permission to bypass permission modals for headless non-interactive CI environments.

Privacy & Zero Telemetry

rho collects nothing. There is zero telemetry, zero background tracking, zero analytics, and zero phone-home pings built into the binary.

Keyboard Shortcuts & Commands

Shortcut Context Action
Escape Any Cancel running turn, abort active tool execution, or dismiss modal popup (navigating back one level in submenus)
Ctrl+C Editor / Modal Clear draft input or search query (never interrupts turns or exits)
Ctrl+D Editor Exit session when editor is empty
Ctrl+L Editor Open interactive provider and model selector modal (fuzzy search)
Shift+Tab Editor Cycle thinking effort (off → minimal → low → medium → high → xhigh → max)
Ctrl+O Editor Open interactive session turn history DAG tree viewer
Ctrl+S Selector Modals Save currently selected model or thinking level as default
Enter Agent running Queue immediate steering message to execute after active tool
Alt+Enter Any Enqueue follow-up prompt to FIFO message queue (or newline)

Slash Commands

Instant in-session commands typed directly into the multiline editor:

Command Description
/help Open interactive command reference and shortcut modal
/model Open interactive model and provider switcher modal (Ctrl+L)
/route Toggle or inspect automatic model tier routing (/route [on|off])
/thinking Set reasoning effort level (Shift+Tab)
/settings Open interactive runtime settings modal (block style, framing, role models, thinking, tools & permissions with hierarchical back navigation and in-place updates)
/resume Interactive session selector to resume historical conversations
/rewind Rewind conversation history to an earlier checkpoint turn
/mcp Open the interactive Model Context Protocol modal and toggle external tool servers
/compact Manually trigger context compaction with an optional focus directive (e.g. /compact "focus on tests")
/tree View session turn DAG tree and branch navigation (Ctrl+O)
/collab Start P2P live pairing session or manage active collaborators (/collab [start|stop|link|peers|kick|rotate])
/exit Exit the interactive session cleanly (Ctrl+D)
rho model selector modal with fuzzy search

Collab: Zero-Infrastructure P2P Live Pairing

rho includes zero-infrastructure, end-to-end encrypted terminal-to-terminal collaboration powered by Iroh. Pair with teammates or secondary devices directly from the terminal without central servers, cloud accounts, or third-party relays.

Starting a Collab Session (Host)
/collab

The host generates ephemeral Ed25519 node identities and cryptographic capability links:

Joining as Guest
rho join "rho://<node_id>?relay=<relay_url>#<secret>"

In interactive terminals, rho join launches directly into the full-screen terminal interface mirroring the host's layout:

Headless & IDE RPC Server Mode

For editor extensions (VS Code, Neovim, Zed) and headless automation harnesses, rho provides a fully concurrent, non-blocking JSON-lines RPC server over standard I/O:

Starting RPC Mode
rho --mode rpc

Unlike synchronous wrappers, rho's RPC loop processes client commands concurrently while turns run. Clients can abort running tasks, steer execution at tool seams, resolve interactive permission prompts, and navigate conversation tree DAGs without blocking stdout.

RPC Commands Reference

Command Parameters Description
prompt { "message": "..." } Start an agent turn asynchronously. Emits streaming text, reasoning chunks, and tool events.
steer { "message": "..." } Inject a steering prompt delivered immediately after the active tool finishes.
abort {} Interrupt active model generation or abort executing tool processes immediately.
tool_response { "approval_id": "...", "decision": "allow" | "deny" | "edit: <cmd>" | "always" } Resolve a pending permission prompt emitted by tool_approval_request.
get_state {} Query active session ID, model, provider, thinking level, and status (idle, busy, waiting_approval).
get_tree {} Retrieve the complete conversation history DAG, checkpoints, active leaf ID, and entry previews.
switch_branch { "node_id": "..." } Rewind or branch the conversation DAG to a previous turn or checkpoint.
set_node_label { "node_id": "...", "label": "..." } Assign or clear a human-readable bookmark label on a tree node.
list_sessions {} Enumerate saved session files, turn counts, last modified timestamps, and titles.
resume_session { "session_id": "..." } Switch the active engine to another saved session ID.
fork_session { "node_id": "..." } Fork the active branch or checkpoint into an isolated new session file.
set_model { "model": "<provider>/<model>" } Hot-swap the active inference model at runtime.
set_thinking { "level": "off" | "minimal" | "low" | "medium" | "high" | "xhigh" | "max" } Dynamically adjust reasoning effort for supported reasoning models.
compact { "instructions": "..." } Trigger manual context compaction, optionally passing custom focus instructions.
exit {} Cleanly terminate active tasks and shut down the daemon.

Interactive Tool Approval Flow

When a tool executes a mutating command requiring user consent, rho emits a tool_approval_request event and transitions to status: "waiting_approval":

Tool Approval Event
{"type":"tool_approval_request","approval_id":"appr-b618","tool":"bash","arguments":{"command":"cargo check"},"description":"Run cargo check"}
{"type":"status_changed","status":"waiting_approval"}

The client displays a native UI modal and responds with tool_response:

Client Decision Response
{"type":"tool_response","approval_id":"appr-b618","decision":"allow"}

Dynamic Context Compaction & Token Budgeting

Long-running coding sessions inevitably encounter context window exhaustion. rho incorporates an adaptive, resilient compaction engine designed to preserve critical repository findings while reclaiming token capacity:

The rho Lifecycle Hooks Subsystem

Lifecycle hooks in rho are lightweight, one-shot executable scripts in .agents/hooks/. When events occur, rho pipes event details as single-line JSON to the script's stdin and reads the decision JSON from stdout.

Hook Events

Event File Payload (stdin) Description
on_tool_call { event, tool_name, args, turn, session_id } Intercept tool calls before execution. Can allow, stop, skip, rewrite arguments, or prompt the user.
on_tool_result { event, tool_name, args, output, is_error } Inspect or transform tool output after execution.
on_invalid_tool_call { event, tool_name, args, available_tools } Intercept hallucinated or misspelled tools to retry or halt.
on_completion_call { event, turn, prompt } Audit prompt before LLM provider completion.
turn_start { event, prompt, turn, session_id } Notifies turn initiation with initial user prompt.
turn_end { event, status, tool_calls_count, turn, session_id } Notifies turn completion.

Example: Blocking Destructive Commands

.agents/hooks/on_tool_call (chmod +x)
#!/bin/sh
read -r EVENT

# Intercept dangerous commands
if echo "$EVENT" | grep -Eq 'rm -rf|git reset --hard'; then
  echo '{"action":"stop","reason":"Destructive command blocked by hook"}'
fi

Example: RTK Token Optimization

Use RTK (Rust Token Killer) to automatically filter and compress verbose CLI output (saving 50–90% on context tokens). See examples/hooks/rtk-rewrite.py for the ready-to-use Python recipe.

Configuring Model Context Protocol (MCP) Servers

MCP servers are tool providers configured via standard JSON in ~/.config/mcp/mcp.json or ~/.agents/mcp.json (global) or .mcp.json (local workspace root). rho supports both local stdio child processes (with lazy on-demand startup and automatic 10-minute idle process reaping) and remote streamable-http (with OAuth 2.1 authentication and SSE streaming). All exposed tools are automatically namespaced:

CLI & Interactive Commands
# Inspect, test, and manage MCP servers
rho mcp list
rho mcp test filesystem
rho mcp login remote-jira
rho mcp add db "https://mcp.db.example.com/mcp"

# In the interactive REPL:
/mcp
~/.agents/mcp.json or .mcp.json
{
  "mcpServers": {
    "filesystem": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-filesystem", "/Users/username/Desktop"]
    },
    "github": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-github"],
      "env": { "GITHUB_TOKEN": "${GITHUB_TOKEN}" }
    }
  }
}

When configured MCP servers expose more tools than the deferral threshold (defer_threshold, default 4), rho automatically defers tool schemas behind tool_search to minimize prompt token overhead. The model searches on-demand and dynamically activates matching tools with full schemas for subsequent turns, or can optionally specify execute to run matching tools in the same turn without extra latency.