pun is a BYOK AI coding agent written in Zig.
It provides a CLI/TUI, multiple LLM providers, sandboxed tools, MCP, plugins, memory, session history, and a web UI.
v0.7 — 60/60 tests passing.
Current features include:
- 8+ LLM providers
- Encrypted API key vault
- Workspace and command restrictions
- Network controls
- Audit logging and token limits
- MCP server and resources
- Plugin loading/unloading
- Multi-session history and search
- Web UI with WebSocket streaming
- Headless browser tools
- Persistent memory
Requirements: Zig 0.14.0
zig build
zig build test
zig build run -- --helpBinary:
zig-out/bin/pun
Initialize the config:
./zig-out/bin/pun config initStore an API key:
export PUN_VAULT_PASSPHRASE="your-passphrase"
./zig-out/bin/pun vault set anthropic sk-ant-...Start pun:
./zig-out/bin/punOne-shot mode:
./zig-out/bin/pun -p "refactor src/main.zig"Batch mode:
./zig-out/bin/pun -f tasks.json --jsonSupported providers include:
- Anthropic
- OpenAI
- OpenAI-compatible APIs
- Google Gemini
- Z.ai GLM
- DeepSeek
- Mistral
- xAI Grok
Provider configuration is stored in:
~/.pun/config.toml
Example:
[providers.anthropic]
kind = "anthropic"
api_key_env = "ANTHROPIC_API_KEY"
default_model = "claude-sonnet-4-5"Keys are checked in this order:
- Encrypted vault
- Environment variable
- Config file
api_key
pun restricts what its tools can do.
- Workspace path jail
- Command allow/deny rules
- Network allowlist
- Encrypted secrets vault
- Prompt-injection checks
- Append-only audit log
- Token limits
- Confirmation prompts
- Shell timeouts
- Optional Docker isolation
Network access for shell commands is disabled by default.
Built-in tools include:
read_file write_file edit_file
list_dir grep run_command
fetch_url web_search run_python
run_zig git_status git_diff
git_log git_commit todo_add
todo_update todo_list spawn_agent
browser_* memory_*
pun Interactive TUI
pun -p "prompt" One-shot prompt
pun -f task.json Batch mode
pun config init Create config
pun config show Show config
pun vault set <key> <value> Store a secret
pun vault get <key> Get a secret
pun vault list List vault keys
pun version Show version
pun help Show help
MIT. See LICENSE.