PostgreSQL
A separate database per project, there from the start.
Say what you want built and Studio writes the code, with the preview running right where you are. The finished app lands on a runlot project that already has a database, login, file storage, mail, and a Git repository.
Build me an order screen. Keep the menu in the database.
Nothing of ours stands between an edit and the look that follows it. Development happens wherever the UI is open, and runlot sees the commits and the deploys.
Home is one box. Send what you want built and the app is named, a workspace opens, and the first turn starts. There is no form to fill in.
The preview runs on your own machine on the desktop, and inside the browser tab on the web. When the agent writes a file the screen carries on from where it was instead of starting over.
Publishing goes build → preview deploy → smoke → promote behind one button. The preview runs against a branch of the database, so your production data is not what gets checked.
Where the output lands is what Studio is for. There is no database, login, or storage left to attach afterwards.
A separate database per project, there from the start.
Email, GitHub, and Google sign-in through one env.auth.
Uploads and public files through env.storage.
Send from the app's address, and mail sent to it reaches your worker.
One commit per turn. The repository belongs to the project.
Connect a domain you already own; certificates are issued and renewed.
Logs, domains, members, and billing are read in the dashboard. Studio links to those pages rather than building them again. The database is the exception: a real client lives inside Studio.
The desktop app runs the agent on your machine, under your own Claude or ChatGPT subscription. What you already pay for becomes the tool you build with.
A turn that ran on a subscription spends no runlot AI credit. The model picker marks your subscription no credit charged, and what it used shows against the subscription's own rolling 5-hour and 7-day limits.
Nothing has to be connected first. The first turn runs on runlot's hosted model and AI credit, and a subscription is connected from the model picker whenever you want.
Subscription tokens and API keys sit in the OS keychain. They do not reach our servers.
Closing the window leaves the menu-bar app running. Launch at login is on by default, and only Quit in its menu ends it.
While the desktop app is running, its model can answer from other places too. Every part of this is switched on by the person lending it.
My desktop appears in the model picker at studio.runlot.io, and a turn started in the browser runs on the model on your machine. Installing the desktop app and then opening a browser does not send you back to the hosted lane.
Turn it on for a project and a member's Studio desktop answers that app's env.ai.run from its own subscription. No credit is charged. Whether an unanswered call falls back to credit is a second switch.
The default is off: the lender turns lending to apps on and picks the models one at a time. A lent call runs with every tool off and does inference only, so it cannot reach that machine's files, and only anthropic/* and openai/* models take this path.
Open one project on both and an edit on either side appears on the other. There is no handover and no lock.
There is one sign-in. Log in on either side and the same organization's app list opens.
The desktop app runs on your subscription; the web opens right now.
macOS · Apple silicon or Intel