Skip to content
kazma.
Search Kazma Documentation & Site
ع Star 6 Get Started
Features

Everything Kazma does.

69 features in 9 areas, every line checked against the code and marked with its status. What isn't built yet is listed at the end.

Source: docs/FEATURES.md, updated 29 September 2026.

What the statuses mean

Shipped
works out of the box or one setting away
Opt-in
works once you install or configure the named extra
Partial
works, with the limit stated
Not built
people ask; it is not there

One assistant, everywhere you talk to it

The same assistant, the same memory and the same approvals in the browser, the terminal and your chat apps.

  • Web chat with streaming answers, a step-by-step activity view per answer, and approvals inline

    Where: /chat Docs
    Shipped
  • Telegram, Discord and Slack: text, photos and documents, voice notes transcribed, approve/deny buttons, per-platform allowed-user lists

    Where: kazma-gateway Docs
    Shipped
  • Each chat app's Test diagnoses the connection: the token, the chat or channel Kazma delivers to, direct messages, allowed users, and what became of the last message a person sent

    Where: Settings → Providers & Connectors → Platform Connectors Docs
    Shipped
  • Tables in an answer are rewritten as lines for Telegram, Discord and Slack, so they read on a phone

    Where: kazma_gateway/chat_tables.py
    Shipped
  • Terminal UI, including a file editor

    Where: kazma-tui Docs
    Shipped
  • Command line: one-shot questions (kazma ask), and the Agent Client Protocol for editors (kazma acp)

    Where: kazma-cli Docs
    Shipped
  • An MCP server: other agents can use Kazma's tools, with the same approval gate (kazma mcp)

    Where: kazma mcp Docs
    Shipped
  • Spoken replies (text-to-speech) and speech input; click-to-play in web chat

    Where: Settings → Voice Docs
    Shipped
  • Live two-way voice in the browser through LiveKit

    LIVEKIT_URL and keys

    Opt-in
  • English and Arabic interface, full right-to-left layout; your words, the model's replies, names and server diagnostics are shown as written, each paragraph in its own language's direction (English left to right, Arabic right to left) in either interface

    Where: Every page, the login page included Docs
    Shipped

Models

Bring the model you trust — a cloud provider, or one that runs on your own machine.

  • 20 provider presets: OpenAI, DeepSeek, Groq, xAI, OpenRouter, Mistral, Together, Fireworks, Perplexity, Cohere, AI21, NVIDIA and Z.AI (OpenAI-compatible); native Anthropic, Google Gemini (incl. Vertex), Azure OpenAI and AWS Bedrock; and any custom OpenAI-compatible endpoint

    Where: Settings → Providers Docs
    Shipped
  • Local models through Ollama and LM Studio

    Where: Settings → Providers Docs
    Shipped
  • A provider's Test sends a real completion, not just a ping

    Where: Settings → Providers
    Shipped
  • Best model per task for multi-agent workers; image questions go to a vision-capable model

    Where: models/selection.py
    Shipped
  • When a model fails over to another, you are told (page + banner)

    Where: observability/model_fallback.py
    Shipped
  • Token and cost per answer; a cost breaker that halts runaway spending

    Where: Chat footer, dashboard
    Shipped

Safety and control

Nothing risky happens without you, and untrusted text is treated as data.

  • Dangerous actions wait for your approval — on chat, multi-agent and pipeline paths alike; unclassified tools are gated by default

    Where: Threat model Docs
    Shipped
  • Plans checked against memory before they act: a reminder date is anchored to what you said, not what the model guessed; catastrophic shell commands are refused before the approval card

    Where: Commitment layer Docs
    Shipped
  • Web pages, search results, documents and recalled memory are fenced as untrusted data; the effect is measured on a public benchmark

    Where: Prompt injection: the numbers Docs
    Shipped
  • Secrets in an encrypted vault (AES-256-GCM); never passed to programs a tool starts; masked on every screen and API

    Where: security/vault.py
    Shipped
  • Protections against server-side request forgery, cross-site requests, and request floods

    Where: security/ssrf.py, csrf.py, rate_limit.py
    Shipped
  • Login by secret, local users or OIDC single sign-on; admin, operator and viewer roles

    Where: /login Docs
    Shipped
  • Several users or teams on one install

    built for one trusted operator; multi-user separation is enforced for memory and chats, not audited end to end

    Partial
  • Code the agent runs in an isolated container

    Docker (KAZMA_CODE_EXEC_DOCKER=force) or E2B

    Where: tools/code_exec.py
    Opt-in

Memory

It remembers what matters, shows you what it used, and forgets what you tell it to.

  • Remembers conversations and the facts in them, across chats, with when each fact became true

    Where: Memory Docs
    Shipped
  • Recall by evidence: a memory is used only when it matches the question well enough — nothing when nothing does

    Where: memory/recall.py
    Shipped
  • Every answer shows which memories it used

    Where: Chat activity: "Memory used"
    Shipped
  • "About me": a short text you write, read at the start of every reply

    Where: Settings → Memory
    Shipped
  • Weekly topic summaries of long threads

    Where: Memory page
    Shipped
  • Forget one memory or a whole chat; keep a chat out of memory; export everything

    Where: Chat menu → Memory…, Memory page
    Shipped
  • Works in Arabic and English, Gulf dialect included

    Where: memory/query_terms.py
    Shipped
  • Nothing lost by accident: archiving never erases a memory's text

    Where: memory/macro_sleep.py
    Shipped
  • Shared memory between installs through Postgres

    memories and facts mirror; each install keeps its own vectors and graph

    Partial

Knowledge and documents

Give it your files and sites; it reads, searches, converts and writes documents — Arabic included.

  • Knowledge Library: add files, web pages or whole sites; search by keywords and by meaning; Arabic-aware

    Where: /knowledge Docs
    Shipped
  • Documents: safe upload (quarantine, file-type checks, macro rejection), text and OCR from PDF, Word, Excel and PowerPoint, Arabic included

    Where: /documents Docs
    Shipped
  • Virus scanning of uploads

    needs ClamAV installed

    Where: documents/malware.py
    Opt-in
  • Convert, split, merge and redact documents; generate reports as Word, PDF or HTML with correct Arabic typography

    Where: /documents Docs
    Shipped
  • Deep web research with sources: search, read, crawl, summarize

    Where: /research Docs
    Shipped
  • Web search through SearXNG (self-hosted metasearch, in the Docker setup)

    Where: tools/web_search.py
    Shipped
  • Reading hard pages through Firecrawl, Jina or a real browser

    keys / Playwright

    Where: tools/read_url.py
    Opt-in
  • Scraping through a rotating residential proxy

    Where: Settings → System → Proxy
    Opt-in
  • Image generation (Pollinations with no key; DALL-E, Stability, Flux with keys) and image understanding

    Where: tools/image_gen.py
    Shipped

Work on code

An editor, git and GitHub — and every write goes through your approval.

  • Web IDE: browse, edit, patch, run, git — every write through the approval gate

    Where: /ide Docs
    Shipped
  • Clone and switch repositories; the agent always works in the active one

    Where: /workspace
    Shipped
  • GitHub: branches, commits, pull requests, through a GitHub App or a token

    Where: git_github_manager skill
    Shipped
  • Code search across the repository (ripgrep plus symbols)

    Where: kazma_core/code_index
    Shipped
  • Steer a running task (/steer), abort it, plan first (/plan), long missions (/long)

    Where: Chat commands Docs
    Shipped
  • Rewind or branch a conversation from any earlier step

    Where: /replay, /fork Docs
    Shipped

Many agents at once

Split a job across workers that are created when needed and watched while they run.

  • Six ways to run workers: dispatch, broadcast, pipeline (with approval checkpoints), fan-out with voting, consult, conditional

    Where: /swarm, kazma swarm Docs
    Shipped
  • Workers created on demand from templates — none need registering first

    Where: swarm/autoscaler.py
    Shipped
  • Circuit breakers, retries, timeouts and output checks per worker

    Where: swarm/reliability.py
    Shipped
  • Durable multi-step runs through Temporal

    Where: swarm/durable_temporal.py
    Opt-in

How the six patterns flow

Six ways to split work across workers — pick one to see how it flows.

Dynamic Autoscaling Enabled

Fan-Out & Voting

Parallel Consensus
Topology: 1 → [3 Parallel] → 1

Dispatches identical or partitioned tasks across multiple isolated workers simultaneously, aggregating outputs via weighted voting or consensus deduplication.

Execution Flow Nodes

Supervisor Worker Alpha (Coder) Worker Beta (Tester) Worker Gamma (Security) Consensus Aggregator
Recommended for: Complex audits, competitive code synthesis, and high-assurance verification.

Automation and connected accounts

Mail, calendars, reminders and posts — handled in the chat where you asked.

  • Reminders and scheduled tasks, delivered to the chat you asked from

    Where: /scheduled
    Shipped
  • X (Twitter): drafts, schedule, post through the official API, reply to mentions

    Where: /x Docs
    Shipped
  • Email (Gmail, Outlook) and calendar (Google, Microsoft)

    Where: Settings → Email Docs
    Shipped
  • More than one mail account (several Gmail, Outlook or IMAP), each with its own calendar, named in chat by name or address

    Where: Settings → Email → Other accounts Docs
    Shipped
  • Skills from the open agentskills.io ecosystem: search, install from GitHub, signed and verified

    Where: /skills Docs
    Shipped
  • MCP tools from any MCP server (stdio, SSE, streamable HTTP)

    Where: /mcp Docs
    Shipped

Running it

Built to be run for months: it restarts itself, backs itself up, and tells you what happened.

  • A supervisor that restarts on real failure, reloads gracefully and pages you over Telegram

    Where: scripts/service/kazma_guard.py
    Shipped
  • One status card per restart: how long Kazma was down and whether each chat app connected (start and stop messages are optional)

    Where: Settings → Adapters & Routes → Server status messages Docs
    Shipped
  • Backups of everything every 6 hours, snapshotted locally and offsite (restic), checked daily, with a weekly restore rehearsal of the database

    Where: Disaster recovery Docs
    Shipped
  • Move an install to another machine or OS in one bundle

    Where: kazma migrate Docs
    Shipped
  • Back up your settings to a file and restore them: you see what will change first, the keys you have are never replaced, a lost key comes back from the vault without typing it, and the restore can be undone

    Where: Settings → System Docs
    Shipped
  • Health checks that make a real round trip; alerts to Telegram, Discord or Slack; a daily digest and a weekly resilience report

    Where: /health/deep
    Shipped
  • Old chat step history pruned on a schedule you set

    Where: Settings → System
    Shipped
  • Postgres for settings, chats, tasks and checkpoints; SQLite with no setup

    Where: Postgres Docs
    Shipped
  • Prometheus metrics; OpenTelemetry and Langfuse traces

    Where: /metrics Docs
    Shipped / Opt-in
  • Updates in one command: on a supervised install it waits for the chats to go quiet, stops Kazma, installs and starts it again

    Where: kazma update Docs
    Shipped
  • Fault injection to test retries and failover: slow or failing model calls, tool calls and reply saves (other targets have no injection point yet); off unless enabled

    Where: KAZMA_CHAOS_ENABLED Docs
    Opt-in

Not built

People ask for these; they aren't there. Listed so you don't have to look.

  • Not built

    A paid bug bounty (responsible disclosure only — SECURITY.md).

  • Not built

    Cryptographic trust tiers for skills beyond HMAC verification, and signed delegation between agents.

  • Not built

    A hardening check that runs at startup: kazma-security.yaml is read by no code; the hardening report runs on demand.

  • Not built

    A security audit of multi-tenant, internet-facing deployments. Kazma is built for one trusted operator.