Everything Kazma does.
69 features in 9 areas, every line checked against the code and marked with its status. What isn't built yet is listed at the end.
Source: docs/FEATURES.md, updated 29 September 2026.
What the statuses mean
- Shipped
- works out of the box or one setting away
- Opt-in
- works once you install or configure the named extra
- Partial
- works, with the limit stated
- Not built
- people ask; it is not there
One assistant, everywhere you talk to it
The same assistant, the same memory and the same approvals in the browser, the terminal and your chat apps.
- Shipped
Web chat with streaming answers, a step-by-step activity view per answer, and approvals inline
Where: /chat Docs - Shipped
Telegram, Discord and Slack: text, photos and documents, voice notes transcribed, approve/deny buttons, per-platform allowed-user lists
Where: kazma-gateway Docs - Shipped
Each chat app's Test diagnoses the connection: the token, the chat or channel Kazma delivers to, direct messages, allowed users, and what became of the last message a person sent
Where: Settings → Providers & Connectors → Platform Connectors Docs - Shipped
Tables in an answer are rewritten as lines for Telegram, Discord and Slack, so they read on a phone
Where: kazma_gateway/chat_tables.py - Shipped
Terminal UI, including a file editor
Where: kazma-tui Docs - Shipped
Command line: one-shot questions (kazma ask), and the Agent Client Protocol for editors (kazma acp)
Where: kazma-cli Docs - Shipped
An MCP server: other agents can use Kazma's tools, with the same approval gate (kazma mcp)
Where: kazma mcp Docs - Shipped
Spoken replies (text-to-speech) and speech input; click-to-play in web chat
Where: Settings → Voice Docs - Opt-in
- Shipped
English and Arabic interface, full right-to-left layout; your words, the model's replies, names and server diagnostics are shown as written, each paragraph in its own language's direction (English left to right, Arabic right to left) in either interface
Where: Every page, the login page included Docs
Models
Bring the model you trust — a cloud provider, or one that runs on your own machine.
- Shipped
20 provider presets: OpenAI, DeepSeek, Groq, xAI, OpenRouter, Mistral, Together, Fireworks, Perplexity, Cohere, AI21, NVIDIA and Z.AI (OpenAI-compatible); native Anthropic, Google Gemini (incl. Vertex), Azure OpenAI and AWS Bedrock; and any custom OpenAI-compatible endpoint
Where: Settings → Providers Docs - Shipped
Local models through Ollama and LM Studio
Where: Settings → Providers Docs - Shipped
A provider's Test sends a real completion, not just a ping
Where: Settings → Providers - Shipped
Best model per task for multi-agent workers; image questions go to a vision-capable model
Where: models/selection.py - Shipped
When a model fails over to another, you are told (page + banner)
Where: observability/model_fallback.py - Shipped
Token and cost per answer; a cost breaker that halts runaway spending
Where: Chat footer, dashboard
Safety and control
Nothing risky happens without you, and untrusted text is treated as data.
- Shipped
Dangerous actions wait for your approval — on chat, multi-agent and pipeline paths alike; unclassified tools are gated by default
Where: Threat model Docs - Shipped
Plans checked against memory before they act: a reminder date is anchored to what you said, not what the model guessed; catastrophic shell commands are refused before the approval card
Where: Commitment layer Docs - Shipped
Web pages, search results, documents and recalled memory are fenced as untrusted data; the effect is measured on a public benchmark
Where: Prompt injection: the numbers Docs - Shipped
Secrets in an encrypted vault (AES-256-GCM); never passed to programs a tool starts; masked on every screen and API
Where: security/vault.py - Shipped
Protections against server-side request forgery, cross-site requests, and request floods
Where: security/ssrf.py, csrf.py, rate_limit.py - Shipped
Login by secret, local users or OIDC single sign-on; admin, operator and viewer roles
Where: /login Docs - Partial
Several users or teams on one install
built for one trusted operator; multi-user separation is enforced for memory and chats, not audited end to end
- Opt-in
Code the agent runs in an isolated container
Docker (KAZMA_CODE_EXEC_DOCKER=force) or E2B
Where: tools/code_exec.py
Memory
It remembers what matters, shows you what it used, and forgets what you tell it to.
- Shipped
Remembers conversations and the facts in them, across chats, with when each fact became true
Where: Memory Docs - Shipped
Recall by evidence: a memory is used only when it matches the question well enough — nothing when nothing does
Where: memory/recall.py - Shipped
Every answer shows which memories it used
Where: Chat activity: "Memory used" - Shipped
"About me": a short text you write, read at the start of every reply
Where: Settings → Memory - Shipped
Weekly topic summaries of long threads
Where: Memory page - Shipped
Forget one memory or a whole chat; keep a chat out of memory; export everything
Where: Chat menu → Memory…, Memory page - Shipped
Works in Arabic and English, Gulf dialect included
Where: memory/query_terms.py - Shipped
Nothing lost by accident: archiving never erases a memory's text
Where: memory/macro_sleep.py - Partial
Shared memory between installs through Postgres
memories and facts mirror; each install keeps its own vectors and graph
Knowledge and documents
Give it your files and sites; it reads, searches, converts and writes documents — Arabic included.
- Shipped
Knowledge Library: add files, web pages or whole sites; search by keywords and by meaning; Arabic-aware
Where: /knowledge Docs - Shipped
Documents: safe upload (quarantine, file-type checks, macro rejection), text and OCR from PDF, Word, Excel and PowerPoint, Arabic included
Where: /documents Docs - Opt-in
Virus scanning of uploads
needs ClamAV installed
Where: documents/malware.py - Shipped
Convert, split, merge and redact documents; generate reports as Word, PDF or HTML with correct Arabic typography
Where: /documents Docs - Shipped
Deep web research with sources: search, read, crawl, summarize
Where: /research Docs - Shipped
Web search through SearXNG (self-hosted metasearch, in the Docker setup)
Where: tools/web_search.py - Opt-in
Reading hard pages through Firecrawl, Jina or a real browser
keys / Playwright
Where: tools/read_url.py - Opt-in
Scraping through a rotating residential proxy
Where: Settings → System → Proxy - Shipped
Image generation (Pollinations with no key; DALL-E, Stability, Flux with keys) and image understanding
Where: tools/image_gen.py
Work on code
An editor, git and GitHub — and every write goes through your approval.
- Shipped
Web IDE: browse, edit, patch, run, git — every write through the approval gate
Where: /ide Docs - Shipped
Clone and switch repositories; the agent always works in the active one
Where: /workspace - Shipped
GitHub: branches, commits, pull requests, through a GitHub App or a token
Where: git_github_manager skill - Shipped
Code search across the repository (ripgrep plus symbols)
Where: kazma_core/code_index - Shipped
Steer a running task (/steer), abort it, plan first (/plan), long missions (/long)
Where: Chat commands Docs - Shipped
Rewind or branch a conversation from any earlier step
Where: /replay, /fork Docs
Many agents at once
Split a job across workers that are created when needed and watched while they run.
- Shipped
Six ways to run workers: dispatch, broadcast, pipeline (with approval checkpoints), fan-out with voting, consult, conditional
Where: /swarm, kazma swarm Docs - Shipped
Workers created on demand from templates — none need registering first
Where: swarm/autoscaler.py - Shipped
Circuit breakers, retries, timeouts and output checks per worker
Where: swarm/reliability.py - Opt-in
Durable multi-step runs through Temporal
Where: swarm/durable_temporal.py
How the six patterns flow
Six ways to split work across workers — pick one to see how it flows.
Fan-Out & Voting
Parallel ConsensusDispatches identical or partitioned tasks across multiple isolated workers simultaneously, aggregating outputs via weighted voting or consensus deduplication.
Execution Flow Nodes
Automation and connected accounts
Mail, calendars, reminders and posts — handled in the chat where you asked.
- Shipped
Reminders and scheduled tasks, delivered to the chat you asked from
Where: /scheduled - Shipped
X (Twitter): drafts, schedule, post through the official API, reply to mentions
Where: /x Docs - Shipped
Email (Gmail, Outlook) and calendar (Google, Microsoft)
Where: Settings → Email Docs - Shipped
More than one mail account (several Gmail, Outlook or IMAP), each with its own calendar, named in chat by name or address
Where: Settings → Email → Other accounts Docs - Shipped
Skills from the open agentskills.io ecosystem: search, install from GitHub, signed and verified
Where: /skills Docs - Shipped
MCP tools from any MCP server (stdio, SSE, streamable HTTP)
Where: /mcp Docs
Running it
Built to be run for months: it restarts itself, backs itself up, and tells you what happened.
- Shipped
A supervisor that restarts on real failure, reloads gracefully and pages you over Telegram
Where: scripts/service/kazma_guard.py - Shipped
One status card per restart: how long Kazma was down and whether each chat app connected (start and stop messages are optional)
Where: Settings → Adapters & Routes → Server status messages Docs - Shipped
Backups of everything every 6 hours, snapshotted locally and offsite (restic), checked daily, with a weekly restore rehearsal of the database
Where: Disaster recovery Docs - Shipped
Move an install to another machine or OS in one bundle
Where: kazma migrate Docs - Shipped
Back up your settings to a file and restore them: you see what will change first, the keys you have are never replaced, a lost key comes back from the vault without typing it, and the restore can be undone
Where: Settings → System Docs - Shipped
Health checks that make a real round trip; alerts to Telegram, Discord or Slack; a daily digest and a weekly resilience report
Where: /health/deep - Shipped
Old chat step history pruned on a schedule you set
Where: Settings → System - Shipped
Postgres for settings, chats, tasks and checkpoints; SQLite with no setup
Where: Postgres Docs - Shipped / Opt-in
Prometheus metrics; OpenTelemetry and Langfuse traces
Where: /metrics Docs - Shipped
Updates in one command: on a supervised install it waits for the chats to go quiet, stops Kazma, installs and starts it again
Where: kazma update Docs - Opt-in
Fault injection to test retries and failover: slow or failing model calls, tool calls and reply saves (other targets have no injection point yet); off unless enabled
Where: KAZMA_CHAOS_ENABLED Docs
Not built
People ask for these; they aren't there. Listed so you don't have to look.
- Not built
A paid bug bounty (responsible disclosure only — SECURITY.md).
- Not built
Cryptographic trust tiers for skills beyond HMAC verification, and signed delegation between agents.
- Not built
A hardening check that runs at startup: kazma-security.yaml is read by no code; the hardening report runs on demand.
- Not built
A security audit of multi-tenant, internet-facing deployments. Kazma is built for one trusted operator.