Research with sources
Search runs through Brave Search. Numbered citations open the source, and they point only to pages Nawa actually read.
Everything turns around a nucleus.
In Arabic, the nucleus is نواة, nawa.
The core your work turns around.
A desktop assistant for Windows that works with the language model of your choice.
What it does
You chat with Nawa, and it can research on the web, build and run applications in a workspace of its own, drive a browser, control the desktop through plugins, and review code changes, while you decide what it may do without asking.
Search runs through Brave Search. Numbered citations open the source, and they point only to pages Nawa actually read.
The coder writes the app in a workspace of its own, runs its tests and clicks through it in a real browser before calling it ready. Open it in the drawer and keep it in Artifacts.
A built-in headless Chromium for its own work, and Chrome control, which opens a Chrome window with a persistent profile so you sign in to sites once.
The Desktop Control plugin lists windows and their controls, acts on Windows applications, and checks the result.
A project links chats to a real folder. Coding changes are saved as Git checkpoints, so you can ask to undo a particular change.
The files a chat changed are listed in one place, and their diffs open in the drawer beside the conversation.
Schedule recurring tasks, each approved by you and checked before it runs, and gather saved artifacts into dashboards.
Gmail, Google Calendar, Drive, Slack, GitHub, Notion and more, or any MCP server, local or remote, with a permission for each tool.
Memory you can read and approve, and context counted in tokens, never characters, with every compaction shown in the transcript.
@imageModels
Connect a cloud provider with its key, or point Nawa at a server on your own hardware. Each role can use a different model.
Connect a providerCloud
On your hardware
Add an OpenAI-compatible image server, such as Qwen-Image-2.1, and type @image to ask for a picture.
How it works
Every turn runs the same agentic loop, with real files, Git as the safety net, and the transcript as memory.
Nawa resolves the models, reads the AGENTS.md files that apply, and builds the tool list.
It builds the exact request, counts its tokens, and compacts older history if it would not fit.
Text and tool calls stream into the transcript as they arrive.
Every tool call is checked against the chat's permission mode; one that needs you pauses on a card.
Tools run in the sandbox and report exit codes, output and page elements back, until the model answers.
A turn ends on a verified answer, a real blocker or your Stop, never on a timer. Its transcript, commits and memory are kept.
Nawa owns the guarantees
Truthful observations and errors, stable identity, persistence, permissions, transactions, tool execution, validation, process lifecycle, and state consistency.
The model owns the decisions
Interpreting intent, planning, selecting tools, researching, coding, diagnosing, and adapting.
Instructions, agents and skills
Beyond what you type into a chat, three things shape how Nawa works: instruction files you write, the agents it delegates to, and the skills those agents pick up.
Instructions, agents and skillsAGENTS.md holds standing instructions in plain Markdown. Where a file lives decides what it governs, and the deepest one that applies wins.
%APPDATA%\Nawa\config\AGENTS.mdEvery chat and project on this profile
my-app\AGENTS.mdThat project and the agents it delegates to
my-app\reports\AGENTS.mdThat folder and everything under it
What you say in the chatOutranks any file
Changes apply from the next request. Nothing in an instruction file grants a permission.
For work that deserves a context of its own, Nawa delegates to an agent: a role with its own instructions, tools, model and effort. Five are built in.
Describe a role in a chat to create your own. Customising a built-in agent keeps the original, ready to restore.
A skill is a packaged procedure with its own steps, scripts and references. An agent picks one up when a task matches it, or when you name it.
Ask for one of your own, such as your monthly report. Plugins can bring skills too.
Safety
Pick a permission mode for each chat. When Nawa needs more, a card names the tool and the exact command, and waits for Allow once, Always allow or Deny. It never times out.
nawa-exec.exe under a low-integrity restricted token, on a private desktop.%APPDATA%\Nawa, with keys encrypted.Manual
Asks before every gated action.
Accept edits
Works freely inside the chat's workspace; asks before shell commands.
Plan
Reads, computes and researches; gated actions are denied.
Auto Default
Runs ordinary work; asks before risky actions such as destructive commands.
Bypass permissions
Runs gated actions; durable automation changes still ask.
Prompts, files and observations supplied to a cloud model or connected service are transmitted to that provider; local storage does not mean all processing stays on this computer.
Windows
One installer, no account, nothing else to install. Nawa brings its own engine, runtimes and sandbox.
For the current user, with a Start-menu shortcut. You connect a model provider; no Nawa account is needed.
It checks every six hours, downloads in the background, and keeps your settings, chats and artifacts.
Node.js, Git, ripgrep, a headless Chromium and the sandbox runner come with it.
Right-click files and choose Ask Nawa to open a compact prompt about them.
The taskbar icon shows how many finished chats you have not seen yet.
Nawa serves its own handbook, so it works offline and matches the version you run.
Make it yours
Nawa opens in Nawa Dark. Pick another under Settings → General → Theme template, and the whole app takes on its colours, surfaces and corners at once.
Appearance settingsNawa for Windows 10 and 11 is opening to early users a few at a time. Tell us a little about yourself, and we'll email you a download link when your place comes up.
You're on the list.
We'll email when your download is ready.
Until then, the handbook shows everything Nawa does.