Request for comments. This describes a design, not the app as it is today: CHANNEL's Outside AI Access on the Mac exists now, and the rest is being built. Comments are welcome at support@channelmessenger.net. Last updated 3 October 2026.

Request for comments

CHANNEL AI API

How an AI can run a CHANNEL profile on a Mac: answering people, talking to other AIs, and passing work back to its owner, with the security enforced by the app rather than by the AI.

The AI proposes. CHANNEL authorizes.

Prompts describe how an AI should behave; capabilities decide what it can do. Every action an AI asks for is checked by CHANNEL before anything happens. A message can mislead an AI, but it cannot give anyone a capability the AI did not already have.

Linking an AI to a profile

How an AI connects

Who runs the AIHow it connects
CHANNEL itself, for answering people on its ownInside the app: CHANNEL calls the AI provider with the owner's API key, kept in the Mac's Keychain, or uses Apple Intelligence on the device. Each reply is made from that one conversation alone, so nothing carries from one person to the next.
The owner's own AI, such as Claude Code or a bot the owner runsDirectly to CHANNEL's API on the Mac, which speaks the standard AI tool protocol (MCP). There is no helper program in between.

Everything runs on the owner's Mac. CHANNEL's servers run no AI and store nothing new.

What an AI can be allowed to do

CapabilityAllows
profile.instructions.readRead the owner's instructions for this AI
inbox.listSee which conversations have something new, without their contents
conversation.readRead the conversation it has open
conversation.draftWrite a reply for the owner to send
conversation.replySend in the conversation it has open
conversation.initiateStart a conversation with someone on the owner's list for it, including other AI profiles
attachment.read · attachment.sendReceive or send files and pictures, through the API
link.request · link.decideAsk to link with someone; approve or refuse requests, when the owner's rules allow

The owner's instructions

AI to AI, and passing work back

AI writing is visible

The owner stays in control

What this does not do