Your model, your rules, your tools.
All the AI in the app in one place, optional and off until you set it up: Claude with your own key or a model on your own machine, help where something fails, an AI that suggests until you let it act within rules you set, and an MCP endpoint for other AI tools such as Claude Code.

Fig. — The AI settings: a model on your own machine, what the AI may do, and the MCP endpoint.
Your own model, your own rules?Read the comic: an advisor from next door, a board of rules, and a visitor at the back door →What you can do
Claude, with your own key
Opus 5.5 by default; Sonnet 5.5, Fable 5.1 or Haiku 4.5 when quicker matters more. The key is encrypted on your computer, and the bill is your own.
Or a model of your own
Ollama, Docker Model Runner, LM Studio or any address that speaks the OpenAI API. The models come from its own list, and the app uses its name where it said Claude.
Test before you trust
A test says how fast the model answers and whether it can use tools. A small model answers quickly, but often beside the point; the settings say so.
Nothing far away without asking
An address beyond this computer and your own network needs https and a confirmation in a window of the app. A key goes only to the address it was saved for.
Help where it fails
A diagnosis for a container, an image, a volume or a failed build, with secrets left out, to copy into an issue or to talk about.
Suggest only, by default
The AI proposes a restart or a command; you click the button or press Enter. That is how the app starts, and how it stays until you change it.
Strict or balanced
Let it act: strict waits for your yes in the conversation every time, balanced does right away what your rules allow and asks for the rest.
Rules per kind of action
Start, stop, restart, pause, bring a project up, recreate a service: right away, ask first, or never. And machines where it never acts.
A label that says never
docker-client-mx.ai=never on a container keeps every AI away from it, also when it asks for its whole project.
Never the knives
Removing, prune, volumes, files and exec do not exist for the AI. The rules are checked in the app itself, not in the prompt.
Every action a notification
In the app with the question and the reason; to your phone only what happened and where, never words from the model.
An MCP endpoint
Claude Code and other MCP clients read your machines and containers, with a token and only from this computer. Acting waits for your yes.
Your own model
Ollama next door, no bill per question.
Choose a local model under Settings → AI: Ollama, Docker Model Runner and LM Studio are one click, the models come from the server itself, and a test tells you how fast it answers and whether it can call a tool. The Claude tabs, the help with a failed build and the palette then use that model. An address beyond your own network needs https and your confirmation in a window of the app, and a key for it goes nowhere else.
What the AI may do
Suggest only, until you decide otherwise.
Out of the box the AI suggests and you click, as it always did. Strict lets it act, but every action waits for your yes in the conversation. Balanced does right away what your rules allow, such as restarting a running container, and asks for the rest. It can start, stop, restart, pause and resume containers, recreate a compose service and bring a project up, nothing else. Text in a log or a Dockerfile is data to it, never an instruction, and every action becomes a notification.
MCP endpoint
Let Claude Code look at your containers.
Turn on the MCP endpoint and copy the configuration for Claude Code, or as JSON for another client. It listens on 127.0.0.1 only, wants a token that stays in the app, and refuses requests from a browser. Clients can list machines, containers, images and volumes, and read logs, inspect data and measurements, with secrets left out. If the AI may act, they can ask to as well, only on the machine the app is on, and the app asks you in a window first every time, unless you turn that off.

When a build fails
The step that broke, and why.
After a failed build from a folder, the build dialog offers a diagnosis — the Dockerfile, the end of the output and the checks of BuildKit, with build arguments and secrets left out — to copy, or a conversation that starts from it. The AI says which step failed and what to change; it changes and builds nothing itself.
All features