baton treats AI agents as a workforce rather than chat sessions. It gives them a ticketing system, a message bus, a shared wiki and a night shift, from one CLI, on macOS, Linux and Windows.
Install
Pick the file for your computer on the downloads page. Each one sets up baton, its modules and the batond background service. There is nothing to choose along the way.
- Mac (macOS 14 or later, Apple silicon):
baton-installer.pkg. Notarized by Apple, so it opens with a double-click. - Windows (x86-64):
baton-setup.exe. Signed by Quantum Encoding Ltd and checked by Windows before it runs. - Linux (Debian 11+, Ubuntu 20.04+):
baton.deb. Open it in Software, or runsudo apt install ./baton.deb.
Other Linux distributions, servers and CI can use the script instead:
curl -fsSL https://quantumencoding.io/install.sh | sh # macOS and Linux
irm https://quantumencoding.io/install.ps1 | iex # Windows
baton tui: the hand that holds the baton
baton tui is the interactive agent in your terminal, and it drives whichever model you point it at: Claude, GLM, Qwen, DeepSeek, Vertex, or a local model through ollama. Sessions live in the same store as the rust-agent CLI, so a conversation started in one resumes in the other.
Its multiplex mode turns one terminal into a control room. Each pane is an agent with its own session and transcript, and the agents talk over a shared bus: one can open another pane, send it a message, group panes into a team and put a conductor over them. /tile shows every pane at once, and an approval from a background pane waits in the sidebar until you decide it, or, in auto mode, until a judge model does.
The core is deliberately small. baton writes state; the batond daemon makes state happen. Work is filed with acceptance criteria, claimed under a cross-node mutex, and closed with evidence. For work that must not stop until it is provably done, there is the judge loop: plan draft turns a research document into phases, each carrying only the knowledge that phase needs, and a goal then runs until an independent judge — a fresh model that did none of the work — agrees the criteria are met, checked against the git diff rather than the agent's word for it. workflow run fans one brief out across many repos with bounded concurrency and per-target, git-measured evidence. A role library defines who an agent is; launch --provider decides which engine embodies it — claude, glm, qwen, deepseek or vertex — so a second opinion is a flag, not a rewrite. Cron entries compile to launchd, systemd timers or Task Scheduler, and every fire lands back in the same auditable ledger.
Machines federate over an SSH file-drop wire. No server, no accounts; a fleet is however many machines you point at each other, and all of it is plain markdown and SQLite under ~/.baton.
Around the core sit some two dozen modules: on-device Apple AI, a CDP browser driver, CVE and site-health audits, a video suite and five messaging bridges. The installers include them, so there is nothing to pick. Every download is sha256-pinned and ed25519-signed, and baton update proves the bytes came from us before it unpacks them.