blog · Artikel auf Englisch
An open-source alternative to Claude Cowork — with local models
Cowork put an AI agent into a folder on your desktop, and it does that well. Snotra does the same as open source: any model, local ones included, no account, and nothing changes without asking. An honest comparison, including what Snotra can’t do yet.
In January, Anthropic moved an agent into a folder. Claude Cowork — at first a research preview for Max subscribers on the Mac, generally available on every paid plan for macOS and Windows since April — lets Claude work on the files in a folder you choose. It reads them, writes new ones, runs code in a sandbox and hands back a finished spreadsheet instead of a chat reply. Anthropic describes it as the architecture behind Claude Code, for people who don’t live in a terminal.
Snotra, the open-source desktop agent I have been building since May, starts from the same idea: the folder is the workspace, and the agent works inside it. It gets there with different choices — about models, about accounts, about when to ask. This article is about those choices, and it tries to be fair about where Cowork is simply ahead.
One note on the name: on September 16, Anthropic began merging Cowork and chat into a single Claude. Whatever the feature ends up being called, the comparison below is about the product.
What Cowork does well
If you already pay for Claude, Cowork is hard to beat on its own ground:
- The models. Cowork runs on Anthropic’s frontier models, and a folder agent is only as good as the model that decides what to open next.
- Finished documents. Spreadsheets with working formulas and slide decks come out directly. Office formats are an output of their own, not a conversion step.
- It keeps going without you. Scheduled tasks run in Anthropic’s cloud while your computer is off, and sessions carry over to the web and the phone apps, which are in beta.
- Isolation on every platform. Code runs in a Linux virtual machine on your computer or in a temporary sandbox on Anthropic’s infrastructure — on the Mac and on Windows alike.
- An ecosystem. Connectors, plugins, skills, sub-agents working in parallel, a built-in browser and computer use.
- Controls for companies. Role-based access, a compliance API, OpenTelemetry export, and a deployment mode that serves Claude through Amazon Bedrock, Google Cloud or Microsoft Foundry.
If those are the things you need, Cowork is the better tool, and nothing below is meant to talk you out of it.
Where the two differ
Side by side, as of September 2026:
| Claude Cowork | Snotra | |
|---|---|---|
| Source code | Proprietary | Open source, Apache 2.0 |
| Models | Claude only | OpenAI, Anthropic, Google, Ollama and any OpenAI-compatible server |
| Local models | Not supported | In the same list as the cloud models |
| Account | Anthropic account and a paid plan | None |
| Price | Paid plans; Pro is $20 a month | Free; you pay your model provider, or nothing for a local model |
| Platforms | macOS, Windows, Linux in beta; web and mobile | macOS (Apple Silicon), Windows (x64), Linux (x64) |
| Where code runs | A VM on your computer or a sandbox in Anthropic’s cloud | A sandbox on macOS and Linux; not isolated on Windows yet |
| Default | Manual approval | Asks before every change; commands off until you switch them on |
| Office files | Built in | Through a skill and a program on your machine |
| While you’re away | Scheduled tasks in the cloud | Nothing runs while the app is closed |
Any model, including the one on your laptop
Cowork uses Claude models. Organizations can serve those models through a cloud provider or a gateway of their own, but Anthropic’s documentation is clear that this path is meant for Claude; there is no supported way to plug in a model from another vendor or one running on your machine.
In Snotra, local and cloud models sit in one list, and you pick per conversation. Ollama gets its native API; LM Studio, MLX-LM, llama.cpp and vLLM come as templates of a generic OpenAI-compatible provider, which also reaches gateways like OpenRouter. The tools, the approval rules and the prompt stay the same whichever model answers.
For a folder agent, that choice matters more than for a chat. The agent’s job is to read your files, and with a cloud model every file it reads becomes part of a request to someone else’s server. With a local model, the folder stays on your disk. I wrote about what that asks of the harness in What local models taught me about my agent harness.
The honest counterpart: a model that fits on a laptop is not a frontier model. In my own measurements, an 8B model on Ollama got two of five tool calls right in the best of three setups. For hard, open-ended work you will still want a large model — and in Snotra that can be Claude as well, with your own API key.
No account, no subscription, no telemetry
Cowork needs an Anthropic account and a paid plan; the Free plan doesn’t include it. How much you get done depends on your plan’s usage limits, and Anthropic notes that Auto mode, which has a classifier check each action, uses those limits up faster.
Snotra has no account because there is no server to hold one. You bring an API key, stored with your operating system’s encryption, or a local model that needs none. Cloud models cost what your provider charges per token; a local model costs electricity and time. There is no telemetry, not even opt-in. At startup the app asks GitHub whether a newer version exists, and only speaks up if there is one.
Asking before it acts
Both tools ask before they act, and both let you stop the asking. The difference lies in the defaults, and in what a single click can’t switch off.
Cowork’s default is manual approval. An Auto mode lets a classifier decide what is safe, and a third mode skips approvals altogether. Permanently deleting files needs an explicit “Allow”.
Snotra’s default mode, Smart, lets the agent read without asking, and asks before every change and before any targeted access to a sensitive file — .env, keys, credentials. Overwriting a file puts a copy of the old version in the trash first. Running shell commands and Python is switched off as shipped. Once you switch it on, every single run gets its own card with the complete command or source, the shell, the working directory and whether it runs isolated. There is deliberately no “allow for this session”. You can let exactly one simple command line — git status, say — run without asking in one folder; the same command with a flag added asks again. Auto exists too, but you switch it on yourself, for one chat or for a folder you trust.
Neither approach makes an agent safe from what it reads. Anthropic says plainly that the chance of a prompt-injection attack is “still non-zero”, and advises against pointing Cowork at sensitive or financial files. The same advice holds for Snotra. What it adds is that text fetched from the web counts as material, not instruction, and every tool call after it goes through the approval again.
What Snotra doesn’t do yet
- No sandbox on Windows. On macOS and Linux, commands and Python run isolated: they write only inside the project folder and reach only the domains on the approval card. On Windows they run with your rights, and the card says “Not isolated” in amber. Cowork isolates on every platform.
- Unsigned builds. macOS and Windows warn on first launch until signing is done (#19).
- Apple Silicon only on the Mac; there is no Intel build.
- Text files only. Snotra’s own file tools read and write text. Word, Excel or PDF take a skill and a program on your machine that does the converting.
- Nothing in the background. No scheduled tasks, no cloud sessions, no phone app. When the app is closed, nothing runs.
- No browser control. The agent can search the web, with a Tavily key, and read a page’s text, but it doesn’t drive a browser or your screen.
- MCP over stdio only. Remote MCP servers over HTTP are still open (#341).
- One person, no company. Snotra is a personal open-source project, and interfaces and configuration can still change.
Other open-source options
Snotra isn’t the only answer to the search that may have brought you here. As of September 2026, going by their own repositories:
- OpenWork — a desktop Cowork alternative built on OpenCode, MIT-licensed at its core, with local models through Ollama or OpenAI-compatible servers.
- Eigent — a multi-agent “Cowork desktop” under Apache 2.0, with local models through vLLM, Ollama or LM Studio.
- AionUi — a desktop interface for command-line agents such as Claude Code and Codex, under Apache 2.0.
- Goose — the closest match to Snotra, and a good tool. It runs autonomously by default, where Snotra asks.
- Jan — local-first and open source. Its folder agent is in preview builds; the stable app is a chat client.
Open source, any model, MCP and skills are common ground among them by now. What sets Snotra apart is less the feature list than how carefully it acts inside your folder.
Which one to pick
Take Cowork if you already pay for Claude, want the strongest model on every task, need finished Office documents, or want work to carry on while your laptop is closed.
Take Snotra if you want to read the code of the thing that works in your folder, choose the model per conversation — a local one included — and do without an account or a subscription, with an agent that asks before it changes anything.
The two don’t exclude each other, either. Snotra runs Claude models just as well, with your own API key, billed per token instead of per month.
Trying it
Snotra is free and runs on macOS, Windows and Linux: download it here, or read the source on GitHub. The longer story of why it exists is in Why I built an open-source AI agent desktop.
If you come from Cowork, I’d like to hear what you miss. The Discussions are open for exactly that.