How It Works
Transcodes is an AI onboarding manual for a team. You create one Persona in the desktop app, then apply that same bundle to Claude Code, Cursor, Codex, and Antigravity.
A Persona is an Instruction, focused Rules, repeatable Skills, and a Knowledge Base. Versioning publishes a numbered revision to the organization. Each teammate downloads that revision and applies it on their own device.
⚡ 6 min readOn Windows, please run the installer as administrator
Supports Windows 10 and later
The Windows installer is x64 and supports Windows 10 and later. Run it as administrator.
Optional: authentication and action governance
Hosted sign-in, RBAC, and step-up are separate from creating a Persona. Use them when a person must prove permission before a sensitive action. AI Agent (MCP) installation is Coming Soon.
| Who | Passkey login (no passwords) |
| What | RBAC per resource:action — deny / allow / allow + step-up |
| Proof | Biometric step-up before dangerous actions |
| Record | Step-up MFA, SDK events, and guard outcomes in audit log |
The browser SDK is the path available today.
AI Agent (MCP)
| Path | For | Status |
|---|---|---|
| A | Guard risky shell / MCP calls | Coming Soon |
The three actors
| Actor | Surface |
|---|---|
| End user | Transcodes Auth — login, manage passkeys |
| Operator | Desktop app — roles, tokens, RBAC matrix |
| Human approver | Transcodes Auth — step-up before risky actions |
| AI agent | MCP in IDE — same RBAC as the token holder |
Login, step-up, and credential management share Transcodes Auth (sign-in · step-up · console). Your app redirects with ?sid=…; no embedded auth UI.
Login
SDK: redirectToSignIn({ redirectUri }) → handleSignInCallback() on return. Private keys stay on device; the server stores only public keys.
Step-up
Already logged in, but the action is dangerous — prove it again with biometrics (delete member, change roles, AI calling retire_member).
SDK: redirectToStepUp({ resource, action }). Session TTL: 10 minutes. Full guide: Step-up Auth.
RBAC
| Level | Meaning |
|---|---|
| 0 | Deny |
| 1 | Allow |
| 2 | Allow + step-up |
Resources (members, roles, …) × actions (create, read, update, delete). Same matrix for SDK and MCP — backend is the authority. See RBAC.
AI agents
The agent acts as the member in its token. Read/list operations proceed; tier-2 actions are blocked until a human completes step-up.
Manage credentials directly in the Transcodes desktop app. Never paste credentials into chat.
Auth methods
Passkey (primary) · TOTP · hardware key · email OTP · passcode (recovery). Register at least two methods per member.
What you still own
| Transcodes | You |
|---|---|
| WebAuthn, hosted auth page, JWT issuance | App UI and business logic |
| RBAC storage & enforcement | Role/resource setup in the desktop app |
| Audit log storage | Optional trackUserAction from your app |
| AI Agent (MCP) — Coming Soon | Host plugin install is not available yet |
Transcodes is not a full app-security platform — you still own CSP, XSS prevention, and HTTPS.