Request Access →
Consus Launcher

Paste a key once. Every tool opens ready.

A small, open source desktop app for macOS and Windows. Click Claude Desktop, ChatGPT, Claude Code, Codex, or Pi, and it opens already set up for the Consus gateway, with the models your key can call.

macOS 12 or later, Apple silicon or Intel. Windows x64 or ARM64. You'll need a Consus API key from your admin.

Video: Consus Launcher opening ChatGPT, already set up with an ITAR model

How it works

One time. Then every tool is one click.

  1. 01 Open the portal Sign in the way you normally do, through your company's identity provider.
  2. 02 Create a key Name it after the machine and copy it. It's shown once.
  3. 03 Paste it in the Launcher It goes into the macOS Keychain or Windows Credential Manager. After that, every tool is one click.
The tools

Five tools, set up the right way.

Each tool is set up with the models your key can call, read from the gateway each time the Launcher starts. Your own setup is left alone, and signing out removes only what the Launcher wrote.

Tool How it opens Where its settings go
Claude Desktop The app, in gateway mode Its own gateway configuration. No Anthropic account needed.
ChatGPT The app, in Codex mode Merged into ~/.codex/config.toml, key by key.
Claude Code Terminal Its own profile. Your ~/.claude is never touched.
Codex CLI Terminal Its own profile, apart from ~/.codex.
Pi Terminal Its own profile. Your ~/.pi is never touched.

A tool that isn't installed links to its vendor. Consus never installs software.

What it does not do

A front door, not a gateway.

The Launcher writes each tool's settings and opens it. That's all. Your tools talk to the Consus gateway directly, and what a key can call is enforced there, not on the laptop.

It makes two kinds of request, both to Consus: the model list for your key, and a public file naming the newest release. The key itself is never written to a file.

  • No proxy and no TLS interception, ever
  • No enforcement, monitoring, or config repair
  • No analytics, telemetry, or crash reporting
  • No tray icon, autostart, or background process
  • No local database
  • No auto-update. New versions come from GitHub Releases
For IT admins

Push it with the MDM you already run.

Deploy the signed .pkg or .msi through Jamf, Intune, or Group Policy, then push org settings in a configuration profile (macOS) or the registry (Windows). The Portal's Launcher page writes the settings file for you from your choices.

Setting What it does
EndpointURL Where every tool sends requests, for example your own logging proxy. Default https://api.consus.io.
ComplianceLevel The level every tool is set up for: itar (default), fedramp-low, fedramp-moderate, fedramp-high, il2, il4, or il5, each optionally +itar.
Tools Which of the five tools people see. A tool left out has its Launcher settings removed.
OrgName Shown in the Launcher's header.
UpdateNotice Whether it says when a new version is out. Off by default on managed machines.

Hiding a tool is a convenience, not a control. What a key can call is enforced by the Consus gateway, from the policies in your Portal.

macOS bundle ID
io.consus.launcher
Apple Team ID
K4P2D65BQD
macOS signing
Developer ID, notarized by Apple
Windows signing
Microsoft Artifact Signing
Full admin guide, including PPPC permissions →
Install

Open source, signed, and built in public.

  • Apache-2.0. Read every line before you deploy it.
  • Release builds run only in public GitHub Actions, never on a laptop.
  • Every release ships CycloneDX SBOMs and SHA256SUMS.
  • Signed by Consus Industries, Inc. on macOS and Windows.
Download the .dmg, .pkg, or .msi →
macOS, from Terminal
$ curl -fsSL https://raw.githubusercontent.com/consusindustries/consus-launcher/main/install.sh | sh

# Downloads the latest release from GitHub, checks it against
# SHA256SUMS.txt, and installs only if the checksum matches.

Need a key?

Keys come from your Consus admin, in the Portal. Not a customer yet? Start here.