The limiter counts attempts by the key login:<email>. Bug in
APP-101
— the key is not normalized.
What the client gets
429 with a Retry-After, as in RFC 6585. The body gives no hint whether the account exists.
Open questions
Fixed 15-min window or sliding? Ask Oleg.
Do we need a captcha after 5 attempts — see APP-108
Git
Your branch tells it what you’re on
Add your repositories in Settings → Git. The branch is read from .git/HEAD: when its name carries a task id like APP-112, that task shows at the top of the window, and the PR state comes from your own gh or glab. No bindings, no plugins.
~/src/acme-webmain
$Switched to branch 'APP-112-flaky-sync-test'
mainWorking on APP-112PR #57 · in review
Flaky test in the sync suite
APP-112to do · in 3 days
PR #57 · in review
On a branch switch the task moves to In Progress by itself. That can be turned off in Settings → Git.
Keyboard
Every key does one thing, everywhere
Keys as in Vim: j and k through lists, d for done, g to go, y to copy. They follow the physical key, so they work in any keyboard layout, and any shortcut can be rebound. Press one.
Single letters act on the task under the cursor and only while you aren’t typing; Ctrl shortcuts work everywhere. On this site: Ctrl K or / searches, g g goes to the top.
Style
Bold style by default. Quiet when you want it
The bold style: fills, counters, colour for what’s urgent and key hints on screen. Quiet takes all that away: outlines instead of fills, colour only where it means something. Switch in Settings, no restart. Drag the divider.
No browser inside. The Linux AppImage carries its own Qt, nothing else to install.
0 services
Nothing in the background
Runs while its window or tray icon is open. Starting at login only if you turn it on.
MIT
Open source
Source, build and change history are on GitHub.
$0
Free
No paid tier, no trial, no account.
Your data
One file you can open in any editor
Offline
Tasks, meetings and notes live in one file, state.json. The network is used only for the update check and for what you connect yourself.
No sign-up
Download, open, work. No account, no email.
Read-only until you turn it on
By default nothing is written to your trackers. Status write-back is turned on per tracker: “Change the status in Jira when I move a card”. Before every write the task is checked again; if the tracker changed it meanwhile, nothing is sent. Titles, descriptions and comments are never written.
You can roll back
Scheduled backups (daily by default, the last 20 kept) and a time machine: hourly snapshots for two days, daily ones for a month.
Next to the file: a backups folder with the scheduled copies and a history folder with the time machine’s snapshots.
Tracker tokens are not in state.json. On Windows they go to the system credential store; the macOS and Linux builds keep them in a secrets.json next to it that only your user can read.
Notes export as a folder of Markdown files that Obsidian opens as-is, and import back from one.
Cards from a tracker also carry a local layer: your own notes, checklist, tags and dates. A sync never overwrites it.
What the app sends on its own
The complete list. If it isn’t here, Tabless doesn’t send it. No analytics. After a crash the app offers a report: you see all of it, choose what goes in, and send it yourself as a GitHub issue. The app never sends it on its own.
Update checkon start · off in Settings → About
Asks GitHub whether a newer version exists. Sends nothing about you or your data. Downloads the update only when you click Update, and checks it against the release’s checksums.
Trackersonly the ones you connect
Pull your tasks — by hand, or on a timer if you set one. A status is written back only where you turned write-back on.
Browser sign-inwhen you click Connect
Your browser opens the tracker’s own sign-in page; Tabless never sees your password.
Calendar linksonly if you subscribe
Downloads the .ics file at the link you added, every 15 minutes by default.
PR stateonly for repositories you add
Runs your own gh or glab about once a minute. Off in Settings → Git.
Mattermostonly if connected
Reads the people in your channels to offer them as @mentions. Posts nothing.
Pictures in notesonly when you click
Images from the web in a note load when you ask to show them.
Browser sign-in: GitHub, GitLab, Sentry, Jira, Trello, Todoist, Asana, ClickUp, Bitbucket. Gitea and Forgejo: a token, or browser sign-in through your own OAuth app. Redmine: an API key. Mattermost: a token or your login; the password itself is not stored.
FAQ
Questions
Is it free?
Yes. Open source under the MIT license, with no paid tier, no trial and no account.
Does it work offline?
Completely. Your data is a file on your disk. The network is needed only for the update check and for the trackers and calendars you connect yourself.
Can I use it on more than one machine?
Yes, by moving the data: export the profile to JSON and import it on the other machine — importing only adds and never overwrites a profile. Or copy state.json while the app is closed.
Can my team share a board?
No, it’s a personal workspace. Shared work stays in your team’s tracker: issues are pulled in, and by default nothing is written back. Status write-back is turned on per tracker; it exists for GitHub, GitLab, Gitea, Forgejo and Jira.
Can I bring my Obsidian notes?
Yes. Notes import from a folder of .md files (you see what comes in first) and export to a new folder. [[wiki-links]] stay as they are; the .obsidian folder is skipped.
Which languages does the app speak?
English and Russian, switchable in Settings.
Download Tabless
Free and open source under MIT. For Windows, macOS and Linux.