Vani Code (Preview)
Vani Code is a coding agent in your editor, backed by the Vani API. Ask it to explain code, fix a bug or
make a change. It reads your files, proposes edits you can review as diffs, and runs commands
with your approval.
Preview. Version 0.1.0 is an early release. Expect rough edges, and please report what you
find.
Getting started
- Open the Vani Code view from the Activity Bar (or press
Cmd+Alt+V / Ctrl+Alt+V).
- Choose Paste API key (or run Vani: Sign in with API key). VS Code asks for your Vani API
key in a password box. Don't have one? Choose
Get an API key to open your Vani account's API keys page.
- Type a message and press Enter.
Your key is kept in VS Code's secret storage (your operating system's keychain). It's never stored
in settings or files, never shown in the chat panel, and sent only to the Vani API. Sign out
removes it.
Choosing a model
The model picker lists the models your Vani plan includes. Where a model supports it you can also
pick a thinking effort, and turn on Fast for models with a fast variant (it uses more of your
allowance). The usage gauge shows how much of your allowance you've used and when it resets;
View usage opens your usage page in Vani.
Modes and approvals
Vani never changes a file or runs a command without your say-so, unless you've chosen a mode or
setting that allows it.
| Mode |
Reading files |
Editing files |
Running commands |
| Ask (default) |
Yes |
Shows a diff; you accept or reject each change |
Asks every time, unless the command is on your allowlist |
| Accept edits |
Yes |
Applied right away and listed in the chat (use Rewind to undo) |
Asks every time, unless the command is on your allowlist |
| Plan |
Yes |
No |
No. Vani investigates and proposes a plan, which you can approve to start working |
Some files always ask before an edit, even in Accept edits: for example .vscode/, CI workflows,
Git hooks, .env files, node_modules/, and configs that tools load on their own (ESLint,
Prettier, tsconfig.json, test and bundler configs). Vani never writes inside .git/.
Reading a file that may contain secrets (such as .env or private keys) asks first, because its
contents would be sent to Vani.
Accept edits: edits apply without asking. Tools you have running, such as tests, linters and
watchers, may run the edited code.
Commands
When Vani wants to run a command, you see the exact command, the folder it runs in and its time
limit. Choose Allow once, Reject, or, for common read-only and test commands, Always
allow that command prefix. Always-allowed prefixes are saved in the vani.terminal.allowlist
setting, which you can edit at any time.
Commands run on your computer with your permissions. Vani doesn't sandbox them. Approve only
commands you understand. Allowing a test or build command (like npm test) lets Vani run code
in your project, including code it just edited.
No folder open
With no folder open, Vani is a plain chat: it has no file or command tools.
Untrusted folders
In a folder you haven't trusted (VS Code's Restricted Mode), Vani can read but not change files,
run commands or fetch web pages. Trust the folder to unlock them.
Context: mentions, selection and attachments
- Type
@ to mention a file or folder in your workspace. Mentioned files are sent with your
message. Files that may hold secrets are marked with a warning.
- The current file and your selection appear as chips above the box; remove a chip to leave it
out. A selection from a file that may hold secrets starts out removed. Add it back if you want
to send it.
- Attach files by picking, dragging or pasting them: images, PDF, Word, text, Markdown, CSV,
audio and video, up to 20 per message and 95 MB each (or less, depending on your plan).
Text, Markdown and CSV files up to 50,000 characters are sent inside your message; other
attachments are uploaded to Vani. Either way their contents go to Vani.
Web pages
Vani can fetch a web page when it helps answer you. Each fetch shows you the full address and
asks first. You can choose Allow domain to let Vani fetch from that exact site without
asking, except for addresses that look like they carry data, which always ask. Allowed sites are
saved in vani.webFetch.allowedDomains.
Fetches are https only, read text pages only (anything past 2 MB is cut off), follow redirects
only within the same site, send no cookies or credentials, and never reach your own computer or
private networks. Vani makes at most 20 fetches per message. Pages Vani used are listed under the
answer as Sources.
By default Vani connects to websites directly, so web fetches fail on networks that allow only
proxied traffic. To use your proxy (http.proxy, or HTTPS_PROXY), turn on
vani.webFetch.useProxy. Fetches through a proxy are labelled "via proxy". Vani then can't check
where an address actually leads, so a site name that resolves to a service inside your network
becomes reachable through the proxy.
Progress, history and rewind
- During a longer task Vani keeps a Plan checklist up to date. Each step it takes is shown
with how long it took.
- Your chats are saved per workspace in VS Code's storage for this extension, outside your
project folder, so they're never committed. Open a past chat from History and carry on.
Text that came from files marked as possibly holding secrets isn't saved, and anything that
looks like an API key is masked. Each chat keeps up to 10 MB and each workspace up to 200 MB
(chats and rewind snapshots together); the oldest chats are dropped first. Delete a chat, or
clear the whole history, at any time.
- Rewind takes the chat, the files Vani edited, or both back to an earlier message. It
restores only files changed by Vani's edits, not the effects of commands.
Status bar
The Vani item in the status bar shows whether you're signed in, connecting or offline, and
which model is selected. Click it to sign in, retry the connection or open the chat.
Keyboard shortcuts
| Action |
macOS |
Windows / Linux |
| Open the Vani chat |
Cmd+Alt+V |
Ctrl+Alt+V |
| New chat |
Cmd+Alt+N |
Ctrl+Alt+N |
| Stop |
Cmd+Alt+. |
Ctrl+Alt+. |
| Show history |
Cmd+Alt+Y |
Ctrl+Alt+Y |
No default shortcut approves a prompt or accepts an edit.
Settings
Open them with Vani: Open Settings. These are user settings only. A project's own
.vscode/settings.json can't change them.
| Setting |
Default |
What it does |
vani.defaultModel |
empty |
The model new chats start with, e.g. anthropic/claude-sonnet-5.5. Empty uses the last model you picked; an unknown or unavailable model is ignored |
vani.defaultEffort |
empty |
The thinking effort new chats start with (low to max). Empty uses the last effort you picked; an effort the model doesn't support is ignored |
vani.terminal.allowlist |
empty |
Command prefixes that run without asking |
vani.terminal.maxTimeoutSeconds |
600 |
The longest a command may run |
vani.agent.maxSteps |
25 |
Steps per message before Vani pauses and asks to continue |
vani.agent.protectedPaths |
empty |
Extra file patterns whose edits always ask |
vani.webFetch.allowedDomains |
empty |
Sites Vani may fetch without asking |
vani.webFetch.useProxy |
off |
Fetch web pages through your configured proxy |
Privacy and security
- What is sent to Vani: your messages, plus the files, selections, attachments, command output
and web pages that you or Vani bring into the chat. They're processed by Vani and the AI model
provider you picked. Nothing else is sent, and there's no telemetry.
- Your API key stays in secret storage and is sent only to the Vani API. On Linux without a
keyring, VS Code may store secrets with weaker protection.
- Content is untrusted. Text in files, command output, attachments and web pages can't approve
anything or change your mode or settings. Only your own actions can: clicks in the Vani panel,
or Accept and Reject in the diff editor.
- Saved chats stay on this computer. They can still hold secrets Vani didn't recognise (for
example, in command output or quoted in an answer). Delete them when you no longer need them.
- Commands aren't sandboxed (see Commands).
Requirements
- VS Code 1.93 or later. It should also work in VS Code-compatible editors that support this
version, but it has been tested on VS Code.
- A Vani account and API key.
License
Proprietary. See the LICENSE file included with the extension.