SuperGPT local mirror
SuperGPT is a source-only, OpenAI-signed local mirror.
The target installer makes a byte-identical copy of the user's current official ChatGPT app, then launches it with an external Luma Cloud model provider. The dashboard DMG is not public-ready yet.
Target customer journey
These are the intended release steps. While the DMG remains source-only, customers should not use repository builds or unpublished artifact URLs.
Local mirror prerequisites
The official app, shared Codex state and Luma device credential each retain a separate authority.
Delivery model
One helper DMG, one untouched official source, one changed model provider.
The DMG carries only Luma-owned external helpers. The signed application is always copied locally from the user's verified official installation.
Helper DMG
Public download unavailable
The target generic macOS DMG is honestly ad-hoc signed and requires explicit approval of the exact helper. It contains only the installer, external launcher and Doctor—no ChatGPT app copy, customer credential or user state.
Local signed mirror
/Applications/ChatGPT.app → ~/Applications/SuperGPT.app
The installer makes a byte-identical local copy of the current official app. It does not patch, rename internally or re-sign the bundle.
External provider
https://api.lumaos.cloud/v1
An external launcher applies a command-scoped Luma Cloud provider to the copied stock Codex. The official app keeps its official route.
Boundary
What the local mirror owns and what stays stock.
All Luma-owned behavior stays outside the signed bundle. Shared Codex state remains shared, Electron state remains separate, and the official app stays on OpenAI's route.
OpenAI-signed mirror
External launcher
Shared Codex Home
Separate Electron state
Device credential
Hash-verified helpers
Redacted local evidence
macOS safety
Doctor keeps the mirror current without mutating either signed app.
Source acceptance is signature- and identity-based rather than version-based. Every copy and swap is staged, verified and recoverable.
Source
Copy
Official app
OS trust
Doctor
Rollback
Uninstall
Acceptance boundary
Verify the signed mirror, shared state, bounded Luma features and automatic recovery.
A clean-Mac run must prove every boundary below. Opening a local window or passing source-only tests does not make the dashboard DMG public-ready.
Byte-identical signature
External Luma provider
Shared and separate state
Remote Control blocked
Luma Usage; Dictation gated
Automatic Doctor
Troubleshooting
Stop safely, collect evidence, then escalate.
Treat source verification, OS trust, provider, shared-state, Remote and Doctor failures as release findings. Preserve the official app, shared ~/.codex and last-known-good mirror.
DMG is unavailable
This is expected while the release is source-only. Do not construct, reuse or share an unpublished artifact URL.
Browser sign-in expires or is rejected
Return to SuperGPT and choose its built-in Sign in action again, then complete Google or email-code sign-in on the Luma Cloud page. Never put activation JSON, device tokens or recovery keys in a support message or command line.
Official source is rejected
Install the current official ChatGPT app from OpenAI and retry. Do not modify, re-sign or bypass verification of either app.
Luma inference fails
Capture the visible request id and sanitized launch receipt. Do not substitute a localhost or private upstream URL, and do not alter the official app route.
Remote Control is unavailable
This source-only SuperGPT contour closes Remote Control routes until they receive an explicit reviewed Luma desktop contract. The official ChatGPT app may remain open.
Dictation is unavailable
This is expected until the Gateway subscription-entitlement admission is deployed, a bounded included-key device canary passes, transcription traffic is enabled and the exact user-approved helper DMG passes clean-Mac E2E. Only the current canonical included SuperGPT key of an active subscription qualifies, through its device bearer or the explicitly selected Recovery Key path. API Wallet, portable, legacy, and other-product keys cannot qualify; do not add desktop billing logic or redirect audio to official OpenAI services.
Doctor reports blocked
Keep using the last-known-good mirror while the current official app or provider seam is unsafe. A failed recopy must roll back without touching the official app or shared ~/.codex.
Remove SuperGPT
Close SuperGPT and copy the safe uninstall command from the dashboard. It revokes the paired device when reachable and deletes its local Keychain/profile state. Never delete shared ~/.codex; it belongs to both official ChatGPT and SuperGPT.
Wrong endpoint in a client
Use https://api.lumaos.cloud/v1. Do not paste localhost, shard, VPS, or OmniRoute URLs into customer tools.
Support request
Send OS, architecture, ChatGPT source version, mirror receipt, Doctor state, visible request id and sanitized logs. Do not send API tokens, cookies or auth files.
Truth gate
The current helper DMG is source-only and must not be presented as working public software.
Do not publish repository builds, helper commands, packages, ZIPs or executables merely because a route or file exists.
Public readiness requires an immutable helper candidate, checksum and dashboard metadata plus clean-Mac proof of byte identity, OpenAI signature, device pairing/revocation, Product DB subscription-only Luma Dictation, truthful Usage, Doctor recopy and rollback. Remote Control remains explicitly unavailable behind a separate future feature gate.
Related setup docs
Use these when a user needs an external CLI or IDE key instead of the source-only SuperGPT desktop path.
Reviewing the source-only local mirror?
Preserve the official app and shared ~/.codex, use only the immutable candidate under review, and include sanitized mirror and Doctor receipts with any finding.
