Ledge.sh: open-source Markdown notebook that runs code blocks locally or over ssh
Ledge.sh, shown on Show HN, is a Markdown notebook aimed at developers and DevOps. The idea is simple: write a note, press ⌘↩ on a code block, and its output streams in beneath the block. The code can run in your shell, in your project, on your machine, or on a server.
Shell blocks run in a persistent shell that belongs to the note, so a cd, an exported variable or an activated virtualenv carries into the next run. The frontmatter can set cwd: and env: to control where the note's shells start and what they carry. A norun flag on a fence removes the Run button, for a command you are quoting rather than running. The output panel also handles interactive prompts such as a sudo password or a [y/N] question.
The remote story is the centre of the pitch. Point Ledge at a machine over ssh and the notes live there: the server holds the files and runs the shells, and the app on your computer is only a window onto it. The server side is installed with a curl-to-sh one-liner shown on the page. Alternatively, add a host: line to a note's frontmatter and every run in that note happens over ssh on that host, while the note itself stays where it is. A confirm option makes Ledge show the code, name the machine and ask before running. Keys, agents, ~/.ssh/config and 2FA work as they do in a terminal. cwd and env travel with a remote run; profiles and secrets never do. Python, node and other interpreted blocks also run on the host, with a per-machine interpreter override in Settings.
Profiles are the way to keep secrets out of notes. A profile is a named file of environment variables kept outside the notes folder, for example ~/.config/ledge/profiles/deploy.env, a plain dotenv file readable only by you. A note carries only the profile's name. An env: line overrides a value for one note, and envFile: loads a project's own dotenv for anything that is not a secret.
Ledge also runs on iPhone and iPad, again as a window onto the same server. The phone holds no notes; it reads, edits and runs what is on the server. A ledge pair command prints on the server, and the phone signs in with a key made in the Secure Enclave that never leaves the device and can speak to Ledge and nothing else. Keys such as ^C, ^D, Escape and the arrows sit above the keyboard, so you can interrupt a command, quit a pager or move around in htop.
For AI agents, Ledge ships an MCP server. claude mcp add ledge -- ledge mcp connects Claude Code, and any MCP agent can read, search, create and edit notes through it. A prompt code block is itself runnable: ⌘↩ pipes it to the agent and the reply streams in beneath it. Templates carrying a prompt block can give every morning a one-keystroke briefing. Locking a note encrypts its body on disk behind a passphrase; agents never see it, sync services carry ciphertext, and reading it requires an unlock.
Notes are plain Markdown files in ordinary folders, so syncing is syncing a folder (iCloud Drive, Dropbox, git, Syncthing or whatever you already use), and there is no database on the side. Attaching a project folder turns its Markdown files into notes in place, running their blocks in the project; removing the folder from Ledge touches no files. A workspace that is a repo can commit and push every note with one run. ledge backup puts an encrypted copy of the notes in an S3-compatible bucket every hour.
The page also lists the notes-app basics. Python, Node, Ruby and PHP run out of the box; a redis block feeds redis-cli, pointed at staging or prod by the note's REDIS_URL; TypeScript uses a Bun runtime bundled with the app, so ts blocks run with nothing installed; adding an interpreter is one line in Settings. ⌘J opens today's note from a daily template with {{date}} and {{yesterday}} tokens. ⌘D and ⇧⌘D split the view left and right or top and bottom, with tabs per pane, and ⌘1 to ⌘9 switch workspaces, each with its own pane layout. Syntax hides away from the caret, pasting from a web page, Slack or Google Docs produces Markdown, ⌘P opens a note by title and # switches to full-text search, wikilinks address titles, and backlinks and an outline each get a panel. Inline #hashtags or a tags: line organise notes, favorites pin to the top of the sidebar, and deleted notes sit in a Trash section for 30 days. A command-line tool lists, reads, searches, creates and appends from any terminal, with results on stdout, conversation on stderr and a --json switch.
Ledge is free and open source under Apache-2.0, with no account required. The example notes on the landing page (signups, MRR, release notes) are demo content showing how it looks in use.
Key facts
- Ledge is a Markdown notebook for developers and DevOps: press ⌘↩ on a code block and the output streams in beneath it, locally or on a server.
- Shell blocks run in a persistent per-note shell; a host: line in the frontmatter sends every run in the note over ssh, and cwd and env travel with it but profiles and secrets never do.
- iPhone and iPad are windows onto the same server, which holds all notes; the phone signs in with a Secure Enclave key.
- Ledge ships an MCP server, so any MCP agent can read, search, create and edit notes; prompt blocks pipe to the agent with the same run key.
- Notes are plain files with no database, locked notes are encrypted on disk, and the project is free and open source under Apache-2.0 with no account required.
Why it matters
Ledge puts runnable code, its output and the prose around it in one Markdown file, and lets the same note run on your laptop or on a remote server. For people who keep runbooks, release checklists and debugging notes, that turns documentation into something executable. The MCP server and runnable prompt blocks also make the notes reachable by AI agents, while locked notes stay sealed from them.
Who it affects
The page targets developers and DevOps engineers, especially those who work on remote machines over ssh and want to read and run their runbooks from a phone. People who already sync Markdown folders with iCloud Drive, Dropbox, git or Syncthing can point Ledge at them. Teams using Claude Code or another MCP agent get a notes store the agent can read and edit.
How to use it
Write a note, put a command in a code block and press ⌘↩. For a remote machine, install the server with the curl one-liner shown on the page and point the app at it, or add a host: line to a note's frontmatter to run that note over ssh. Keep secrets in a profile file outside the notes folder and name the profile in the frontmatter. To connect Claude Code, run claude mcp add ledge -- ledge mcp. Ledge is free and open source under Apache-2.0, and no account is required.
How solid is it
The only source is the product's own landing page, so every capability described is a claim by Ledge rather than something independently tested. The page gives no release date or version for Ledge itself, no user numbers, benchmarks or reviews. Figures like signups and MRR on the page belong to demo notes, not to Ledge. The design choices, such as plain files, no database, open licence and keys that never leave the Secure Enclave, are concrete and checkable in the open-source code.
Risks and caveats
Running commands on a remote host from a notebook needs care: the page offers a confirm option that shows the code, names the machine and asks before running, and it is worth turning on for production hosts. The server is installed by piping a curl download into sh, as shown on the page. The page does not name a maintainer or company for Ledge, and it does not say which agents besides Claude Code have been tested with the MCP server. It also does not say which operating systems the desktop app supports, beyond mentioning iPhone and iPad and macOS-style shortcuts.
“Free and open source under Apache-2.0. No account required, and no database on the side.”
— Ledge landing page