General Information
The desktop application is the managed way to operate 404 on a supported machine. It provides an interface for selecting a browser profile, running the local engine, configuring host trust and routing, and handling available updates. A product build may include account or license activation. Check the current product offering for availability and terms.
The pieces it manages
| Component | Responsibility |
|---|---|
| Desktop app | Setup, controls, updates, host proxy and certificate trust integration. |
| STATIC | Local Rust proxy; receives supported browser traffic and creates the upstream HTTP/TLS connection using the selected profile. |
| Rose on Windows | Alpine-based WSL2 root filesystem with STATIC and the Linux eBPF packet path. WSL2 supplies the kernel. |
| Local control API | Engine readiness, CA status, profiles, and telemetry for local coordination. It is not the browser proxy listener. |
The browser must route through STATIC for supported modifications to apply. The app can manage that setting, but the destination still sees the public IP of your chosen network route. Signing into a personal account or sending identifying content can also identify the session.
Desktop or self-hosted CLI
Use the desktop path when you want the app to coordinate installation and host settings. Use the self-hosted CLI when you want to stage the releases, configure profiles, trust the generated CA, and route the browser yourself. The Windows CLI guide imports a distro named 404-cli; the documented desktop app uses 404. Those installations should not be mixed up during cleanup.
Where to go next
Read Features for the app surface, Before you install for the host changes, and Getting started for the first session. The deeper architecture describes where each component acts.