Threadmark is an installed, local-first note app built with Tauri 2, React,
TypeScript, Rust, and SQLite. This prototype supports notes, tags, [[wiki links]], backlinks, search, and snapshot synchronization through the private
Google Drive appDataFolder.
Prerequisites:
- Node.js 22 and npm
- Rust stable
- The Tauri 2 prerequisites for your operating system
Install and validate the project:
npm install
npm run build
cargo test --manifest-path src-tauri/core/Cargo.tomlRun the installed desktop application:
npm run devDo not open the Vite URL directly in a browser. Notes use Tauri IPC and SQLite, which are only available in the native application window.
Notes are stored in threadmark.sqlite3 under the operating system's Tauri
application-data directory for com.threadmark.notes.
- Create a project in Google Cloud Console.
- Configure the OAuth consent screen and add test users while the app remains in testing.
- Enable the Google Drive API.
- Create a Web application OAuth client for desktop. Add
http://localhostas an authorized redirect URI; the plugin selects a free local port for the callback. - Copy
.env.exampleto.envand enter the web client ID and secret. Never commit.env. An installed desktop application cannot keep this embedded client secret confidential.
The requested Drive scope is
https://www.googleapis.com/auth/drive.appdata. Threadmark can only access its
own hidden application-data files, not the user's normal Drive documents.
Authentication opens in the system browser on desktop.
Install the Windows Tauri prerequisites, then build on Windows:
npm install
npm run tauri buildTauri writes the installer artifacts under src-tauri/target/release/bundle.
Windows packaging must be performed on Windows.
Install Android Studio, the Android SDK, NDK, command-line tools, and the Rust Android targets described by the Tauri prerequisites. Initialize the generated Android project once:
npm run tauri android initIn Google Cloud Console, create an Android OAuth client with package name
com.threadmark.notes and the SHA-1 fingerprint of the signing key. Keep the
Web client configured in .env; the Android registration associates that app
identity with the native Google Credential Manager flow.
Run or build Android with:
npm run tauri android dev
npm run tauri android buildUse the debug keystore SHA-1 during development and register the release signing-key SHA-1 before distributing a release build.
Sync downloads a single JSON snapshot from Drive, merges notes by their update timestamp, then uploads the resulting local snapshot. It is suitable for the prototype but does not yet provide per-change conflict history, background refresh, or durable token refresh across restarts.