Agent
A versioned teammate: model, prompt, tools, skills, MCP, harness. Opening an Agent lands on its home session — a pinned inbox that survives crash and reconnect.
Open source · self-hostable
Message a teammate, not a throwaway chat. The home session keeps the event log across crash and reconnect. A long-lived home runtime (bridge or herdr) keeps working when the laptop is closed. Isolated turns still get ephemeral sandboxes — this is not an always-on shared VM. Any LLM provider, any sandbox, self-hosted.
Works with Cloudflare · Kubernetes · Anthropic · OpenAI-compatible · E2B & Daytona (self-host)
Apache 2.0 · no vendor lock-in · same codebase cloud or self-host
How it fits
Four steps from API key to a live agent. Click any card for a short explanation and links.
Interactive Click any component for details. Collapse columns with the chevrons on small screens.
Primitives
A platform for running agent fleets, not a chat UI. Four objects carry the whole model.
A versioned teammate: model, prompt, tools, skills, MCP, harness. Opening an Agent lands on its home session — a pinned inbox that survives crash and reconnect.
A conversation with a durable event log (SessionDO, persist-before-broadcast). Home is long-lived; extra sessions stay ephemeral for isolated work.
The execution sandbox: packages, network policy, container image. Reusable across agents, so a fleet shares one runtime shape.
A credential store that never enters the sandbox. An outbound proxy injects tokens at the network layer, matched by URL.
Demo
Pick a use case and follow trigger → agent → result — including the local bridge, Kubernetes, and the browser sandbox.
One agent, wired to your stack
Customer threads open sessions; answers are drafted from your docs.
Building blocks
What an agent assembles: reusable know-how (skills), external tools over MCP, and durable outputs (artifacts) that land in the session log.
Reusable prompt fragments + files mounted into the sandbox and injected into the system prompt. Write once, attach to any number of agents; versioned and auditable.
Connect remote MCP servers — GitHub, Linear, Firecrawl, anything. Every call is proxied through the control plane, the only layer that holds the upstream credential; the sandbox never sees it.
What agents produce: files in /workspace, session outputs, memory-store notes, generated reports and charts. The Console session Inspector aggregates them on the Artifacts tab from the event log — no extra storage layer. An agent can mark a keep-this deliverable with the opt-in output_file tool (`agent.output_declared`); those are badged ★ Declared output.
Request path
Every message runs the same durable path: the session log records it, the harness drives the model loop, tools run in the sandbox, and the outbound proxy injects vault credentials the sandbox never sees.
Request — what runs here
Your message streams in over SSE. The harness appends it to the session's event log first — written durably before anything else runs — then hands it to the model loop.
Flexibility
Point models at Anthropic, an OpenAI-compatible gateway, or your own endpoint; run tools on Cloudflare Containers, Kubernetes, OpenShell, a browser WASM VM, your machine via the CLI, a micro-VM vendor, or a Worker isolate. The control plane owns context, state, and memory on a durable spine — so model and sandbox layers swap without rewriting the rest.
Three swappable layers
Explore
The details live on their own pages — pick a thread to pull.
The meta-harness design, architecture layers, and the durable session lifecycle.
Everything the platform gives you — and why it's drop-in compatible.
Real workflows: ship code, run production, answer customers, work a thread.
Multi-agent fleets, any sandbox provider, and bridging your own machine.
Read the docs, try the hosted deployment, or clone the same codebase.