Open source platform for autonomous AI coworkers. Build bots from the UI, give each one its own computer (browser, files, shell), let them work together as teams and workflows, and put them on a schedule as routines. Three admin agents run the platform; Platform Builder builds everything else from plain language.
Built on Agno AgentOS (FastAPI) with models served through OpenRouter, a Next.js web UI with its own auth, and Postgres. Every agent and team also speaks AG-UI and A2A, so other clients can use them.
Browser ──► web (Next.js :3000) ──► backend (Agno AgentOS :8000) ──► OpenRouter
│ Basic auth (optional) │ OS_SECURITY_KEY bearer auth
│ /api/os proxy adds key │ admin agents, Studio, scheduler, policy gateway
│ ├──► Postgres (sessions, runs, built components, audit log)
│ └──► supervisor ──► one computer container per bot
│ (Chromium + workspace + shell, no DB access)
| Agents | Click + Create → Agent, or ask Platform Builder. Pick tools from the palette, including computer. |
| Teams | Create → Team and pick member agents. The team leader delegates; each member's work shows as an activity line in the reply. |
| Workflows | Create → Workflow and order the agents as steps; each step gets the previous step's output. |
| Routines | Ask the Builder ("every weekday at 9, have the researcher summarise AI news"). Routines lists them; run now, pause, or resume. |
| Channels | Every conversation is a server-side session. Pick up any channel later, from any browser; runs still going reattach. |
| Computers | A bot with the computer tool gets its own browser (logins persist), workspace, and shell. The side panel shows its live screen and an audit trail of what it did, and what policy refused. |
Admin agents can never be a team member or workflow step, so nothing built from the UI can reach their privileged tools.
These are the default agents from Agno's AgentOS template, adapted for OpenBuildrOS. They are defined in code
(backend/agents/) and always served.
| Agent | Id | What it does |
|---|---|---|
| Platform Builder | platform-builder |
Turns plain language into agents, teams, workflows, and routines with Agno Studio (StudioTools), and publishes them so they appear in the sidebar. Archiving, deleting versions, and deleting routines pause for your approval in the UI. |
| Platform Manager | platform-manager |
Read-only. Reports usage, tokens, runs, latency, failures, traces, and built components (AgentOSTools). |
| Platform Engineer | platform-engineer |
Read-only. Reads the backend source and explains how it is wired, with file paths (WorkspaceContextProvider). .env files are excluded. |
- Click + Create, choose Agent, Team, or Workflow, and fill in the form. Or just ask Platform Builder in chat ("Build a research agent that searches the web and cites sources").
- The Builder discovers the exact tool and model names in the registry, calls Studio's
create_agent,create_team, orcreate_workflowwithpublish=true, and reports the published version. - The new component appears in the sidebar. Select it and chat.
New agents can only use what the Studio registry declares (backend/app/registry.py): calculator, web search,
file generation (JSON/CSV/TXT/HTML), and, when computers are on, computer. The UI reads this list from
GET /palette. Adding a capability is a reviewed code change to that file. Archiving components and deleting
versions or schedules pause for your approval in the UI.
Each bot that has the computer tool works on its own machine:
browse,read_page,click,type_text: a headless Chromium whose profile (cookies, logins) persists;list_files,read_file,write_file: the bot's workspace;run_shell: commands in the workspace, as an unprivileged user, with a minimal environment and a timeout.
Every action goes through one gateway in the backend (backend/app/computer.py):
- Policy (
backend/app/policy.py,COMPUTER_POLICY): JSONdenyandallowrules that match on tool, bot id, host, and a regex over the URL, command, or path. Deny wins; anything no allow rule matches is refused. Browsing private, loopback, link-local, and cloud-metadata addresses is always refused unlessallow_private_hostsis set. A malformed policy stops the backend from starting. - Audit: every decision is written to the
openbuildr_audittable before the action runs, and again if it fails.GET /audit?bot_id=reads it; the UI shows it under the live screen. - Only then is the bot's computer called. A refusal goes back to the model as text, and the chat shows the call as refused with the rule that refused it.
COMPUTER_MODE picks how computers run:
| Mode | How | Use for |
|---|---|---|
per-bot (default) |
The supervisor (supervisor/) starts one container per bot on first use, from openbuildros-computer, and stops it after COMPUTER_IDLE_MINUTES. Each has its own workspace volume, all capabilities dropped, no-new-privileges, PID/memory/CPU limits, and sits on the computers network, which cannot reach Postgres. Set COMPUTER_RUNTIME=runsc to run them under gVisor. |
Production |
shared |
One computer service (--profile shared-computer) keeps bots apart by directory and browser context. Shell commands share one container. |
Local development, tests |
off |
No computer tool. | Deployments that don't need it |
The supervisor is the only service with the Docker socket, and it only ever starts containers from the computer image with those fixed limits. Treat it as privileged: anyone who controls it controls Docker.
Prerequisites: Docker with Compose v2, GNU Make, OpenSSL, and an OpenRouter API key.
make env # creates .env with generated OS_SECURITY_KEY, DB_PASSWORD, COMPUTER_TOKEN, SUPERVISOR_TOKEN
# edit .env: set OPENROUTER_API_KEY, and UI_PASSWORD if anyone else can reach the UI
make up # builds the images (including the bot computer) and waits until every service is healthyOpen http://localhost:3000.
| Command | What it does |
|---|---|
make up / make down |
Start / stop the stack (data is kept in the pgdata volume) |
make logs, make ps |
Follow logs, show health |
make clean |
Stop and delete the database volume |
make install |
Local dev dependencies (backend/.venv, frontend/node_modules) |
make dev-backend, make dev-frontend |
Hot-reload dev servers (backend uses SQLite, RUNTIME_ENV=dev) |
make lint, make test |
Lint/format/type checks and tests for the backend, frontend, computer, and supervisor |
make e2e |
Build the full stack (per-bot computers included) against a fake model and run the Playwright journeys |
make lock |
Re-resolve each Python service's requirements.txt from its requirements.in |
All settings are environment variables; .env.example documents each one.
| Variable | Required | Purpose |
|---|---|---|
OPENROUTER_API_KEY |
yes | OpenRouter key. Only the backend container sees it. |
OS_SECURITY_KEY |
yes | Bearer token for the AgentOS API. The web server adds it to proxied calls; the browser never sees it. |
DB_PASSWORD |
yes | Postgres password (use URL-safe characters; make env generates hex). |
UI_PASSWORD, UI_USERNAME |
recommended | HTTP Basic auth in front of the whole UI. |
OPENROUTER_MODEL_ID |
no | Default model for every agent (default anthropic/claude-sonnet-4.5). Must support tool calling. |
RUNTIME_ENV |
no | prd (default) refuses to start without the two keys; dev relaxes that and enables /docs. |
OPENROUTER_MAX_RETRIES, OPENROUTER_TIMEOUT |
no | Retries for transient model failures (default 3) and request timeout in seconds (default 120). |
OPENROUTER_FALLBACK_MODELS |
no | Comma-separated models OpenRouter fails over to. |
WEB_CONCURRENCY |
no | uvicorn worker processes. More than 1 requires REDIS_URL. |
REDIS_URL |
with >1 worker | Shares resumable run streams across workers (docker compose --profile scale up -d). |
CORS_ORIGINS |
no | Extra browser origins allowed to call the API directly. |
COMPUTER_MODE |
no | per-bot (default), shared, or off; see Bot computers. |
COMPUTER_TOKEN |
when computers are on | Shared secret between the backend and bot computers. |
SUPERVISOR_TOKEN |
in per-bot mode |
Shared secret between the backend and the supervisor. |
COMPUTER_POLICY |
no | JSON deny/allow rules for computer actions. Default: allow all but private-network browsing. |
COMPUTER_MEMORY, COMPUTER_CPUS, COMPUTER_IDLE_MINUTES, COMPUTER_RUNTIME |
no | Per-bot container limits (default 2g, 1), idle shutdown (default 30), and an optional runtime such as runsc. |
The backend is a standard AgentOS. Every endpoint needs Authorization: Bearer $OS_SECURITY_KEY.
- AgentOS REST:
/agents,/teams,/workflowsand their/runs(form fieldsmessage,stream,session_id,user_id; SSE when streaming), resumable runs withbackground=true+/runs/{run_id}/resumeand/cancel,/continuefor approvals,/sessions,/schedules, traces, metrics, components. WithRUNTIME_ENV=dev, interactive docs are at http://localhost:8000/docs. You can also connect the backend to os.agno.com. - OpenBuildrOS:
GET /palette(tools new agents may use),GET /computers/{bot_id}/screen(PNG of a running computer),GET /audit?bot_id=&limit=(computer actions and decisions). - AG-UI:
POST /ag-ui/{agent_id}/aguiandPOST /ag-ui/teams/{team_id}/aguifor every agent and team, including ones built at runtime, for CopilotKit or any AG-UI client (backend/app/agui.py). - A2A: agent cards at
/a2a/agents/{id}/.well-known/agent-card.json, messages at/a2a/agents/{id}/v1/message:sendand:stream, for every agent including built ones.
The backend port is published on 127.0.0.1 only. The UI reaches the backend over the internal Compose network.
curl -N -H "Authorization: Bearer $OS_SECURITY_KEY" \
-F message="Is the platform healthy?" -F stream=true \
http://localhost:8000/agents/platform-manager/runs- Model calls. Transient failures (connection errors, 408, 409, 429, 5xx) are retried by the OpenAI SDK with
exponential backoff, jitter, and
Retry-After. The retry happens before any token streams, so output is never duplicated. 4xx errors such as a bad key fail fast. Every request has a timeout, and OpenRouter can fail over toOPENROUTER_FALLBACK_MODELS. There is no extra retry library: one layer, in the client that knows the protocol. - Dropped streams. The UI starts every run with
background=true, so the agent keeps running on the server if the browser disconnects. Each event carries anevent_index. When a stream ends early or the network fails, the UI calls AgentOS'sPOST /agents/{id}/runs/{run_id}/resumewith the last index it saw. It retries up to five times with exponential backoff and jitter, and shows "Reconnecting (n/5)…" meanwhile. Replayed events at or below that index are dropped, so nothing repeats or goes missing (frontend/lib/resilient.ts). Completed runs are replayed from the database once the in-memory buffer has expired. - Stop cancels the run on the server (
/cancel), since aborting the request would leave a background run going. - Reopening a channel whose run is still going reattaches to it through
/resumefrom the first event.
- Put the web service behind a TLS-terminating reverse proxy. Set
UI_PASSWORD, or add your own SSO in front. - Every image runs as a non-root user (except the supervisor, which needs the Docker socket) and has a health check; Compose sets CPU and memory limits.
- Bot computers can browse the internet. Narrow that with
COMPUTER_POLICYallow rules (for example{"tool": "browse", "host": "*.example.com"}), and useCOMPUTER_RUNTIME=runscwhere gVisor is available. - The UI proxy forwards only the endpoints the UI uses (
frontend/lib/proxy-rules.ts), not the whole admin API, and stamps every run with the signed-in UI user (UI_USERNAME) so the browser cannot pick its own identity. Studio records that user as the owner of what it builds. - Studio components, sessions, schedules, traces, and the audit log live in Postgres. Back up the
pgdatavolume, and the per-botobr-computer-*-workspacevolumes if bots keep files you need. - Agno telemetry is off by default (
AGNO_TELEMETRY=falseinbackend/app/settings.py,telemetry=Falseon AgentOS).
backend/
app/main.py AgentOS entrypoint: admin agents, registry, scheduler, A2A, extra routes
app/agui.py AG-UI for every agent and team, resolved per request
app/computer.py Computer toolkit and gateway (policy, audit, then the bot's computer)
app/policy.py Deny/allow rules and the private-network guard
app/audit.py The audit log table
app/settings.py Environment settings and the OpenRouter model factory
app/db.py Postgres or SQLite from DATABASE_URL
app/registry.py What Platform Builder may build with
app/functions.py Deterministic workflow steps
agents/ builder.py, manager.py, engineer.py, studio.py (admin agents stay out of teams)
tests/ pytest suite and fake_llm.py (scripted OpenAI-compatible server)
computer/ The bot computer: FastAPI over Playwright, workspace files, and a shell
supervisor/ Starts and stops one computer container per bot
frontend/
app/components/ Workspace, Sidebar, ChatView, ToolCard, CreateDialog, RoutinesDialog, ComputerPanel
app/api/os/ Server-side proxy to AgentOS
lib/ SSE parser, resumable streams, chat state, tool cards, API client, proxy rules
proxy.ts Optional Basic auth
tests/, e2e/ Vitest unit tests, Playwright journeys
Tests never call OpenRouter. backend/tests/fake_llm.py is an OpenAI-compatible server with scripted replies.
It can make the Builder call Studio's real create_agent, create_team, create_workflow, create_schedule,
and archive_component, and make built agents use their computer, so the tests cover the full path: UI →
proxy → AgentOS → Studio → database → the new agent, team, or workflow answering → its computer, policy, and
audit log.
The Hyperframes video pipeline from the original PRD is out of scope for this version.