Open Agents.dev

Vercel's open-source reference application for a durable cloud coding-agent loop that lives outside a replaceable execution sandbox.

Decision

Keep as a reference architecture; do not install it as a Kevin-Wiki runtime. It is the clearest current implementation of an external durable agent workflow over a separately managed sandbox. Its lifecycle and authority lessons belong in the brain, sandbox, workflow, and Agent Machines owners. It has no release or tag authority, unresolved production issues, and a Vercel-specific deployment surface, so the exact Git commit remains the version.

Source thesis

Guillermo Rauch's launch post argues that off-the-shelf coding agents lack a company's institutional knowledge, integrations, and custom workflows. The defensible asset shifts from only the code produced to the factory that can reliably produce and improve it. For Kevin-Wiki, that reinforces a practical test: captured knowledge compounds only when it changes stable instructions, workflows, skills, routing, projects, or proof—not when it merely becomes another saved page. Source: X/@rauchg, 2026-04-14

Audited architecture

The current repository documents and implements three layers:

Web -> durable agent workflow -> sandbox VM
Layer Current responsibility
Web/control surface Authentication, sessions, chat, stream reconnection, preferences, sharing, and GitHub integration
Agent workflow Durable multi-step loop, persisted messages, usage, cancellation, post-finish actions, and recovery ownership
Sandbox VM Filesystem, shell, git checkout/branch, dev servers, preview ports, snapshot, hibernate, and restore

The architectural point is that the agent is not the sandbox. Agent and sandbox lifecycles can change independently, and the VM remains a tool-bearing execution environment rather than the canonical control plane. That directly corroborates Agent Sandboxes and the trust topology in the Kevin brain. Source: vercel-labs/open-agents README and implementation at cf865e94de7729751c747171785b6ce57e7b178c, reviewed 2026-08-11

Authority audit

The implementation has distinct authority surfaces; they must not be collapsed into one “approved” state:

  • the bash tool auto-allows a small read-only command set and asks for approval on dangerous or unknown commands;
  • auto commit/push and auto PR are saved user preferences that default to false;
  • once enabled, post-finish commit/push can run after a successful turn without a fresh per-turn approval;
  • commit creation verifies write access, avoids committing to the default branch, uses an expected remote head, and mints repository- and permission- scoped GitHub App tokens;
  • PR creation requires a non-default branch that is fully pushed;
  • public chat sharing is explicit and revocable, hides reasoning/tool bodies in its Markdown view, and applies environment-content redaction.

This is substantially safer than unconditional auto-publish, but preference- level opt-in is not a universal substitute for run-level authority. Kevin's workflow receipt must record whether commit, push, PR, share, deploy, or other external mutations were enabled and the evidence they produced. Sensitive targets may require fresh approval even when a standing preference exists. Source: pinned repository files packages/agent/docs/approval-system.md, apps/web/app/workflows/chat.ts, apps/web/lib/chat/auto-commit-direct.ts, apps/web/lib/chat/auto-pr-direct.ts, and share routes, reviewed 2026-08-11

Lifecycle lessons

The repository's own failure ledger is more valuable than the “runs infinitely” copy:

  • snapshot creation shuts down the current sandbox and must be modeled as a transition, not a passive backup;
  • long-gap lifecycle work needs a durable scheduled workflow, not a request- local timer;
  • concurrent snapshot responses need idempotent reconciliation;
  • workflow leases are claimed after a successful start, or a canceled kickoff can strand false state;
  • status and reconnect probes must stay read-only, or observation can keep an idle worker alive;
  • server lifecycle state must be authoritative over conflicting client clocks and presentation heuristics.

These are concrete state-machine requirements for any persistent-agent product, including Agent Machines. Source: pinned docs/agents/lessons-learned.md, reviewed 2026-08-11

Current source snapshot

Field Verified state
Repository vercel-labs/open-agents
Revision cf865e94de7729751c747171785b6ce57e7b178c
Stars / forks 5,775 / 756 at capture
License MIT
Releases / tags none
Runtime Node 24, pnpm 11.5.1, private TypeScript monorepo
Package authority source commit; the public open-agents npm package is unrelated

Deployment documentation is not perfectly synchronized. The README and .env.example name POSTGRES_URL and BETTER_AUTH_SECRET as minimum runtime variables, while the in-app deploy route also requests BETTER_AUTH_URL and ENCRYPTION_KEY; the captured template HTML contains both Open Agents and Open Harness parameter payloads. Verify the exact revision and runtime code before deploying instead of copying a scraped template string.

Open issues include file-content prompt-injection guarding, OpenTelemetry, non-atomic final-message/stream clearing, Workflow beta compatibility, network egress approval, complete web-fetch persistence, and deployment resource defaults. These are held production gaps, not reasons to discard the source.

Held signals

  • “Run infinitely” and “nothing is ever lost” remain marketing claims until failure injection proves recovery, idempotence, and canonical history.
  • The correlated Aurora DSQL reply is a relevant elastic app-generation database pattern, not a default database decision.
  • The launch image is a useful system-layer visual, but it only names AI SDK, Gateway, Sandbox, and Workflow DevKit; the repository supplies the proof.

Timeline

  • 2026-08-11 | Replayed the complete X source and self-thread, reviewed the launch visual, captured the current site/template/repository and open issues, and audited lifecycle, approval, GitHub mutation, and sharing paths. Kept Open Agents as a commit-pinned reference architecture; promoted external-loop, lifecycle-reconciliation, and authority-surface lessons while holding install, reliability, and DSQL-default claims. Source: capture manifest and pinned repository audit
  • 2026-06-30 | First deep review pinned commit cf865e94de7729751c747171785b6ce57e7b178c, found no release tags, and rejected the unrelated npm package as version authority. Source: GitHub/npm/Brin
  • 2026-04-14 | Guillermo Rauch announced the open-source reference platform. Source: X/@rauchg