Open Agents.dev
Vercel's open-source reference application for a durable cloud coding-agent loop that lives outside a replaceable execution sandbox.
Decision
Keep as a reference architecture; do not install it as a Kevin-Wiki runtime. It is the clearest current implementation of an external durable agent workflow over a separately managed sandbox. Its lifecycle and authority lessons belong in the brain, sandbox, workflow, and Agent Machines owners. It has no release or tag authority, unresolved production issues, and a Vercel-specific deployment surface, so the exact Git commit remains the version.
Source thesis
Guillermo Rauch's launch post argues that off-the-shelf coding agents lack a company's institutional knowledge, integrations, and custom workflows. The defensible asset shifts from only the code produced to the factory that can reliably produce and improve it. For Kevin-Wiki, that reinforces a practical test: captured knowledge compounds only when it changes stable instructions, workflows, skills, routing, projects, or proof—not when it merely becomes another saved page. Source: X/@rauchg, 2026-04-14
Audited architecture
The current repository documents and implements three layers:
Web -> durable agent workflow -> sandbox VM
| Layer | Current responsibility |
|---|---|
| Web/control surface | Authentication, sessions, chat, stream reconnection, preferences, sharing, and GitHub integration |
| Agent workflow | Durable multi-step loop, persisted messages, usage, cancellation, post-finish actions, and recovery ownership |
| Sandbox VM | Filesystem, shell, git checkout/branch, dev servers, preview ports, snapshot, hibernate, and restore |
The architectural point is that the agent is not the sandbox. Agent and
sandbox lifecycles can change independently, and the VM remains a tool-bearing
execution environment rather than the canonical control plane. That directly
corroborates Agent Sandboxes and the trust topology in the Kevin brain.
Source: vercel-labs/open-agents README and implementation at
cf865e94de7729751c747171785b6ce57e7b178c, reviewed 2026-08-11
Authority audit
The implementation has distinct authority surfaces; they must not be collapsed into one “approved” state:
- the bash tool auto-allows a small read-only command set and asks for approval on dangerous or unknown commands;
- auto commit/push and auto PR are saved user preferences that default to
false; - once enabled, post-finish commit/push can run after a successful turn without a fresh per-turn approval;
- commit creation verifies write access, avoids committing to the default branch, uses an expected remote head, and mints repository- and permission- scoped GitHub App tokens;
- PR creation requires a non-default branch that is fully pushed;
- public chat sharing is explicit and revocable, hides reasoning/tool bodies in its Markdown view, and applies environment-content redaction.
This is substantially safer than unconditional auto-publish, but preference-
level opt-in is not a universal substitute for run-level authority. Kevin's
workflow receipt must record whether commit, push, PR, share, deploy, or other
external mutations were enabled and the evidence they produced. Sensitive
targets may require fresh approval even when a standing preference exists.
Source: pinned repository files packages/agent/docs/approval-system.md,
apps/web/app/workflows/chat.ts, apps/web/lib/chat/auto-commit-direct.ts,
apps/web/lib/chat/auto-pr-direct.ts, and share routes, reviewed 2026-08-11
Lifecycle lessons
The repository's own failure ledger is more valuable than the “runs infinitely” copy:
- snapshot creation shuts down the current sandbox and must be modeled as a transition, not a passive backup;
- long-gap lifecycle work needs a durable scheduled workflow, not a request- local timer;
- concurrent snapshot responses need idempotent reconciliation;
- workflow leases are claimed after a successful start, or a canceled kickoff can strand false state;
- status and reconnect probes must stay read-only, or observation can keep an idle worker alive;
- server lifecycle state must be authoritative over conflicting client clocks and presentation heuristics.
These are concrete state-machine requirements for any persistent-agent product,
including Agent Machines. Source: pinned
docs/agents/lessons-learned.md, reviewed 2026-08-11
Current source snapshot
| Field | Verified state |
|---|---|
| Repository | vercel-labs/open-agents |
| Revision | cf865e94de7729751c747171785b6ce57e7b178c |
| Stars / forks | 5,775 / 756 at capture |
| License | MIT |
| Releases / tags | none |
| Runtime | Node 24, pnpm 11.5.1, private TypeScript monorepo |
| Package authority | source commit; the public open-agents npm package is unrelated |
Deployment documentation is not perfectly synchronized. The README and
.env.example name POSTGRES_URL and BETTER_AUTH_SECRET as minimum runtime
variables, while the in-app deploy route also requests BETTER_AUTH_URL and
ENCRYPTION_KEY; the captured template HTML contains both Open Agents and Open
Harness parameter payloads. Verify the exact revision and runtime code before
deploying instead of copying a scraped template string.
Open issues include file-content prompt-injection guarding, OpenTelemetry, non-atomic final-message/stream clearing, Workflow beta compatibility, network egress approval, complete web-fetch persistence, and deployment resource defaults. These are held production gaps, not reasons to discard the source.
Held signals
- “Run infinitely” and “nothing is ever lost” remain marketing claims until failure injection proves recovery, idempotence, and canonical history.
- The correlated Aurora DSQL reply is a relevant elastic app-generation database pattern, not a default database decision.
- The launch image is a useful system-layer visual, but it only names AI SDK, Gateway, Sandbox, and Workflow DevKit; the repository supplies the proof.
Timeline
- 2026-08-11 | Replayed the complete X source and self-thread, reviewed the launch visual, captured the current site/template/repository and open issues, and audited lifecycle, approval, GitHub mutation, and sharing paths. Kept Open Agents as a commit-pinned reference architecture; promoted external-loop, lifecycle-reconciliation, and authority-surface lessons while holding install, reliability, and DSQL-default claims. Source: capture manifest and pinned repository audit
- 2026-06-30 | First deep review pinned commit
cf865e94de7729751c747171785b6ce57e7b178c, found no release tags, and rejected the unrelated npm package as version authority. Source: GitHub/npm/Brin - 2026-04-14 | Guillermo Rauch announced the open-source reference platform. Source: X/@rauchg