Open Agents is an open-source reference app for building and running background coding agents on Vercel. It includes the web UI, the agent runtime, sandbox orchestration, and the GitHub integration needed to go from prompt to code changes without keeping your laptop involved.
The repo is meant to be forked and adapted, not treated as a black box.
This fork uses a standard dev-before-production branch model:
feature branch -> PR into develop -> Vercel dev
develop -> release PR into main
main -> Vercel Production
Use develop for integration/dev testing and main for production releases.
The stable dev deployment is:
https://open-agents-env-dev-dennisons-projects.vercel.app
Backlogged feature PRs should be retargeted to develop. Production releases
should be batched through release PRs from develop to main after dev smoke
passes.
See Backlog PR Operator Prompt for a reusable prompt that can guide an agent through retargeting, updating, testing, merging, and batching the existing PR backlog.
Open Agents is a three-layer system:
Web -> Agent workflow -> Sandbox VM
- The web app handles auth, sessions, chat, and streaming UI.
- The agent runs as a durable workflow on Vercel.
- The sandbox is the execution environment: filesystem, shell, git, dev servers, and preview ports.
The agent does not run inside the VM. It runs outside the sandbox and interacts with it through tools like file reads, edits, search, and shell commands.
That separation is the main point of the project:
- agent execution is not tied to a single request lifecycle
- sandbox lifecycle can hibernate and resume independently
- model/provider choices and sandbox implementation can evolve separately
- the VM stays a plain execution environment instead of becoming the control plane
- chat-driven coding agent with file, search, shell, task, skill, and web tools
- durable multi-step execution with Workflow SDK-backed runs, streaming, and cancellation
- isolated Vercel sandboxes with snapshot-based resume
- repo cloning and branch work inside the sandbox
- optional auto-commit, push, and PR creation after a successful run
- session sharing via read-only links
- optional voice input via ElevenLabs transcription
A few details that matter for understanding the current implementation:
- Chat requests start a workflow run instead of executing the agent inline.
- Each agent turn can continue across many persisted workflow steps.
- Active runs can be resumed by reconnecting to the stream for the existing workflow.
- Sandboxes expose ports
3000,5173,4321, and8000, can optionally use a configured base snapshot, and hibernate after inactivity. - Auto-commit and auto-PR are supported, but they are preference-driven features, not always-on behavior.
See apps/web/.env.example for the full list. Summary:
POSTGRES_URL=
BETTER_AUTH_SECRET=NEXT_PUBLIC_VERCEL_APP_CLIENT_ID=
VERCEL_APP_CLIENT_SECRET=NEXT_PUBLIC_GITHUB_CLIENT_ID=
GITHUB_CLIENT_SECRET=
GITHUB_APP_ID=
GITHUB_APP_PRIVATE_KEY=
NEXT_PUBLIC_GITHUB_APP_SLUG=
GITHUB_WEBHOOK_SECRET=REDIS_URL=
KV_URL=
AI_GATEWAY_API_KEY=
RATE_LIMIT_TIMEOUT_MS=
OPEN_AGENTS_RESOURCE_PROFILE=
VERCEL_PROJECT_PRODUCTION_URL=
NEXT_PUBLIC_VERCEL_PROJECT_PRODUCTION_URL=
VERCEL_SANDBOX_BASE_SNAPSHOT_ID=
ELEVENLABS_API_KEY=REDIS_URL/KV_URL: required in production for rate-limited session, sandbox, PR, and agent-work endpoints. Some non-critical caches fall back to in-memory when not configured, but production rate limiting fails closed.AI_GATEWAY_API_KEY: optional explicit key for Vercel AI Gateway. Vercel deployments can use OIDC auth automatically.RATE_LIMIT_TIMEOUT_MS: optional timeout override for Redis-backed rate-limit checks.OPEN_AGENTS_RESOURCE_PROFILE: optional deployment resource profile. Set tohobbyto use Hobby-compatible defaults for chat and sandbox resources; leave unset for standard behavior.VERCEL_PROJECT_PRODUCTION_URL/NEXT_PUBLIC_VERCEL_PROJECT_PRODUCTION_URL: canonical production URL for metadata and some callback behavior.VERCEL_SANDBOX_BASE_SNAPSHOT_ID: optional base snapshot for fresh sandboxes. If unset, sandboxes start from Vercel's standard Sandbox runtime. Use a snapshot created in/accessible to your own Vercel scope.ELEVENLABS_API_KEY: voice transcription.
-
Fork this repo.
-
Import the repo into Vercel. Neon Postgres is auto-provisioned if you use the deploy button above.
-
Generate a secret for session signing:
openssl rand -base64 32 # BETTER_AUTH_SECRET -
Add env vars in Vercel project settings:
POSTGRES_URL= BETTER_AUTH_SECRET=
-
Deploy once to get a stable production URL.
-
Create a Vercel OAuth app with callback URL:
https://YOUR_DOMAIN/api/auth/callback/vercel -
Add these env vars and redeploy:
NEXT_PUBLIC_VERCEL_APP_CLIENT_ID= VERCEL_APP_CLIENT_SECRET=
-
If you want the full GitHub-enabled coding-agent flow, create a GitHub App using:
- Homepage URL:
https://YOUR_DOMAIN - Callback URL:
https://YOUR_DOMAIN/api/auth/callback/github - Setup URL:
https://YOUR_DOMAIN/api/github/app/callback
In the GitHub App settings:
- use the GitHub App's Client ID and Client Secret for
NEXT_PUBLIC_GITHUB_CLIENT_IDandGITHUB_CLIENT_SECRET - make the app public if you want org installs to work cleanly
- Homepage URL:
-
Add the GitHub App env vars and redeploy.
-
Add Redis/KV before testing production project creation. Then optionally add
OPEN_AGENTS_RESOURCE_PROFILE=hobbyfor Hobby-compatible resource defaults, the canonical production URL vars, and your ownVERCEL_SANDBOX_BASE_SNAPSHOT_IDif you want fresh sandboxes to start from a preconfigured image.
-
Install dependencies:
bun install
-
Create your local env file:
cp apps/web/.env.example apps/web/.env
-
Fill in the required values in
apps/web/.env. -
Start the app:
bun run web
If you already have a linked Vercel project, you can pull env vars locally with vc env pull.
Authentication is handled by Better Auth with Vercel and GitHub as social providers. All auth routes are served from the /api/auth/[...all] catchall.
Create a Vercel OAuth app and use this callback:
https://YOUR_DOMAIN/api/auth/callback/vercel
For local development, use:
http://localhost:3000/api/auth/callback/vercel
Add both the production callback and this local callback to the same Vercel OAuth app. When BETTER_AUTH_URL is set, Vercel sign-in uses that canonical callback URL; local development without BETTER_AUTH_URL derives the callback from the local request host.
Then set:
NEXT_PUBLIC_VERCEL_APP_CLIENT_ID=...
VERCEL_APP_CLIENT_SECRET=...Use only the openid, email, and profile scopes unless the Vercel app explicitly supports more. A redirect with invalid_scope usually means the app is requesting a scope such as offline_access that was not enabled for that app.
You do not need a separate GitHub OAuth app. Open Agents uses the GitHub App's OAuth credentials as a Better Auth social provider, plus the App's installation tokens for repo access.
Create a GitHub App for installation-based repo access and configure:
- Homepage URL:
https://YOUR_DOMAIN - Callback URL:
https://YOUR_DOMAIN/api/auth/callback/github - Setup URL:
https://YOUR_DOMAIN/api/github/app/callback - make the app public if you want org installs to work cleanly
For local development, use http://localhost:3000 as the homepage URL, http://localhost:3000/api/auth/callback/github as the callback URL, and http://localhost:3000/api/github/app/callback as the setup URL.
Then set:
NEXT_PUBLIC_GITHUB_CLIENT_ID=... # GitHub App Client ID
GITHUB_CLIENT_SECRET=... # GitHub App Client Secret
GITHUB_APP_ID=...
GITHUB_APP_PRIVATE_KEY=...
NEXT_PUBLIC_GITHUB_APP_SLUG=...
GITHUB_WEBHOOK_SECRET=...GITHUB_APP_PRIVATE_KEY can be stored as the PEM contents with escaped newlines or as a base64-encoded PEM.
bun run web # run dev server
bun run check # lint + format check
bun run fix # lint + format fix
bun run typecheck # typecheck all packages
bun run ci # full CI: check, typecheck, tests, migration check
bun run sandbox:snapshot-base # refresh sandbox base snapshotapps/web Next.js app, workflows, auth, chat UI
packages/agent agent implementation, tools, subagents, skills
packages/sandbox sandbox abstraction and Vercel sandbox integration
packages/shared shared utilities