Self-hosted · v0.6

Put agents inside
your governance boundary

The self-hosted workspace for team agents — agents do the work, your team keeps control. Engines are pluggable (faux / pydantic-ai / ACP driving Claude Code, Gemini CLI), and SSO, auditing, and cost attribution are all built into the community edition.

$ make init && cd deploy$ docker compose -f compose.demo.yml up -d --build --wait# Open http://localhost:3000/register — the first-run wizard guides you to demo mode

WHY INAGENT

Governance is the foundation of the community edition, not a plugin behind a paywall

CapabilityInAgent (community edition)The category norm
SSO (OIDC + PKCE)Built in — org-level config, JIT provisioning, enforced SSO domainsCommonly behind an enterprise paywall
Audit logsappend-only storage, admin UI, CSV exportUsually an enterprise tier or a paid plugin
Usage / cost attributionFour levels (org / workspace / user / session) with an aggregate viewCost reports are typically a paid feature
Trace observabilityOTel + trace waterfall UITrace viewers are typically a paid feature
HITL oversightNative: command approval cards / structured questions / permission requests routed to approvalMostly bolt-on toolkits or external layers
Coding agent enginesACP drives Claude Code / Gemini CLI inside the governance sandboxLocked to a homegrown runtime, or no support for external coding agents
Secret governanceAES-GCM vault encryption at rest, keys never echoed back, egress placeholder substitutionPlaintext environment variables or basic encryption

CAPABILITIES

From conversations to governed team work

Workspace

  • Multi-model chat with per-session engine switching
  • Streaming over SSE; reconnect and replay without message loss
  • Mid-run steering
  • Automatic context compaction + /compact
  • Session search / pin / share, file attachments

Pluggable engines

  • faux scripted demo engine (no API key)
  • pydantic-ai: four tiers plus a fallback chain
  • ACP drives Claude Code / Gemini CLI
  • Coding agents run inside the governance sandbox

Governance

  • Org / workspace role levels and invites
  • OIDC SSO (PKCE + JIT + enforced SSO domains)
  • append-only audit log + CSV export
  • AES-GCM secret vault; keys are never echoed back
  • Three-action command policy: deny / confirm / allow

Sandbox

  • One persistent container per (user, workspace)
  • Non-root, memory / CPU / PID limits
  • Data persists across sessions
  • File tree + web terminal

Ecosystem

  • Skills: SKILL.md compatible + registry sync
  • MCP: stdio / HTTP + OAuth + usage auditing
  • Artifacts: five versioned types, with preview for every format
  • Anonymous share links

Automation

  • cron schedules / webhook triggers (HMAC, replay dedup)
  • Native GitHub / Stripe signature compatibility
  • Standalone runner service; runs survive api restarts
  • Results delivered to Feishu; automation = trigger + specialist

Channels & observability

  • Feishu / DingTalk bots running as the bound user
  • In-IM HITL button approvals and questions
  • OTel tracing + trace waterfall
  • Usage attribution across four levels (org / ws / user / session)

First run

  • First-run wizard guides you through setup or demo mode
  • Keyless demo mode (faux engine)
  • A productized 15-minute evaluation path
  • demo → full: data stays in place

DEPLOY

docker compose up — your data stays yours

$ make init$ cd deploy$ docker compose -f compose.demo.yml up -d --build --wait
$ cp ../.env.example .env$ docker compose up -d --build --wait# demo → full: data stays in place

China-region registry-mirror overlay, offline air-gapped installs, OTel observability — see the ops manual shipped in the deployment bundle.

FAQ

Frequently asked questions

What is the SSO tax — and why doesn't InAgent have one?

Plenty of teams only discover at procurement that SSO, audit logs, and usage reports are gated behind an expensive enterprise tier — the community calls this the SSO tax. InAgent's commitment: SSO, auditing, cost attribution, and trace viewing are all in the community edition. There is no enterprise edition and no held-back feature flags — what you deploy is the complete product.

What are the sandbox security boundaries?

Every (user, workspace) pair gets one persistent container: non-root (uid 1000), memory / CPU / PID limits, and the default seccomp profile. Secrets never enter the sandbox. For production, we recommend a docker socket proxy instead of mounting the socket directly; when you need egress control, enable the egress MITM proxy profile — secrets are injected as placeholders and swapped for real values at the network boundary, with auditing.

Can I skip Claude Code, or swap out the engine?

Yes. Engines are pluggable through the RuntimeAdapter SPI: the faux demo engine needs no API key at all; pydantic-ai targets multiple providers (four tiers plus a fallback chain); and the ACP adapter drives real coding agents such as Claude Code / Gemini CLI. Switching happens per session — you are never tied to a homegrown runtime.

Does it support offline (air-gapped) deployment?

Yes. Run deploy/scripts/airgap-export.sh on a networked machine to export a deployment bundle, then docker load on the target machine and bring the stack up offline. For China-region environments there is also a registry-mirror overlay (covering base images and the pnpm registry), so you can build without a proxy.

How far do the internal IM integrations go?

The Feishu / DingTalk bots run as the bound user and support streaming cards, HITL button approvals and question cards, and artifact delivery. Automation results can also be delivered to Feishu. DingTalk uses a long-lived Stream connection, so no public callback endpoint is needed.