any-bot
40 model providers wired in, hosted or local, on your keys — with a containment boundary that fails closed.
Reasoning runs on an authorized hosted or bring-your-own rail. Exact external actions do not go through a model at all — they are fixed server operations. Those two sentences are the whole security posture of the model layer, and everything else follows from them.
Each bot identity carries its own provider and model. An expensive lane and a cheap lane can run side by side in the same swarm on the same work, and be compared on measured output rather than on preference. Swapping a provider becomes a decision with evidence behind it.
Keep reading
One shell for every app. The left ribbon is drawn from the app you opened, and the URL decides — never a cached preference.
Learn more → Connections308 hand-audited connector specs ship in the repo. Your token is encrypted per user, and the model never sees it.
Learn more → Work routingA request becomes a ticket, a ticket becomes phases, and phases are dispatched to accountable bot identities over durable streams.
Learn more → StateFour stores, each doing the job it is genuinely better at — and one of them is optional on purpose.
Learn more → OperationsThe stack watches itself, files its own incident tickets and does root-cause analysis on them — with the repair still gated on a human.
Learn more → ReachA bot is an identity, not a location — and an identity can live on the desktop where your browser is already signed in.
Learn more → InteropAgents that are not yours can be given a scoped door into the swarm — and oshal bots can call out through the same protocol.
Learn more → The wallAuth per route, credentials the model never sees, per-user data scoping, and a fail-closed gate between a commit and the public.
Learn more →