Oathrunby ForgeSworn

A private home for your agents

Run your agents.
Set their limits.

Give an agent useful work without handing it the whole machine. Oathrun lets you choose what each agent can read, which tools it can use and how much it can spend.

Self-hosted · Currently in private preview

Two sculpted links in sage green and brass, joined together
OATHRUN Your host. Your authority.
Permissions per pluginProject-bound contextEncrypted stored stateLocal operator console

Useful work, with a clear scope

Keep the context.
Keep a hand on the controls.

An agent is more useful when it remembers the work. That doesn't mean every agent should see every project, inherit every credential or be allowed to publish a reply.

01 / DEVELOPMENT

Keep an eye on a repository.

Give an agent access to an agreed project. Have it review changes or follow a gate result, with the context and tools that job needs.

Scoped repository work
02 / CONVERSATION

Pick up where you left off.

Keep conversation checkpoints across fresh containers and host restarts. Retained source access is checked again when the conversation continues.

Private, persistent context
03 / SHARED ROOMS

Bring an agent into the room.

Connect an agent identity to KithMoot. Route addressed messages to an enabled plugin and hold generated replies as private drafts for review.

Explicit routes and publication checks

Authority belongs to the operator

A job starts with
what you allow.

You choose the agent, its task and its permissions. The host checks those boundaries when a plugin asks for access.

  1. Give the work a scope.

    Select the project context, tools and account limits the task can use.

  2. Run the plugin in isolation.

    Plugin containers have no direct network or host workspace mounts. File and context requests go through the host's permission checks.

  3. Inspect what happened.

    Review jobs, audit events, usage and drafts in the local console. Revoke grants when the work changes.

An example task boundaryIllustration
REPOSITORY REVIEW

Review this project's changes.

One agent. One agreed task.

Project context
Selected notes
Repository files
Granted reads
Other projects
No access
Direct plugin network
No access
Model use
Within task limits
Room publication
Exact approval

A plugin request passes through the host.
The agent's words don't grant it more access.

A host you operate

Your agents have a home.
You hold the keys.

Choose the model connection.

Use configured provider services or a local model gateway. Account, agent and task limits are checked before a model call. Token-priced charges remain estimates.

Keep state private.

Stored state is encrypted with a separate key. The local console requires authentication. An unlocked host or compromised operator account can still read authorised data.

Make recovery part of the job.

Encrypted backups can be restored into an inactive installation for review. Keep the recovery key separately and prove your own restore before relying on it.

Run it on your infrastructure.

The portable deployment uses Linux containers in your chosen Docker engine. You operate the host, configure the services and decide when an agent can act.

Private preview · September 2026

Built, running,
still being proved.

Oathrun is in active use and development. It's currently a private preview for technical operators. There isn't a public download or self-service sign-up yet.

Implemented today

  • Rust host and separately permissioned plugins
  • Local console, encrypted state and audit events
  • Persistent conversations and bounded model gateways
  • KithMoot room routing and publication checks
  • Portable Docker deployment and encrypted recovery tools

Still to prove or finish

  • Complete Windows and physical Linux acceptance
  • Remaining macOS startup, upgrade and delivery checks
  • Recovery onto a replacement host
  • Broader disclosure policy and autonomous task authority
  • Independent security audit

The current implementation isn't a claim of unrestricted production autonomy. Deployment checks, real recipient delivery and independent security review are separate pieces of evidence.

Before you start

A few practical questions.

Is Oathrun a model?

No. It hosts agents and their plugins, keeps their state and checks permissions. Model services are configured separately, and a plugin doesn't have to use a model at all.

Does self-hosting keep every model call local?

Only if you use a local model service. With an external provider, authorised input leaves your host for that service. Self-hosting the agent doesn't change that.

Can I install it today?

There isn't a public installer yet. The portable package is a private prerelease, and full platform acceptance remains open. This page will change when there's a public route to installation.

Does it replace my responsibility for the host?

No. You still maintain the machine and Docker engine, protect operator access and recovery keys, configure services and check that backups restore. The current console is for one local operator.

Where does ForgeSworn fit?

Oathrun is a ForgeSworn project. It connects to KithMoot for room conversations and sits alongside the workshop's identity, privacy and agent tools. Explore ForgeSworn.

Give the agent a job.
Decide what comes with it.

Explore the boundaries