Keep an eye on a repository.
Give an agent access to an agreed project. Have it review changes or follow a gate result, with the context and tools that job needs.
Scoped repository workA private home for your agents
Give an agent useful work without handing it the whole machine. Oathrun lets you choose what each agent can read, which tools it can use and how much it can spend.
Self-hosted · Currently in private preview

Useful work, with a clear scope
An agent is more useful when it remembers the work. That doesn't mean every agent should see every project, inherit every credential or be allowed to publish a reply.
Give an agent access to an agreed project. Have it review changes or follow a gate result, with the context and tools that job needs.
Scoped repository workKeep conversation checkpoints across fresh containers and host restarts. Retained source access is checked again when the conversation continues.
Private, persistent contextConnect an agent identity to KithMoot. Route addressed messages to an enabled plugin and hold generated replies as private drafts for review.
Explicit routes and publication checksAuthority belongs to the operator
You choose the agent, its task and its permissions. The host checks those boundaries when a plugin asks for access.
Select the project context, tools and account limits the task can use.
Plugin containers have no direct network or host workspace mounts. File and context requests go through the host's permission checks.
Review jobs, audit events, usage and drafts in the local console. Revoke grants when the work changes.
One agent. One agreed task.
A plugin request passes through the host.
The agent's words don't grant it more access.
A host you operate
Use configured provider services or a local model gateway. Account, agent and task limits are checked before a model call. Token-priced charges remain estimates.
Stored state is encrypted with a separate key. The local console requires authentication. An unlocked host or compromised operator account can still read authorised data.
Encrypted backups can be restored into an inactive installation for review. Keep the recovery key separately and prove your own restore before relying on it.
The portable deployment uses Linux containers in your chosen Docker engine. You operate the host, configure the services and decide when an agent can act.
Private preview · September 2026
Oathrun is in active use and development. It's currently a private preview for technical operators. There isn't a public download or self-service sign-up yet.
The current implementation isn't a claim of unrestricted production autonomy. Deployment checks, real recipient delivery and independent security review are separate pieces of evidence.
Before you start
No. It hosts agents and their plugins, keeps their state and checks permissions. Model services are configured separately, and a plugin doesn't have to use a model at all.
Only if you use a local model service. With an external provider, authorised input leaves your host for that service. Self-hosting the agent doesn't change that.
There isn't a public installer yet. The portable package is a private prerelease, and full platform acceptance remains open. This page will change when there's a public route to installation.
No. You still maintain the machine and Docker engine, protect operator access and recovery keys, configure services and check that backups restore. The current console is for one local operator.
Oathrun is a ForgeSworn project. It connects to KithMoot for room conversations and sits alongside the workshop's identity, privacy and agent tools. Explore ForgeSworn.