Universal AI agent platform

Your software,
operated by AI.

Connect an API, an MCP server or a database. AgentOS learns what it can do, turns it into an agent your team directs in plain language, and refuses to run anything it cannot independently verify.

checks before any call runs
6 checks before any call runs
credentials sent to the model
0 credentials sent to the model
roles, plus per-member overrides
5 roles, plus per-member overrides

execution trace

paused
  1. Message Delete every customer inactive since 2023
  2. Plan delete_customer · 32 matches
  3. Ownership connection belongs to this workspace
  4. Permission customer.delete — granted
  5. Schema 2 arguments validated
  6. Policy needs a human DELETE · CRITICAL — approval required

Nothing was deleted. The run is waiting for someone to approve delete_customer — with exactly these 32 records.

Systems AgentOS connects to

  • MCP servers
  • REST APIs
  • OpenAPI 3
  • PostgreSQL
  • MySQL
  • Webhooks
  • Telegram
  • Slack
  • WhatsApp
  • Email

The difference

A chatbot answers.
An employee gets it done.

A chatbot

  • Reads what you pasted into it, and nothing else
  • Describes the steps you should take yourself
  • Forgets your systems the moment the tab closes
  • Has no idea who you are or what you may touch

An AgentOS agent

  • Reaches into the systems you connected, live
  • Carries the work out and reports what changed
  • Keeps a step-by-step trace you can audit later
  • Runs under your permissions, and stops when it should

Capabilities

Everything between “connect it” and “trust it”

One registry, whatever the source

An MCP server, a REST endpoint, an OpenAPI document and a SQL table all arrive as the same kind of thing: a described, schema-checked tool with a risk level attached.

  • read
  • create
  • update
  • delete
  • execute
  • export
  • analytics

Credentials the model never sees

Secrets are encrypted with a key separate from the application key and injected by the connector at call time — never a prompt, a response or a log.

Agents that draft themselves

Point AgentOS at a system and it proposes the tools, instructions and permissions. You review before anything is deployed.

Approval that actually binds

A decision authorises one call with exactly the arguments a person reviewed — re-planning cannot reuse it.

Traceable long after the fact

Intent, tool choice, policy decision and result are kept per run, in a tamper-evident chain.

One agent, wherever your team already is

Web chat, Telegram, WhatsApp, Slack and email reach the same runtime under the same policy set. Configure the agent once.

  • Web chat
  • Telegram
  • WhatsApp
  • Slack
  • Email
  • REST API

How it works

Four steps, then it is working for you

  1. 01

    Connect

    Give AgentOS a URL and a credential. It never leaves the vault in readable form.

  2. 02

    Discover

    Endpoints, tables and schemas are inspected and normalised into tools.

  3. 03

    Review

    You see the drafted agent — its tools, its limits, what needs approval — before deploying.

  4. 04

    Direct

    Ask in plain language. It works, reports back, and pauses when a human should decide.

Security model

The model is an untrusted planner

An LLM can propose delete_customer with any arguments it likes. That is a request, not an instruction — and AgentOS treats it as one.

  1. The tool exists, and this agent is allowed to use it
  2. Your workspace owns the underlying connection
  3. The acting user holds the required permission
  4. The arguments validate against the tool’s schema
  5. Policy permits this operation at this risk level
  6. A human has approved, when approval is required

Pricing

Start free. Pay when it earns its keep.

Free

$0 /mo

Connect one system and see an AI employee work.

Start free

Starter

$49 /mo

Put agents to work across a handful of systems.

Choose this plan
Most popular

Pro

$199 /mo

Multi-channel agents with human approval.

Choose this plan

Compare every plan feature by feature →

FAQ

Questions people ask first

Something not covered here? Ask us directly.

What can an AgentOS agent actually do?

Whatever the system you connect exposes. AgentOS inspects an MCP server, REST API, OpenAPI document or database and turns its capabilities into tools an agent can call — reading records, creating them, running reports. It cannot do anything the connected credential is not permitted to do.

Can the AI model see my credentials?

No. Credentials are encrypted with a key separate from the application key and are injected by the connector at call time. They are never placed in a prompt, a model response, a log line or a browser. The model only ever sees tool names and argument schemas.

What stops the AI deleting something it should not?

The model is treated as an untrusted planner: it proposes a call, and the platform independently verifies that the tool exists, the agent may use it, your workspace owns the connection, the acting user holds the permission, and the arguments match the schema. Destructive operations pause for human approval, and an approval authorises exactly one call with exactly the arguments that were reviewed.

Which AI providers are supported?

The runtime is provider-agnostic. Anthropic, OpenAI, Google and OpenAI-compatible endpoints are supported, and the provider is configuration rather than code — switching does not change how your agents behave.

Do I need to write any code?

No. You connect a system, AgentOS discovers what it can do, and you review the generated agent before deploying it. Editing instructions, enabling or disabling individual tools and deciding which ones need approval are all done in the interface.

What happens if my subscription lapses?

There is a grace period before anything changes. After it, paid features are restricted but nothing is deleted — your connections, agents, execution history and audit trail are preserved, and paying restores access immediately.

Put an AI employee to work this week

Connect one system, review the agent it drafts, and see what it takes off your plate. Free plan, no card required.