Workspace
- Multi-model chat with per-session engine switching
- Streaming over SSE; reconnect and replay without message loss
- Mid-run steering
- Automatic context compaction + /compact
- Session search / pin / share, file attachments
Apache-2.0 · Self-hosted · v0.6
The self-hosted workspace for team agents — agents do the work, your team keeps control. Engines are pluggable (faux / pydantic-ai / ACP driving Claude Code, Gemini CLI), and SSO, auditing, and cost attribution are all built into the community edition.
$ make init && cd deploy$ docker compose -f compose.demo.yml up -d --build --wait# Open http://localhost:3000/register — the first-run wizard guides you to demo modeWHY INAGENT
| Capability | InAgent (Apache-2.0 community edition) | The category norm |
|---|---|---|
| SSO (OIDC + PKCE) | Built in — org-level config, JIT provisioning, enforced SSO domains | Commonly behind an enterprise paywall |
| Audit logs | append-only storage, admin UI, CSV export | Usually an enterprise tier or a paid plugin |
| Usage / cost attribution | Four levels (org / workspace / user / session) with an aggregate view | Cost reports are typically a paid feature |
| Trace observability | OTel + trace waterfall UI | Trace viewers are typically a paid feature |
| HITL oversight | Native: command approval cards / structured questions / permission requests routed to approval | Mostly bolt-on toolkits or external layers |
| Coding agent engines | ACP drives Claude Code / Gemini CLI inside the governance sandbox | Locked to a homegrown runtime, or no support for external coding agents |
| Secret governance | AES-GCM vault encryption at rest, keys never echoed back, egress placeholder substitution | Plaintext environment variables or basic encryption |
CAPABILITIES
DEPLOY
$ make init$ cd deploy$ docker compose -f compose.demo.yml up -d --build --wait$ cp ../.env.example .env$ docker compose up -d --build --wait# demo → full: data stays in placeChina-region registry-mirror overlay, offline air-gapped installs, OTel observability — for the full deployment matrix see the ops manual.
FAQ
Plenty of teams only discover at procurement that SSO, audit logs, and usage reports are gated behind an expensive enterprise tier — the community calls this the SSO tax. InAgent's commitment: SSO, auditing, cost attribution, and trace viewing are all in the community edition. The project is Apache-2.0 with no enterprise edition and no held-back feature flags — what you deploy is the complete product.
Every (user, workspace) pair gets one persistent container: non-root (uid 1000), memory / CPU / PID limits, and the default seccomp profile. Secrets never enter the sandbox. For production, we recommend a docker socket proxy instead of mounting the socket directly; when you need egress control, enable the egress MITM proxy profile — secrets are injected as placeholders and swapped for real values at the network boundary, with auditing.
Yes. Engines are pluggable through the RuntimeAdapter SPI: the faux demo engine needs no API key at all; pydantic-ai targets multiple providers (four tiers plus a fallback chain); and the ACP adapter drives real coding agents such as Claude Code / Gemini CLI. Switching happens per session — you are never tied to a homegrown runtime.
Yes. Run deploy/scripts/airgap-export.sh on a networked machine to export a deployment bundle, then docker load on the target machine and bring the stack up offline. For China-region environments there is also a registry-mirror overlay (covering base images and the pnpm registry), so you can build without a proxy.
The Feishu / DingTalk bots run as the bound user and support streaming cards, HITL button approvals and question cards, and artifact delivery. Automation results can also be delivered to Feishu. DingTalk uses a long-lived Stream connection, so no public callback endpoint is needed.