Keeps the sandbox's own decisions on tool calls final: a mod someone installs can neither answer nor overturn them.

<a href="https://intentic.dev"><img src="docs/marketing/intentic-lotus.svg" alt="intentic lotus" width="76" height="76"></a>
<h1>intentic</h1>
Run Claude Code, Codex, Cursor and Gemini side by side, each on its own git worktree.<br> They keep working when you close the browser. Nothing lands until you read the diff.</p>
<a href="https://github.com/intentic/intentic/releases/latest"><img alt="Latest release" src="https://img.shields.io/github/v/release/intentic/intentic?sort=semver&label=release&labelColor=24211e&color=e07b27"></a> <a href="LICENSE"><img alt="License: MIT" src="https://img.shields.io/badge/license-MIT-e07b27?labelColor=24211e"></a> <a href="#get-started"><img alt="Runs on Linux, macOS and Windows" src="https://img.shields.io/badge/runs%20on-Linux%20%C2%B7%20macOS%20%C2%B7%20Windows-e07b27?labelColor=24211e"></a> <a href="https://discord.gg/3veuzYp32T"><img alt="Join the Discord" src="https://img.shields.io/badge/chat-Discord-e07b27?logo=discord&logoColor=white&labelColor=24211e"></a>
<h3><a href="https://intentic.dev/demo/">Try the live demo</a> · <a href="https://intentic.dev/download">Download</a> · <a href="https://app.intentic.dev">Create a workspace</a></h3>
<a href="https://intentic.dev/demo/"> <img src="docs/marketing/readme/hero-light.jpg" alt="The intentic workspace: a board of coding agents in Attention, Active and Finished lanes, a plan for Stripe checkout waiting for approval in the docked chat, and the same board on a phone." width="100%"> </a>
<sub><a href="https://intentic.dev/docs">Docs</a> · <a href="https://intentic.dev/features/run/">Features</a> · <a href="https://intentic.dev/compare/">Compare</a> · <a href="https://intentic.dev/changelog/">Changelog</a> · <a href="https://discord.gg/3veuzYp32T">Discord</a></sub>
You hand out tasks, agents plan and work in parallel, and you review the result. All of it runs in a sandbox on a machine you control.
<img src="docs/marketing/readme/flow-light.png" alt="How a task moves through intentic in five steps: describe the task, approve the plan, run in parallel on separate git worktrees, walk away while runs continue, then review the diff and land it." width="100%">
curl -fsSL https://intentic.dev/connect | sh -s -- <SETUP_CODE>
On Windows, use PowerShell or the desktop app for Windows and Linux. The tunnel dials out, so no ports need opening.
To try it before installing anything, open the live demo: the real app on a recorded workspace. The quickstart covers the desktop app, Docker Compose and scripted installs.
One board shows every agent, sorted by who needs you. Each card shows the model, the branch, the diff size and the cost. Every agent works on its own git worktree, so ten agents never edit the same checkout.
<img src="docs/marketing/readme/board-light.png" alt="The fleet board: Attention, Active and Finished lanes holding agents on Claude Sonnet, Claude Opus, Claude Haiku and GPT-5.2 Codex, subagents under a parent run, a run started from Discord, a Land now button on finished work, and a banner offering to resume six runs when Codex has room again." width="100%">
Agents read the code, write a plan and wait. Approve it, or reply to keep planning. Permission modes range from plan-only to fully automatic, per turn.
<img src="docs/marketing/readme/plan-light.png" alt="The chat: a four-step plan for adding Stripe checkout, two things the plan needs from you (a secret and an image change), and a bar with Approve and Keep planning." width="100%">
Finished work waits on its branch with the agent's own report. Read it file by file, then land it or discard it.
<img src="docs/marketing/readme/review-light.png" alt="A finished agent run under review: its branch agent/soft-deletes, four changed files with line counts, the schema diff, a Land now button, and the agent's summary of what it did and what is left to decide." width="100%">
The sandbox is a daemon on your machine, not a browser tab. Terminals stay open and turns finish without you. Any browser reopens the same board, phone included.
<img src="docs/marketing/readme/phones-light.png" alt="Three phones showing the same sandbox: the fleet board, an agent's report on its branch, and the list of changed files waiting to land." width="100%">
Agents run on your own Claude, ChatGPT, Cursor, Google, Grok, Kimi or Z.ai account, or on a local model. intentic never meters tokens or adds a markup. Connect several accounts and see every plan's limits in one place.
<img src="docs/marketing/readme/providers-light.png" alt="Supported agents and plans: Claude Code on Claude Pro or Max, Codex on a ChatGPT plan, Cursor Pro, Gemini with a Google sign-in, SuperGrok, Kimi Code, GLM on the Z.ai Coding Plan, Meta with a Model API key, any ACP agent, and local models." width="100%">
<img src="docs/marketing/readme/usage-light.png" alt="The Usage page: a note that intentic will not charge these amounts, API-equivalent cost, turns, tokens and cache hit rate, then the plan limits of each connected Claude account and a summary that two of six accounts have room." width="100%">
Connect GitHub, PostgreSQL, Sentry, Stripe, Discord, SSH, a VPN or any MCP server. Each card shows what a connection adds before you save it. Credentials stay inside your sandbox.
<img src="docs/marketing/readme/capabilities-light.png" alt="The capability catalog grouped by Platform, Code and issues, Observability, Data, Communication and Business: Docker, GitHub, Sentry, PostgreSQL, Discord and Stripe among them, with the connected ones marked." width="100%">
Wake an agent on a schedule, a push, a failed pipeline, a Sentry alert, a payment, an email or a Discord message. An optional check command decides whether each run starts. Every run shows up on your board.
<img src="docs/marketing/readme/automations-light.png" alt="Automations: a docs check after work lands, a nightly dependency audit, a Discord on-call responder, a certificate renewal reminder, a visitor chat and a CI failure webhook, plus templates for new ones." width="100%">
<img src="docs/marketing/readme/architecture-light.png" alt="Architecture: a browser, the desktop app or a phone reaches the sandbox over a private outbound tunnel. The sandbox is a Docker container on your machine holding agents on separate branches, terminals, browsers, MCP servers, code search and secrets. You review and land work into your repositories. intentic.dev keeps only your sign-in and the sandbox's address." width="100%">
| If you use | Examples | intentic is |
|---|---|---|
| Coding agents and CLIs | Claude Code, Codex, OpenCode, Gemini CLI, Kimi Code | where you run them: one worktree each, a shared workspace, review before landing |
| AI code editors | Cursor, GitHub Copilot, Zed, JetBrains AI | a companion: keep your editor for inline work |
| Multi-agent workspaces | Conductor, Superset, T3 Code, Synara, Nimbalyst | the closest alternative: MIT, any browser or phone, any Docker host |
| Cloud coding agents | Devin, Jules, Codex cloud, Claude Code on the web | the self-hosted option: your always-on machine, your accounts |
| Self-hosted assistants | OpenClaw, Hermes Agent | focused on repositories, branches and review |
Each comparison page includes the case for picking the other product.
Yes. Every sandbox, capability, automation and shared workspace is free, with no tiers or card. You pay your AI provider directly. An optional hosted sandbox exists for people who would rather not run a machine.
Claude Code (Opus, Sonnet, Haiku), Codex, Cursor, Gemini, Grok, Kimi Code, GLM and Meta's models, picked per conversation. Any ACP agent, such as OpenCode, connects as a capability, and local models run through llama.cpp or any OpenAI-compatible endpoint.
On your machine, as plain git. Your browser reaches the sandbox over a private tunnel. The platform never receives your files, and secret files such as .env never pass through the connection.
A computer with Docker and a Google account. No public IP, open ports or Cloudflare account. If Docker is missing, the installer offers to install it.
It can make mistakes, so it proposes a plan first and works on its own branch. You read every diff before it lands, environment changes need your approval, and permissions are adjustable per turn.
It is a working product, and it is new. Start with low-risk work and review the results. The changelog lists every release.
Questions go to Discord, bugs to Issues. A star helps other developers find the project.
CONTRIBUTING.md covers setup, builds and checks, and ARCHITECTURE.md explains how the parts connect. Coding agents working in this repository start at AGENTS.md.
| Area | What lives there |
|---|---|
| _editor | The web app you look at, plus desktop and mobile shells and the UI kit |
| _sandbox | The daemon that owns a project's sandbox, and the CLIs agents use inside it |
| _platform | The hosted plane: sign-in, sandbox registry, tunnels, database |
| _extensions | Bundled extensions: agents, connectors, automations, viewers |
| _shared | Contracts and SDKs more than one part is written against |
| _search | iq and lsp: how agents find code |
| _devices | What runs on your own machines: device agent, browser extension |
| _deploy | The deployment tool: intent to running servers |
| _site | intentic.dev and the interactive demo |
| _tools | Shared config, checks, test harnesses, maintainer scripts |
The pictures in this README are drawn from the demo build by _site/site/scripts/readme. Run pnpm -C _site/site readme to redraw them.
MIT. Report security issues as described in SECURITY.md.
hooks/register.mjs 20 lines1// Intentic's policy mod for Claude Code. Loaded first (managed `prependPlugins`, ../../../managed-settings.json), it
2// holds one line: whether a tool call runs is decided by the sandbox, not by a mod someone installed.
3//
4// The daemon's guards (the command gate, secret rewriting and redaction, action rules, persona scope) are Agent SDK
5// callback hooks, which Claude Code dispatches as `classic.*` events and settles in `tool.check`. A user's mod runs
6// before both: answering `classic.PreToolUse` without passing it on means the daemon's hook never runs, and answering
7// `tool.check` with allow overturns its deny. Claude Code's own guard (`sec-default@builtin`) only holds hooks that
8// managed settings declare, which the daemon's are not. Measured on CLI 2.1.288 against a scripted model: both
9// routes ran a command the daemon had refused, and with this mod first neither did.
10//
11// `next.to(e, "builtin")` skips the users' mods for these events and lets the built-in mods and Claude Code's own
12// dispatch (settings hooks, plugin shell hooks, SDK callbacks) decide. A user's mod keeps every other event, including
13// `tool.call`, where it can still refuse a call or ask before one.
14const decidedBySandbox = ($, e, next) => next.to(e, "builtin");
15
16export function register(on) {
17 on("tool.check", decidedBySandbox);
18 on("classic.*", decidedBySandbox);
19}
20