SLOPSHOPPER

intentic-guard

Keeps the sandbox's own decisions on tool calls final: a mod someone installs can neither answer nor overturn them.

newguard
A shopper browsing a rack in a slop shop
README

<a href="https://intentic.dev"><img src="docs/marketing/intentic-lotus.svg" alt="intentic lotus" width="76" height="76"></a>

<h1>intentic</h1>

Run Claude Code, Codex, Cursor and Gemini side by side, each on its own git worktree.<br> They keep working when you close the browser. Nothing lands until you read the diff.</p>

<a href="https://github.com/intentic/intentic/releases/latest"><img alt="Latest release" src="https://img.shields.io/github/v/release/intentic/intentic?sort=semver&amp;label=release&amp;labelColor=24211e&amp;color=e07b27"></a> <a href="LICENSE"><img alt="License: MIT" src="https://img.shields.io/badge/license-MIT-e07b27?labelColor=24211e"></a> <a href="#get-started"><img alt="Runs on Linux, macOS and Windows" src="https://img.shields.io/badge/runs%20on-Linux%20%C2%B7%20macOS%20%C2%B7%20Windows-e07b27?labelColor=24211e"></a> <a href="https://discord.gg/3veuzYp32T"><img alt="Join the Discord" src="https://img.shields.io/badge/chat-Discord-e07b27?logo=discord&amp;logoColor=white&amp;labelColor=24211e"></a>

<h3><a href="https://intentic.dev/demo/">Try the live demo</a> · <a href="https://intentic.dev/download">Download</a> · <a href="https://app.intentic.dev">Create a workspace</a></h3>

<a href="https://intentic.dev/demo/"> <img src="docs/marketing/readme/hero-light.jpg" alt="The intentic workspace: a board of coding agents in Attention, Active and Finished lanes, a plan for Stripe checkout waiting for approval in the docked chat, and the same board on a phone." width="100%"> </a>

<sub><a href="https://intentic.dev/docs">Docs</a> · <a href="https://intentic.dev/features/run/">Features</a> · <a href="https://intentic.dev/compare/">Compare</a> · <a href="https://intentic.dev/changelog/">Changelog</a> · <a href="https://discord.gg/3veuzYp32T">Discord</a></sub>

How it works

You hand out tasks, agents plan and work in parallel, and you review the result. All of it runs in a sandbox on a machine you control.

<img src="docs/marketing/readme/flow-light.png" alt="How a task moves through intentic in five steps: describe the task, approve the plan, run in parallel on separate git worktrees, walk away while runs continue, then review the diff and land it." width="100%">

Get started

  1. Sign in with Google. No card, no forms.
  2. Paste one command on the laptop, desktop or server that will host your sandbox. The setup page shows it with your code filled in, and the command offers to install Docker if it is missing.
   curl -fsSL https://intentic.dev/connect | sh -s -- <SETUP_CODE>

On Windows, use PowerShell or the desktop app for Windows and Linux. The tunnel dials out, so no ports need opening.

  1. Connect an AI account and give an agent its first task.

To try it before installing anything, open the live demo: the real app on a recorded workspace. The quickstart covers the desktop app, Docker Compose and scripted installs.

Features

Run a fleet of coding agents in parallel

One board shows every agent, sorted by who needs you. Each card shows the model, the branch, the diff size and the cost. Every agent works on its own git worktree, so ten agents never edit the same checkout.

<img src="docs/marketing/readme/board-light.png" alt="The fleet board: Attention, Active and Finished lanes holding agents on Claude Sonnet, Claude Opus, Claude Haiku and GPT-5.2 Codex, subagents under a parent run, a run started from Discord, a Land now button on finished work, and a banner offering to resume six runs when Codex has room again." width="100%">

Approve the plan before any code changes

Agents read the code, write a plan and wait. Approve it, or reply to keep planning. Permission modes range from plan-only to fully automatic, per turn.

<img src="docs/marketing/readme/plan-light.png" alt="The chat: a four-step plan for adding Stripe checkout, two things the plan needs from you (a secret and an image change), and a bar with Approve and Keep planning." width="100%">

Read every diff before it lands

Finished work waits on its branch with the agent's own report. Read it file by file, then land it or discard it.

<img src="docs/marketing/readme/review-light.png" alt="A finished agent run under review: its branch agent/soft-deletes, four changed files with line counts, the schema diff, a Land now button, and the agent's summary of what it did and what is left to decide." width="100%">

Close the browser. The agents keep going.

The sandbox is a daemon on your machine, not a browser tab. Terminals stay open and turns finish without you. Any browser reopens the same board, phone included.

<img src="docs/marketing/readme/phones-light.png" alt="Three phones showing the same sandbox: the fleet board, an agent's report on its branch, and the list of changed files waiting to land." width="100%">

Bring the AI plans you already pay for

Agents run on your own Claude, ChatGPT, Cursor, Google, Grok, Kimi or Z.ai account, or on a local model. intentic never meters tokens or adds a markup. Connect several accounts and see every plan's limits in one place.

<img src="docs/marketing/readme/providers-light.png" alt="Supported agents and plans: Claude Code on Claude Pro or Max, Codex on a ChatGPT plan, Cursor Pro, Gemini with a Google sign-in, SuperGrok, Kimi Code, GLM on the Z.ai Coding Plan, Meta with a Model API key, any ACP agent, and local models." width="100%">

<img src="docs/marketing/readme/usage-light.png" alt="The Usage page: a note that intentic will not charge these amounts, API-equivalent cost, turns, tokens and cache hit rate, then the plan limits of each connected Claude account and a summary that two of six accounts have room." width="100%">

Wire agents into your stack

Connect GitHub, PostgreSQL, Sentry, Stripe, Discord, SSH, a VPN or any MCP server. Each card shows what a connection adds before you save it. Credentials stay inside your sandbox.

<img src="docs/marketing/readme/capabilities-light.png" alt="The capability catalog grouped by Platform, Code and issues, Observability, Data, Communication and Business: Docker, GitHub, Sentry, PostgreSQL, Discord and Stripe among them, with the connected ones marked." width="100%">

Start agents on events

Wake an agent on a schedule, a push, a failed pipeline, a Sentry alert, a payment, an email or a Discord message. An optional check command decides whether each run starts. Every run shows up on your board.

<img src="docs/marketing/readme/automations-light.png" alt="Automations: a docs check after work lands, a nightly dependency audit, a Discord on-call responder, a certificate renewal reminder, a visitor chat and a CI failure webhook, plus templates for new ones." width="100%">

Where it runs

<img src="docs/marketing/readme/architecture-light.png" alt="Architecture: a browser, the desktop app or a phone reaches the sandbox over a private outbound tunnel. The sandbox is a Docker container on your machine holding agents on separate branches, terminals, browsers, MCP servers, code search and secrets. You review and land work into your repositories. intentic.dev keeps only your sign-in and the sandbox's address." width="100%">

  • The sandbox is a Docker container on your laptop, desktop or server. Put it on an always-on machine and work continues while your laptop sleeps.
  • The platform stores your sign-in and your sandbox's address. It never receives your files, prompts or credentials.
  • The sandbox, CLI, workspace and platform are all MIT-licensed, in this repository. Read what runs on your hardware before you run it.

How it compares

If you useExamplesintentic is
Coding agents and CLIsClaude Code, Codex, OpenCode, Gemini CLI, Kimi Codewhere you run them: one worktree each, a shared workspace, review before landing
AI code editorsCursor, GitHub Copilot, Zed, JetBrains AIa companion: keep your editor for inline work
Multi-agent workspacesConductor, Superset, T3 Code, Synara, Nimbalystthe closest alternative: MIT, any browser or phone, any Docker host
Cloud coding agentsDevin, Jules, Codex cloud, Claude Code on the webthe self-hosted option: your always-on machine, your accounts
Self-hosted assistantsOpenClaw, Hermes Agentfocused on repositories, branches and review

Each comparison page includes the case for picking the other product.

FAQ

Yes. Every sandbox, capability, automation and shared workspace is free, with no tiers or card. You pay your AI provider directly. An optional hosted sandbox exists for people who would rather not run a machine.

Claude Code (Opus, Sonnet, Haiku), Codex, Cursor, Gemini, Grok, Kimi Code, GLM and Meta's models, picked per conversation. Any ACP agent, such as OpenCode, connects as a capability, and local models run through llama.cpp or any OpenAI-compatible endpoint.

On your machine, as plain git. Your browser reaches the sandbox over a private tunnel. The platform never receives your files, and secret files such as .env never pass through the connection.

A computer with Docker and a Google account. No public IP, open ports or Cloudflare account. If Docker is missing, the installer offers to install it.

It can make mistakes, so it proposes a plan first and works on its own branch. You read every diff before it lands, environment changes need your approval, and permissions are adjustable per turn.

It is a working product, and it is new. Start with low-risk work and review the results. The changelog lists every release.

Community and contributing

Questions go to Discord, bugs to Issues. A star helps other developers find the project.

CONTRIBUTING.md covers setup, builds and checks, and ARCHITECTURE.md explains how the parts connect. Coding agents working in this repository start at AGENTS.md.

AreaWhat lives there
_editorThe web app you look at, plus desktop and mobile shells and the UI kit
_sandboxThe daemon that owns a project's sandbox, and the CLIs agents use inside it
_platformThe hosted plane: sign-in, sandbox registry, tunnels, database
_extensionsBundled extensions: agents, connectors, automations, viewers
_sharedContracts and SDKs more than one part is written against
_searchiq and lsp: how agents find code
_devicesWhat runs on your own machines: device agent, browser extension
_deployThe deployment tool: intent to running servers
_siteintentic.dev and the interactive demo
_toolsShared config, checks, test harnesses, maintainer scripts

The pictures in this README are drawn from the demo build by _site/site/scripts/readme. Run pnpm -C _site/site readme to redraw them.

License

MIT. Report security issues as described in SECURITY.md.

Source 1 files
hooks/register.mjs 20 lines
1// Intentic's policy mod for Claude Code. Loaded first (managed `prependPlugins`, ../../../managed-settings.json), it
2// holds one line: whether a tool call runs is decided by the sandbox, not by a mod someone installed.
3//
4// The daemon's guards (the command gate, secret rewriting and redaction, action rules, persona scope) are Agent SDK
5// callback hooks, which Claude Code dispatches as `classic.*` events and settles in `tool.check`. A user's mod runs
6// before both: answering `classic.PreToolUse` without passing it on means the daemon's hook never runs, and answering
7// `tool.check` with allow overturns its deny. Claude Code's own guard (`sec-default@builtin`) only holds hooks that
8// managed settings declare, which the daemon's are not. Measured on CLI 2.1.288 against a scripted model: both
9// routes ran a command the daemon had refused, and with this mod first neither did.
10//
11// `next.to(e, "builtin")` skips the users' mods for these events and lets the built-in mods and Claude Code's own
12// dispatch (settings hooks, plugin shell hooks, SDK callbacks) decide. A user's mod keeps every other event, including
13// `tool.call`, where it can still refuse a call or ask before one.
14const decidedBySandbox = ($, e, next) => next.to(e, "builtin");
15
16export function register(on) {
17    on("tool.check", decidedBySandbox);
18    on("classic.*", decidedBySandbox);
19}
20