Operator or individual
CLI or small console
Create Agents and Sessions, follow streamed Items, return function results, and manage Vault credentials.
rat-things sessions list
A cloud for your agents · Self-hosted in your AWS account
Run durable, isolated agents in your AWS account. Hand off from local Codex, start work from Slack or Linear, trigger it from a schedule or your product, and let bounded tasks keep running without your laptop.
Engineering preview · self-hosted in your AWS account · not ready for untrusted multi-tenant production
Local Codex is one fast path into Rat Things. The AWS backend becomes a durable execution layer when a task needs time, parallel agents, schedules, connected accounts, or an entry point beyond your laptop.
Bring the Codex access included with your ChatGPT plan—no OpenAI Platform API key or Bedrock setup required—or start from Slack, Linear, a schedule, your product, or the API.
npm ci
npm run codex:login
# official ChatGPT browser login
rat-things local \
"Inspect this repo and fix the test"
local Codex → local tools → local files
rat-things sessions create \
--file session.json
Agent → Session → Turns and Items
Rat Things is a self-hosted AWS stack with no central Rat service. A CLI, your product, another agent, a schedule, or a signed provider event can use the same public API and durable Session model.
Operator or individual
Create Agents and Sessions, follow streamed Items, return function results, and manage Vault credentials.
rat-things sessions list
Embedded product
Keep customer identity and the provider app in your product or AWS account. The self-hosted Rat stack can run PKCE callbacks and refresh; credentials remain in your Secrets Manager.
POST /v1/agents
Agent-to-agent
Give an agent the deployment URL. It discovers the installed contract, starts with Agents and Sessions, and opens deeper controls only when needed.
GET /.well-known/rat-things
Agent quickstart
Events and schedules
Schedules select an owned Agent and environment. Signed provider events submit Session input through separate authenticated ingress.
cron(0 8 ? * MON-FRI *)
The host decides whether one deployment serves one person or many authenticated users. Rat derives an owner from each trusted principal and keeps Agents, Sessions, Vaults, and files within that boundary.
Start with an approved request in Slack. Let one isolated Session find the source context, check Linear for existing work, and create or update the issue through exact OAuth-backed operations.
Slack and Linear are separate verified Connections. The agent receives only the accounts and operations admitted before launch; neither credential enters its prompt or workspace.
Explore integrations, accounts, and permissionsResolve the security review and confirm the rollout owner before the annual renewal is finalized.
Created from the approved #customer-ops decision. Added the two open items and rollout note.
Just now · app actorConnect Slack and Linear through deployment-owned OAuth. Rat verifies each provider identity and stores issued credentials in the host vault.
Select the Slack read and Linear read/write operations this Session needs. Provider scopes, grants, profiles, and resource limits all intersect.
Search the source thread and existing issues first. The agent can create, update, or comment only through reviewed GraphQL documents.
The Slack thread, Linear result, Turn and Item history, generated files, and native Codex context remain traceable across clients and compute.
Connect both accounts, choose what Rat Things can do, and keep every handoff tied to the conversation that started it.
Install a verified Linear workspace, choose its account and operation grants, and expose the needed actions through declared MCP or application-function tools.
Sessions retain tool activity and results. Keep notification delivery separate from tool access, and enforce duplicate-creation protection in the tool implementation.
Set up LinearLinear, Slack, and Stripe are built-in examples of Rat's Integration Contract, not the boundary of the system. Add the OAuth or API services your deployment needs by declaring authentication, account identity, operations, schemas, and a fixed provider origin—then compile each reviewed adapter into the trusted host.
The connection manager, permission intersection, credential broker, agent tools, CLI, and desktop controls reuse that contract instead of inventing a new integration path.
Build a trusted integrationPublish authentication choices, account metadata, operation schemas, access levels, and required provider scopes.
Resolve the provider's real tenant and subject before a credential becomes an installed Connection.
Intersect provider authority, the persistent grant, the profile, and declared tools and resource constraints.
Generate safe account setup, health, reconnect, “used by,” and agent-tool surfaces from the installed contract.
Bind signed provider events and schedules to owned Agents and submit work through Sessions.
Extensions are trusted host code. Rat does not load arbitrary provider packages inside the agent. Credentials stay in the host vault, provider calls use reviewed adapters, and the agent receives only admitted operation schemas.
The reference console creates Sessions, displays streamed Items, submits function results, and cancels active Turns. Saved history remains available after a reload.
Manage reusable Agents and write-only Vault credentials from the same authenticated client.
rat-things sessions listreads the same durable Session resources.
rat-things consoleopens the local signed client for your deployment.
The reference console and CLI use the same Agents, Sessions, Turns, Items, environments and Vault contracts.
Accepted input belongs to a durable Session Turn. Rat stores Items and artifacts outside compute. S3 Files preserves workspace and native checkpoints for replacement workers; interrupted processes are not recreated by file recovery.
Verify IAM or a provider signature and derive the owner.
Commit Session input with an idempotent receipt.
Resolve the saved Agent configuration and restore available native state.
Launch or resume Codex with the tools and access resolved before the run.
Retain Turn Items and saved artifacts. Delete the Session when its worker is no longer needed.
Choose permissions before creating a Session. The agent can use what you allowed; everything else is unavailable. Rat never pauses to ask for more permission during a Turn.
Read the complete capability contractInside the envelope
Admitted shell, files, browser actions, network destinations, and connected-account operations are available within the resolved Session configuration.
Outside the envelope
The tool is missing, IAM returns AccessDenied, URL or egress policy blocks the destination, or the broker rejects the operation before reading a credential.
No suspended permission state: denied operations do not create approval requests. To change authority, configure an Agent and create a new Session with the required tools and environment.
Configure an Agent, start a Session, or bind it to a rate or cron schedule.
Verify several accounts per integration, monitor health, reconnect the same identity without rebinding workflows, and narrow provider access before use.
Expose browser operations through functions or MCP, constrain their access, and retain selected screenshots and recordings as Session artifacts.
Read Turns and Items, send follow-up input, submit function results, and continue work across clients.
Keep generated files privately, inspect them through owner-gated viewers, or create expiring external links.
API calls, schedules and signed provider events use the same Agent, Session, Turn and Item primitives.
Discover OpenAPI, JSON Schemas, integration manifests, stable errors, and capability profiles from each deployment.
Use the Codex access included with your ChatGPT plan locally, then delegate explicitly to OpenAI-authenticated cloud agents. Bedrock is optional.
Sessions, files, schedules, connections, and results live outside ephemeral compute. Each Session resolves its authority before execution and retains Turns and Items for connected clients.
Choose provider accounts and grants before launch. Keep provider credentials in the configured vault or trusted tool service.
The console, CLI and API read the same durable Turns and Items. Signed provider bindings add input and deliver saved results.
Retain native checkpoints and workspace files outside the worker. Recovery uses saved state; live processes require the original connected worker.
Read Session activity and saved Items, continue with new input, and download selected artifacts through the authenticated API.
Manual work, durable schedules, and signed provider events use the same Session lifecycle and saved-result delivery model.
Your deployment pays for its API and relay baseline, connected workers, model usage, storage and networking. A worker that preserves live processes continues to consume compute while idle.
Understand the cost driversAccount for the complete deployment
Measure startup, continuation and cost in your own region with the selected backend and model. Retention policies and explicit Session deletion control resources that outlive a Turn.
Your product, another agent, a CLI, or a signed event submits work. Rat authenticates it, accepts a Session input, executes it in your AWS account, and retains the result.
Architecture guide