io.github.readyagentsdev/readyagents
OfficialProvides a docker compose command to run the ReadyAgents engine in a container.
Mentions the GitHub repository and issue tracker for the project.
Supported platform for running the engine.
Supported platform for running the engine.
The README includes an architecture diagram in Mermaid format, but this is not an integration target.
Mentions that core workflows using builtin tools do not need Node.js, but Node.js is not an integration target.
Allows agent workflows to use OpenAI's LLM models via a BYOK (bring your own key) setup.
Uses Pydantic for output_schema on agent nodes, but this is an implementation detail, not a service integration.
The package is distributed on PyPI and installable via pip.
The engine is written in Python and requires Python 3.11–3.14, and can be installed via pip.
Allows defining agent workflows as YAML files.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@io.github.readyagentsdev/readyagentsRun the calc_pipeline workflow and show me the result"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
ReadyAgents Core
ReadyAgents runs YAML agent workflows locally. Every node is checkpointed, so a run pauses for human approval, resumes from where it stopped, and replays offline as a regression test. Your keys, your machine, no daemon.
Site: readyagents.dev. Repo: github.com/readyagentsdev/readyagents-core.
Tried it? Open an I-ran-this issue. We are not launching. We are listening.
This repository is the free core. You keep the provider account and the bill. Install with pip install readyagentsdev, or from this clone.
60-second start
Requires Python 3.11–3.14 on Linux, macOS, or Windows. Current version is 2.0.10. Install with pip install readyagentsdev, or from this clone. The 2 versions the core contract only; extras carry their own maturity tiers.
pip install readyagentsdev
readyagents new my-flow
readyagents run my-flow/workflow.yaml
readyagents runs listThe wheel ships the example workflows too — no clone needed:
readyagents new f --from-example calc_pipeline
readyagents run f/workflow.yamlreadyagents new --list-examples shows all of them.
Or from a clone:
git clone https://github.com/readyagentsdev/readyagents-core.git
cd readyagents-core
python -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
pip install -e .
readyagents run examples/calc_pipeline.yaml
readyagents runs list
readyagents doctorreadyagents run examples/calc_pipeline.json is the same graph.
HITL next: docs/first-ten-minutes.md.
Related MCP server: OpenClaw MCP bridge
What it does
Define agent workflows as YAML or JSON (nodes + edges)
Run agent, tool, condition, transform, approval, parallel, include, foreach, and decide nodes. Agent nodes may declare a
tools:allowlist for a bounded tool-use loop.type: decideis experimental; see docs/decisions.md.Persist after every node and resume a paused or failed run from the last successful node
Inspect past runs:
readyagents runs list/show/replay/fork/diff/freeze/report(local HTML)Scaffold a starter:
readyagents new my-flow(basic,approval,research,pipeline,review,foreach,agent-tools,gated,decide)Builtin tools with zero extra servers:
now,calc,json_get,list_dir,read_file,write_fileMCP client and server (
readyagents mcp serve,readyagents mcp probe) with official tasks and MRTR approvalsPolicy, spend ledger, budgets and caps: per-node token/cost,
--estimate/--max-spendcaps, model fallback, JSON logs
Beyond the core, 40+ opt-in extras ship in the same install — teams, studio, browser, knowledge, distillation, registry, environments and more. Each is listed with its maturity tier and its limits in docs/extras.md. None of them is required, and none of them changes how the core behaves.
The agent firewall (taint, tool policy, MCP pinning — security model, policy) is defence in depth, not a solution to prompt injection.
Architecture
flowchart LR
YAML[Workflow YAML/JSON] --> Engine
subgraph Core["ReadyAgents Core"]
Engine[Workflow engine]
Tools[Builtin tools]
LLM[BYOK LLM providers]
MCP[MCP client / server]
Packs[Pack loader]
end
Engine --> Tools
Engine --> LLM
Engine --> MCP
Packs --> Engine
Packs --> Tools
LLM --> OpenAI[OpenAI]
LLM --> Anthropic[Anthropic]
LLM --> Compat[OpenAI-compatible]CLI
Command | Purpose |
| Write |
| Scaffold workflow + README + |
| Import n8n / LangGraph / CrewAI / trigger-action exports (structural translation only) |
| Schema-validate a workflow (source-located errors on failure) |
| Print/write/check the generated workflow JSON Schema |
| Score a keyless fixture suite (exit 0/1) |
| Declaration-driven cases scored with eval; distinct failures frozen |
| Reflective prompt optimization against your eval suite |
| Versioned prompts beside the workflow; rollback restores exactly |
| Declared environments and pinned releases |
| Local agent inventory from declared roots (Annex VIII export is a draft) |
| Local one-node adapters from consented runs (pack trains; holdout required) |
| Copy a source pin onto a target after eval/fixture/bench/health/approval gates |
| Restore the previous release atomically; never auto-forwards |
| Consent-gated correction datasets (production data) |
| Execute (or |
| Foreground: one workflow, many JSONL/CSV rows (opt-in) |
| Data-residency attestation (technical evidence, not legal compliance) |
| Offline wheel set for |
| Resume a paused or failed run |
| Evaluate wait conditions (lazy; starts no timer or daemon) |
| Inject a signed event (unsigned events are refused) |
| Validate a firewall policy file (fail closed) |
| Show which tools each node may call and why |
| Local evidence pack |
| Walk the hash-chained audit trail |
| TokenOps: aggregate the local spend ledger (informational vs the provider invoice) |
| Deterministic Mermaid routing (executes nothing) |
| Inject an approval; |
| Queue of paused gates the caller may see |
| Time-bounded, single-hop, revocable approval delegation |
| List or revoke local delegations |
| Verify an assertion against local trust anchors |
| Workload fingerprint (never the private key) |
| List persisted runs |
| Node timeline + stored state ( |
| Local HTML summary of a run |
| New run from stored inputs |
| Delete one local run record |
| Prune succeeded/failed/cancelled runs (paused kept; in-window records refused unless |
| Time machine: fork a run, diff two, freeze a cassette, migrate JSON→SQLite |
| Small governed catalog ( |
| Supply-chain: signatures prove origin, not safety |
| Foreground localhost approval page |
| Foreground localhost canvas and run inspector |
| Dry model catalog and routing explain (no provider call) |
| Stdio MCP server (builtin tools); |
| Read-only |
| Foreground A2A door for one workflow (loopback by default) |
| Deterministic Agent Card (no network) |
| Read-only remote card diagnostic (no secret values) |
| Local scoped memory (offline except optional embeddings) |
| Ingest, sync, cite, and forget knowledge documents (foreground only) |
| Inspect intermediate tables: head, schema, stats |
| Inspect declared triggers, dry-run mappings, list events (starts no listener) |
| Install, list, export, and remove Agent Skills (open format; no marketplace) |
| Emit project context: how to run, validate, and test workflows here |
| Build, install, and catalog workflow packages (review-before-install) |
| Cluster failures by fingerprint over the run store (no daemon, no telemetry) |
| Offline-by-default benchmark suite with labelled engine vs live timing |
| List, show, close, replay, and freeze conversational sessions (turns are runs) |
| Foreground loopback surfaces (stops with the process) |
| List installed / local packs |
| Read-only platform / extras / permissions / loopback / run-store / sovereign diagnostic |
| Print version |
Examples (no keys unless noted)
File | What it shows |
| Builtin tools, transform, condition |
| Same graph as |
| Human-in-the-loop pause / resume |
| Keyless loopback OpenAI-compat path (no live model) |
| Two-approver gate (keyless) |
| Lazy deadline, |
| Two sequential approval gates |
| Parallel branches + approval |
| Sub-workflow |
| Include + parallel + approval ( |
| Agent node (needs a key) |
| Classify then branch (needs a key) |
|
|
| Agent |
| Sequential foreach + |
| Policy gate on tainted |
| Starter firewall policy |
|
|
|
|
| Builtin |
| Keyless |
|
|
|
|
|
|
| Keyless |
| Keyless |
| Local |
| Approval then |
| Keyless env deploy + |
Docs
Connectors (small catalog; write-shaped ops gate by default)
Sovereign mode (in-process egress refuse, not an OS sandbox)
Cost / TokenOps (informational vs the provider invoice)
Time machine (record / replay / fork / diff / freeze)
A2A (untrusted remote content; delegation can exfiltrate; not certification)
Memory (untrusted; delayed injection and scope escape)
Scale and batch (opt-in foreground batch; benchmarks labelled engine vs live)
Streaming (opt-in
--stream; not audio)Guardrails / output contracts (opt-in
contract:; declared rules)Multi-agent teams (opt-in
type: team; closed members; no quality claim)Model routing (opt-in
routing:; declared policy)Multimodal I/O (opt-in
MediaPart/type: document/type: transcribe; extras; not an OCR claim)Knowledge pipelines (opt-in
type: ingest; citations/freshness)Data pipelines (opt-in
type: table/type: classify)Long-horizon waits (opt-in
type: wait; lazywake)Event triggers (opt-in
triggers:; no listener in core; at-least-once plus idempotency)Agent Skills (opt-in
type: skill; open format)Governed browser use (opt-in
type: browser; declared actions; no CAPTCHA; optional pack)Conversational sessions (opt-in
type: converse; loopbackserve chat; no audio in core)Environments and rollout (opt-in
readyagents.env.yaml; pinned releases; gated promote)Migration (opt-in
readyagents import; structural translation only)Agent registry (opt-in
readyagents registry; declared roots; draft Annex VIII export)Distillation (opt-in
readyagents distill; pack-owned training; holdout-gated adapters)Packaging (opt-in
readyagents package; review-before-install)Simulation (opt-in
readyagents simulate; declaration-driven cases)Self-healing (opt-in
readyagents health/recovery:; fingerprints and fail-safe gates)Benchmarks (opt-in
readyagents bench; offline cassettes)Supply-chain trust (signatures prove origin, not safety)
Continuous pack (optional, separate distribution)
Compliance evidence (Articles 12–14 mapping; not certification)
Install extras
LLM and MCP extras are optional.
pip install "readyagentsdev[openai]"
pip install "readyagentsdev[anthropic]"
pip install "readyagentsdev[gemini]"
pip install "readyagentsdev[bedrock]"
pip install "readyagentsdev[vertex]"
pip install "readyagentsdev[mcp]"
pip install "readyagentsdev[all]"
pip install "readyagentsdev[image]"
pip install "readyagentsdev[pdf]"
pip install "readyagentsdev[audio]"
pip install "readyagentsdev[table]"From a clone, the same extras are pip install -e ".[openai]" (and anthropic /
gemini / bedrock / vertex / mcp / all). The optional [otel] extra is
not included in [all]; it starts no collector (see
observability.md). The optional [sign] extra (Ed25519
artifact signatures), [jwt], [gemini], [bedrock], [vertex], [image],
[pdf], [audio], and [table] extras are also not in [all]. Unsigned default runs
never import them. Codecs are extras; core installs stay text-only. Pandas is
optional for table ops; stdlib is sufficient.
Then cp .env.example .env and paste your own keys. Core workflows that only use builtin tools do not need extras, keys, or Node.js.
docker compose run --rm readyagents run examples/calc_pipeline.yaml
make smokeWhat is not in this repository
Always-on packs are waitlisted and not for sale.
Always-on / continuous workers are not in Core. The optional readyagents-pack-continuous distribution (separate repository, not a Core extra) can run configured workflows from an explicit foreground command. Installing Core still starts no scheduler or listener.
Hosted control plane. Hosted recovery and remote run stores. SSO, multi-tenant teams, billing.
The core has persist, resume, and approval pauses for a local one-shot. It does not run always-on.
License
Apache License 2.0. See LICENSE.
Security
Please report vulnerabilities as described in SECURITY.md. Public contact: info@readyagents.dev. Do not commit API keys. Local operator files such as .env are gitignored.
This server cannot be deployed
Maintenance
Related MCP Connectors
Workflow diagnostics, capability routing, and x402 settlement for MCP-compatible agents.
Nifty's MCP server — exposes tasks, projects, messages, and files as tools for AI agents.
Open-source Zapier/n8n alternative as an MCP server: agents build, run and debug your workflows.
Agent-native collaboration network: orchestrate a team of long-running agents from any MCP client.
Related MCP Servers
- AlicenseAqualityBmaintenanceEnables an AI agent to run local tools on the user's own machine via stdio, including command execution, workspace file read/write, and system status checks.52MIT
- AlicenseNot gradedqualityCmaintenanceExposes OpenClaw gateway tools to MCP clients like Claude Code and Codex, enabling local tool calls, file operations, and subagent session management through a stdio MCP server.195 npmMIT
- AlicenseNot gradedqualityBmaintenanceEnables MCP clients to run declarative agents and DAG workflows as plain tools, with parallel nodes, review loops, and per-run least-privilege sandboxing.6 npmMIT
- FlicenseNot gradedqualityBmaintenanceEnables MCP clients to discover and execute operational tools such as database mutations and system diagnostics over stdio, with deterministic structured outputs and Langfuse observability.-