Skip to main content
Glama
README.md
# OpenTool

A self-hostable gateway for agent tools, with Supabase authentication, scoped agent keys, provider credentials, permissions, accounting reservations, REST, and MCP.

The runtime dispatches real provider requests. There is no demo fallback. Unconnected providers fail explicitly. The catalog contains 25 bounded operations; each needs its own permitted provider account. Automated contract tests are separate from paid-provider acceptance and must not be represented as live verification.

- [Setup and development](docs/development.md)
- [Provider support and verification](docs/providers.md)
- [Contribution guide](CONTRIBUTING.md)
- [Security and publication controls](security/RELEASE.md)

Supabase is the application database and authentication service. MCP uses expiring keys scoped to a single agent. Browserbase uses a separate bounded Node worker. Platform AI features must use OpenRouter; catalog lookup and provider execution do not require a model.

Internal accounting allowances are configured by the owner. They are not supplier-confirmed charges or guaranteed spending caps on a BYOK account. Pending and ambiguous outcomes retain reservations. Manual reconciliation records the owner's supplier reference and charge attestation.

This repository is not a security certification or a claim that every provider has passed paid acceptance. Release only after the deployment-specific gates in the development guide pass.