Self-hosted AI agent infrastructure.
The backend that powers Orquesta Terminal. Manage projects, agents, and teams.
Run on your own machine or a shared VM.
Orquesta Cloud · Terminal Product · Quick Start · Features
Orquesta OSS is the self-hosted backend for the Orquesta ecosystem. It provides:
- A project/agent management dashboard
- WebSocket server for real-time agent ↔ terminal communication
- Authentication (multi-user, for teams on shared VMs)
- Agent token management and session routing
- Local database (SQLite via Prisma)
It's the infrastructure layer that Orquesta Terminal connects to.
git clone https://github.com/Getorquesta/orquesta-oss.git
cd orquesta-oss
npm install
npx prisma db push
npm run devOpen http://localhost:3000 — create an account, create a project, generate an agent token.
Then connect an agent:
node agent/index.js --token oat_YOUR_TOKEN_HERECreate projects, invite team members, assign roles. Each project gets its own agent tokens and prompt history.
Agents connect via WebSocket with oat_ tokens. The server routes terminal sessions, relays events, and tracks heartbeats.
Built on better-auth — email/password login. Designed for teams sharing a dev VM where each person needs their own identity.
Real-time event relay between agents and the Terminal frontend:
session:start/input/output— PTY lifecyclehook:init-project— Hook enrollmentsessions:external-*— Import detection- Agent online/offline status
Every prompt executed through the system is logged with status, tokens used, git branch, and metadata.
Generate oat_ tokens per project. Tokens authenticate agents and scope them to specific projects.
┌─────────────────────────────┐
│ Orquesta Terminal │ ← The product (github.com/Getorquesta/orquesta-terminal)
│ (connects here) │
└──────────────┬──────────────┘
│
▼
┌═══════════════════════════════════════════════════════════┐
║ Orquesta OSS (this repo) ║
║ ║
║ ┌──────────┐ ┌──────────────┐ ┌───────────────────┐ ║
║ │ Next.js │ │ Socket.io │ │ Prisma + SQLite │ ║
║ │ API │ │ Server │ │ (data/dev.db) │ ║
║ └──────────┘ └──────────────┘ └───────────────────┘ ║
║ ║
║ ┌──────────────────┐ ┌──────────────────────────────┐ ║
║ │ better-auth │ │ Agent relay & routing │ ║
║ │ (multi-user) │ │ (session:*, hook:*, etc.) │ ║
║ └──────────────────┘ └──────────────────────────────┘ ║
╚═══════════════════════════════════════════════════════════╝
▲
│ oat_ token
│
┌──────────────┴──────────────┐
│ Agent (agent/index.js) │
│ Runs on your machine │
└─────────────────────────────┘
| Layer | Technology |
|---|---|
| Framework | Next.js 15 |
| Database | Prisma + SQLite |
| Auth | better-auth |
| Realtime | Socket.io |
| PTY | @homebridge/node-pty |
| Styling | Tailwind CSS v4 |
Copy .env.example to .env and configure:
DATABASE_URL="file:./data/dev.db"
BETTER_AUTH_SECRET="your-secret-here" # openssl rand -base64 32
BETTER_AUTH_URL="http://localhost:3000"BETTER_AUTH_SECRET signs your sessions — generate your own and keep it out of
git. Docker Compose reads it from the environment (or a local .env) and
refuses to start without one.
| Command | Description |
|---|---|
npm run dev |
Start dev server (port 3000) |
npm run build |
Production build |
npm start |
Start production server |
npx prisma db push |
Apply schema to database |
npx prisma studio |
Browse database |
Read SECURITY.md before putting this on a network: it covers the
BETTER_AUTH_SECRET requirement, how sessions and oat_ agent tokens are
authenticated, and what the agent can do on the host. Found a vulnerability?
Email security@getorquesta.com instead of opening an issue.
- orquesta-terminal — Terminal workspace product
- getorquesta.com — Hosted platform (cloud alternative)
MIT
