Your own AI agent.
It keeps working when you leave.

An open-source autonomous agent you run yourself. It pursues goals, remembers, writes its own skills, talks to you on any chat app — and can hold a wallet that pays its own way, under hard caps.

$ curl -fsSL https://polyrob.dev/install.sh | bash
polyrob
$ polyrob run "Find five new open-source agent frameworks,
  compare them, and save a table with sources"

plan    3 steps
search  web · 14 results
browse  github.com · 5 repositories read
write   workspace/agent-frameworks.md
✓ done  5 rows · every row cites its source

$ polyrob chat
you  what did you find?
rob  Two of the five ship a stable release. The table
     is in your workspace — want me to watch them weekly?
Example session, shortened.
MITfree, self-hosted, no account
6chains it can trade on
9places to talk to it
anymodel — cloud or local
01 · Autonomy

Give it a goal. It works until it is done.

Most agents stop when the chat stops. POLYROB keeps a goal board, runs on a schedule and wakes itself to follow up. It is off until you switch autonomy on.

Durable goal board

A backlog that survives restarts. Goals can wait for other goals and retry after an outage.

Scheduled runs

Plain-language or cron schedules. Results arrive in your chat, with the files attached.

Self-wake

It returns to idle work to continue or follow up, with guards so it never loops.

Writes its own skills

It turns what worked into reusable skills — quarantined, scanned and reviewed before use.

Parallel sub-agents

It hands a subtask, or 2–5 in parallel, to child agents with a narrower toolset.

Questions that wait for you

When a job needs a decision, it asks on every owner channel and waits for your answer.

02 · Money & crypto

An agent with a wallet — and a guard it cannot talk past.

The agent can hold its own key, trade, deploy, bridge, invoice and get paid. Every money feature is off on a fresh install and switches on one by one. Every on-chain write goes through the same guard:

  1. 1Declarewhat leaves and what must arrive
  2. 2Simulateon a pinned RPC, before signing
  3. 3Assertbalance + approval changes match
  4. 4Capper-tx limit, daily cap, owner queue
  5. 5Sign & recordone ledger you can read back
EthereumBaseArbitrum PolygonRobinhood ChainSolana
Trade

Swaps on six chains

Uniswap V3 first with an aggregator fallback on EVM; Jupiter on Solana. Exact-amount approvals.

Research

Screens a token first

Liquidity, holders, LP lock, creator stake and history. A partial screen says it is partial.

Build

Deploys its own token

Fixed-supply ERC-20, verified byte for byte — no mint, no owner. Token-2022 on Solana.

Launch

Launchpad + fee claims

Create and seed on a launchpad, then claim the creator fees it earned.

Move

Cross-chain bridge

Arrival is proven by the destination balance. Not landed yet means in flight, not failed.

Connect

Any dapp, as a wallet

An injected wallet in its own browser lets it use sites with no API. Off-chain signatures are refused.

Call

Any contract

A generic write: the agent states the most that leaves and the least that returns; simulation decides.

Hold

NFTs

See, hold, send and revoke. There is deliberately no verb that grants approval.

Get paid

x402 + invoices

Pay per request in USDC, sell its own endpoints, send QR invoices and run subscriptions.

Identity

ERC-8004 on-chain

Registers as an on-chain agent with verifiable reputation that other agents can check.

Markets

Polymarket + Hyperliquid

Reads markets; orders are dry-run until you set the switches, the caps and approve.

Control

Caps, not taps

Sub-agents never spend. A session a stranger touched never reaches a money verb.

Payments & wallet guide →

03 · Tools

It uses real tools — and ships what it builds.

Web + real browser

A fast page reader for most pages, and a full browser to log in, click, fill forms and screenshot.

Structured web data

AnySite: 200+ sites (LinkedIn, Reddit, GitHub, SEC, jobs, reviews) through one tool. Perplexity search with citations.

MCP, both ways

Connect any MCP server and its tools appear. Or expose POLYROB to Claude Desktop, Cursor and others.

Code + files

Edits codebases, runs tests and code — locally, in hardened Docker or over SSH. Reads PDF, docx, CSV, JSON.

Publishes live apps

Puts a built app behind a public URL and keeps it running. You approve the first deploy.

Email, X and voice

Its own email inbox, its own X account (each post owner-approved) and local voice transcription.

04 · Channels

One agent. Every place you talk.

Each chat app is an adapter on one contract, so the same agent, memory and goals follow you. Send it photos and files; it sends files back. Run every channel in one process with polyrob gateway.

TerminalWeb consoleTelegram WhatsAppDiscordSlack SignalEmailX DMs

Live progress

Every channel shows the current step, tool, time, cost and any approval it waits on.

Group chats

Rooms get their own roles and a read-only toolset. Only the owner administers them.

Web console

Chat, Work, Money, Inbox and Agent views in one real-time console, with a command palette.

05 · Memory

It remembers what matters.

Hierarchical memory based on H-MEM, stored on your machine and on by default.

Organized in phases

A session summary, phase memories and recent steps — not one flat log.

Forgets by importance

Recency, relevance and frequency decide what stays — not age alone.

Knowledge base

Load folders into a knowledge base. Put @file, @url or @diff in a message.

Evolving identity

A fixed core you write, plus a self-model it refines — each edit reviewed first.

06 · Safety

You stay in charge.

  • Off until you turn it on. Autonomy, the wallet and each money feature are separate switches.
  • One stop that actually stops. /pause from any channel halts all autonomous work, and it survives a restart.
  • Untrusted input is data, never instructions. Web pages, emails and tool output are marked before the model sees them.
  • Four access roles. Owner, correspondent, group member or denied — strangers get a narrower toolset.
  • High-impact actions wait for you. Approvals fail closed on denial or timeout.
  • Skills are quarantined. Written or installed, each skill is scanned and reviewed before it can act.
  • Spend budgets. A run stops at its dollar limit and says so, instead of claiming success.
  • Your machine, your keys. No hosted version, no account, no dependency on us.

Security model →

07 · Under the hood

Built to run for months, not minutes.

Runtime
Python 3.11+ · Linux, macOS, WSL2 · SQLite storage, no external database
Models
Native multi-provider layer, no agent framework: OpenAI, Anthropic, Gemini, DeepSeek, OpenRouter, NVIDIA NIM — plus any compatible endpoint (Ollama, LM Studio, vLLM) in one YAML file. Switch mid-session.
Context
Prompt caching for stable prefixes, compaction for long sessions, optional extended thinking
Interfaces
CLI + REPL · REST API · OpenAI-compatible /v1 · A2A (JSON-RPC + SSE) · MCP server · Socket.IO console
Extend
Skills (SKILL.md), MCP servers, custom model providers
Instances
Isolated named profiles on one machine; export a profile as a package without its keys or memories
Build a product
Per-tenant isolation, usage metering, credits and x402 billing are in the core
Deploy
Installer or pipx · Docker · systemd service · Fly.io · updates with snapshot and rollback

Architecture →   Compare with other agents →

08 · FAQ

Questions

Is it free?

Yes. The whole engine is MIT-licensed, with no paid tier and no feature behind a paywall. You pay only your model provider — or nothing with a local model.

Which models can it use?

OpenAI, Anthropic, Gemini, DeepSeek, OpenRouter and NVIDIA NIM are built in, plus subscription and regional rows. Any OpenAI- or Anthropic-compatible endpoint — Ollama, LM Studio, vLLM, a company gateway — goes in one providers.yaml file.

Does it act on its own?

Only if you ask. A fresh install answers you and does the task you give it. Switch autonomy on and it keeps a goal board, runs schedules and follows up by itself.

Is it safe to give it a wallet?

The wallet is off by default. When on, every write is simulated and checked against what the agent declared, then a per-transaction limit, a daily cap and your approval queue apply. Start on a testnet with a small cap.

How do I stop it?

Send /pause from any channel, the CLI or the console. It stops all autonomous work, or one scope such as trading, and the stop survives a restart. /resume starts it again.

Where does my data go?

It stays on the machine you run it on. The only calls out go to your model provider and the tools you enable.

Is it a coding agent?

It edits code and runs tests, but it is a general agent: it browses, researches, messages, schedules, remembers and can hold a wallet. It runs as a long-lived service, not only in one terminal.

Can I move from Hermes or OpenClaw?

Yes. There are migration guides for Hermes and OpenClaw, and a dated comparison of what each project does.

Can I run it on a server for other people?

Yes. Run it as a service with the web console, the REST API or the OpenAI-compatible API. Tenant isolation, metering and credits are built in. See deployment postures.

Can I run more than one agent?

Yes. Named profiles give each agent its own keys, persona, skills, memory and goals on one machine.

How do I extend it?

Write a skill as a SKILL.md file, install one from a folder or a git repo, connect an MCP server or declare a new model provider. See skills.

What do I need to run it?

Python 3.11+ on Linux, macOS or WSL2 and one model key. The installer does the rest; the browser engine is optional.

Start in three steps

1

Install

One command. It finds Python 3.11+, adds the polyrob command and runs a setup wizard.

2

Connect a model

Paste a key from any provider, or point it at a local model.

3

Give it work

polyrob chat to talk, polyrob run "…" for one task.

$ curl -fsSL https://polyrob.dev/install.sh | bash

Prefer pip? pipx install "polyrob[all]" — see the install guide.