OMA
Agents your organization can own, approve, and audit.
OMA (Open Multi-Agent) is a self-hosted TypeScript agent runtime: consequential actions wait for durable, tamper-evident approvals, and every run leaves a record you can verify offline, byte for byte.
Website · Docs · Examples · npm
English · 中文
No telemetry. No hosted control plane. Your keys, your models — cloud, local (Ollama, vLLM, llama-server), or Chinese providers — your environment. Nothing stops working when the people who built it leave.
Get started
Requires Node.js 20 or newer. For production, use a currently maintained Node.js LTS release. Node.js 20 is upstream-EOL and retained only as a migration compatibility window; OMA will remove it in the next major release, no earlier than 2026-10-31.
Scaffold a PR review agent, security analysis agent, or teaching DAG:
npm create oma-app@latest my-oma
In an interactive terminal, that one command selects a starter and runtime, installs dependencies, and runs a deterministic local demo. The demo needs no API key and makes no model request: scripted model responses drive the real OMA scheduler, result aggregation, and offline dashboard.
Or add OMA to an existing backend:
npm install @open-multi-agent/core
import { FileStore, OpenMultiAgent } from '@open-multi-agent/core'
// Your keys and your endpoint: a hosted provider, or a local server through baseURL.
const oma = new OpenMultiAgent({
defaultProvider: 'openai',
defaultModel: 'gpt-5.4',
// Consequential tool calls (file writes, shell) pause for a human decision.
onToolCall: ({ consequential }) => (consequential ? { action: 'suspend' } : { action: 'allow' }),
})
const team = oma.createTeam('ops', {
name: 'ops',
agents: [{ name: 'operator', systemPrompt: 'Reconcile overdue invoices.', toolPreset: 'readwrite' }],
})
// The checkpoint store keeps the run and its pending approvals durable.
const result = await oma.runTeam(team, 'Find overdue invoices and draft the reminders.', {
checkpoint: { store: new FileStore('./.oma/run.json') },
})
// result.status?.code === 'suspended' until a reviewer decides result.pendingApprovals,
// each bound to a hash of exactly what the reviewer was shown.
Set OPENAI_API_KEY to run this example. Providers covers other hosted models, local servers, OpenAI-compatible endpoints, and AI SDK providers.
runAgent() runs a single agent, runTasks() executes an explicit pipeline, and runTeam() plans from a goal. The Core package guide walks through all three modes, provider and credential setup, and the production checklist. The example index lists every runnable example across basics, cookbook workflows, patterns, providers, and integrations.
Durable approvals
A plan, task dispatch, or tool-call gate can return suspend. The request is stored beside the checkpoint, bound to a SHA-256 hash of exactly what the reviewer saw, and the run resumes from that content after a restart. A decision is atomic and first-wins; a tampered request or a store without compare-and-set fails closed.
approval/durable.ts · durable-approval.test.ts (16 cases) · durable-approval-validation.test.ts (7 cases) · Guide
Verifiable journal
Attach a journal backend and the run records every block the model saw, every tool call and result, and every context rewrite. verifyRun() reads it back cold, offline, and checks that each block's named source event still reproduces it byte for byte; an evicted window is reported as inconclusive, not as a failure. It proves lineage and content, not that the file was never edited.
journal/verify.ts · journal/hash.ts · verify-run.test.ts (11 cases) · Guide
Governance floor
Declare governanceIntent: 'required' with requiredRoles, and the run is judged on an execution receipt: which roles ran, in what order, with which dependency edges, and whether an independent review happened. The evaluator never sees agent output text, and a run can succeed and still report unsatisfied.
orchestrator/governance.ts · observability/execution-receipt.ts · governance-floor.test.ts (16 cases) · Guide · Receipts
Runs where you run
- No telemetry, no hosted control plane. A library with no OMA backend or account, and none planned. It makes no analytics, license, update, or phone-home request. Self-hosting
- Your keys, your models. Built-in adapters for Anthropic, OpenAI, Azure OpenAI, Bedrock, Gemini, Grok, and Copilot, and for DeepSeek, Doubao, Hunyuan, MiniMax, MiMo, and Qiniu; Ollama, vLLM, and llama-server through
baseURL; any OpenAI-compatible endpoint and Vercel AI SDK providers. Providers - Egress policy.
offlineorallowlist, checked before a built-in adapter connects. A child policy can only tighten its parent, an unenforceable transport fails closed, and process and ACP backends sit outside it. LLM egress policy
Built with OMA
open-multi-agent launched 2026-04-01 under MIT. Known users and integrations to date:
- temodar-agent by Ali Sünbül. WordPress security analysis platform running OMA's built-in tools (
bash,file_*,grep) inside a Docker runtime. Confirmed production use. (~60 stars) - Mark Galyan runs OMA fully offline on local quantized models, using the coordinator and context compaction to keep autonomous agent loops alive under tight VRAM limits. Contributor since the framework's first month.
- Engram: "Git for AI memory." Syncs knowledge across agents instantly and flags conflicts. (repo, ~80 stars)
More users and integrations
Users
- PR-Copilot by kidoom. AI pull-request review assistant running an OMA review team, with
defineToolrepo-context tools and a customContextStrategyfor token-aware diff compression. - StuFlow by znc15. Terminal AI coding assistant on OMA's orchestration core, driving
runAgent/ `runTasks