The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the AgentRaaS wrap listing page.
The agent reliability platform.
AgentRaaS sits between your AI agents and every real-world action, giving you three things at once, not one trick: reliability (exactly-once execution, circuit breaking, proven under real concurrent load, not just claimed), responsibility (budget/loop limits and human-in-the-loop approval before the calls that matter), and accountability (a full audit trail and per-agent identity — scope-restricted credentials — for every action taken). Connect it via webhook, SDK-style headers, or native MCP. Self-hosted or cloud.
Your n8n workflow hits Stripe. It times out. n8n retries.
Result: The customer is charged twice.
Your agent calls HubSpot to create a contact. The request succeeds, but the response is lost. The agent retries.
Result: Two duplicate contacts in your CRM.
AgentRaaS is a reliability layer that guarantees exactly-once execution of agent actions — proven under real concurrent load with an automated test suite.
How it works:
pip install agentraas gives you three tools that run entirely on your machine. Start here, and add the server when your team wants the dashboard, human approval and one audit trail.
Find the calls your agent would run twice. The chaos tester lets each write request execute, then drops the response (the failure that turns a retry into a double charge) and reports every action that ran twice. It exits non-zero, so it can fail CI (GitHub Action).
Fix them with a decorator backed by local SQLite or your own Redis:
Wrap any MCP server so identical write-tool calls run once and every call is logged. Listed in the official MCP Registry as io.github.sumedhchatse/agentraas:
Full options: src/sdk/README.md. The TypeScript client and exactlyOnce are on npm: npm install agentraas (src/sdk-js).
Open http://localhost:13001/dashboard — requires an account (register/login, encrypted password storage). New accounts get their own org automatically — nothing technical required just to see a working dashboard.
/guide — worth reading if any of the above is unfamiliarOption 1 — clone this repo (fastest):
Option 2 — from AgentRaaS Cloud: register at agentraas.io, connect
your first agent, then download the self-host package from the
dashboard's Account menu (unlocks once you've connected an agent). Same
install.sh, just packaged with your Cloud account already wired up.
Option 3 — one-click cloud deploy (Render):
Provisions the Community edition (web service + managed Postgres + Redis)
from render.yaml — no server of your own needed. Uses
Containerfile.render, a
variant that bakes public/ and config/ into the image instead of the
bind-mounts compose.yaml uses locally, since Render doesn't support
those. Verified locally end-to-end (build, boot, /health, and the
landing page all serving from the built image) before this button
shipped.
install.sh handles everything that used to be a manual multi-step
process: generating JWT_SECRET and CREDENTIALS_ENCRYPTION_KEY, building
the API image, starting the stack, running every migration in order,
handling SELinux relabeling if applicable, and a clean recreate at the end.
The first run compiles the Rust service from source — expect a few minutes
on that step; it isn't a hang.
Then open http://localhost:13001/dashboard and register a new account
— self-hosted instances are single-tenant, so whoever registers first is
just the first user, no special admin bootstrap needed. (Option 2's
account is pre-registered instead — use "Forgot password" to set a
password for this instance.)
A real gotcha worth knowing, if you ever touch the setup manually: on
SELinux (Fedora/RHEL-family hosts), bind-mounted files can end up with the
wrong context and the container fails with EACCES errors. install.sh
handles this automatically; if you're troubleshooting by hand, fix it with:
and from then on, always use podman-compose down && up -d (full recreate)
after changing files on the host — never plain restart, which doesn't
re-apply the SELinux label.
Services:
http://localhost:13001localhost:15432localhost:16379Runs real integration tests against the running server — concurrent duplicate
requests, sequential replay, distinct-payload isolation, and failure/retry
recovery — not mocked unit tests. Uses the built-in mockpay service, so no
real API keys are needed to run them. (These are plain Node HTTP-client tests
that live alongside the Rust service; the server itself has no Node in it.)
Plus a native Rust unit-test suite covering the dedup hashing, loop-detection, and checkpoint logic directly — including golden-value tests that pin the dedup hash format so it can't silently shift:
Both run on every push/PR via .github/workflows/rust-test.yml.
AgentRaaS exposes an MCP gateway for Claude Desktop, Cursor, and other MCP clients:
All tool calls through this gateway are deduplicated, validated, rate-limited, and logged.
Curated, pre-configured integrations (no code required — see config/services.json):
Stripe, Twilio, HubSpot, Calendly, Shopify, Zoho, Razorpay, WhatsApp,
Zapier, Make, Adyen, Mollie, Airwallex, Xendit, PayPal, Salesforce, Slack,
Klarna, Paystack, GoCardless, Opn Payments, plus the built-in mockpay
for safe testing.
Need something not on this list? Register it as a Custom Action from the dashboard — any URL, any auth type, protected by the same dedup/audit/ rate-limit pipeline, with an SSRF guard so it can't be pointed at internal infrastructure.
To add a new curated integration permanently, add an entry to
config/services.json following the existing pattern — no code changes needed.
If you're only calling Stripe by hand from your own backend, its native
Idempotency-Key header is genuinely enough — you don't need this. The
honest case for AgentRaaS is narrower and specific:
The hardest case for exactly-once is a call that ran but whose response never came back. AgentRaaS handles it in two ways:
Idempotency-Key: agentraas-<hash>, one
stable value per logical action, so a provider that honors the header
(Stripe and others) runs the action once even if a retry or replay reaches
it again.409), the caller gets 504, and
it goes to the dead-letter queue. A replay from there reuses the same key
and, once it succeeds, identical calls get its result.A refused connection or DNS failure means nothing was sent, so those are still retried as normal. Steps for resolving one: docs, Troubleshooting.
| DIY Idempotency Keys | AgentRaaS | |
|---|---|---|
| Code changes | Modify every API call, only where the provider supports it | Change the URL |
| No-code support | ❌ Not possible — no-code tools can't set custom headers | ✅ Paste webhook URL (n8n, Make, Zapier) |
| Providers without native idempotency | Build your own dedup logic per provider | One proxy, same guarantee, every service |
| Multiple services | Different logic per API | One proxy, all services — plus any custom endpoint |
| Credential management | Build yourself | Self-serve, encrypted at rest |
| Validation, circuit breaker, rate limiting | Build yourself | Built-in |
| Audit trail, dashboard | Per-provider at best | One trail across every service you call |
Fail-closed by design, not fail-silent. AgentRaaS sits in the request path between your agent and the real API. If it's unreachable, your call to it fails — it does not silently succeed un-deduped. There is no fallback path anywhere in the SDK, the n8n node, or the MCP gateway that quietly calls Stripe or Twilio directly when AgentRaaS doesn't respond. That's deliberate: routing around an outage would mean the exact retry-storm double-charge scenario this product exists to prevent happens silently, at the one moment you'd least want it to. Treat it like any other proxy or database on your critical path — standard timeout/retry handling on the calling side applies, same as it would for any dependency.
Latency: we haven't published real p99 numbers yet. Self-hosted, it's one network hop to a service running on your own infrastructure, not a call out to us — but we're not putting an unmeasured number here. On the roadmap, not fabricated.
You don't need to pay to use AgentRaaS. Community is free and open
source, with no action limit when you self-host it, and it's the version we
recommend starting with. Team and Enterprise add approvals, seats, SSO and
support for companies that need them, cloud-hosted or self-hosted. The
Enterprise module (src/api-gateway-rs/crates/api/src/ee/: SSO, RBAC, HMAC,
DLP, HA, SIEM export) is source-available under a separate commercial
license, see LICENSE.md.
| Community | Team | Enterprise | |
|---|---|---|---|
| Price | $0/mo | $49/mo | Custom, from $499/mo |
| Deployment | Self-hosted only | Cloud-hosted or self-hosted | Cloud-hosted or self-hosted/on-prem |
| Actions/month, self-hosted | Unlimited | Unlimited | Unlimited |
| Actions/month, cloud-hosted | n/a (not offered) | 10,000 | Unlimited |
| Team seats | 1 | 3 | Unlimited |
| Payload dedup, MCP gateway, dashboard | ✅ | ✅ | ✅ |
| Fuzzy/semantic similarity dedup | — | ✅ | ✅ |
| Human-in-the-Loop approval gateway (Slack + SLA auto-escalation) | — | ✅ | ✅ |
| Audit log | Local Postgres, tamper-evident | Local Postgres, tamper-evident | + SIEM export |
| Client tenants / white-label | — | — | ✅ unlimited |
| Inbound webhook receivers | — | — | ✅ |
| Inbound HMAC verification, PII/DLP redaction | — | — | ✅ |
| SSO (OIDC), RBAC | — | — | ✅ |
| Agent Identity / Agent Passport (scoped, short-lived agent tokens) | — | — | ✅ |
| HA clustering | — | — | ✅ |
| Support | GitHub & Discord | GitHub & Discord | Priority, SLA-backed |
Community also has a free-to-try flavor on AgentRaaS Cloud (no install,
capped at 500 actions/month — the only tier/deployment combination with
any cap at all; self-hosting removes it entirely, on any tier). Get
started or self-host from /dashboard, or contact
support@agentraas.io for Enterprise sales.
Step-by-step fixes from quick checks to deeper digging (API errors, library mode, MCP wrap, chaos tester, self-hosting) are in the Troubleshooting section of the docs.
One sentence: everything in this repo is dual-licensed MIT/Apache-2.0
(genuinely open, no restrictions — LICENSE-MIT /
LICENSE-APACHE) except the enterprise module
(src/api-gateway-rs/crates/api/src/ee/,
src/api-gateway-rs/crates/core/src/{dlp,hmac_verify}.rs,
compose.ee.yaml), which is under a separate fair-code/source-available
commercial license — see LICENSE.md.
The enterprise module (SSO, RBAC, HMAC verification, DLP, distributed rate
limiting, HA) implements Team/Enterprise-tier features, required for
production use beyond a trial — see the Pricing section above or contact
support@agentraas.io. It's source-available in this repo (you can read
it, same as the core), just not freely redistributable/rebrandable —
LICENSE.md has the exact terms, including the metered
free tier for AgentRaaS-hosted deployments (500 actions/month) and the
fact that self-hosting is unlimited on every tier. (This repo also keeps
RESTRUCTURE_PLAN.md around as internal planning notes on that split —
not required reading, just there if useful.)
See CONTRIBUTING.md for the contribution process and CODE_OF_CONDUCT.md for community expectations.
Found a security vulnerability? Do not open a public issue — see SECURITY.md for the private disclosure process.
Built with: Rust (Axum/Tokio/sqlx), Redis, PostgreSQL, Podman, and the fear of double-charging a customer at 2 AM.