The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Lobu listing page.
Lobu is an open-source, event-sourced context layer for AI agents. Every tool call, data change, device signal, API event, and conversation becomes an event, linked to the entities and identities it belongs to — a person, a project, a customer, a home, a company. That gives agents a live, queryable model of your world instead of a transcript they forget when the session ends.
ChatGPT, Claude, Codex, and your own agents read and write that same permission-aware history and current context, whether you're wiring up your own accounts or an entire company's stack. When a responsibility should outlive one chat, any agent can discover and hand it to a persistent Lobu specialist over MCP.
Connect your tools once. Every agent resumes from the same live context.
The 86-second narrated demo shows ChatGPT using Lobu over MCP to pull connected context and call governed tools without leaving the conversation. The same shared context remains available to Claude, Codex, and custom agents.
https://github.com/user-attachments/assets/c07e7c23-a29b-4b05-895e-51dcb935bac4
Point any MCP client at Lobu. No Lobu agent runtime or lobu.config.ts is required.
Complete OAuth when prompted, connect the sources you want to share, and ask your agent to use Lobu when it needs shared context.
The same MCP endpoint works with Claude Code, Codex, OpenCode, Antigravity, ChatGPT, Claude Desktop, Cursor, and custom MCP clients. Run lobu connect to detect a client, install the supported MCP and skill bundle, or get the exact native handoff when the host requires UI setup. Authentication happens in that agent on first use.
Setup guides: Claude · ChatGPT · Codex · Grok
Ask from Claude Code, Codex, or ChatGPT:
What did we decide about enterprise onboarding, and what changed since the last release?
Lobu searches shared, durable organizational memory under the caller's permissions, regardless of which agent asks. The answer can combine connected discussions, project activity, customer records, saved decisions, and typed company entities without rebuilding that context from scratch in every chat.
Ask your primary agent:
Ask our customer-researcher specialist to review the latest feedback and propose the next three interviews.
The agent discovers the specialists available to you, selects the right one, delegates the task, and brings the result back. The specialist has its own identity, instructions, tools, durable conversations, and access policy.
To the user this stays one conversation in their primary agent. The specialist itself persists: it remains available to other authorized people and agents instead of disappearing with the current chat.
Instead of every agent rebuilding the same state through per-session tool calls, Lobu runs a shared data layer:
MCP is for doing. Lobu's event graph is for knowing.
The primitives don't change between a single person's accounts and an entire company's stack — only what's connected does. Identities, entities, events, history, and policy work the same way at either scope.
Agents can search and save memory, query structured entities, inspect connected sources, and delegate to Lobu specialists without moving to a new chat interface or adopting Lobu's runtime.
Docs: Memory · Claude · ChatGPT · Codex
Create a specialist for a durable responsibility: customer research, support triage, release coordination, incident follow-up, or an internal domain. People can talk to it from the Lobu web app or Slack, while other agents can call the same specialist over MCP.
Scaffold and run one locally:
lobu run starts the local stack with an embedded Postgres database by default and opens the web UI on :8787. It applies the project's lobu.config.ts automatically only in embedded mode. To use external Postgres, set DATABASE_URL, ensure pgvector is available, then authenticate and apply the project to that runtime separately.
Docs: Getting started · Agent workspace · Skills · Slack
The same governed data and operations are available without an agent:
Or from Node and TypeScript:
Mint a token with lobu token create. The MCP tools and typed SDK operations share the server-side tool registry and access rules; lobu memory run and lobu memory exec dispatch through the MCP endpoint.
Connectors collect activity on a schedule or through webhooks. Discussions, project changes, customer records, API events, and saved agent knowledge land in the same append-only history.
Typed entities connect that history to the things you care about: Company, Project, Customer, Incident, or schemas you define. Corrections supersede old facts rather than erasing their provenance.
Connectors are extensible. You can build them in TypeScript, and coding agents can use Lobu's connector contract and validation flow to create integrations for sources Lobu does not ship with.
Docs: Memory · Connectors · API
A Lobu specialist has a stable role, instructions, memory, tools, and conversation history. It can be reached from web chat or Slack and called by external agents through client.conversations.send.
Specialists use role files for identity and instructions: IDENTITY.md, SOUL.md, and USER.md. Guardrails can inspect input, output, and tool calls. Destructive MCP calls require in-thread approval unless they are explicitly pre-approved through defineAgent({ tools: { preApproved } }) in lobu.config.ts; action results return to the shared event log.
External agents do not ask users to write delegation code. They pass scripts like these to Lobu's query_sdk and run_sdk MCP tools:
Docs: Agent workspace · Guardrails · Security
Automations are versioned background responsibilities activated manually, on a schedule, by a connector event, or by another Automation's durable output. They read governed sources, persist structured results, and can notify Slack, open a ticket, or start agent work while nobody is in chat.
Collection and activation stay independent: connect a source once, keep its durable history useful to every authorized agent, then choose whether a responsibility should run on a schedule or immediately when a matching event arrives. Polling connectors, authenticated webhooks, and Automation outputs use their appropriate ingestion paths but converge on the same durable Automation run lifecycle. Initial syncs establish a baseline without flooding subscribers; repeated deliveries are deduplicated.
See the activation and chaining model.
Shared context and delegation over MCP do not require Lobu to execute code for the calling agent. When a Lobu specialist needs a shell, the built-in runtime provides lightweight just-bash execution. Remote sandbox providers such as Vercel Sandbox can be connected for workloads that need stronger isolation or more compute.
Which sandbox runs the code is a deployment choice. Lobu provides the shared context, permissions, and governance around it.
Lobu specialists can serve Slack, Telegram, WhatsApp, Discord, Teams, Google Chat, the web app, and a REST API. Channel conversations remain separate while reading the same authorized organizational context.
Setup: Slack · Telegram · Discord · WhatsApp · Teams · Google Chat
Runtime configuration is managed through the web app or the same org-scoped REST API used by the CLI. Local lobu.config.ts projects support validation and repeatable apply workflows.
Docs: CLI reference · lobu apply
Use the embedded runtime locally or self-host Lobu with external Postgres. Production guides: Docker · Cloud · Kubernetes
Permissions and audit stay on Lobu's gateway. Lobu MCP servers and the credential-brokering layer handle provider and connector credentials, OAuth and token refresh, and third-party API proxying. Workers receive scoped placeholders or short-lived provider-derived access, never OAuth tokens or durable stored credentials. Destructive MCP calls require in-thread approval unless explicitly pre-approved, and connected data remains organization-scoped.
The built-in just-bash and embedded execution modes are policy and convenience boundaries, not VMs for hostile code. Use a remote sandbox provider when the workload needs a stronger isolation boundary.
Docs: Security · Secret proxy · Guardrails · Threat model
We are working with technical teams that already use Claude Code, Codex, ChatGPT, or custom agents and want those agents to share company context or delegate to persistent specialists.
The best starting point is one team, one or two connected sources, and one repeated responsibility. Talk to the founder or reach out on X/Twitter.