The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the OpenWork MCP Gateway listing page.
OpenWork is the free, open-source alternative to Claude Cowork and Codex: a desktop app for macOS, Windows, and Linux where AI agents do real work on your own files. It is built on OpenCode, works with any model — 50+ providers, your own API keys, or local models via Ollama — and lets teams share skills and MCP servers.
Download OpenWork · GitHub releases · Docs
Read this in: 简体中文 · 繁體中文 · 日本語
Add one OpenWork MCP to Codex, Claude Code, Cursor, or another compatible agent and reuse the same skills, MCPs, and connected services across your tools, teammates, and machines. Create something once, share it with coworkers or friends, or keep it for yourself.
The desktop app is there when you want a dedicated workspace, but it is not required. You can use OpenWork from the agent you already have. For larger organizations, the admin interface lets you publish capabilities, manage access, and configure shared or per-user connections.
Already use an AI agent? Copy this prompt and paste it into Claude Code, Cursor, Codex, ChatGPT, or any agent that can run commands on your computer.
The OpenWork MCP brings your assigned skills, plugins, MCP connections, Google Workspace, and Microsoft 365 capabilities into any compatible agent.
It exposes four tools: search_capabilities finds what you can use, execute_capability runs it, and list_skills / get_skill list your skills and read one SKILL.md directly. After adding the MCP, your client opens a browser so you can sign in and choose your OpenWork organization.
Add this to opencode.json:
Use this remote MCP server URL:
OpenWork Den is the control plane for managing OpenWork across a team or organization.
This repository uses a directory-split license, similar to GitLab:
ee/ is MIT — the desktop app and core platform are open source, free for any use.ee/ (OpenWork Den — the org control plane) is under the OpenWork EE License, a source-available license. The code is public so you can audit exactly what you deploy. Production use requires an OpenWork subscription, except that it is free for organizations with up to 5 users, free to evaluate for 30 days at any size, and always free for development and testing. Each ee/ release additionally converts to MIT two years after publication.Versions released before this license was adopted remain under their original license (FSL-1.1-MIT). See pricing and the subscription terms.
The fastest path from a fresh clone to a running dev build.
.nvmrc (nvm use picks it up).package.json (packageManager); run corepack enable to use the pinned version automatically. Never use npm or yarn.Signed-off-by trailer (git commit -s). See CONTRIBUTING.md.| Path | What lives there |
|---|---|
apps/ | the desktop app: React UI (apps/app), Electron shell (apps/desktop), and openwork-server (apps/server) (MIT) |
packages/ | shared core packages (MIT) |
ee/ | OpenWork Den — the org control plane, MCP gateway, and inference (EE License, see Licensing) |
evals/ | executable test specs built on @openwork/testkit — see evals/README.md |
worlds/ | declarative dev/test environment definitions for pnpm world |
docs/ | operator, feature, and release docs |
.opencode/skills/ | repository agent skills (testing, release, Daytona, and more) |
All executable coverage lives in evals/specs/**/*.test.ts; app-driving journeys use .e2e.test.ts.
Runtime-observable changes need test evidence on the PR. AGENTS.md and evals/README.md describe the verification contract and vocabulary.
dev (the default branch) and open your PR against dev.git commit -s.ee/ additionally require a CLA.For one checkout, keep using pnpm dev; with no extra environment variables it reuses the existing shared dev profile.
To run multiple git worktrees at once, use:
That sets OPENWORK_DEV_PROFILE=auto, derives a stable profile name from the worktree path, lets Electron choose a free CDP port, and asks Vite for a free dev-server port. You can also choose a named profile, for example OPENWORK_DEV_PROFILE=my-feature OPENWORK_ELECTRON_REMOTE_DEBUG_PORT=0 PORT=0 pnpm dev.
dev:worktree also defaults OPENWORK_ELECTRON_USE_MOCK_KEYCHAIN=1. A brand-new profile has no stored credentials, so on macOS the real keychain prompts as soon as Chromium persists an authenticated cookie, and that modal blocks Electron's main loop until it is dismissed. Set OPENWORK_ELECTRON_USE_MOCK_KEYCHAIN=0 if you specifically want the system keychain in an isolated profile.
Dev startup prints a banner like [openwork] dev profile=... cdp=http://127.0.0.1:9823; use it to find the profile directory and pass the CDP URL to local tooling.
If a second instance cannot get the profile lock it now says so and exits, instead of lingering with an open CDP port and no window.
To run the OpenWork UI in a browser against a local openwork-server (no desktop shell):
pnpm dev:headless-web is a compatibility alias for the same script. The alias
remains foreground by default and accepts --detach; world up is foreground
unless --detach is explicit.
This is an isolated launcher:
tmp/headless-server.json and never reads ~/.config/openwork/server.json--replaceopenwork-server with a stable owner bearer forced into the UI. Crash-restarts keep open tabs working. The privileged host token stays on the server process and is never inlined into the Vite bundle./api/den (forwarded to the Den control plane) and the app pins its Den API there via VITE_DEN_API_BASE_URL, so Cloud calls are never CORS-blocked and stale localStorage base URLs are cleared on loadtmp/dev-headless-web.json (0600), and allows browser calls to the local server only from the web app's own origins — not every site you visit5178, server 8778; falls back to free ports when taken, override with OPENWORK_WEB_PORT / OPENWORK_PORT)dev-headless; stop it with pnpm world down dev-headless before launching it againScript-specific options must follow --:
--replace restarts the headless runtime with fresh tokens; add
--keep-tokens to retain the previous tokens. --rotate-tokens is also
accepted by this script. These are not generic world options.
Open the printed Web URL. Cloud sign-in in headless web uses the copy/paste handoff (hosted Den cannot redirect session grants back to http://127.0.0.1):
Point Den at a local stack with OPENWORK_DEV_DEN_PROXY_TARGET=http://127.0.0.1:3005 while pnpm dev:web-local is running. Set OPENWORK_DEV_HEADLESS_WEB_DEN_PROXY=0 to disable the Den wiring.
The other checked-in scripts include worlds/headless-prod-live.ts and
worlds/desktop-prod-live.ts. Both intentionally share installed production
state and require their script-specific opt-in after --, for example
pnpm world up desktop-prod-live -- --allow-shared-state. List scripts and
running receipts with pnpm world list. The headless
production world is hard-limited to loopback; remote-access/public-host settings
are refused because its browser session uses production credentials.