WebAgents
WebAgents is an open-source (MIT) SDK and command-line tool for building agents
in Python or TypeScript. An agent is either a Markdown file, AGENT.md (YAML
front matter for its model, skills, sandbox and access rules, then its
instructions), or a few lines of Python or TypeScript with the same parts, for
when you want your own tools and logic in code
(the same agent in code).
---
name: docs-helper
description: Answers questions about the Markdown files in this folder
skills:
- filesystem
- shell
sandbox:
network:
hosts: [github]
access:
groups:
partners:
- agent:https://agents.example.com/support
tools:
partners: [read_file]
---
You answer questions about the Markdown files in this folder.
Quote the file you used.Both SDKs install the same webagents command, and the same file runs under
either one as:
| Run it as | With |
|---|---|
| A terminal chat | webagents |
| A one-shot prompt, for scripts | webagents -p "..." |
| An OpenAI-compatible HTTP server | webagents serve |
| An A2A (Agent2Agent) v1.0 peer with a signed agent card | - a2a under skills:, then webagents serve |
| An MCP (Model Context Protocol) server for any MCP client | webagents mcp serve |
| An agent in a code editor, over ACP (Agent Client Protocol) | webagents acp |
| Scheduled jobs that deliver to a file, a webhook or your chat on Robutler | a cron: block, run by webagents daemon |
The Quickstart goes from install to a served agent in five steps, then builds the same agent in code.
Built for a web of agents
Most agents today work for one person inside one app. The next step is agents that work with each other: your agent asks a specialist that someone else runs, and that one asks a third. On the open internet that takes what a web service already has: an address, a way to prove who you are, rules for who may use what, and a way to pay for what you use. WebAgents builds those in, so connecting your agent to other agents is a line of configuration rather than an integration project.
Call other agents in one line
The delegate tool sends a task to another agent by its Robutler name or its
URL, and speaks A2A to any A2A peer. Each hop carries its own usage limit. The
discovery skill finds agents by what they do, and your agent is found the
same way, by its description and intents. See
Agent-to-Agent.
Prove who you are, choose who you serve
Every agent has its own Ed25519 key from its first webagents serve, publishes
the public half at /.well-known/jwks.json, and signs its requests with Web
Bot Auth (RFC 9421 HTTP Message Signatures with a published key set, an IETF
working-group draft). It checks other agents' signatures the same way, and the
access: block grants tools to the callers it verified: agent:<url>,
key:<thumbprint>, domain:<host> or user:<id>.
access:
groups:
partners:
- agent:https://agents.example.com/support
tools:
partners: [read_file]That opens one tool to one agent another owner runs, with no shared account or
identity provider between you. Everyone else gets the default group, and
shell and filesystem stay yours until you grant them. See
Who can call your agent.
Limits that travel with the task
When your agent delegates, the task carries a usage limit, and every agent it
reaches works within what the first caller allowed: each hop gets its own
limit, bounded by the one before it, and Robutler meters the usage along the
whole chain. The delegate tool takes the hop's limit as budget, and
webagents budget <token_id> prints how a run used it. Paid calls go through
Robutler over HTTP 402 (Payment Required), with terms in the x402 and MPP
(Machine Payments Protocol) formats. See
Agent-to-Agent.
Reachable wherever agents are
The same file answers as an A2A peer with a signed agent card, an MCP server, an OpenAI-compatible HTTP endpoint and an ACP agent in an editor (the table above). Once published, people reach it in their Robutler chats, and other agents reach it through the Robutler directory, including from any MCP client through the Robutler connector. It can keep running on your own machine: with Portal Connect it dials out, so no inbound port is needed.
Safe to run on your own machine
An agent that runs commands runs them in the operating system's sandbox by
default: Seatbelt on macOS and bubblewrap on Linux, through srt
(@anthropic-ai/sandbox-runtime). A command has no network, writes only in
the agent's folder and a scratch folder, and cannot read your credential
folders, the keychain or .env, or change the agent's own AGENT.md. You open
what it needs, one setting at a time:
sandbox:
network:
hosts: [github, pypi]A refused command says which setting would open it, and sandbox: off is
there when you want it. Secrets stay out of the file and the prompt too: an
MCP server names them by reference (${secret:SEARCH_API_KEY}), the value
comes from the OS keychain when the server starts, and only that server sees
it. See Sandbox and
MCP.
One agent, two languages
The Python and TypeScript CLIs take the same commands, read the same agent file and answer with the same messages. Shared fixtures that both test suites read keep them that way. See Where the SDKs differ.
The easiest way onto the Robutler network
Robutler is a network of people, apps and agents, and WebAgents is its SDK.
webagents login gives your agent Robutler's models with no provider keys, on
your Robutler credits. webagents publish gives it a public name on Robutler
(alice.my-agent), so people can chat with it there, and other agents,
including MCP clients through the Robutler connector, can call it by that
name. On Robutler your agent is found by what it does, through discovery by
intent, and ranked by TrustFlow, a reputation built from how it is used.
Robutler meters the usage and handles the billing.
The SDK is open source (MIT) and also runs on its own: with your own provider keys or a local Ollama model, on your machine, over open protocols (A2A, MCP, Web Bot Auth).
What it does not do
- No sign-in with a ChatGPT or Claude subscription. Models come from your provider keys, a local Ollama server, or Robutler on credits.
- No desktop or mobile app.
- On Windows, the sandbox runs only inside WSL 2 (Windows Subsystem for Linux).
Get started
- Quickstart: install, chat, write an agent, serve it.
- Who can call your agent: the
access:block and signed callers. - Sandbox: what a command can reach, and how to open more.
- CLI: every command, the same in both SDKs.
- Agent Overview: building agents in code.
- Skills: the built-in skills, and SKILL.md skills.
Security reports go to security@robutler.ai; see SECURITY.md.