Agents that work.
Security you trust.
Deploy autonomous LLM agents with zero-trust, capability-based security. Fine-grained ACLs, cryptographically signed tokens, persistent memory with Git, and 1000s of concurrent agents—all in a 10MB binary.

Zero-Trust Architecture
Capability Tokens
Cryptographically signed tokens specify exactly what each agent can access: files, domains, token budget, timeout.
Fine-Grained ACLs
Filesystem and domain whitelists prevent unauthorized access. Agents cannot escape their boundaries.
Cost Control
Per-agent token budgets and timeouts prevent runaway costs and hung processes.
agentforge spawn writer \
--fs-allow "/articles/**" \
--domain-allow "api.openai.com" \
--domain-allow "github.com" \
--token-budget 500000 \
--timeout 1800
# Token: hmac_xyz...
# Status: ready
# Capabilities enforced at every call19 Powerful Tools
File I/O
Read, write, delete files with ACL protection
Web Search
Google search integration with domain whitelist
MeMex Memory
Git-versioned memory with semantic search
Message Bus
CSP-based inter-agent communication
LLM Integration
Call any LLM provider directly
Pipelines
DAG-based workflow orchestration
Why AgentForge?
vs OpenClaw
- ✓ Capability-based security
- ✓ Filesystem ACLs
- ✓ Domain whitelisting
- ✓ Cost control
- vs Full host access
AgentForge
Zero-trust by default. Capability tokens. Fine-grained ACLs. Real cost control. Built in Go for 1000s concurrent agents.
Full Comparison →vs Hermes
- ✓ Persistent memory
- ✓ Pipeline orchestration
- ✓ Token tracking
- ✓ Audit trails
- vs No security controls
Start Building Secure Agents
Open source, self-hosted, or managed. Choose your deployment model.