The open-source, self-hosted runtime for teams running agents in production. Every step lands in your Postgres before the next one runs, so a crash or a kill -9 resumes where it died, and you can read what the agent did, what it cost, and why it stopped.
A resumed run never re-pays for a completed model call.
The kill matrix kills the worker after every single write point and the run still finishes.
Your VPC. Your keys. Apache-2.0, forever.
"90% of the work is checkpointing, delivery tracking, and human oversight. Agent logic is 10%."
Every serious agent team rebuilds the same plumbing: queues, checkpoints, retries, approval flows. Toren is that 90%, built once and kill-tested in CI, so your team ships the 10% that's actually yours.
Every model call and tool call is recorded in a Postgres event log the moment it completes. The run's state is the log, so nothing that lives in a process can die with one.
Agents as durable processes: files define the agent once, then run it, schedule it, talk to it, let a conversation launch its background jobs. All of it rides one event log; kill any of it and nothing re-pays. Parked work costs nothing: not a worker, not a container, not a poll loop.
export default async function (ctx) { // one planner task; the model decides // what deserves research const plan = await ctx.wave("plan", [ctx.task("planner", ctx.input)]); // your code turns the plan into a // dynamic parallel fan-out const topics = parse(plan.results[0].output); const found = await ctx.wave("research", topics.map(t => ctx.task("researcher", t)), { onTaskFailure: "collect" }); // park for a human: zero compute const memo = await ctx.wave("write", [ctx.task("writer", join(found))]); return memo.results[0].output; }
effects: "external", // recorded once, never re-run idempotency: "keyed", // retries carry a stable key approval: "always" // parks until a human signs
const t = new TorenClient({url, token}); const {runId} = await t.startRun({input}); const run = await t.waitForRun(runId);
$ toren dev → console: localhost:7433/console live runs · event timelines one-click approvals · API keys # pre-authed link, zero setup
$ toren dev --dir crews/ serving 3 agents (research, support, billing) each crew: own event log, own schema, shared nothing
you> run the weekly report
agent> Started. I'll message
you when it lands.
# parked at $0 · survives anything
agent> Report's ready: 42 pages.$ toren schedule create
--process daily-digest
--cron "0 8 * * *"
# fire records survive any crash;
# one occurrence, one run, eversandbox: true # bash + files, a real workspace kill the worker mid-build: the successor reconnects the same workspace and keeps going
One runtime underneath: the same durable substrate runs your chat assistant, your overnight coding job, your scheduled pipelines, and the background runs a conversation spawns. Different shapes of agent, one guarantee.
A framework for the agent, a workflow engine for durability, a sandbox vendor for the computer, glue for the rest. Every seam is yours to build and yours to debug at 3am.
| The layer | Assembled | In Toren | |
|---|---|---|---|
| 01 | The agent loop | LangChain / CrewAI / your code | built in: task loops, subagents, waves |
| 02 | Durability | + Temporal or Inngest, wired in | the event log is the runtime |
| 03 | A computer | + E2B or Modal, state on you | sandbox: true, survives the worker |
| 04 | Scheduling | + cron and idempotency glue | exactly-once, covered by the kill matrix |
| 05 | Talking to it | + a bot framework per channel | durable sessions: console, CLI, HTTP, Telegram |
| 06 | Approvals & console | build it yourself | built in, parked at $0 compute |
| 07 | Deploy | compose all of the above | docker compose up · toren deploy-aws |
Six systems with six failure modes, or one runtime on one Postgres event log, where a kill -9 anywhere loses nothing.
Postgres is the entire stack: state, queue, and event log in one boring database. The scaffold runs offline; no API keys required to feel it work.
npx toren-run init → toren run
One Terraform apply into your AWS: SQS, RDS, Fargate workers, an authenticated HTTP API. Your VPC, your keys, your data boundary. Identical binary.
toren deploy-aws --region eu-central-1 --yes
Everything the runtime does is Apache-2.0. Features never move behind a paid tier: the full runtime, the CLI, the console, the AWS deploy, approvals, scheduling, the API and SDK.
I will deploy Toren into your VPC with you, fix what breaks the same day (that is how the last five field reports went), and you keep an Apache-2.0 fork no matter what happens to me or the project. Start a thread on GitHub Discussions and say what you are running.
Planned for teams that want the ops handled, built on the same open runtime. Tracked on the docs status page; nothing on this page moves behind them.
The scaffold runs offline with a mock model, so the first kill -9 costs nothing. Postgres is the only thing to install.
Star it on GitHub · File an issue when it breaks · Read the FAQ