Toren runs agents
that work for days,
do real work,
and survive anything.

The open-source, self-hosted runtime for teams running agents in production. Every step lands in your Postgres before the next one runs, so a crash or a kill -9 resumes where it died, and you can read what the agent did, what it cost, and why it stopped.

FIG. 1 · RUN 7f3a2c10 · TWO WAVES, ONE MURDERKILL TEST
WAVE research · task w0t0 WAVE research · task w0t1 WAVE write · task w1t0 kill -9 resumed · 0 tokens re-paid recorded once
CLAIM 01 · AN ASSERTION IN CI

A resumed run never re-pays for a completed model call.

CLAIM 02 · AN ASSERTION IN CI

The kill matrix kills the worker after every single write point and the run still finishes.

CLAIM 03 · BY CONSTRUCTION

Your VPC. Your keys. Apache-2.0, forever.

19 releases in three weeks
5 production field reports, each fixed the same day
1 pilot in production on Fargate + RDS, two agents, Telegram
"They fixed the last report same-day." pilot incident report
"90% of the work is checkpointing, delivery tracking, and human oversight. Agent logic is 10%."
what the production field reports keep saying, in different words

Every serious agent team rebuilds the same plumbing: queues, checkpoints, retries, approval flows. Toren is that 90%, built once and kill-tested in CI, so your team ships the 10% that's actually yours.

Kill it. It keeps working.

Every model call and tool call is recorded in a Postgres event log the moment it completes. The run's state is the log, so nothing that lives in a process can die with one.

KILL TEST · LIVE TRANSCRIPT

One agent. Every surface.

Agents as durable processes: files define the agent once, then run it, schedule it, talk to it, let a conversation launch its background jobs. All of it rides one event log; kill any of it and nothing re-pays. Parked work costs nothing: not a worker, not a container, not a poll loop.

workflows/weekly-report.ts A NAMED PROCESS · WAVES FAN OUT

export default async function (ctx) {
  // one planner task; the model decides
  // what deserves research
  const plan = await ctx.wave("plan",
    [ctx.task("planner", ctx.input)]);

  // your code turns the plan into a
  // dynamic parallel fan-out
  const topics = parse(plan.results[0].output);
  const found = await ctx.wave("research",
    topics.map(t => ctx.task("researcher", t)),
    { onTaskFailure: "collect" });

  // park for a human: zero compute
  const memo = await ctx.wave("write",
    [ctx.task("writer", join(found))]);
  return memo.results[0].output;
}

tools/send.ts DURABILITY ATTRS

effects: "external",
// recorded once, never re-run
idempotency: "keyed",
// retries carry a stable key
approval: "always"
// parks until a human signs

anywhere.ts TYPED CLIENT

const t = new TorenClient({url, token});
const {runId} = await t.startRun({input});
const run = await t.waitForRun(runId);

The whole machine FIG. 2 · ONE BORING DATABASE

CLI · API QUEUE WORKERS EVENT LOG(postgres) hintsleasestruth LOCAL: postgres is all three boxes on the right · AWS: SQS + Fargate + RDS · same binary, same log

/console BUILT-IN CONSOLE

$ toren dev
→ console: localhost:7433/console
live runs · event timelines
one-click approvals · API keys
# pre-authed link, zero setup

crews/ ONE DEPLOYMENT, MANY AGENTS

$ toren dev --dir crews/
serving 3 agents (research,
  support, billing)
each crew: own event log,
own schema, shared nothing

toren chat DURABLE CONVERSATIONS · 4 CHANNELS

you> run the weekly report
agent> Started. I'll message
       you when it lands.
# parked at $0 · survives anything
agent> Report's ready: 42 pages.

toren schedule CRON · EXACTLY ONCE, PROVEN

$ toren schedule create
    --process daily-digest
    --cron "0 8 * * *"
# fire records survive any crash;
# one occurrence, one run, ever

agent.yaml A DURABLE COMPUTER

sandbox: true
# bash + files, a real workspace
kill the worker mid-build:
the successor reconnects the
same workspace and keeps going

One runtime underneath: the same durable substrate runs your chat assistant, your overnight coding job, your scheduled pipelines, and the background runs a conversation spawns. Different shapes of agent, one guarantee.

SPEC · MEASURED IN CI
0
tokens re-paid on resume
every
write point covered by the kill matrix
1
dependency to run locally
$0
compute while a run waits, hours or weeks

The alternative is a stack you assemble yourself.

A framework for the agent, a workflow engine for durability, a sandbox vendor for the computer, glue for the rest. Every seam is yours to build and yours to debug at 3am.

The layerAssembledIn Toren
01The agent loopLangChain / CrewAI / your codebuilt in: task loops, subagents, waves
02Durability+ Temporal or Inngest, wired inthe event log is the runtime
03A computer+ E2B or Modal, state on yousandbox: true, survives the worker
04Scheduling+ cron and idempotency glueexactly-once, covered by the kill matrix
05Talking to it+ a bot framework per channeldurable sessions: console, CLI, HTTP, Telegram
06Approvals & consolebuild it yourselfbuilt in, parked at $0 compute
07Deploycompose all of the abovedocker compose up · toren deploy-aws

Six systems with six failure modes, or one runtime on one Postgres event log, where a kill -9 anywhere loses nothing.

One dependency locally. Your AWS in production.

LOCAL · FREE FOREVER

docker compose up

Postgres is the entire stack: state, queue, and event log in one boring database. The scaffold runs offline; no API keys required to feel it work.

npx toren-run init → toren run

PRODUCTION · YOUR ACCOUNT

toren deploy-aws

One Terraform apply into your AWS: SQS, RDS, Fargate workers, an authenticated HTTP API. Your VPC, your keys, your data boundary. Identical binary.

toren deploy-aws --region eu-central-1 --yes

Open source, forever.

Everything the runtime does is Apache-2.0. Features never move behind a paid tier: the full runtime, the CLI, the console, the AWS deploy, approvals, scheduling, the API and SDK.

RUNNING IT FOR REAL?

Design partners

I will deploy Toren into your VPC with you, fix what breaks the same day (that is how the last five field reports went), and you keep an Apache-2.0 fork no matter what happens to me or the project. Start a thread on GitHub Discussions and say what you are running.

LATER

Hosted and BYOC tiers

Planned for teams that want the ops handled, built on the same open runtime. Tracked on the docs status page; nothing on this page moves behind them.

Run the kill test on your own machine.

The scaffold runs offline with a mock model, so the first kill -9 costs nothing. Postgres is the only thing to install.

Run the quickstart →