Design choices

The decisions behind Appstrate, and what they mean when you ship an agent to a team or embed one in a product.

Appstrate runs agents for teams and inside products. A few design choices explain most of how it behaves. This page lists them, so you can check each one against what you need.

What you get

ChoiceWhat it means
Open source coreThe platform is Apache 2.0. The @appstrate/module-ee module (Stripe billing and credit quotas) is source-available and opt-in.
Self-hostDocker Compose, or Bun alone with no Docker for development. See Self-hosting.
Multi-tenantOrganizations, spaces and end-users, with typed permissions and roles. See Multi-tenancy.
Bring your own modelOpenAI, Anthropic, OpenAI-compatible endpoints. See Models.
Sandboxed runsOn the docker backend each run gets its own container and network, and on the opt-in firecracker backend its own microVM. The default process backend is for development and is not a security boundary. See Sandbox and sidecar.
Credentials out of the model's reachA sidecar injects credentials into outbound requests. The agent never sees the secret.
Everything over an APIThe dashboard uses the same REST API (OpenAPI 3.1) you do. See API reference.
Portable packagesAgents, skills, integrations and MCP servers ship as AFPS packages with semantic versioning and integrity checks.

Sidecar isolation

On the docker and firecracker backends, an agent runs on its own network, next to a sidecar. The agent talks to the sidecar over MCP. The sidecar holds the credentials and adds them to outbound requests just before they leave. A prompt injection can make the agent say anything, but it cannot read a token it never had. See Architecture.

Prompt-driven, not graph-driven

An Appstrate agent gets a goal such as "summarize important emails and notify me on Slack", and the model decides which tools to call and in what order. You author a prompt, not a graph of steps. The trade-off is less predictability. Output schemas and run history keep it in check.

AFPS and Skills

A SKILL.md file is a valid AFPS unit. AFPS wraps skills in a package model with a manifest.json, semantic versioning, declared dependencies and scoped names, so installs are reproducible and integrity can be verified. See the AFPS specification.

Use it with the tools you already have

You can drive an Appstrate agent from a coding agent through the API, the CLI or an MCP client. Any HTTP client can launch an agent through the API.

Next

On this page