The apps a company actually needs are internal — dashboards over the production database, admin panels, tools full of customer records. They're exactly the apps you can't hand to a hosted builder. agentry lets your AI build them on a server you own, so your code and your data never leave your own infrastructure.
Free in early access · bring your own model, no token markup · macOS & Linux. Read the docs →
The AI writes the code. agentry is everything that makes that code into running software on your own machines — and it works with whatever agent you already use. Three layers, one connection.
An isolated environment on your server with a filesystem, a shell, package managers, and any databases or keys you wire in — so the agent builds against the real thing, not a stub.
An end-to-end encrypted link carries traffic between agentry and your server, so apps get an HTTPS URL anyone can reach while the machine itself stays off the open internet. No DNS, firewall, or certs to manage.
Every deploy is a container image kept in your registry. Ship an update or roll back to any previous build in a click — the URL and custom domain stay put. Take the image and run it anywhere.
Harness-agnostic by design. If it speaks MCP, it works — the CLI
exposes one server,
agentry mcp,
and your agent picks it up like any other.
These are the apps that query your live database and hold your customer records — so where they run isn't a convenience choice, it's a security one. Every hosted app-builder answers it the same way: your data, or a tunnel straight to it, flows through their cloud. agentry runs the app on your own server instead, right next to the data — and never sees either.
The app sits on your own server, right beside the database it reads. The connection to your data never leaves your network.
Your machine opens no inbound ports — there's nothing on it for the internet to scan, find, or attack. It works behind a firewall or NAT.
Make a deployment org-only with one setting, or add real user logins — email/password and SSO with Google, GitHub, Microsoft, or any OIDC provider — with no auth code in your app.
ops.internal
leads.internal
helpdesk.internal
Every request authenticates. Every connection is encrypted. Nothing is trusted because of where it came from. agentry sits in front of your server, not on it — and four properties keep it that way.
End-to-end encrypted, verified on every request, with no implicit trust by network location.
Every device and every server authenticates with its own certificate — no shared passwords or API keys. Lose a laptop? Revoke that one device. Everything else stays live.
agentry handles the public-facing side. Your server doesn't. No port forwarding, no public IP, no SSH key handed to a third party.
Every certificate carries an organization identifier, checked on every request. One company's sandboxes and apps are unreachable from another's connection — even with a perfectly valid device cert.
Sandbox created. Server enrolled. Deploy started. Device revoked. Every state change lands in your organization's audit log with the actor, IP, and timestamp — nothing to turn on.
The first step takes a minute. The rest is just prompting your agent and clicking deploy.
Paste one line on any Linux box — your laptop, a $5 VPS, bare metal. It connects over an encrypted link and registers in seconds. No DNS, no firewall rules, no certificates.
Wire up Claude Code, Cursor, Roo, or any MCP client once, then just ask: "use agentry to build me…". It works in a real sandbox on your server.
One click builds a container, runs it on your server, and hands back a public URL. Roll back, add a domain, or move it to a bigger box whenever you like.
Internal tools aren't only screens — they're the scheduled jobs and webhooks behind them: a morning report, a webhook that files incoming data, a nightly backup. Describe it; your agent writes it, runs it on the same server as the app, and records every run — all still inside your own infrastructure.
The agent writes features; agentry covers the platform work that usually eats your week. None of it leaves your server.
Every deploy is saved as a versioned image. Ship an update, or roll back to any past build in a click — same URL, seconds later.
Serve from app.yourco.com.
Add a couple of DNS records; HTTPS certificates are provisioned
and renewed for you.
Put a login on any app — email/password plus Google, GitHub, Microsoft, or any OIDC provider. Your code reads the user from a header; you write no auth.
Bind Postgres, Redis, S3, a vector store, or an AI key to your server once — every app the agent builds picks up the credentials automatically.
Keep the agentry runtime current from the dashboard. It pulls the latest, swaps itself in, and rolls back automatically if anything looks wrong.
Prototype on your laptop, ship to a production box, keep a staging host on the side. Switch between them in a click; bindings follow each server.
agentry itself is free. You have exactly two costs — and both stay small, because one machine hosts everything and you pay your AI provider directly, at cost.
| A small server | ~ / month | Comfortably runs |
|---|---|---|
| Hetzner CX22 2 vCPU · 4 GB |
~$5 | several apps + live sandboxes |
| Hetzner CX32 4 vCPU · 8 GB |
~$10 | a dozen-plus apps |
The number that matters: this is per server, not per app. Ten internal tools on one CX22 is still ~$5/month. Per-app platforms bill you again for every app — and again for each add-on database. Build twenty tools here and your hosting bill doesn't move.
| Model | ~ / 1M tokens | Good for |
|---|---|---|
| Open / Flash tier | cents | cheap, high-volume iteration |
| Claude Sonnet | ~$3 / $15 | the all-round sweet spot |
| Frontier (Opus / GPT) | premium | the hardest problems |
You bring the key; agentry never resells tokens or adds a margin. Because you choose the model, you choose the price — prototype on something cheap, switch to a frontier model only for the hard parts, no re-wiring.
Rough figures, early 2026 — check each provider for current rates. Want the worked-out example? See the cost breakdown →
Other AI builders host your app, hold your data, and meter your usage. agentry is the opposite bet: it's the front door, and your machine is the house. Bring your own model, your own server, your own data — and keep all three.
Code, data, and the running apps all live on hardware you control. Turn agentry off and nothing moves — it was already yours.
Every app is a standard container. Take the image and run it on any Docker host, with or without us. No data to extract, no export wizard.
Per-device certificates, mutual TLS on every hop, per-org isolation, audit by default. Your server never opens an inbound port.
No metered tier, no token markup, no per-app fee. You pay your server provider and your model provider — nothing to us.
Free in early access. Build every internal app your company needs on infrastructure you own — your code, your data, your apps, yours to keep.