A minimal, extensible, agent-native knowledge base that keeps shared context current and inspectable
See the codePoint OpenLore at a folder of Markdown and every agent on your team reads the same files, whether it's Claude Code, Codex, Cursor or a CI job. Agents use the tools they already know, like cat, grep and find. You decide who can see and change what.
One-click hosted server. See Deploy OpenLore to Render.
Install and serve a folder:
brew install --cask aakarim/tap/lore
openlore ./docs
SSH runs on port 2222. The web view and MCP share port 8080. The contents of ./docs appear at /.
Connect an agent:
# Claude Code
claude mcp add --transport http openlore http://localhost:8080/mcp
# Codex
codex mcp add openlore --url http://localhost:8080/mcp
# Anything with a shell
ssh -p 2222 localhost "grep -r 'retry' /"
Tell your agents when to use it:
ssh -p 2222 localhost agents >> AGENTS.md
Or let your agent do the whole setup:
ssh openlore.sh teach | claude
Not on Homebrew? See the Quickstart for Linux and Windows.
For one agent in one repository, do that.
OpenLore is for when several agents, repositories or people need the same knowledge, and you need to say who can read, write or publish what. Update a file once and every agent sees the new version on its next read.
There's no vector database, ingestion pipeline or SDK. Your knowledge stays as ordinary Markdown.
ro, publish, and rw grants, path aliases, and
private home directories.lore meta, query it with jq, and validate Google's
Open Knowledge Format (OKF)
bundles and Agent Skills close to the write path.OpenLore is built on Wish for SSH transport. A connection is handled entirely against a virtual filesystem:
shell tool.OAuth clients use delegated identities, so durable write provenance distinguishes
direct work by adil from work performed as adil/claude@claude.ai. Delegates
can inherit no more authority than their principal and can be narrowed by
docset and capability deny lists. CIMD clients can additionally authenticate
with vendor-hosted metadata and private_key_jwt; see
Authenticated OAuth Clients.
The normal shell cannot invoke bash, exec, curl, or arbitrary host
processes. Embedded documentation is always read-only. Explicitly trusted
identities can be granted narrowly scoped asynchronous processing through the
spawn capability.
OpenLore is read-only by default. Writable deployments keep a single,
policy-controlled write path for redirects, append, tee, patch, sed -i,
file moves, publishing, and trusted external jobs.
echo "# Research" | publish /backend/findings.md
cat change.diff | patch /backend/api.md
sed -i 's/old/new/g' /backend/runbook.md
Writes are whole-object atomic swaps. Compare-and-swap protection rejects stale edits by default, docset grants constrain the target, and plugins can validate or defer a write before it commits.
See Writing and publishing for user-facing setup and Write system internals for the implementation model.
See the Quickstart for Homebrew, Linux and Windows releases, and which installations include the dashboard. To build OpenLore yourself, see Building from source.
Place documentation in assets/lore/ and build. The resulting binary contains
the docs and serves them read-only at /docs when run with no directory
argument:
make dashboard-build # optional: include the web UI
go build -o my-docs ./cmd/openlore
Produce cross-platform binaries with your docs embedded:
- uses: aakarim/openlore@v1
with:
docs-dir: ./docs
config: ./openlore.yml
See Ways to use OpenLore for direct VS Code editing, MCP stdio, MCPB desktop packaging, SSHFS, and Go library usage.
Use the bundled setup skill to create <team>-lore, a small customer-owned
repository containing openlore.yml, a thin Containerfile pinned to an
official OpenLore release, and deployment artifacts. It builds a working local
server and verifies HTTP, MCP, authenticated SSH, writes, and persistence before
deployment:
ssh openlore.sh setup | amp
The generated repository keeps initial lore.json policy and SSH-visible files
under gitignored .local/. The first deployment initialises an empty persistent
volume from that state. Root openlore.yml remains the Git/IaC authority and is
deployed separately to /var/lib/openlore/config/openlore.yml; it is not baked
into the image. Later lore.json and filesystem edits on the server are
authoritative and are never overwritten by image updates.
Additional instruction commands support the full lifecycle:
onboarding adds initial identities, roles, homes, and folders locally;deploy selects Fly.io, Railway, AWS, Google Cloud, Azure, DigitalOcean, or a
custom deployment and verifies a shared persistence/networking contract;upgrade prepares only the pinned base-image version change so existing CD
can deploy it.Provider deployments require HTTPS/MCP, authenticated OpenLore SSH,
administrative shell access, and a persistent /var/lib/openlore volume. Where
the provider supports it, deployment configures public port 22 to forward to
OpenLore port 2222. Otherwise it reports the assigned port and recommends an
external TCP forwarding system.
The published container contains only OpenLore. It deliberately contains no
onboarding policy or server configuration. Before the service starts, the
deployment must put openlore.yml and lore.json in the persistent config
directory and run:
./out --config /var/lib/openlore/config/openlore.yml
This keeps configuration independently deployable: a simple deployment can
copy openlore.yml onto the volume, while Kubernetes can project the same file
from a ConfigMap. Use the deploy skill for Fly.io, Railway, AWS, Google Cloud,
Azure, DigitalOcean, or custom infrastructure. The repository's Railpack and
Fly files provide the image, persistent-volume, and port wiring; they do not
seed or mutate configuration at process startup.
For a quick hosted server without a customised repository, use the
Deploy to Render button. Unlike the Railpack and Fly files,
its start script writes a starter openlore.yml and lore.json to an empty
disk on first boot. Render serves HTTPS, MCP and the web view only; it has no
public TCP ingress for OpenLore SSH.
Railway assigns its SSH TCP proxy a public hostname and port. Standard SSH port 22 requires an external raw TCP load balancer. Fly.io can map public port 22 to OpenLore's internal port 2222 with a dedicated address. Raw SSH has no hostname or SNI routing, so one listener cannot route multiple domains on port 22.
The container workflow publishes latest from main; releases also publish
VERSION, vVERSION, major, and minor image tags.
The same pages, in the same groups, are published at openlore.sh/docs.
| Page | Contents |
|---|---|
| What is OpenLore | Serve, connect, scope, govern and observe in one page |
| Changelog | Current version, release notes, compatibility notes, and versioned docs |
| Page | Contents |
|---|---|
| Quickstart | Install OpenLore, serve a folder, and connect an agent |
| Claude Code | Connect Claude Code over MCP and scope what it sees |
| Codex | Connect Codex over MCP |
| Cursor | Connect Cursor over MCP |
| OpenCode | Connect OpenCode over MCP |
| Any agent over SSH | Connect a coding agent or CI job over SSH and give it an identity |
How OpenLore works: transports, identity, writes, rules, and observation.
| Page | Contents |
|---|---|
| Ways to use OpenLore | SSH, MCP, web, SSHFS, embedded binaries, GitHub Action, MCPB, and library usage |
| Auth | Authentication posture, how SSH keys, certificates, passkeys, OAuth tokens and inbox credentials resolve to an identity, roles, docsets, aliases, homes, and workload identity federation |
| Writing and publishing | Write modes, inboxes, conflict handling, what a successful write does and does not check, and jobs |
| Folder rules | .lore/config.yaml and lore.json rules, layering, permissions, rejection messages, and growth limits |
| Plugins and formats | Provider interfaces, Open Knowledge Format validation, lore validate, lore meta, and the Agent Skills plugin |
| Dashboard and metrics | Dashboard authentication, facts versus activity, and the file viewer |
Task walkthroughs.
| Page | Contents |
|---|---|
| Configure the server | Create openlore.yml, precedence over embedded config and flags, analytics, and debug logging |
| Let an agent publish into an inbox | Accept contributions from an agent without letting it edit anything else |
| Browse and edit from an editor | Direct VS Code and SFTP editor setup without a local project mirror |
| Run headlong / shellm | Use OpenLore over SSH from headlong's shellm engine, including its housekeeping skill |
| Build from source | Build the web UI and binary yourself, or build without the web UI |
| Deploy OpenLore to Render | One-click Render deployment, first passkey sign-in, upgrades, and custom domains |
Lookup material: commands, keys, endpoints, interfaces, and internals.
| Page | Contents |
|---|---|
| Command reference | Complete shell, introspection, publishing, syntax, CLI command, and flag reference |
| openlore.yml reference | Generated reference for every key openlore.yml accepts |
| Rules standard library | Generated reference for compiled-in rule members and their parameters |
| HTTP inbox API | POST /inbox/{docset} with bearer or HMAC credentials, and the token endpoints |
| OAuth clients | CIMD client identity, private_key_jwt, mTLS corroboration, and signing-key rotation |
| Write system internals | Filesystem layering, write seam, admission middleware, and async jobs |
| Build the dashboard | Frontend build and backend-only Go builds |
| Security evaluation | Threat model and security properties |
os/exec.See SECURITY.md for the full security evaluation.
Apache License 2.0 — Copyright © 2026 Adil Karim
OpenLore bundles third-party open-source components. Their licences and required
notices are listed in
assets/legal/THIRD_PARTY_NOTICES.md, with
full licence texts in assets/legal/licenses/. These are
embedded in the binary and served by the running service at /legal.
894 followers · starred Sep 2026
188 followers · starred Aug 2026
A minimal, extensible, agent-native knowledge base that keeps shared context current and inspectable
See the codePoint OpenLore at a folder of Markdown and every agent on your team reads the same files, whether it's Claude Code, Codex, Cursor or a CI job. Agents use the tools they already know, like cat, grep and find. You decide who can see and change what.
One-click hosted server. See Deploy OpenLore to Render.
Install and serve a folder:
brew install --cask aakarim/tap/lore
openlore ./docs
SSH runs on port 2222. The web view and MCP share port 8080. The contents of ./docs appear at /.
Connect an agent:
# Claude Code
claude mcp add --transport http openlore http://localhost:8080/mcp
# Codex
codex mcp add openlore --url http://localhost:8080/mcp
# Anything with a shell
ssh -p 2222 localhost "grep -r 'retry' /"
Tell your agents when to use it:
ssh -p 2222 localhost agents >> AGENTS.md
Or let your agent do the whole setup:
ssh openlore.sh teach | claude
Not on Homebrew? See the Quickstart for Linux and Windows.
For one agent in one repository, do that.
OpenLore is for when several agents, repositories or people need the same knowledge, and you need to say who can read, write or publish what. Update a file once and every agent sees the new version on its next read.
There's no vector database, ingestion pipeline or SDK. Your knowledge stays as ordinary Markdown.
ro, publish, and rw grants, path aliases, and
private home directories.lore meta, query it with jq, and validate Google's
Open Knowledge Format (OKF)
bundles and Agent Skills close to the write path.OpenLore is built on Wish for SSH transport. A connection is handled entirely against a virtual filesystem:
shell tool.OAuth clients use delegated identities, so durable write provenance distinguishes
direct work by adil from work performed as adil/claude@claude.ai. Delegates
can inherit no more authority than their principal and can be narrowed by
docset and capability deny lists. CIMD clients can additionally authenticate
with vendor-hosted metadata and private_key_jwt; see
Authenticated OAuth Clients.
The normal shell cannot invoke bash, exec, curl, or arbitrary host
processes. Embedded documentation is always read-only. Explicitly trusted
identities can be granted narrowly scoped asynchronous processing through the
spawn capability.
OpenLore is read-only by default. Writable deployments keep a single,
policy-controlled write path for redirects, append, tee, patch, sed -i,
file moves, publishing, and trusted external jobs.
echo "# Research" | publish /backend/findings.md
cat change.diff | patch /backend/api.md
sed -i 's/old/new/g' /backend/runbook.md
Writes are whole-object atomic swaps. Compare-and-swap protection rejects stale edits by default, docset grants constrain the target, and plugins can validate or defer a write before it commits.
See Writing and publishing for user-facing setup and Write system internals for the implementation model.
See the Quickstart for Homebrew, Linux and Windows releases, and which installations include the dashboard. To build OpenLore yourself, see Building from source.
Place documentation in assets/lore/ and build. The resulting binary contains
the docs and serves them read-only at /docs when run with no directory
argument:
make dashboard-build # optional: include the web UI
go build -o my-docs ./cmd/openlore
Produce cross-platform binaries with your docs embedded:
- uses: aakarim/openlore@v1
with:
docs-dir: ./docs
config: ./openlore.yml
See Ways to use OpenLore for direct VS Code editing, MCP stdio, MCPB desktop packaging, SSHFS, and Go library usage.
Use the bundled setup skill to create <team>-lore, a small customer-owned
repository containing openlore.yml, a thin Containerfile pinned to an
official OpenLore release, and deployment artifacts. It builds a working local
server and verifies HTTP, MCP, authenticated SSH, writes, and persistence before
deployment:
ssh openlore.sh setup | amp
The generated repository keeps initial lore.json policy and SSH-visible files
under gitignored .local/. The first deployment initialises an empty persistent
volume from that state. Root openlore.yml remains the Git/IaC authority and is
deployed separately to /var/lib/openlore/config/openlore.yml; it is not baked
into the image. Later lore.json and filesystem edits on the server are
authoritative and are never overwritten by image updates.
Additional instruction commands support the full lifecycle:
onboarding adds initial identities, roles, homes, and folders locally;deploy selects Fly.io, Railway, AWS, Google Cloud, Azure, DigitalOcean, or a
custom deployment and verifies a shared persistence/networking contract;upgrade prepares only the pinned base-image version change so existing CD
can deploy it.Provider deployments require HTTPS/MCP, authenticated OpenLore SSH,
administrative shell access, and a persistent /var/lib/openlore volume. Where
the provider supports it, deployment configures public port 22 to forward to
OpenLore port 2222. Otherwise it reports the assigned port and recommends an
external TCP forwarding system.
The published container contains only OpenLore. It deliberately contains no
onboarding policy or server configuration. Before the service starts, the
deployment must put openlore.yml and lore.json in the persistent config
directory and run:
./out --config /var/lib/openlore/config/openlore.yml
This keeps configuration independently deployable: a simple deployment can
copy openlore.yml onto the volume, while Kubernetes can project the same file
from a ConfigMap. Use the deploy skill for Fly.io, Railway, AWS, Google Cloud,
Azure, DigitalOcean, or custom infrastructure. The repository's Railpack and
Fly files provide the image, persistent-volume, and port wiring; they do not
seed or mutate configuration at process startup.
For a quick hosted server without a customised repository, use the
Deploy to Render button. Unlike the Railpack and Fly files,
its start script writes a starter openlore.yml and lore.json to an empty
disk on first boot. Render serves HTTPS, MCP and the web view only; it has no
public TCP ingress for OpenLore SSH.
Railway assigns its SSH TCP proxy a public hostname and port. Standard SSH port 22 requires an external raw TCP load balancer. Fly.io can map public port 22 to OpenLore's internal port 2222 with a dedicated address. Raw SSH has no hostname or SNI routing, so one listener cannot route multiple domains on port 22.
The container workflow publishes latest from main; releases also publish
VERSION, vVERSION, major, and minor image tags.
The same pages, in the same groups, are published at openlore.sh/docs.
| Page | Contents |
|---|---|
| What is OpenLore | Serve, connect, scope, govern and observe in one page |
| Changelog | Current version, release notes, compatibility notes, and versioned docs |
| Page | Contents |
|---|---|
| Quickstart | Install OpenLore, serve a folder, and connect an agent |
| Claude Code | Connect Claude Code over MCP and scope what it sees |
| Codex | Connect Codex over MCP |
| Cursor | Connect Cursor over MCP |
| OpenCode | Connect OpenCode over MCP |
| Any agent over SSH | Connect a coding agent or CI job over SSH and give it an identity |
How OpenLore works: transports, identity, writes, rules, and observation.
| Page | Contents |
|---|---|
| Ways to use OpenLore | SSH, MCP, web, SSHFS, embedded binaries, GitHub Action, MCPB, and library usage |
| Auth | Authentication posture, how SSH keys, certificates, passkeys, OAuth tokens and inbox credentials resolve to an identity, roles, docsets, aliases, homes, and workload identity federation |
| Writing and publishing | Write modes, inboxes, conflict handling, what a successful write does and does not check, and jobs |
| Folder rules | .lore/config.yaml and lore.json rules, layering, permissions, rejection messages, and growth limits |
| Plugins and formats | Provider interfaces, Open Knowledge Format validation, lore validate, lore meta, and the Agent Skills plugin |
| Dashboard and metrics | Dashboard authentication, facts versus activity, and the file viewer |
Task walkthroughs.
| Page | Contents |
|---|---|
| Configure the server | Create openlore.yml, precedence over embedded config and flags, analytics, and debug logging |
| Let an agent publish into an inbox | Accept contributions from an agent without letting it edit anything else |
| Browse and edit from an editor | Direct VS Code and SFTP editor setup without a local project mirror |
| Run headlong / shellm | Use OpenLore over SSH from headlong's shellm engine, including its housekeeping skill |
| Build from source | Build the web UI and binary yourself, or build without the web UI |
| Deploy OpenLore to Render | One-click Render deployment, first passkey sign-in, upgrades, and custom domains |
Lookup material: commands, keys, endpoints, interfaces, and internals.
| Page | Contents |
|---|---|
| Command reference | Complete shell, introspection, publishing, syntax, CLI command, and flag reference |
| openlore.yml reference | Generated reference for every key openlore.yml accepts |
| Rules standard library | Generated reference for compiled-in rule members and their parameters |
| HTTP inbox API | POST /inbox/{docset} with bearer or HMAC credentials, and the token endpoints |
| OAuth clients | CIMD client identity, private_key_jwt, mTLS corroboration, and signing-key rotation |
| Write system internals | Filesystem layering, write seam, admission middleware, and async jobs |
| Build the dashboard | Frontend build and backend-only Go builds |
| Security evaluation | Threat model and security properties |
os/exec.See SECURITY.md for the full security evaluation.
Apache License 2.0 — Copyright © 2026 Adil Karim
OpenLore bundles third-party open-source components. Their licences and required
notices are listed in
assets/legal/THIRD_PARTY_NOTICES.md, with
full licence texts in assets/legal/licenses/. These are
embedded in the binary and served by the running service at /legal.
894 followers · starred Sep 2026
188 followers · starred Aug 2026