Open-source project
coze-dev/coze-studio avatar
coze-dev/coze-studio

Coze Studio: self-hosting ByteDance's open source agent builder with Docker

An AI agent development platform with all-in-one visual tools, simplifying agent creation, debugging, and deployment like never before. Coze your way to AI Agent creation.

21,654 stars3,122 forksTypeScriptApache-2.0

At a glance

What is it?
Coze Studio is the open sourced core engine of ByteDance's Coze platform: a Go and React agent builder you deploy yourself. It installs with one make target, but you must register an account and configure a model before it does anything useful.
Who is it for?
Coze Studio fits teams that want a visual agent, workflow and knowledge base builder they can run on their own hardware and extend in Go and TypeScript, and who accept that model configuration is a manual first step.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 62 days ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 28, 2026, and from our analysis. They are not legal advice.

DEEP OPEN-SOURCE ANALYSIS

The problem Coze Studio solves, and who it is actually for

Building an agent that works in a demo is easy. Building one that a team can iterate on, publish, and hand to other people is not, because prompts, retrieval, tool calls and multi-step logic end up scattered across scripts. Coze Studio packages those pieces into one visual environment. The README describes it as an all-in-one AI agent development tool that provides the core technologies for agent development: prompt, RAG, plugin and workflow. The audience is stated just as plainly. It is for developers who want no-code or low-code construction of agents, apps and workflows, and for teams building their own low-code AI products on top of a framework rather than from scratch.

The repository is derived from the Coze Development Platform, which the README says has served tens of thousands of enterprises and millions of developers, and the open source version is the core engine of that platform. That provenance explains the shape of the code: this is not a weekend project. The backend is Go, the frontend is React with TypeScript, and the README states the architecture is microservices built on domain-driven design. If you want a small library you can read in an afternoon, this is the wrong repository. If you want a platform whose resource model (agents, apps, workflows, plugins, knowledge bases, databases, prompts) already exists, the value is in adopting that model rather than inventing one.

How the pieces fit: Go microservices, a React studio, and a model layer you must wire up

The visible architecture splits into three parts. The backend in backend/ is Go, the frontend in frontend/ is React and TypeScript, and the two meet through idl/, where the interface definitions live. The README states the overall design is microservices following domain-driven design, which is why the feature list reads like a set of bounded contexts: model service, agent building, app building, workflow building, and resource development for plugins, knowledge bases, databases and prompts.

The model service is the part that most affects day-to-day work. The feature list says it manages the model list and integrates services such as OpenAI and Volcengine. That integration is not automatic. The developer guide states that before deploying the open source version you must configure the model service, otherwise you cannot select models when building agents, workflows and apps. The same applies to plugins: to use official plugins from the plugin store you must first configure them and add authentication keys for third-party services. So the data flow is: you bring provider credentials, register them in the admin area, and only then do the visual builders have anything to call. Common/ holds shared code and helm/ holds deployment charts, while docker/ contains the Compose files and the MySQL and Elasticsearch volumes referenced by the Makefile, including schema.sql and an Elasticsearch index schema, which tells you search and retrieval are backed by those two stores rather than something embedded.

Installing Coze Studio with Docker Compose and building a first agent

The README states the minimum system requirement is 2 cores and 4 GB, and that Docker and Docker Compose must be installed with the Docker service running. Start by cloning the repository.

bash
git clone https://github.com/coze-dev/coze-studio.git
cd coze-studio

On macOS or Linux, the README gives a single make target. The first run pulls images and builds local ones, and the README says this can take a while; the signal that the service is up is the message Container coze-server Started.

bash
make web

On Windows the README uses Compose directly, copying the example environment file first.

bash
cp ./docker/.env.example ./docker/.env
docker compose -f ./docker/docker-compose.yml up

With the service running, open http://localhost:8888/sign, enter a username and password, and register. Then go to http://localhost:8888/admin/#model-management and add a model. The README notes the image version must be greater than or equal to 0.5.0 for this. Only after that is the studio itself usable at http://localhost:8888/. If startup fails, the README points to the FAQ wiki page rather than listing causes inline. The Makefile shows the development path is different: debug depends on env, middleware, python and server, and copies ./docker/.env.debug.example to ./docker/.env.debug if it is missing, so a source checkout and a container deployment are not the same setup.

The public network warning is the most important paragraph in the README

Coze Studio ships with a warning block, and it is unusually direct. It states that if you deploy in a public network environment you should assess security risks first and take protection measures. The named risks are account registration functions, Python execution environments in workflow code nodes, the Coze Server listening address configuration, SSRF, and some horizontal privilege escalations in APIs. It links to the Quickstart wiki page for detail.

Read that as a deployment constraint rather than boilerplate. An open registration endpoint on a public host means anyone can create an account on your instance. A workflow node that executes Python is remote code execution by design, which is fine when the people writing workflows are your own engineers and not fine when they are not. The listening address configuration determines how much of the service is reachable. None of these are bugs in the ordinary sense; they are consequences of shipping a platform that is meant to run a code execution step and an open signup flow. The README does not document rollback or a hardened production profile, so if you need one, you are designing it yourself. For internal or air-gapped use behind a firewall, the calculus is very different from a public deployment.

Where Coze Studio is the wrong tool

Three cases stand out. First, if you want an agent library inside an existing application, Coze Studio is a platform, not a package. You would be running Go microservices, MySQL and Elasticsearch to get behaviour you could otherwise call directly from your own code. Second, if you need a hosted service with no operational surface, this is the opposite: you own the containers, the database, the model credentials and the upgrade path. Third, if your agents are simple prompt-and-response wrappers with no workflow, knowledge base or plugin needs, the feature list here is mostly overhead. The plugin store is a concrete example of the trade-off: it exists, but the developer guide says you must configure plugins and add third-party authentication keys before the official ones work, so the storefront is not a turnkey catalogue.

There is also a version constraint worth naming. The releases listed are v0.5.1 from 2026-02-05, v0.5.0 from 2025-10-29, and v0.5.0-beta from 2025-10-21. The last push to the repository was on 2026-07-29, and the repository is not archived. The gap between the most recent release and the most recent push means main moves ahead of tagged versions, so pinning to a release and tracking main are different commitments.

Dify and n8n as alternatives, and where the approach differs

Dify is the closest comparison in category: an open source platform for building LLM applications with visual orchestration, prompts and retrieval. The practical difference is the centre of gravity. Coze Studio's own framing is a resource model of agents, apps, workflows, plugins, knowledge bases, databases and prompts, with an OpenAPI and a Chat SDK for integrating the results into your own application. If you already think in terms of publishing an agent and then calling it from a client, that model matches. Dify's community and plugin ecosystem are larger, which matters when you want an existing integration rather than writing one.

n8n is a different kind of tool that people reach for in the same situation. It is a general workflow automation engine with a large node library, and it treats LLM steps as one node type among many. If your problem is mostly moving data between SaaS systems with an AI step in the middle, n8n is the more natural fit and Coze Studio is the heavier one. If your problem is an agent with a knowledge base, a tool set and a publishable API, the reverse holds. The honest summary is that Coze Studio's differentiator is the completeness of the agent resource model, not the workflow editor, which every tool in this space now has.

Licence, upgrade cost and what maintenance actually looks like

The repository is Apache-2.0, with LICENSE-APACHE at the top level, and the README badge confirms apache2.0. Apache-2.0 permits commercial use and modification and includes a patent grant, which is why it is a common choice for platform code that companies want to embed. It also means redistribution obligations apply to the licence and notices; that is a description of the licence text, not legal advice, and if you plan to ship a modified Coze Studio as part of a product, a lawyer should read the terms rather than this article.

The upgrade cost is the part teams underestimate. Deployment is Docker Compose against a MySQL schema and an Elasticsearch index schema that live in docker/volumes, and the Makefile exposes sync_db, dump_db and db_migrate scripts, which tells you schema changes are a real part of moving between versions. The README does not document a rollback procedure, so a version bump is a forward migration unless you have your own database backup. Startup itself is not instant: the README warns the first run takes a while to retrieve and build images. If you run this in production, budget for the database migration step and for testing a release before you replace a running instance.

Editorial conclusion

Coze Studio fits teams that want a visual agent, workflow and knowledge base builder they can run on their own hardware and extend in Go and TypeScript, and who accept that model configuration is a manual first step. It does not fit anyone expecting a hosted service or a single-binary install: the README requires Docker and Docker Compose, and the deployment warning lists account registration, Python execution in workflow code nodes, SSRF and API privilege escalation as risks to assess before exposing it publicly. Verify three things first: that your machine meets the stated 2 core, 4 GB minimum; that you have credentials for a supported provider such as OpenAI or Volcengine, since the model-management page is empty until you add one; and that your image version is at least 0.5.0, because the README ties model management to that version.

Frequently asked questions

What is ByteDance coze?

Coze is ByteDance's agent development platform, and Coze Studio is the open source version of its core engine. The README states the platform has served tens of thousands of enterprises and millions of developers, and that the open source release makes the core engine available under Apache-2.0.

What does "coze" mean?

The repository does not define the word. The README uses it as the product name throughout, and the project describes itself as an all-in-one AI agent development tool you can use to build, debug and deploy agents.

How do I install Coze Studio with Docker?

Clone the repository, then run make web on macOS or Linux, or copy ./docker/.env.example to ./docker/.env and run docker compose -f ./docker/docker-compose.yml up on Windows. The README states the service is up when you see the message Container coze-server Started, and that the first run takes a while because images are retrieved and built locally.

Why can I not select a model in Coze Studio?

The developer guide states that the model service must be configured before deployment, otherwise you cannot select models when building agents, workflows and apps. After starting the service, register at http://localhost:8888/sign and add a model at http://localhost:8888/admin/#model-management. The README notes the image version must be greater than or equal to 0.5.0.

What are the security risks of running Coze Studio on a public network?

The README warning lists account registration functions, Python execution environments in workflow code nodes, the Coze Server listening address configuration, SSRF, and some horizontal privilege escalations in APIs. It recommends assessing security risks and taking protection measures before deploying publicly, with details in the Quickstart wiki page.

Official sources

  1. coze-dev/coze-studio on GitHub
  2. Issues
  3. License: Apache-2.0
  4. README
  5. Releases
For maintainers

Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/coze-dev-coze-studio.svg)](https://hysenlabs.com/projects/coze-dev-coze-studio)
Community notes

Community notes