NodeTool ships five editors over one typed graph, with auth off by default
Agent-first Creative Workspace
At a glance
- What is it?
- An AGPL creative workspace where an agent and five editors share a single node graph, invalidation is by staleness rather than regeneration, and providers are called with your own keys. The self-hosted compose file is explicit about its own exposure: local mode means no login, no password, and admin access for anything on a trusted network.
- Who is it for?
- Use NodeTool when a team wants one project file that both an agent and a person can edit, and when paying providers directly on your own keys matters more than a hosted suite. Do not deploy the reference compose file to a public address as written: it publishes a server that authenticates nothing, so the choice is Supabase login or a firewall, and `NODETOOL_TRUST_LOCAL_NETWORKS` has to cover the Docker bridge gateway or every API and websocket call returns 401.
- Can I use it commercially?
- Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
- Is it still maintained?
- Yes. The repository last received commits 1 day ago.
- What is it written in?
- Mainly TypeScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.
Editorial analysis
Local mode means no login, no password, and admin rights for the network
The reference compose file leads with a warning block rather than a service definition, and it is unusually blunt about what the deployment is. Local mode runs with no login and no password, and every request arriving from a trusted network executes as the single admin user `1`, with full access to workflows, files, stored secrets and API keys. The file states it is safe on a laptop, a private LAN or a VPN, and that before it goes on a public IP or is shared with untrusted users you must either enable Supabase auth or keep the port firewalled. The environment file describes the same mechanism from the other side: `NODETOOL_TRUST_LOCAL_NETWORKS` names the source CIDRs that bypass login without a password, and behind Docker a published-port connection arrives from the bridge gateway rather than loopback, so that range has to be included or every API and websocket call 401s. Authentication is opt-in through three Supabase values, read by the web UI at runtime through `GET /api/config`, so no frontend rebuild is needed to turn it on.
The container listens on 7777 and publishes 17777 by default
The quick start is three lines:
cp .env.example .env
docker compose up -dand then you open `http://localhost:17777`. The port you type is not the port the server binds: inside the container the websocket and HTTP server binds to `0.0.0.0:7777`, while the compose file publishes it on the host as `${NODETOOL_PORT:-17777}`. The environment file ships `HOST=0.0.0.0` and `PORT=7777` for the in-container value, so a copied `.env` describes the wrong side of the mapping if you read it as a client. Two other environment choices matter for a real deployment: `DB_PATH` points at a local SQLite file and is commented as the development default, with `DATABASE_URL` for PostgreSQL as the alternative, and all persistent state, including the SQLite database, assets, the vector store, the model cache and the generated secret key, lives under `/workspace` on a named `nodetool-data` volume so it survives restarts and image upgrades. `NODETOOL_VERSION` pins a release and `NODETOOL_IMAGE` points at your own build.
Stale, not regenerated, is how five editors share one project
One invalidation rule runs through every editor, and it is the mechanism worth understanding before anything else. A script voice take is flagged stale when the words change. A timeline clip regenerates when a bound workflow parameter changes, and flags itself stale when the workflow itself is tweaked. A sketch layer flags itself stale when a prompt or an upstream input changes, and the rest of the workflow then receives the flattened image, the mask, and each layer on its own. The point is that nothing silently re-bills a provider: the artefact is marked, and a person decides. The same idea holds at the storyboard level, where revising one shot runs video-to-video on that single clip and swaps it in place rather than regenerating the reel, and where each clip stays linked to its shot after assembly. Entities, characters, locations, styles and props, paste the same descriptor into every prompt that names them, which is what keeps a cast steady across separate generations.
Typed ports refuse a mismatch, so an image cannot land in a text field
Every editor above sits on one canvas, and that canvas is where the type system lives. Dragging a node in and connecting typed ports gives live output at each step, double-clicking the canvas searches for a node, and dragging a connection into empty space shows what fits. The editor refuses a mismatch, which is the concrete form of that typing: an image cannot be connected to a text field. The 3D editor works the same way round, since a scene of primitives and lights can be captured as a depth or composition reference and fed to an image or video model, and the same scene builds and renders with no editor open, so it comes back the same way every time. Cost guidance is stated in the same concrete terms elsewhere in the documentation: a still costs cents and a clip costs dollars, which is the argument for generating stills until one looks right and only then animating that one.
Recipes name the models their chain calls, on your own keys
A recipe is a downloadable bundle that runs on your keys at provider list prices, and the README tabulates what each chain actually calls. The viral video ad recipe runs GPT-5 mini, FLUX.1 Schnell and Kling 2.6. The multilingual dub recipe runs GPT-4o mini Transcribe, GPT-5 mini, OpenAI TTS, Inworld TTS and Sync Lipsync, and hands back one presenter clip lip-synced into a second language with subtitles and a back-translation. The SKU visual set calls Bria background removal, Nano Banana, image relighting, LTX 2.3, a Clarity upscaler and GPT-5 mini to turn one packshot into a cutout, a studio scene, a seasonal relight, a turntable clip, a print master and listing copy. Storyboard to trailer calls GPT-5 mini, Gemini 3.1 Pro, GPT Image 2, Veo 3.1 and Stable Audio 2.5. The billing claim is that NodeTool calls each provider with your key at their price, with no billing unit in between, and Studio itself is free on macOS, Windows and Linux while NodeTool Cloud is in alpha.
Fifty-odd workspaces, and one of them sits outside packages/
The root package is marked private and lists its workspaces, which is the clearest map of what the product is made of: protocol, gpu, timeline, storyboard, the runtimes, image-editor, model3d, kernel, execution, a node SDK and a DSL, then provider packages such as `fal-nodes`, `replicate-nodes`, `kie-nodes`, `elevenlabs-nodes`, `higgsfield-nodes`, `together-nodes` and `topaz-nodes`, several of which are paired with a `*-codegen` package that presumably generates them. One entry breaks the pattern: `reliability/harness` is a workspace outside `packages/`, and it is a dependency of `packages/cli`. That single exception has visible consequences in the Dockerfile, which copies `packages/*/package.json` and `reliability/*/package.json` separately with `--parents`, because npm has to resolve the whole workspace graph without every manifest being hand-listed. The image is built from `node:24.18.0-bookworm-slim`, needs native build tools including `libsecret-1-dev`, and rebuilds `better-sqlite3` in a root postinstall.
Two nightly tags sit next to v0.8.0 in the releases list
The three most recent releases are `v0.8.0` published on 2026-09-25, then `v0.8.1-nightly.20260925.788` and `v0.8.1-nightly.20260926.789` on the following two days. Nightly builds are being cut as named GitHub releases rather than kept as prereleases, so anyone browsing the releases page for a stable download has to filter past build-numbered tags to find the real version. The default branch was last pushed on 2026-10-01, a day before this was written, so the nightly line is moving faster than the stable tag. The licence recorded for the repository is AGPL-3.0, with `LICENSE.txt` at the root, and that matters more than usual for this particular project: the pitch is running the same workflow from the studio, the CLI or an external agent over MCP, which is exactly the shape of embedding a copyleft licence governs. Nothing in the tree settles how that licence applies to a third-party agent calling in.
Editor and agent configuration is committed as product surface
The top level is crowded with configuration that other projects keep out of version control. There are three lint profiles, `.oxlintrc.json`, `.oxlintrc.anti-slop.json` and `.oxlintrc.anti-slop-enforced.json`, alongside `eslint.config.mjs`, plus `skills-lock.json`, `.claude`, `.agents/`, `.jules/`, `.cursorignore`, `.design-sync/` and `.vscode/`. Build and test orchestration is `turbo.json` with `vitest.config.ts` and `react-doctor.config.json`. Beyond the core app there are `chrome-extension/`, `mobile/`, `web/`, `electron/`, `workspace/`, `demo/`, `marketing/`, `plugins/`, `packaging/` and `output/`, and the `demo/` workspace carries its own package.json, a `remotion.config.ts`, a `benchmarks/` directory and `webpack-stubs/`. Deployment artefacts sit next to them: `Dockerfile`, `docker-compose.yml`, `fly.toml`, `install.sh` and `start.sh`. Five agent-facing markdown files at the root, `AGENTS.md`, `CLAUDE.md`, `CONTEXT.md`, `PRODUCT.md` and `MANIFESTO.md`, suggest the repository is read as much by agents as by people.
Editorial conclusion
Use NodeTool when a team wants one project file that both an agent and a person can edit, and when paying providers directly on your own keys matters more than a hosted suite. Do not deploy the reference compose file to a public address as written: it publishes a server that authenticates nothing, so the choice is Supabase login or a firewall, and `NODETOOL_TRUST_LOCAL_NETWORKS` has to cover the Docker bridge gateway or every API and websocket call returns 401. Verify the licence with your own counsel before wiring it into a product, since AGPL-3.0 is the licence recorded here and the MCP surface invites exactly that kind of embedding. Cloud is still alpha, so treat hosted storage as not yet an option.
Frequently asked questions
Does NodeTool need a login to run the self-hosted server?
Not by default. The reference compose file runs in local mode with no login and no password, and every request from a trusted network executes as the single admin user `1` with full access to workflows, files, stored secrets and API keys. Supabase auth has to be enabled, or the port firewalled, before it goes anywhere untrusted.
Which port does the NodeTool Docker deployment expose?
The server binds to `0.0.0.0:7777` inside the container and is published on the host as `${NODETOOL_PORT:-17777}`, so the documented first step opens `http://localhost:17777`. All persistent state, including the SQLite database, assets, vector store, model cache and the generated secret key, lives on the `nodetool-data` volume.
How does NodeTool decide what to regenerate after an edit?
It marks work stale instead of silently re-running it. A voice take goes stale when the words change, a sketch layer when a prompt or upstream input changes, and a timeline clip when its bound workflow is tweaked, in which case the clip flags itself stale rather than regenerating. Revising one shot runs video-to-video on that clip alone.
Which AI providers does a NodeTool recipe call, and who pays?
Each recipe names the chain it calls, for example GPT-5 mini, FLUX.1 Schnell and Kling 2.6 for the viral video ad. NodeTool calls each provider with your own API key at the provider's price, with no billing unit in between, and Studio itself is free on macOS, Windows and Linux while NodeTool Cloud is in alpha.
What licence is NodeTool released under?
The repository records AGPL-3.0, with `LICENSE.txt` at the root. No other licence file sits beside it, and the project can be driven from the studio, the CLI or an external agent over MCP, so check the terms against your own use before embedding it.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/nodetool-ai-nodetool)