Pizza Bot: Amazon open-sources an inbox for long-running AI agent work
A local-first inbox for long-running AI agents, built with DeepAgents and LangGraph.
At a glance
- What is it?
- Built on DeepAgents and LangGraph, Pizza Bot turns AI agent runs into an inbox with Unread and Action queues, checkpointed runs that survive disconnects, cron and webhook triggers, and a local-first security model.
- Who is it for?
- Pizza Bot applies an inbox metaphor to agent work and backs it with serious plumbing: a checkpointed DeepAgents and LangGraph runtime that survives disconnects, cron and webhook triggers for unattended starts, durable approval queues, six model providers including Ollama for local inference, and a local-first security posture with explicit folder grants and loopback-only defaults.
- Can I use it commercially?
- Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository received new commits within the last day.
- What is it written in?
- Mainly TypeScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.
Editorial analysis
An inbox instead of a chat window
Most AI agent tools still assume you sit and watch a run happen. Pizza Bot, developed at Amazon and released under the Apache 2.0 license, makes the opposite bet: agent work behaves like email. You start or schedule a task, go back to your day, and finished work collects in an Unread queue while runs that need a decision collect in Action. Agents keep working when you navigate away or disconnect, with the one requirement that the api-server process stays running.
The inbox framing solves a real workflow problem. Conversations can be grouped into folders without hiding matching work from the global Unread and Action queues, so organization never costs you visibility. Approval requests are durable rather than transient, which means a run that needs human sign-off does not evaporate because you closed the laptop. For anyone running background research jobs, long refactors, or scheduled reports, that model matches how the work actually happens far better than a chat transcript does.
One runtime, three frontends
Under the hood Pizza Bot runs a stateful DeepAgents and LangGraph runtime, and the same React experience ships in an Electron desktop app and the browser. A terminal CLI covers scripts and remote backends. All three frontends talk to the api-server over HTTP and SSE, and checkpointed runs survive client disconnects, so closing the desktop app never kills a run.
The server also starts work on its own. Cron or webhook triggers can kick off runs without an open conversation, which turns the tool into a scheduler for recurring agent jobs. The production graph engine is isolated in packages/runtime-langgraph, and frontends consume protocol projections rather than importing runtime or model bindings directly, a layering rule that keeps the desktop, web, and CLI clients thin and interchangeable. Skills become tool-scoped subagents whose progress shows up in an Activity panel, so delegation stays observable instead of disappearing into a black box.
Bring your own model provider
The api-server needs access to at least one model provider, and the HTTP clients do not. Amazon Bedrock, Anthropic, Google Gemini, OpenAI, OpenRouter, and Ollama are all supported. Bedrock accepts an AWS profile, AWS access keys, or a Bedrock API key with an optional region override, defaulting to AWS_REGION or us-west-2, and it combines its native catalog with the regional Mantle catalog while routing models through Converse, OpenAI Responses or Chat Completions, or Anthropic Messages depending on the advertised API family.
OpenAI and Anthropic accounts also accept custom base URLs for compatible endpoints, with OpenAI able to select Responses or Chat Completions explicitly and Anthropic supporting x-api-key or bearer authentication. A model is picked with PIZZA_MODEL set to provider and id. On the desktop, entered secrets are protected with Electron safeStorage, and server configuration persists only environment-variable references rather than raw credentials, a small detail that keeps the configuration file safe to back up and share.
Local-first by default
The security model reads like a checklist for anyone who has been burned by chatty agent tools. The api-server binds to 127.0.0.1 by default, and binding to anything beyond loopback requires authentication plus an explicit origin allowlist. Application state, including threads, checkpoints, memories, attachments, and logs, stays under a local data root, ~/.pizza-bot-oss by default, and model and tool requests go only to the providers and endpoints you configure.
Filesystem access is granted, not assumed. Each folder added under Settings and Files is read-only unless you allow writes, and remote grants name paths on the backend host, so a connected browser cannot quietly widen its reach. The one warning the project states plainly concerns extensions: MCP servers and plugins can execute commands with your user account's permissions, so install only sources you trust. Installers for macOS, Windows, and Linux ship with a SHA256SUMS file, macOS builds are signed and notarized, and the unsigned Linux packages lean on those checksums for verification.
Extending through MCP, skills, and plugins
Extension follows the same explicit-grant philosophy. MCP servers are added from the UI or through a .mcp.json file in the data root. Agent Skills live under a skills directory in the data root, and plugins package MCP servers and skills together for one-step installation. A skill becomes available once its declared tools are enabled and connected, and in a run it executes as a tool-scoped subagent whose progress appears in the Activity panel.
The override mechanism is thought through: a custom skill can replace a Built-in or Plugin skill that has the same id without modifying the original, and removing the customization reveals the original again. That makes it safe to experiment with a modified version of a bundled skill without forking anything. A built-in Pizza Bot Guide skill rounds out the setup experience by explaining features, suggesting workflows, and pointing to the project documentation, so most questions never need to leave the app.
Getting started and where the code lives
Running from source needs Node.js 24 or newer and three commands:
npm install
npm run build
npm run devnpm run dev starts the Vite frontend and the Electron desktop shell, and the shell forks and supervises its own api-server, matching the packaged application's process model. Configure a model under Settings and Providers before starting a live run. The repository layout keeps the boundaries visible:
apps/ api-server (Hono) | cli | desktop-shell (Electron) | web (React)
packages/ core | runtime-langgraph | inference-providers | plugin-api | plugin-sdk | storage | logging
plugins/ bundled Plugin packages and their packaging workspace
skills/ optional Built-in Agent Skills
tests/ LangGraph compatibility and protocol conformanceDocumentation covers running from source, extension, architecture, standalone backends with Docker and Kubernetes, security defaults, and logging with redaction, and the test suite includes LangGraph compatibility and protocol conformance checks, which is the kind of discipline you want in a tool whose whole job is running your work unsupervised.
Editorial conclusion
Pizza Bot applies an inbox metaphor to agent work and backs it with serious plumbing: a checkpointed DeepAgents and LangGraph runtime that survives disconnects, cron and webhook triggers for unattended starts, durable approval queues, six model providers including Ollama for local inference, and a local-first security posture with explicit folder grants and loopback-only defaults. Released by Amazon under Apache 2.0 with desktop, web, and CLI frontends over one api-server, it is a credible foundation for anyone running AI agents as background labor instead of supervised chats.
Frequently asked questions
What is Pizza Bot?
Pizza Bot is an open-source inbox for long-running AI agent work, developed at Amazon and released under the Apache 2.0 license. It runs agents on a stateful DeepAgents and LangGraph runtime, collects completed work in an Unread queue and approval requests in an Action queue, and offers Electron desktop, browser, and terminal CLI frontends over one api-server.
Does Pizza Bot work with local models?
Yes. Ollama is supported alongside Amazon Bedrock, Anthropic, Google Gemini, OpenAI, and OpenRouter, so the api-server can run against locally hosted models. Only the server process needs provider access; the desktop, web, and CLI clients communicate with it over HTTP and SSE without their own credentials.
Is Pizza Bot safe to run with sensitive folders?
The design is local-first and explicit: the api-server binds to 127.0.0.1 by default, all state stays under a local data root, and each folder must be granted individually through Settings and Files, read-only unless writes are allowed. The main caution is that MCP servers and plugins execute with your user permissions, so only install extensions from sources you trust.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/pizza-bot-app-pizza-bot)