Model or dataset
xpert-ai/xpert avatar
xpert-ai/xpert

Xpert's self-host path asks for 4 GiB of RAM while its own API container is capped at 8

XpertAI is an open-source platform for building, running, and evolving ai agents, providing extensible capabilities and infrastructure for diverse AI systems.

462 stars89 forksTypeScriptAGPL-3.0

At a glance

What is it?
A plugin-first NestJS platform for building and governing AI teams, with agent definitions compiled into LangGraph state graphs, a desktop app that runs approved local shell commands on macOS, and a self-host path short enough to fit in four commands. The interesting seams are in the packaging: a private root manifest, an empty description, and a Python sandbox runner tested from JavaScript.
Who is it for?
Xpert fits a team that wants governance features, permissions, approvals, and audit trails around agent runs rather than a bare model call, and it fits a self-hosting budget of two cores and 4 GiB for evaluation. It does not fit someone expecting a published library, since the root package is private with an empty description and the only GitHub release covers the desktop app.
Can I use it commercially?
Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 2, 2026, and from our analysis. They are not legal advice.

Editorial analysis

Bosi runs local shell commands on macOS, one approval at a time

The desktop app is where local execution actually happens. Assistants configured in the platform can operate a cloud computer or run local Shell commands on macOS, and the stated default is per-command approval, so nothing local runs without a decision per command. Around that sits a workspace model: sign in with your Xpert account, work inside an organization's permissions, discover experts, request access, or create Assistants from templates and apps, and combine conversations, files, and Workbench views in one place. Workspace plugins can be added and then selected per conversation, which means the toolset changes with the thread rather than globally. The division of labour is stated plainly: the platform runs the agents and manages shared resources, and Bosi supplies the desktop experience and that authorized local execution. Self-hosted users switch the server in Connection settings, so the same desktop app points at a local deployment.

Self-hosting is four commands and a stated 2-core, 4 GiB budget

Hosting the platform yourself is described in four lines, and every one of them is a Docker Compose path rather than a Node install:

bash
git clone https://github.com/xpert-ai/xpert.git
cd xpert/docker
cp env.example .env
docker compose up -d

The resource floor is stated as 2 CPU cores, 4 GiB of RAM, Docker, and Docker Compose, with no GPU requirement mentioned. After startup you open `http://localhost/` and complete an initialization step before connecting Bosi, which means the desktop app cannot be pointed at the server until that first-run state exists. Working on the source instead of hosting it takes a supported Node.js LTS and the repository-pinned pnpm through Corepack, so the package manager version is fixed by the repository rather than chosen by the developer. The repository also carries an `env.local` file at the top level, which is a separate convention from the `env.example` to `.env` copy the host path relies on.

The API container defaults to production while the webapp defaults to development

The compose file is an `include` of `docker/docker-compose.infra.yml` plus two services, and the defaults in them disagree about intent. The `api` service sets `NODE_ENV` to production by default and caps Node at `--max-old-space-size=8192`, while `webapp` sets `NODE_ENV` to development and takes no memory cap. The api service waits on `db` and `redis`, points at an `olap` host on port 8080, exposes 3000 without publishing a host port, and mounts four volumes including a `/sandbox/` directory and a plugins directory. Its healthcheck is not a curl probe but `node healthcheck.cjs` every 30 seconds with a 10 second timeout, 3 retries, and a 10 second start period, and the process itself runs under `pm2-runtime` with `restart: unless-stopped`. Two details read as dated: the `links` key next to an explicit `networks` entry, and the commented-out `HOST` and `PORT` lines in the environment block.

The root manifest is private, versioned 3.0, and has an empty description

The root package.json carries `"name": "xpert.ai"`, `"version": "3.0"`, `"license": "AGPL-3.0"`, and `"private": true`, with `"description": ""` left empty. It also names an author company, XpertAI Co. LTD, and a keyword list of Xpert, AI, Agent, and Copilot. The private flag sits oddly next to a README badge pointing at a published npm package, `@xpert-ai/contracts`, so the repository publishes selected packages while its root does not. The version number disagrees with the release history too: the only GitHub release is `desktop-v0.2.0`, named Bosi 0.2.0 and dated 2026-09-30, while the manifest says 3.0 and the most recent push is dated 2026-10-01. The dev scripts show the shape of the monorepo: `start` runs an api server and a cloud server side by side, the cloud script first runs a hardcoded-colour theme check and then launches with a 12288 heap cap, and an Angular variant is served on port 4400 against a client base that defaults to 4200.

A JavaScript script shells out to python3 to test the sandbox runner

Two npm scripts point at a runner that the architecture section never names. `start:nsjail:dev` composes three files, the root `docker-compose.yml` plus a base and a dev override under `.deploy/nsjail-runner/`, and brings up a service called `nsjail-runner` with build and no-dependency flags. The matching test is `test:nsjail-runner`, which runs `python3 .deploy/nsjail-runner/test_runner.py`. So a TypeScript and NestJS monorepo carries a Python test entry point for the process that contains agent code execution, and the api service mounts a `/sandbox/` volume for it. The architecture section does list governed infrastructure, with scoped identities, approvals, audit, and usage spanning the API, workers, and plugins, but its final bullet on the data layer stops mid-word at `PostgreSQL + pgve`, so the storage story is unfinished in the text.

Two kinds of plugin, two different trust levels

The plugin story has a split that matters more than the extension list. Native npm plugins register NestJS modules, providers, configuration, and lifecycle hooks, with extension points for models, tools and MCP, middleware, Skills and templates, workflows, integrations, connectors, data and RAG, execution, storage, views, and collaboration. Conversation resources are the other kind: standard Agent Plugin packages supply Skills and MCP resources through Git or ZIP import, and their use is controlled by workspace grants, versioned bindings, and per-run resource snapshots. Those imported bundles do not load server code, which is the property that separates them from the native plugins. The rest of the runtime follows from the same layering. Agent definitions compile into LangGraph state graphs, workflows add branches, parallel paths, iteration, and subflows, checkpoints preserve state for interruption and human input, and Workbench views are rendered through View Manifests and an iframe bridge.

The platform map lists seven areas, and one of them is a widget kit

The capability table is worth reading as a scope statement. Agent Studio authors digital experts, multi-agent workflows, tools, knowledge, and middleware. Files and Knowledge parses files, retrieves evidence with RAG and GraphRAG, and cites sources. Agentic BI and Data Xpert queries and acts on enterprise data through semantic models and governed tools. Agentic Apps and Workbench delivers business applications with Assistant tools and interactive review views. MCP, Skills, and Plugins extends models, integrations, tools, middleware, and managed runtimes. ChatKit and Embedding is the odd one out, aimed at embedding streaming chat, files, tools, and widgets into React, Vue, Angular, SAP UI5, or Web Components, which puts a front-end integration kit in the same list as the agent runtime. Operations closes it by tracking tasks, tool calls, usage, logs, metrics, and retention.

Bilingual READMEs, two license files, and a design review document at the root

The repository root is unusually crowded, and the extra files say how the project is run. Documentation comes in two languages, README.md and README_zh.md, and the English one links a desktop guide, a plugin marketplace, a self-hosting page, and a documentation site as four separate entry points. Licensing has two files, a root LICENSE and a LICENSES.md that the README badge row points at, alongside the AGPL-3.0 field in the manifest. There is a design review document, `design-qa.md`, with a matching screenshot at the top level, plus `AGENTS.md`, `CHANGELOG.md`, a `.changeset/` directory, a `.verdaccio/` directory for a local registry, a `.storybook/` directory, jest configuration, four Tailwind workspace files, and a `git-hooks/` directory. None of that is unusual for a large monorepo, but it means the README is an index into a much larger working surface rather than a description of the whole.

Editorial conclusion

Xpert fits a team that wants governance features, permissions, approvals, and audit trails around agent runs rather than a bare model call, and it fits a self-hosting budget of two cores and 4 GiB for evaluation. It does not fit someone expecting a published library, since the root package is private with an empty description and the only GitHub release covers the desktop app. Verify three things before committing. Which licence document governs the code you intend to reuse, given a root LICENSE and a separate LICENSES.md. Whether the conversation resource import path is the trust level you want, since those bundles supply Skills and MCP resources but do not load server code. And whether the Python sandbox runner matters to you, since it is exercised by a script outside the TypeScript toolchain and is not named in the architecture section.

Frequently asked questions

What is xpert-ai/xpert?

A plugin-first NestJS platform for building and governing AI teams, plus Xpert Bosi, its desktop app. Agent definitions compile into LangGraph state graphs, and the platform supplies the runtime, permissions, approvals, and audit trails that plugins extend.

What does self-hosting Xpert require?

Two CPU cores, 4 GiB of RAM, Docker, and Docker Compose. You clone the repository, copy `env.example` to `.env` inside `xpert/docker`, run `docker compose up -d`, then open http://localhost/ and complete initialization before connecting Bosi.

Can Xpert Bosi run shell commands on my own machine?

On macOS, yes, and each command needs approval by default. Configured Assistants can also operate a cloud computer. The platform runs the agents and manages shared resources, while Bosi provides the desktop experience and that authorized local execution.

Are Xpert plugins allowed to load server code?

It depends on the kind. Native npm plugins register NestJS modules, providers, configuration, and lifecycle hooks, while conversation resources imported from a Git or ZIP archive supply Skills and MCP resources only and do not load server code.

Which version of Xpert is published?

The root package.json is private, carries version 3.0, and has an empty description field. The single GitHub release is `desktop-v0.2.0`, named Bosi 0.2.0 and dated 2026-09-30, and the most recent push on the default branch is dated 2026-10-01.

What license is Xpert released under?

AGPL-3.0, declared in the root package.json, with a LICENSE file at the top level and a separate LICENSES.md beside it that the README badge row links. Check which of the two governs the code you intend to reuse.

Official sources

  1. Issues
  2. License: AGPL-3.0
  3. Project website
  4. README
  5. xpert-ai/xpert on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/xpert-ai-xpert.svg)](https://hysenlabs.com/projects/xpert-ai-xpert)