Multi-tenant agents with per-user OAuth isolation

Open-source backend formulti-user AI agents

Give every user an isolated agent workspace with OAuth, connected sources, shared memory, watchers, and secrets agents never see.

Start building
Active use case: Market
lobu-prod
Connectors
6
Connections
6
Feeds
18
Devices
2

Devices

Local data into memory

Files, Screen Time, browser history — sources that only live on your machine.

Secure browser auth

Cookies and tokens stay on-device. Lobu's servers never see them.

Local notifications

Chat events, watcher triggers, and tool calls in your menu bar.

Hybrid execution

Pin sensitive workloads to your device. Everything else runs serverless.

macOS
Menu bar app · .dmg
Serverless
Free in beta

Connections

Pick from the catalog

50+ built-in connectors. OAuth, API key, or browser session.

Bring your own MCP server

Point Lobu at any MCP endpoint. Tools wire into memory automatically.

Let your agent write one

Lobu runs agent-authored TypeScript connectors serverlessly — no hosting.

Any auth shape

API key, OAuth, browser session, or none. Credentials stay where you choose.

Crunchbase
Crunchbase integration
LinkedIn
LinkedIn integration
News feeds
News feeds integration
Deal memos
Deal memos integration
Custom SDK
Custom SDK integration
GitHub
github.com
HubSpot
CRM
LinkedIn
People
Memory

Source-backed context, kept fresh.

Connect a source once. Lobu types it into memory agents can search and cite. Watchers refresh it on schedule.

Read the memory guide
Skills

One agent, every surface.

Bundle tools, packages, and network access into a skill. The same agent runs in Slack, Telegram, REST, MCP, and ChatGPT — no per-platform plumbing.

Explore skills
GitHub triage skill
Packaged capability
Installed

Give agents issue intake, owner routing, and safe GitHub actions in one reusable bundle.

Instructions
Triage new issues
Tools
GitHub MCP + gh
Network
api.github.com
Policy
Approve comments
Contract review
Support desk
Revenue research
Runs on your infrastructure

One gateway, isolated workers, no leaked secrets.

Lobu receives messages at the gateway, starts sandboxed worker processes on demand, and proxies tools, memory, and credentials so agents stay isolated from your real keys.

Messaging platforms
Slack
Block Kit, interactive actions
Telegram
Mini App, inline buttons
WhatsApp
Reply buttons, list menus
Discord
Servers, DMs, markdown replies
Teams
Channels, bots, enterprise workflows
Google Chat
Cards v2, Workspace spaces
  • Link users across platforms with single sign-on
  • Approval flows, rich cards, buttons, and more
Bring your own agent
Lobu Memory
Lobu
Control Plane
  • Workers never see secrets
  • HTTP proxy with domain allowlist
  • MCP proxy with per-user OAuth
  • BYO provider keys (Anthropic etc.)
Equip your agent
Lobu Skills
OpenClaw Runtime
User A
isolated
OpenClaw Runtime
User B
isolated
OpenClaw Runtime
User C
isolated
  • One sandbox per user and channel
  • Subprocess isolation with just-bash virtual filesystems
  • systemd-run hardening on Linux production hosts
  • No direct internet access (gateway proxy only)
  • Nix reproducible environments
  • OpenTelemetry for observability

Build your first
multi-user agent.