We earn commissions when you shop through the links below. Full disclosure →
A self-hosted runtime for governed agentic networks: instead of an agent library you import into your own app, AgentArea runs agents durably as infrastructure, with VPC-style network isolation between them, tool-approval workflows, ReBAC authorization, and full audit trails. Built on Temporal for durable execution, provider-agnostic via LiteLLM, and extensible through hosted MCP servers.
Pick AgentArea when you want agents run as long-lived infrastructure — Temporal for durable execution, Ory Kratos for identity, a LiteLLM proxy for any model provider — rather than a library inside your own app, and you have the machine for it: the compose file defines 16 services (API, worker, events, frontend, MCP manager and sandbox runner, plus `postgres:18`, Valkey 8, Temporal 1.29.1, Kratos 1.3.1, RustFS object storage and a handful of one-shot init/migration jobs; upstream's own requirements page counts it as 14 containers). It is Apache-2.0 and at version 0.0.14 as of September 2026 — early, and its own requirements page publishes no sizing figure. If what you actually want is a coding agent with a browser UI, OpenHands is the simpler install.
What you need
Any VPS with at least 4096 MB of RAM
A domain you control — most self-hosted setups need HTTPS in front of them
Paid link — we earn a commission if you shop through it.
Install
Run these commands on your server:
# AgentArea — official bootstrap script (README Quick Start). Downloads only the runtime bundle# (Compose file + auth/Temporal config) into ./agentarea and generates its credentials — no clone.curl -fsSL https://raw.githubusercontent.com/agentarea/agentarea/main/scripts/install.sh | sh# At a terminal it asks "Start AgentArea now? [Y/n]"; without one (CI, provisioning) it only downloads —# either way, everything after this is plain Docker Compose from ./agentarea:cd agentarea && docker compose up -d # first run pulls images (a few minutes) → http://SERVER_IP:3000# add an LLM provider key (Anthropic/OpenAI/etc.) under Settings, then create an agent
AgentArea is pre-1.0 and its self-host docs are candid about what bites:
non-negotiableOur snippet's ./agentarea/agentarea doctor, pull and up commands do not exist. scripts/install.sh downloads docker-compose.yaml, .env.example and the Kratos and Temporal configs into ./agentarea, writes a .env with generated secrets (VERSION=latest, random Postgres and RustFS credentials, a Fernet key), warns if Docker is missing, then offers to start; the manual start is cd agentarea && docker compose up -d. Re-running the installer is also the upgrade path — "Everything else in this directory is managed by the installer and is replaced when you run it again"; only .env is yours.
non-negotiableThe installer writes VERSION=latest, and the upgrade guide says "Pin X.Y.Z for any deployment you care about. latest moves under you on someone else's schedule." Upgrading is the guide's VERSION=0.0.13 docker compose -f docker-compose.yaml pull followed by the same up -d with the new number; migrations "are not reversible in practice", so back up first and check all five component images moved together.
non-negotiableBy default the stack publishes 3000 (web), 8000 (API), 7999 (MCP manager) and 4433 (Kratos public API) on the host, and the self-host guide warns that .env.example ships a published test KRATOS_JWKS_B64 — "Anyone can mint tokens your API will accept. Replace it before exposing the API to a network you do not control." (As of September 2026 the file actually ships the variable empty and the installer generates the key per install; check what ended up in your .env either way.) Behind a domain you must set API_BASE_URL, ORY_SDK_URL/ORY_BROWSER_URL and PUBLIC_S3_ENDPOINT, because a Kratos session cookie "scoped to localhost is not sent to app.example.com, so login appears to succeed and every subsequent request is anonymous."
non-negotiableSECRET_MANAGER_ENCRYPTION_KEY is the Fernet key that encrypts every stored credential — "A database backup without it restores ciphertext nobody can open, and there is no recovery path." Back up every Postgres database with pg_dumpall — the compose stack creates agentarea, temporal and kratos; the backup guide's list adds openfga, which only the Helm stack has — the two RustFS buckets with rclone sync, and .env; on restore, put the original key back before anything else starts.
non-negotiableThe 4 GB floor matches docs/deployment.md ("4GB+ RAM, 20GB+ storage" for Compose), but docs/self-host/requirements.md says "No sizing figure has been measured for this repo, so none is published here" and the developer quickstart asks for 16 GB — treat 4 GB as where the stack starts, not where agents run comfortably. Sandboxing is containers, not kernels: "Egress rules constrain the network; they do nothing about a container escape."