Skip to content

Open source · Self-hosted · Coming soon

Run your AI agents without nasty surprises

Self-hosted agents fail in two expensive ways: they get left open to the internet, and they quietly burn model credits. GambaOS watches both, and manages OpenClaw and Hermes from one panel.

Want it when it drops?

One email when it launches. Unsubscribe anytime.

Free and open source. Your keys never leave your machine. Download →

Security audit

2 to fix
57 / 100

Real audit result

What an untuned default deployment usually scores the first time.

  • NET-01 Gateway bound to 0.0.0.0 — reachable from the internet
  • AUTH-03 No access password set
  • WS-02 Workspace scope is restricted

What it does

Built around what actually goes wrong

Not a feature list — three problems that cost self-hosters real money.

01

Security audit

Find the door you left open

Tens of thousands of agent deployments sit exposed on the public internet. One click checks your gateway binding, authentication, channel policies and workspace scope, then links straight to the page that fixes each finding.

  • Scores your deployment out of 100
  • Every finding links to the setting that fixes it
  • Runs locally — nothing is sent anywhere

Checks

  • Gateway binding Critical
  • Authentication Warning
  • Channel policy Pass
  • Workspace scope Pass

Each finding links straight to the setting that fixes it.

02

Cost guard

Hear about it before the bill does

Idle heartbeats can quietly ship your full context to the model every few minutes. Set a monthly budget and GambaOS projects month-end spend at your current rate, warning you while there is still time to act.

  • Projects month-end spend from your current burn rate
  • Warns at your threshold, not after the invoice
  • Breaks spend down by model and channel
This month Over budget
Budget Today
03

Two engines, one panel

OpenClaw and Hermes side by side

Models, channels, agents, sessions, logs and scheduled tasks — managed the same way whichever engine you run, so switching does not mean relearning your tools.

  • One interface for both runtimes
  • Models, channels, sessions, logs, scheduled tasks
  • Switch engines without relearning the panel

OpenClaw

  • Models
  • Channels
  • Sessions
  • Scheduled

Hermes

  • Models
  • Channels
  • Sessions
  • Scheduled

Same operations, either runtime.

Boundaries

Why you can leave this running

A panel that holds your API keys has to earn that. Here is what it does and does not do.

Runs on your machine
A desktop app, or a container on your own VPS. There is no GambaOS cloud to send your data to.
Keys stay local
API keys live in your own config. The panel reads them to talk to your providers, and that is the end of it.
No telemetry
The upstream analytics were removed, not hidden behind a flag. The panel does not phone home.
AGPL-3.0
The whole panel is open source. Read it, fork it, audit it before you trust it with your keys.

Blog

Notes on running self-hosted AI agents without losing money or leaking your data.

All posts →
6 min read

Turning an AGPL panel into a product, in public

What it actually takes to fork an open-source project into something with its own name — the telemetry, the revenue placements, the naming, and the parts that went wrong.

Read →

5 min read

Why your model bill creeps up every month

Agents do not bill like chatbots. Heartbeats, growing context, retries and cache misses each cost almost nothing per call and a lot per month. Here is where the money actually goes.

Read →

Be first through the door

Builds are being prepared. Leave your email and we will send the download link the day it opens — nothing else.

One email when it launches. Unsubscribe anytime.