- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Documented (README)
- !No description
git clone https://github.com/federico2001/OpenGlassResumen de Tools
# OpenGlass
A neutral witness for agent-to-agent interactions. See [`docs/SPEC.md`](docs/SPEC.md) and [`CLAUDE.md`](CLAUDE.md).
## Run locally
```sh
docker compose up --build -d --wait
curl -k https://localhost/health # {"status":"ok","checks":{"mongo":"ok","s3":"ok"}}
```
Caddy serves `https://localhost` with a certificate from its internal CA. `-k` skips verification. To trust the CA instead:
```sh
docker compose cp caddy:/data/caddy/pki/authorities/local/root.crt ./caddy-root.crt
curl --cacert caddy-root.crt https://localhost/health
```
| Service | URL | Notes |
| ------- | --- | ----- |
| web | https://localhost/ | Next.js |
| api | https://localhost/health, `/v1/*` | Fastify. Runs `migrate` on every start. |
| mcp | https://localhost/mcp | |
| mongo | `mongodb://localhost:27017/openglass?directConnection=true` | `mongo:7`, single-node replica set `rs0` |
| minio | http://localhost:9001 (console) | bucket `openglass-records`, Object Lock on. User `openglass` / `openglass-dev-secret`. |
| mailpit | http://localhost:8025 | Catches all outgoing email |
MinIO no longer publishes official images, so compose uses the maintained community build [`pgsty/minio`](https://hub.docker.com/r/pgsty/minio), pinned to a release.
## See it in action
[`examples/witnessed-negotiation`](examples/witnessed-negotiation) is a runnable, end-to-end demo: two agents register, get claimed, negotiate a purchase order over a witnessed session, close it, and independently verify the resulting record — against the real API, not a mock. See [`examples/README.md`](examples/README.md).
## Risk policy
[`/spec/openglass-policy`](spec/openglass-policy) is a small, versioned, vendor-neutral YAML format for classifying an agent's action as `low`/`medium`/`high` risk — deciding *when* an action is worth a witnessed record, separate from the attestation mechanism itself (`docs/SPEC.md` §12). Reference evaluators: [`core-js`](core-js) (`@openglass/core`) and [`core-py`](core-py) (`openglass-core`), kept in sync by a shared set of test vectors. See [`docs/POLICY.md`](docs/POLICY.md) for the guide.
## Integrations
[`otel-js`](otel-js)/[`otel-py`](otel-py) (`openglass-otel`) plug into an already-OpenTelemetry-instrumented agent: a `SpanProcessor` reads GenAI spans, classifies each against an `openglass-policy`, and opens an attestation for the risky ones — no OpenGlass-specific code in the agent itself. See [`examples/otel-integration`](examples/otel-integration) for a runnable demo. [`langchain-py`](langchain-py) (`openglass-langchain`) does the same for [LangChain](https://www.langchain.com/) tool calls via a `BaseCallbackHandler` — see [`examples/langchain-integration`](examples/langchain-integration). [`/integrations/_template`](integrations/_template) is the starting point for a new framework-specific integration, including the conformance tests every integration must pass.
The public [`/integrations`](https://openglass.glass/integrations) page is the request board: a card per framework (from a static catalog, [`apps/api/data/integrations.yaml`](apps/api/data/integrations.yaml)), voting and a request form (gated on the existing owner login, not GitHub OAuth — see the PR that added this for why), and an admin view at `/integrations/admin` to update status. Admin access needs the `ADMIN_EMAILS` env var set (comma-separated owner emails) — nobody is an admin until it is.
[`scripts/adoption-review.ts`](scripts/adoption-review.ts) is a runnable report over that board's live data (vote leaderboard, the 3 frameworks to prioritize next, new requests) — run it yourself or from your own cron, whenever you want it, rather than it running unattended:
```sh
node --experimental-strip-types scripts/adoption-review.ts
# optionally: OG_ADMIN_SESSION_COOKIE="og_session=..." to include the request queue (admin-only)
```
## Develop and test
```sh
corepack enable
pnpm install
pnpm -r build
pnpm -r typecheck
pnpm -r test # starts a throwaway mongo:7 container (needs Docker)
```
### Same tests, different MongoDB
The database is configured by `MONGODB_URI` and nothing else. With `MONGODB_URI` unset, the tests start a throwaway `mongo:7` container. With it set, they run against that server instead. Each test file uses its own `og_test_<random>` database and drops its collections afterwards.
```sh
# the local compose Mongo
MONGODB_URI='mongodb://localhost:27017/openglass?directConnection=true' pnpm -r test
# an Atlas free-tier cluster: only the URI changes
MONGODB_URI='mongodb+srv://<user>:<password>@<cluster>.mongodb.net/openglass?retryWrites=true&w=majority' pnpm -r test
```
For the Atlas run:
- The database user needs `readWriteAnyDatabase` and `dbAdminAnyDatabase`. Tests create per-file databases, and `migrate` runs `collMod` to set validators.
- Your IP must be on the cluster's access list.
The production app user only needs `readWrite` and `dbAdmin` on the `openglass` database.
### Schema changes
- Collections are defined in [`packages/db/src/models`](packages/db/src/models). Each has a Zod model, a `$jsonSchema` validator generated from that model, and named indexes. `migrate` applies all of them idempotently on api start, under a lock.
- Data changes go in versioned scripts: `pnpm --filter @openglass/db migration:create <name>`, which writes to `packages/db/migrations`.
## Deploy
`main` is built, pushed to ECR and deployed to a single EC2 instance by [`.github/workflows/deploy.yml`](.github/workflows/deploy.yml). The AWS resources and first-time setup are in [`infra/README.md`](infra/README.md).
Lo que la gente pregunta sobre OpenGlass
¿Qué es federico2001/OpenGlass?
+
federico2001/OpenGlass es tools para el ecosistema de Claude AI con 0 estrellas en GitHub.
¿Cómo se instala OpenGlass?
+
Puedes instalar OpenGlass clonando el repositorio (https://github.com/federico2001/OpenGlass) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar federico2001/OpenGlass?
+
Nuestro agente de seguridad ha analizado federico2001/OpenGlass y le ha asignado un Trust Score de 77/100 (tier: Trusted). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene federico2001/OpenGlass?
+
federico2001/OpenGlass es mantenido por federico2001. La última actividad registrada en GitHub es del 2026-09-28, con 0 issues abiertos.
¿Hay alternativas a OpenGlass?
+
Sí. En ClaudeWave puedes explorar tools similares en /categories/tools, ordenados por popularidad o actividad reciente.
Despliega OpenGlass en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/federico2001-openglass)<a href="https://claudewave.com/repo/federico2001-openglass"><img src="https://claudewave.com/api/badge/federico2001-openglass" alt="Featured on ClaudeWave: federico2001/OpenGlass" width="320" height="64" /></a>Más Tools
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
An AI skill that provides design intelligence for building professional UI/UX across multiple platforms.
🪨 why use many token when few token do trick. Viral skill + proxy for coding agents that cuts 65% of tokens by talking like a caveman.
CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
The fastest, litest AI Gateway. Rust core with Python SDK. Call 100+ LLM APIs in OpenAI (or native) format with cost tracking, guardrails, load balancing, and logging [Bedrock, Azure, OpenAI, Anthropic, OpenAI, VertexAI, vLLM, Nvidia NIM]
Use Claude Code, Codex, VSCode, Pi, and OpenCode (and 6 other harnesses) for free (1.3B+ free tokens) from your terminal, app, IDE, or phone, and now from the browser with native browser sessions (multi-harness + multi-model) like OpenClaw (voice supported + ToS friendly)