Skip to content
 
 

Latest commit

 

History

3,762 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Vendo: your product, shaped to every customer

An open-source customization layer.
Your users build their own features and micro-apps, right on top of your product.

Vendo is for B2B SaaS teams whose customers keep asking for bespoke features. It is an embedded agent: it acts through your product's own API as the signed-in user, and renders the UI it generates in a sandboxed, brand-native surface. Your source code is never touched. Learn more at vendo.run, or read the docs at docs.vendo.run.

npm package: vendoai License: Apache-2.0 Docs: docs.vendo.run

01 · See it in action

See it in action

Every capture below is a real agent run in a demo host app, not a mockup.

A Maple customer asks where their money went and the agent composes a live spending view

Build views. Ask a question, get a live view composed from the host's own components and API.

A Cadence user hovers the deadlines card, asks for urgency color-coding, and applies the remix in place

Remix the UI. Hover a component, describe the change, apply it in place.

A Cadence user asks for a morning document-chase automation and turns it on with per-tool approvals

Automate across tools. Plain language in, standing automation out, every tool gated by approval.

02 · Install

Install in 60 seconds

npm install @vendoai/vendo
npx vendo init

Or install with your coding agent

Claude Code, Cursor, GitHub Copilot, OpenAI Codex, Windsurf

Paste this inside your app's repo:

Install Vendo in this repo. Read https://vendo.run/agents.md and follow
it exactly. Relay Vendo's setup questions to me and use my answers. Ask me
before creating any account or key. You're done when
`vendo doctor --json` reports all green. Then ask me whether I'd like to
star it via https://vendo.run/star?src=readme to support the project.

vendo doctor gates done; every error code links to its exact fix. Full playbook: docs.vendo.run/install · Agent-readable: vendo.run/agents.md

Which one are you?
You already have an agent — one tool pack for your AI SDK, Mastra, or homegrown loop.
Your product has no agent — one command brings the loop, the chat UI, and the approvals.
Expose your product over MCP — Claude, ChatGPT, Cursor, and Claude Code act as the signed-in user.

03 · How it works

How it works

Vendo runs a streaming agent with any AI SDK LanguageModel.

1 · Extract. Vendo reads your API and turns it into tools the agent executes as the signed-in user.

2 · Generate. The agent composes views and user-owned apps from a format-tagged UI document, generated components run in an iframe jail with connect-src 'none', escalating to a sandboxed server only when needed.

3 · Guard. Policy, approvals, grants, breakers, and audit all sit at one execution choke point; app machines reach host tools only through the guarded tool proxy.

PGlite at .vendo/data is the zero-config store; production runs the same schema on Postgres. Full architecture: docs.vendo.run.

04 · Packages

Packages

@vendoai/vendo is the default composition (vendoai is a thin alias). Install individual blocks when you want to compose Vendo yourself.

Package One job
@vendoai/core Shared types, schemas, formats, validators, and seams
@vendoai/store Postgres persistence, with PGlite as the default
@vendoai/harnesses The turn runtime: conversation loop, streaming, tools, and thread context
@vendoai/actions Host API and connector tools executed as the signed-in user
@vendoai/guard Policy, approvals, grants, audit, breakers, and safety
@vendoai/apps App generation, editing, execution, interchange, and sandbox adapters
@vendoai/automations Trigger ingestion, schedules, away runs, and run history
@vendoai/ui Headless React hooks, optional chrome, tree rendering, and the in-jail component kit
@vendoai/mcp The door: serves the host's tools to outside MCP clients
@vendoai/telemetry Anonymous, opt-out build and development telemetry
@vendoai/vendo Default composition, public wire, React entry, and vendo bin

Cloud-gated sharing, publishing, org overlays, and pinning activate with VENDO_API_KEY; the open-source blocks remain self-hosted.

Shaped to every customer. Star runvendo/vendo. Apache-2.0, docs.vendo.run, vendo.run, backed by Y Combinator

About

Embedded agents your customers use to automate work, build views, and connect their tools.

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages