Open-source AI agent control plane · Apache 2.0

The control plane
your AI agents deserve.

Every team is shipping agents on its own framework and cloud. AgentOven is the one place to govern, connect and prove all of them.

illustrative · 5 agents, 4 clouds
Without AgentOven, five agents built by different teams on different clouds connect directly to models, customer data and actions, and nobody can say who approved them, what data they saw, what they cost or what they did. With AgentOven, every agent goes through one control plane that records owners and approvals, runs guardrails, tracks cost per agent, holds risky actions for a human and keeps an audit trail. YOUR TEAMS' AGENTS WHAT THEY TOUCH support-botLangGraph · AWS claims-agentCrewAI · Azure sales-copilotOpenAI SDK · GCP kyc-checkercustom · on-prem vendor agentthird-party SaaS LLM providersOpenAI · Anthropic · Gemini Customer dataCRM · KYC records Payments & refundsrefunds-api Email & messagingoutbound to customers AgentOven ✓ registry & owners ✓ guardrails ✓ cost per agent ✓ human approvals ✓ audit trail ✓ A2A · MCP · OTel
0shared controls
?agents with a known owner
$0spend attributed
0%actions with an audit trail

Every team ships agents on its own stack, wired straight into models, customer data and actions. Nobody can answer the basic questions.

The problem

Agents are shipping faster than anyone can govern them.

Agents no one owns

Every team ships agents on its own framework and cloud. Nobody has the full list, or knows who approved each one.

Registry, owners and approvals

Data sent to models unchecked

Customer records and PII flow into prompts and tool calls with nothing checking them on the way.

Guardrails on every call

Spend no one can attribute

The AI bill grows every month, and nobody can say which agent or team drove it.

Cost tracked per agent

Actions with no sign-off

Agents issue refunds and email customers. When something goes wrong, there's no approval on record and no trail.

Human gates and audit trail
Works with what you already runLangGraphCrewAIOpenAI SDKAzure OpenAIBedrockVertexOllamaOpenTelemetry
Platform

One oven. Three jobs.

AgentOven is an open-source (Apache 2.0) control plane that governs, connects and tests AI agents across any framework, model and cloud.

Govern

Decide what every agent may do, and prove what it did.

RBAC + SSOApproval gatesAudit trailCost trackingPII detection

Connect

Protocol-driven. Agents stay portable across frameworks and clouds.

A2AMCPOTelACP · roadmap

Prove

Rehearse agents in a simulated world before customers see them.

World schemasScenariosFault injectionTest suitesWorlds · early access
How it's built

One oven, every layer of the agent stack.

From the loop inside a single agent to the approvals around a whole team of them.

The Executor wraps every model call: renders the prompt, runs tools, retries, and stops at max_turns.

agent harnessagent looptool use

A token budget per agent. Recent turns stay, older ones are summarised, and sessions keep state across requests.

context engineeringcompactionmemory

One MCP Gateway per kitchen holds the credentials; agents only see tools. Agents talk to each other over A2A.

MCPA2Atool calling

DAG workflows of agents, routers and fan-outs. A human gate pauses the run until someone approves.

multi-agentorchestrationhuman-in-the-loop

Inputs and outputs are checked before they reach the model or the user, with workspace-wide defaults.

guardrailsprompt injectionLlamaGuard

Test suites catch regressions on every change. Worlds rehearse agents against simulated users and grade what they changed.

evalsRL environmentssimulation

Route by cost, latency or fallback across providers. Every hop is an OpenTelemetry span with cost attached.

LLM routerfallbacktracing
All 14 features, explained →
From bake to production

One agent's path, end to end.

  1. Bake: Register any agent, from any framework, and bake it live with an A2A endpoint.
  2. Govern: Every call is checked for identity, scoped keys and guardrails such as PII detection, and its cost is tracked; risky steps wait at a human gate.
  3. Prove: Agents are rehearsed in a simulated world (early access) and graded on what they changed, not what they said.
  4. Promote: Versions move from dev to staging to production with test results and a human approval on record.
kitchen: payments
Register any agent, from any framework, and bake it live with an A2A endpoint.
Developer experience

Your language. Our oven.

Keep your framework. Register it, bake it, test it and promote it from code or the terminal.

✓Native SDKs for Python, TypeScript and Rust
✓Declarative agentoven apply for GitOps
✓Local server in one command
from agentoven import Agent, AgentOvenClient

client = AgentOvenClient(kitchen="payments")

client.register_agent(Agent(
    name="refund-resolver",
    framework="langgraph",
))

client.bake("refund-resolver", environment="staging")
# 🔥 live at /agents/refund-resolver/a2a
Compare

Not another framework. The layer above them.

CapabilityFrameworksLangGraph · CrewAIHyperscalersFoundry · AgentCore · VertexLLM gatewaysPortkey · LiteLLMAgentOven
Governs agents from any frameworkOwn onlyMostly ownModel callsYes
Approval gates + env promotionDIYVariesNoBuilt in
Immutable audit trailNoYesLogsYes
Native A2A + MCPAdaptersVariesNoYes
Protocol-neutral roadmapn/aVendor-ledn/aYes
Simulated worlds + scenariosNoEvals onlyNoEarly access
Grades on world state, not an LLM judgeNoNoNoEarly access
Multi-cloud modelsYesOwn firstYesYes
Self-host / air-gappedYesNoSomeYes

Full comparison → · Why not a hyperscaler? →

Ready to fire up the oven?

curl -fsSL https://raw.githubusercontent.com/agentoven/agentoven/main/install.sh | sh