Your coding agents are already doing quests. OpenBoard gives them a guild hall.
OpenBoard is a local-first command center for running an AI-agent workforce like an RPG guild: missions become quests, worktrees become outposts, and pull requests become the raid board.
Agent workflows get hard to reason about once several terminals, branches and review loops are active. OpenBoard puts the operational state in one place without pretending to be a general orchestration platform.
- See agents, missions and recent activity live.
- Spawn isolated Git worktrees for Codex missions.
- Pause, resume or message tmux-backed workers.
- Inspect pull requests and arm merge only after green checks and approval.
- Keep the state in a boring local SQLite database.
flowchart LR
UI[React dashboard] <-->|HTTP + WebSocket| API[Express control plane]
API --> DB[(SQLite)]
API --> GH[GitHub CLI]
API --> TMUX[tmux + Codex]
TMUX --> WT[isolated Git worktrees]
One Node process owns the state and local actions. One React app renders it. That is enough for a single-operator tool.
Prerequisites: Node.js 22+, GitHub CLI, and optionally tmux/Codex for live agent control.
npm ci
cp .env.example .env
# configure a GitHub OAuth app, then generate a session secret:
openssl rand -hex 32
npm run dev- Dashboard:
http://localhost:5173 - API:
http://127.0.0.1:3000
The OAuth callback for local development is http://localhost:3000/api/auth/github/callback.
OpenBoard can launch tools on your machine, so shell actions are off by default.
When ENABLE_SHELL_ACTIONS=true:
- the server still listens on
127.0.0.1by default; - only the exact executables
git,gh,tmuxandopenclaware allowed; - commands use argument arrays, not interpolated shell strings;
- repository and worktree paths must stay under
REPO_ROOT; - OAuth is restricted to one GitHub login and protected with a one-time
statevalue; - automated merge is a separate opt-in and requires green checks,
MERGEABLE, andAPPROVED.
This is a local operator tool. Do not expose it directly to the public internet.
npm ci
npm run lint
npm test
npm run build
npm audit --omit=devThe targeted tests cover the dangerous edges: executable allowlisting, path traversal, tmux argument quoting and merge gates. CI runs the same checks on every push and pull request.
OpenBoard is single-user and local-first. It has no team RBAC, distributed queue, plugin marketplace or cloud deployment abstraction. Those belong only after the single-operator workflow proves it needs them.
