DocsFor developers
For developers

A hosted AI coding agent for Discord, Telegram and the browser - nothing for you to run.

Ergod is a hosted AI agent: a frontier-model agentic loop, a Docker sandbox per user with a persistent /workspace, 92 tools, MCP in both directions (it connects to your servers, and Claude Code or Cursor can call it as one), GitHub with ephemeral credentials, shared rooms several people work in at once, and a web dashboard over the same files. You add it to a Discord server or your account, message it on Telegram, or sign in to a browser tab; you host nothing, keep nothing awake and bring no API key unless you want to. Here is how the inside works.

Architecture

One agent. One container per user. One conversation per session.

Every message you send gets routed through the same agentic loop you'd build with the Anthropic, OpenAI, or Vercel AI SDKs - except it's hosted, the tools are pre-wired, and the workspace persists across messages.

1. Discord

Slash command or @-mention

Your message hits Ergod's gateway. It checks rate limit, server config, role/channel allowlists, then routes to your container.

2. Session

Conversation state

Your active /session is loaded - full message history, system prompt, tool schemas, MCP-discovered tools merged in.

3. Container

Per-user Docker sandbox

A Linux container with your /workspace volume mounted. Cold start up to ~20s, warm replies 10-15s. Code, files, installed packages - all yours.

4. Loop

Plan → tool → observe → repeat

The model writes code, runs commands, reads files, fetches the web, fixes its own errors. Until it's done.

5. Output

Files in the channel, files in the browser

Finished files attached in the channel. The same files show up in the dashboard file browser, where you can open one in place, download it, or mint a public link. Tool calls and reasoning stream back as they happen, on both surfaces, from one state machine.

Sandbox

Per-user Docker, persistent volume, full Linux.

Each account gets its own container. Not a shared notebook, not an emulated REPL - a real Linux box with disk, network, and an apt of installed tooling.

  • Isolation. Your personal workspace and history stay yours. When a server channel has no saved choice, Ergod asks before starting: Shared room uses the group’s agent, workspace, and history; Just me uses yours. Ergod remembers the choice. Messages and replies posted in the channel remain visible there.
  • Persistence. The /workspace volume survives across messages, sessions, and restarts. Pip installs stick. Generated files stick. Reset with /workspace reset.
  • Network. Outbound HTTP works - npm, pip, GitHub, web search, MCP servers, the wider internet.
  • Cold start. Up to ~20s on a fresh container. 10-15s when warm. Idle containers hibernate; resume on demand.
  • Storage. 1 GB on Free, 5 GB on Pro, 10 GB on Pro+. Channel sessions get their own quota.
your container
$ uname -a
Linux ergod-u-487a 6.1 #1 SMP x86_64 GNU/Linux

$ which python node go cargo
/usr/local/bin/python
/usr/local/bin/node
/usr/local/go/bin/go
/root/.cargo/bin/cargo

$ ls /workspace
README.md  site/  scripts/  game_state.json

$ pip install pandas
Successfully installed pandas-2.2.3
# (still installed next message)

$ curl https://api.github.com/zen
Anything added dilutes everything else.
Built-in tools

92 tools already wired in.

Every tool is exposed as a structured tool call to the model - same schema as the Anthropic API, same patterns as Claude Code or aisdk.dev. You don't configure any of it.

Filesystem

Read

Read a file with offset/limit pagination. Aliased as read_file.

Write

Create or overwrite a file in the workspace. Aliased as write_file.

Edit

Surgical find-and-replace with unique-string anchoring. Aliased as edit_file.

MultiEdit

Several anchored edits to one file applied as a single operation.

Glob

Find files by pattern. Aliased as list_files.

Grep

Ripgrep-backed regex search over file contents, with context lines.

Code execution

Bash

Arbitrary shell inside the container - pipes, env, subshells, all of it. Also how git and gh run.

REPL

Persistent Python or Node interpreter. Variables, imports and state survive across calls, unlike Bash. Not offered on the hosted product - it runs on the host rather than inside your container, so it is stripped from the schema and the model never sees it.

CodeOutline

Structural outline of a source file - symbols and signatures without reading the whole thing.

LSP

Python language server: go-to-definition, references, hover, diagnostics, rename. Loads on demand.

Web

WebSearch

Live search. Returns titles, URLs and snippets only - the agent follows up with WebFetch.

WebFetch

Fetch a URL as clean text. Falls through to a headless browser when a site blocks the fast path or renders via JS.

BrowserNavigate

Drive a real headless browser - navigate, click, fill, evaluate. On demand, behind a ToolSearch lookup.

BrowserScreenshot

Screenshot the page the browser is on, returned to the model as image input.

Getting artifacts out

Attach

Deliver workspace files to you in the channel - one file, a batch, or a zipped bundle. This is the delivery path; there is no hosted-preview tool.

GenerateImage

Generate an image into the workspace, then Attach it.

Skill

Load a saved skill - a reusable instruction bundle you registered with /skill add.

Memory & sessions

MemorySave

Persist a fact about you across sessions and conversations.

MemorySearch

Keyword, semantic or hybrid recall over stored memories.

MemoryList

List everything currently stored about you.

MemoryDelete

Delete a stored memory by name.

SessionSearch

Search across your past sessions for something you already worked on.

Planning & delegation

EnterPlanMode

Plan a large change and get your sign-off before touching files.

TodoWrite

Track multi-step work in the open, so you can see where a long task is.

Agent

Delegate an isolated sub-task to a sub-agent. On demand, behind a ToolSearch lookup. Pro and above - Free runs one agent at a time.

ToolSearch

The lazy-loader itself. Specialized tools stay dormant until the model asks for them by name.

These are real registered tool names, as the model sees them — a representative selection, not the whole inventory. The registry holds 99 tools; 7 are blocked on the hosted product because they run outside your container, leaving 92reachable from any surface. All 92 are listed on the How it thinks page. Weighing this against running your own? Ergod vs Claude Code and Ergod vs OpenClaw are the honest versions, including where each of them wins; it is not a VS Code alternative, which is the other question people ask in the same breath. Git and GitHub are not separate tools: after /github link, the agent runs ordinary git and gh through Bash with your token in the environment. Sharing a file on a public URL is a dashboard action, not a tool - see below.

MCP - bring your own tools

Anthropic's Model Context Protocol, fully supported.

Connect remote HTTP MCP servers (Linear, Sentry, Supabase, Notion, Stripe, your own) - or run stdio MCP servers directly inside your sandbox. Discovered tools merge into the model's tool list on the next turn. Fuller write-up on the MCP client and server page - and the direction that runs the other way, where your local Claude Code delegates work to Ergod as a hosted MCP server, has its own page.

Remote MCP (HTTP)

Streamable-HTTP transport. OAuth or bearer-token auth. Ideal for SaaS connectors with managed servers.

/mcp add
  name: linear
  url:  https://mcp.linear.app/sse

→ Connected linear.
→ Discovered 7 tools, 2 resources.
→ Available on next turn.

Stdio MCP (in-container)

The server runs as a child process inside your sandbox. Talks JSON-RPC over stdin/stdout. Perfect for npx/uvx servers.

/mcp add-stdio
  name:    fs
  command: npx -y @modelcontextprotocol/server-filesystem /workspace

→ Launched fs.
→ 11 tools available.

Share an MCP server with a whole channel

In a channel session, run /mcp share name: linear as the host and every collaborator in that channel gets access to your Linear connector - without sharing the token. Revoke any time with /mcp unshare. Tokens, headers, and URLs are never visible to other users.

Rooms, technically

One agent, several people, and who is billed for what.

A room is the multiplayer primitive: one conversation, one memory, one workspace, several members. There are three kinds, and they share the same accounting rule — the host provides storage, and each message is metered to whoever sent it. Nobody pays for the room.

A Discord channel’s shared session

Keyed to the guild and channel. Opened by any member with /share-session (or nominated to a sponsor); the sponsor’s account carries the workspace, which is what “Free hosts up to three across servers” limits. Joining is never gated. The first time a member speaks in a channel with no saved choice, their message is held and they pick Shared room or Just me; nothing runs until they do. Closed rooms keep their files 90 days.

A web room, and a DM table

A web room is created from the dashboard (POST /api/rooms); an invite code admits one person and expires in a day; members join from any tier. A game table can be opened to everyone, which lists it on the Play tab. A Discord DM or group DM cannot have a channel session — those are guild-keyed — so a user-installed Activity opened there gets one game room per DM instead, minted by the first press and joined by whoever opens it in that DM.

The table is a sandboxed page; the rules are the server’s

A game in the Activity is one HTML file in a frame with a null origin and no network at all — no fetch, no sockets, no <script src> — talking to the shell by postMessage. For the fourteen board, card and party games a rules module on the server owns the board, the seats, the legal moves and the result; a page posts one proposed action and receives the next state. When Ergod takes a seat, the model picks only from the legal turns the server enumerated, so it cannot invent a move; its spoken line is metered to the same person as the move.

Hosted vs self-hosted

What “no hosting” means in practice.

The honest version, including the parts a self-hosted agent does better.

What you never do

No VM, no bot token, no process to keep alive, no OAuth app, no queue, no upgrade. The container is created by your first message, sleeps after 10 idle minutes on Free and 60 on Pro, and wakes on the next one; your /workspace and installed packages survive the sleep, running processes do not. Model access is included — no API key unless you choose /byok to stretch your usage.

What you give up

You cannot run a daemon between turns, the loop’s source is not yours to modify (the prompt and tool list are published on How it thinks), the model roster is curated per tier rather than anything you like, and there is a usage window rather than a bill that scales to your appetite. A self-hosted agent has none of those ceilings and all of the operations. Ergod vs OpenClaw is that comparison in full.

GitHub

Link once. Commit, push, PR from a chat message.

01

Link a PAT

One-time. /github link with a Personal Access Token. Validated against GitHub's API, then encrypted at rest. Per-user - never shared.

02

Reference a repo

Just say it. “Clone vercel/next.js, find the App Router code, and explain the dynamic-route resolver.”

03

Make changes

Ergod edits files in the cloned repo, runs tests, and shows you the diff before committing.

04

Push or PR

Commit, push to a feature branch, open a PR with a real description, and drop the PR link in chat.

05

Iterate

Reply to redirect: “rename the variable, update the test, repush.” Same conversation, same workspace, same branch.

Security model

Isolation by user. Encryption at rest. Audit by design.

Personal and channel workspaces

Your personal workspace is a Docker container only your account can address. In a server channel, choose Shared room for the group's agent, workspace, and history, or Just me for yours; Ergod remembers the choice. Publishing a public link is a separate action.

Encrypted credentials

GitHub PATs, MCP bearer tokens, OAuth access tokens - encrypted at rest with per-tenant keys. Never logged, never returned to the model in plaintext.

Mention scrubbing

@everyone, @here, and role pings are stripped from Ergod's replies by default. Toggleable per-server.

Role & channel gating

Admins can allowlist/blocklist channels and roles. Combine with Discord's native permission system for fine-grained control.

No model retention

We don't train on your messages. Conversation history is yours; delete a session to wipe it.

Open feedback loop

Every release, every limit, every bug - discussed openly in the Discord. Tell us what to harden.

Limits & quotas

What you get on each tier.

Quotas are per account, whichever door you came in through. A user's tier travels with them across every server that has Ergod. Usage is reported as a percentage of the current window — "62% left today" on Free, "62% left this week" on Pro and Pro+ — never as a count, because heavier tasks consume more and casual chat barely registers. New accounts get a one-time usage bonus on top of any tier — persistent, used last, never expires.

FreeProPro+
Daily usagebaseline + welcome boost2.5× Free5× Free
Cap windowdailyrolling 7-dayrolling 7-day
Workspace storage1 GB5 GB10 GB
Image input✓✓✓
GitHub integration✓✓✓
MCP (remote + stdio)✓✓✓
Web dashboard (chat, files, viewer, public links)✓✓✓
Slash commands in the web composer✓✓✓
Persistent memory✓✓✓
Telegram (same account, same workspace)✓✓✓
Skills (reusable agent playbooks)✓✓✓
Scheduled tasks✓ · 10 per account✓ · 10 per account✓ · 10 per account
Direct DMs to Ergod✓✓✓
Share your own workspace (dashboard rooms, /collab)-✓✓
Channel sessions (whole-channel shared workspace)host 3host morehost more
Model picker (/model set)✓ · small lineup✓ · full shortlist✓ · same set as Pro
Sub-agents (parallel work on one task)-✓✓
Container idle timeout10 min60 min60 min

Pro and Pro+ differ on two rows and match on every other one, which is the honest shape of the tier: Pro+ is a volume tier. It doubles the usage and doubles the workspace, and Pro+ subscribers get priority support from us. Same models, same sub-agents, same social layer, same idle timeout. Take it when you are running out of headroom on Pro — not to unlock anything, because there is nothing behind it to unlock.

Why not roll your own?

You can - we did, so you don't have to.

Building this in-house means a Discord bot, a queue, a sandbox runtime, GitHub OAuth, MCP plumbing, a web dashboard, model routing, billing, and a year of iteration. Or:

Roll your own

Open-source agents exist - but you'll be on the hook

  • Install and configure it locally
  • Maintain your own codebase as agents evolve
  • Debug your own quirks and edge cases
  • Pay for model API directly - agentic loops add up fast
  • Host the bot on your own hardware, 24/7
  • Set up your own GitHub OAuth, MCP plumbing
  • No sandbox isolation - runs on your machine
  • Hard to share with friends safely or securely

Try the agent. In 30 seconds.

Free tier covers everything technical - sandbox, GitHub, MCP, memory, the web dashboard. Drop in, ship something, decide later.