AI agent
OpenHands Agent Canvas
Open-source, self-hosted control center for coding agents. It runs the OpenHands agent or other ACP-compatible agents such as Claude Code and Codex on local, Docker, VM or cloud backends, and can run automations on a schedule or from webhooks.
- Maintainer
- OpenHands (OpenHands organisation on GitHub)
- Licence
- MIT (LICENSE file: "The MIT License (MIT)", Copyright © 2025 OpenHands contributors)
- Last release
- v1.24.0, released 2026-09-25 (marked Latest on the GitHub releases page)
What it can access
An agent can take actions, not only answer questions, so what it is allowed to do on your behalf matters most. This is what the listing states, based on the sources below. Anavem does not rate it safe or unsafe: check it against what you plan to use it for.
Permissions it asks for
- The self-hosting guide states the agent can read and write the filesystem, execute shell commands and reach the network
- Without a sandbox, the README warns the agent-server runs directly on the host with full access to your filesystem
- With the Docker option, the agent can access projects under the PROJECTS_PATH directory you mount
- Automations can integrate with Slack, GitHub, Linear, Notion and more, on a schedule or in response to webhook events (README)
- Each backend connection needs a host URL and an API key (backends docs); the session API key is sent as the X-Session-API-Key header on /api calls
Data it can reach
Docs state: Agent Canvas runs locally by default and can connect to several agent backends: a local process, Docker containers, an always-on VM, your own company infrastructure, or OpenHands Cloud (README: "our commercial offering") or OpenHands Enterprise infrastructure (the backends docs list Cloud or Enterprise as "Managed backend and sandbox infrastructure"). By default, local (npx / npm run dev) listeners bind to loopback only (127.0.0.1); passing --host 0.0.0.0 makes them listen on all interfaces, and the session key is then not injected into the UI. The self-hosting guide states the session API key is stored in browser localStorage on the canvas origin, readable by scripts on that origin, and advises treating the host as a machine that holds production credentials and restricting inbound network access with a firewall. The LLM is configurable ("bring your own model"). (README, docs/SELF_HOSTING.md, docs.openhands.dev, 2026-10-03)
How it is installed or connected
From the repository README, accessed 2026-10-03. The README warns that Option 1 gives the agent full access to your filesystem.
Option 1, without a sandbox (prerequisites: Node.js 24 or later, uv):
npm install -g @openhands/agent-canvas
agent-canvas
Option 2, with a Docker sandbox (macOS / Linux; needs Docker and a host directory for PROJECTS_PATH):
export PROJECTS_PATH="$HOME/projects"
mkdir -p "$PROJECTS_PATH" "$HOME/.openhands"
docker run -it --rm \
-p 127.0.0.1:8000:8000 \
-e AGENT_CANVAS_ALLOW_LAN_SESSION_KEY=true \
-v "$HOME/.openhands:/home/openhands/.openhands" \
-v "${PROJECTS_PATH}:/projects" \
ghcr.io/openhands/agent-canvas:1.24.0
The README also lists a multi-container Docker option and a from-source option, and says to open http://localhost:8000 (or http://localhost:8000/canvas for the Docker image). Windows commands are in README.windows.md. For an internet-facing install, the README points to docs/SELF_HOSTING.md.
Limitations
- Runs agents that can execute shell commands and change files; the README and self-hosting guide say to isolate the host or use Docker and restrict network access
- The repository is now the Agent Canvas front end; the agent server, SDK and automation service live in separate OpenHands repositories (README, repository boundaries table), which were not read for this listing
- README lists "Bring your own model" (use with any LLM), so model access is yours to configure; integrations such as Slack or GitHub need access to those services
- README calls OpenHands Cloud "our commercial offering" and mentions OpenHands Enterprise as an option; their pricing and terms were not read for this listing
Not sure what to look for? Read what to check before installing.
Quick answers
- Who maintains this AI agent?
- OpenHands (OpenHands organisation on GitHub).
- What can it access?
- It asks for: The self-hosting guide states the agent can read and write the filesystem, execute shell commands and reach the network, Without a sandbox, the README warns the agent-server runs directly on the host with full access to your filesystem, With the Docker option, the agent can access projects under the PROJECTS_PATH directory you mount, Automations can integrate with Slack, GitHub, Linear, Notion and more, on a schedule or in response to webhook events (README), Each backend connection needs a host URL and an API key (backends docs); the session API key is sent as the X-Session-API-Key header on /api calls. Docs state: Agent Canvas runs locally by default and can connect to several agent backends: a local process, Docker containers, an always-on VM, your own company infrastructure, or OpenHands Cloud (README: "our commercial offering") or OpenHands Enterprise infrastructure (the backends docs list Cloud or Enterprise as "Managed backend and sandbox infrastructure"). By default, local (npx / npm run dev) listeners bind to loopback only (127.0.0.1); passing --host 0.0.0.0 makes them listen on all interfaces, and the session key is then not injected into the UI. The self-hosting guide states the session API key is stored in browser localStorage on the canvas origin, readable by scripts on that origin, and advises treating the host as a machine that holds production credentials and restricting inbound network access with a firewall. The LLM is configurable ("bring your own model"). (README, docs/SELF_HOSTING.md, docs.openhands.dev, 2026-10-03). We do not label anything safe or unsafe; read the official sources before you install.
- What licence does it use?
- MIT (LICENSE file: "The MIT License (MIT)", Copyright © 2025 OpenHands contributors). Check the terms if you plan to use it commercially.
- What are its limitations?
- Runs agents that can execute shell commands and change files; the README and self-hosting guide say to isolate the host or use Docker and restrict network access. The repository is now the Agent Canvas front end; the agent server, SDK and automation service live in separate OpenHands repositories (README, repository boundaries table), which were not read for this listing. README lists "Bring your own model" (use with any LLM), so model access is yours to configure; integrations such as Slack or GitHub need access to those services. README calls OpenHands Cloud "our commercial offering" and mentions OpenHands Enterprise as an option; their pricing and terms were not read for this listing.
- When was it last released?
- v1.24.0, released 2026-09-25 (marked Latest on the GitHub releases page). Verified Oct 3, 2026.
Sources
- OpenHands repository (GitHub)accessed
- OpenHands README.mdaccessed
- OpenHands LICENSEaccessed
- OpenHands releases (GitHub)accessed
- OpenHands docs/SELF_HOSTING.mdaccessed
- OpenHands docs: Agent Canvas backendsaccessed
Related listings
Other listings in the same category.
OpenAI Agents SDK (Python)
Open-source Python SDK from OpenAI for multi-agent workflows with tools, handoffs, guardrails, sessions, human-in-the-loop, tracing, realtime and voice agents, and sandbox agents. It supports other model providers.
By OpenAI (openai organisation on GitHub) · Verified Oct 3, 2026
CrewAI
Open-source Python framework for multi-agent workflows. Crews are teams of role-based agents; Flows are event-driven workflows. A separate commercial control plane, CrewAI AMP, adds managed deployment and observability.
By crewAI, Inc. (crewAIInc organisation on GitHub) · Verified Oct 3, 2026
LangGraph
Open-source Python framework from LangChain for building long-running, stateful agents as graphs. Its docs list durable execution, human-in-the-loop interrupts, memory and optional deployment on LangSmith.
By LangChain, Inc. (langchain-ai organisation on GitHub) · Verified Oct 3, 2026
AI tools in AI Automation & Agents
Verified tool profiles in the same category.
Zapier
AI Automation & Agents
Workflow automation connecting apps, with Agents and MCP, billed per task
Relevance AI
AI Automation & Agents
Platform for building AI agents and tools, billed in Actions and Vendor Credits
n8n
AI Automation & Agents
Workflow and AI agent platform, hosted by n8n or self-hosted, billed per execution
Make
AI Automation & Agents
Visual automation platform for scenarios and AI agents, billed in credits