← Back to research
•·7 min read·company

Lobu

Lobu is an open-source event-sourced context layer and control plane for agents. just-bash is a policy boundary, not a VM for hostile code. Apache-2.0, with optional usage-billed cloud.

Key takeaways

  • Current positioning is a shared event graph and persistent specialists, usable from Claude Code, Codex, ChatGPT, and custom MCP clients — not only a multi-tenant OpenClaw gateway.
  • just-bash and embedded execution are documented as policy/convenience boundaries, not VMs for hostile code. Use a remote sandbox when you need stronger isolation.
  • Gateway still brokers credentials and MCP; workers are not supposed to see raw secrets. Linux production docs include systemd-run plus IPAddressDeny.
  • Self-host Apache-2.0; optional cloud at $0.000463/vCPU-min, $0.000231/GB-min, $0.15/GB-month, billed per second. The old 50 MB / 300-agent figure is not in the current README.

FAQ

What is Lobu?

An open-source context layer: connectors write an append-only event log linked to entities, then any authorized MCP client can query that history or delegate to persistent Lobu specialists.

Is just-bash a sandbox VM?

No. The README says just-bash and embedded modes are policy and convenience boundaries, not VMs for hostile code. Connect Vercel Sandbox or similar when you need a stronger boundary.

How much does Lobu cost?

Self-host is Apache-2.0. Lobu Cloud (checked September 23, 2026) meters $0.000463 per vCPU-minute, $0.000231 per GB-minute, and $0.15 per GB-month storage, billed per second with scale-to-zero.

Do I have to run Lobu's agent runtime?

No. You can point Claude Code, Codex, OpenCode, ChatGPT, or Cursor at Lobu over MCP without a Lobu agent runtime.

Executive Summary

Lobu has moved from "multi-tenant OpenClaw gateway" to an event-sourced company context layer. The current README (checked September 23, 2026) describes connectors feeding an append-only log, typed entities, permission-aware memory, and persistent specialists callable over MCP. Existing agents (Claude Code, Codex, OpenCode, ChatGPT, Cursor) can connect without running Lobu's own loop.[1]

Isolation claims must be split. Gateway proxying, secret placeholders, and Linux IPAddressDeny are documented for worker HTTP. The same README states that built-in just-bash and embedded execution are not VMs for hostile code. The June 2026 profile's ~50MB/instance and 300-concurrent-agents figures are not in the current README and are not reused here.[1][2]

Originally launched as peerbot.ai in July 2025. The repo header is Apache-2.0. A dated BUSL-to-Apache relicensing note was not on the current README; the June profile recorded a BUSL-1.1 past. Stars: 162 in June 2026, 223 on the GitHub repo page in this September review (the pricing page widget showed 175).[1]

AttributeCurrent evidence
Repositorygithub.com/lobu-ai/lobu
LanguageTypeScript
Stars223 ★ / 31 forks (Sep 23, 2026; 162 in June)[1]
LicenseApache-2.0 (header as of this review)[1]
CreatedJuly 2025
Creator@buremba / @bu7emba

Product Overview

Three documented uses: (1) add shared context to an agent you already run, (2) run persistent Lobu specialists, (3) CLI/TypeScript SDK against the same tools.[1]

The older "OpenClaw for teams" story still shows up in cloud marketing ("Serverless OpenClaw") and channel list. Treat that as a runtime option on top of the context layer, not the only product.[3]

Key capabilities

CapabilityDescription
Shared memoryAppend-only events linked to entities; permission-aware recall.[1]
MCP into existing agentsClaude Code, Codex, OpenCode, ChatGPT, Cursor without a Lobu loop.[1]
MCP proxyGateway handles OAuth and injects scoped tokens; workers should not see raw secrets.[2]
ChannelsSlack, Telegram, WhatsApp, Discord, Teams, Google Chat, web, REST API.[1][4]
Scale to zeroCloud workers billed only while active.[3]
OpenClaw-compatible filesSkills, IDENTITY.md, SOUL.md, USER.md still documented where the OpenClaw runtime is used.[1]

A useful evaluation is npx @lobu/cli@latest connect claude-code, attaching one source, and asking a permission-scoped recall question. That was not executed here.


Technical Architecture

Slack/Telegram/WhatsApp/Discord/Teams/API/MCP clients
        → Gateway (secrets, MCP proxy, approvals)
        → Worker (optional Lobu specialist or just-bash)
        → Postgres (embedded default) / your DB
AspectDetail
DeploymentEmbedded Postgres local default; Docker; Kubernetes Helm.[1]
StateEvent log + entities; Postgres + pgvector path still documented.[1]
IsolationGateway HTTP proxy; Linux systemd-run + IPAddressDeny=any / IPAddressAllow=127.0.0.1. just-bash is not a hostile-code VM.[2][1]
Secretslobu_secret_<uuid> placeholders swapped at 127.0.0.1:8118.[2]
EgressDefault WORKER_ALLOWED_DOMAINS unset means no access. LLM-judged egress is optional and fails closed without a model.[2]
ApprovalsDestructive MCP calls need in-thread approval unless pre-approved in lobu.config.ts.[1]

Mac app and Chrome extension download links remain on the README.[1]


Strengths

  • Shared, permissioned memory across harnesses you already run.[1]
  • Credential brokering that aims to keep tokens off workers.[2]
  • Honest just-bash limitation in the current README.[1]
  • Apache-2.0 self-host plus a usage-billed cloud with the same codebase claim.[3]
  • Channel coverage for Slack, Telegram, WhatsApp, Discord, Teams, API.[4]

Cautions

  • Do not treat just-bash as hostile-code isolation. Pair with a real sandbox for untrusted code.[1]
  • Star count is still small (223). No independent production reviews found in this pass.
  • Effectively a small-maintainer project; bus factor remains a concern for enterprise adoption.
  • Cloud marketing still says "every agent runs in its own sandbox" — read that against the just-bash README caveat.[3][1]
  • Fewer chat platforms than vanilla OpenClaw's long tail.

Pricing & Licensing

TierPrice (Sep 23, 2026)Includes
Self-hostedFreeFull features, Apache-2.0.[1]
Lobu CloudUsage-based$0.000463/vCPU-min + $0.000231/GB-min + $0.15/GB-mo storage; per-second metering, scale-to-zero, no minimums.[3]

Idle agents cost $0 on the cloud page. Hidden costs if self-hosting: your cluster or VM, plus LLM APIs. Funding is not publicly disclosed.


Competitive Positioning

Vs. OpenClaw

AspectLobuOpenClaw
JobShared org context + optional runtimePersonal/self-hosted agent
MCPProxied, secrets isolatedDirect from agent
NetworkGateway + documented Linux IP denyNo built-in isolation
just-bashExplicitly not a hostile VMN/A

Direct competitors

CompetitorDifferentiation
TensolManaged OpenClaw; Lobu is self-host or optional cloud
NanoClawSimpler container isolation
LaunchClawHosted; Lobu is Apache-2.0

Vs. Tembo

Tembo runs coding agents in isolated cloud or licensed self-hosted environments with review and previews.[5] Lobu supplies shared organizational context and an MCP control plane. Complementary: Lobu for governed memory, Tembo for untrusted-code execution. No native integration is documented on tembo.io.

Disclosure: Ry Walker is Tembo's co-founder and CEO.

When to choose Lobu

  • Choose Lobu when: Several agents must share governed company state.
  • Choose Tembo when: You need isolated coding-agent sessions and PR review.
  • Choose OpenClaw when: You want a single personal agent with maximum channels.
  • Choose Tensol when: You want managed OpenClaw without running infra.

Ideal Customer Profile

Best fit:

  • Teams that already run Claude Code/Codex and need shared memory
  • Slack/Telegram deployments that need secret brokering
  • Operators willing to read the security guide, not just the homepage sandbox line

Poor fit:

  • Anyone treating just-bash as a VM
  • Individual users wanting a one-click personal agent
  • Organizations that need a large independent vendor-backed support org

Viability Assessment

FactorAssessment
Financial HealthNot publicly disclosed; commercial cloud meters published rates
Market PositionNiche context layer
Innovation PacePositioning shifted materially since June (context layer + MCP-first)
Community223 stars (Sep 23, 2026)
Long-term OutlookUncertain; architecture is interesting, independent validation is thin

What Developers Say

No independent Hacker News or Reddit review was opened for this refresh. Absence of discussion is not proof of non-use.


Assessment

Use Lobu when several agents must share governed company state. Pair it with a real sandbox (Tembo, Vercel Sandbox, or equivalent) for untrusted code. Do not buy it as a drop-in VM isolation layer.

Recommended for: Teams that need permissioned shared memory across existing harnesses, self-hosted or via the metered cloud.

Not recommended for: Hostile-code isolation, or buyers who need a large support organization.

Outlook: The September README is more honest about just-bash than the June isolation story. Watch whether MCP-into-existing-agents converts into production write-ups.


Research by Ry Walker Research • methodology