Key takeaways
- Current positioning is a shared event graph and persistent specialists, usable from Claude Code, Codex, ChatGPT, and custom MCP clients — not only a multi-tenant OpenClaw gateway.
- just-bash and embedded execution are documented as policy/convenience boundaries, not VMs for hostile code. Use a remote sandbox when you need stronger isolation.
- Gateway still brokers credentials and MCP; workers are not supposed to see raw secrets. Linux production docs include systemd-run plus IPAddressDeny.
- Self-host Apache-2.0; optional cloud at $0.000463/vCPU-min, $0.000231/GB-min, $0.15/GB-month, billed per second. The old 50 MB / 300-agent figure is not in the current README.
FAQ
What is Lobu?
An open-source context layer: connectors write an append-only event log linked to entities, then any authorized MCP client can query that history or delegate to persistent Lobu specialists.
Is just-bash a sandbox VM?
No. The README says just-bash and embedded modes are policy and convenience boundaries, not VMs for hostile code. Connect Vercel Sandbox or similar when you need a stronger boundary.
How much does Lobu cost?
Self-host is Apache-2.0. Lobu Cloud (checked September 23, 2026) meters $0.000463 per vCPU-minute, $0.000231 per GB-minute, and $0.15 per GB-month storage, billed per second with scale-to-zero.
Do I have to run Lobu's agent runtime?
No. You can point Claude Code, Codex, OpenCode, ChatGPT, or Cursor at Lobu over MCP without a Lobu agent runtime.
Executive Summary
Lobu has moved from "multi-tenant OpenClaw gateway" to an event-sourced company context layer. The current README (checked September 23, 2026) describes connectors feeding an append-only log, typed entities, permission-aware memory, and persistent specialists callable over MCP. Existing agents (Claude Code, Codex, OpenCode, ChatGPT, Cursor) can connect without running Lobu's own loop.[1]
Isolation claims must be split. Gateway proxying, secret placeholders, and Linux IPAddressDeny are documented for worker HTTP. The same README states that built-in just-bash and embedded execution are not VMs for hostile code. The June 2026 profile's ~50MB/instance and 300-concurrent-agents figures are not in the current README and are not reused here.[1][2]
Originally launched as peerbot.ai in July 2025. The repo header is Apache-2.0. A dated BUSL-to-Apache relicensing note was not on the current README; the June profile recorded a BUSL-1.1 past. Stars: 162 in June 2026, 223 on the GitHub repo page in this September review (the pricing page widget showed 175).[1]
| Attribute | Current evidence |
|---|---|
| Repository | github.com/lobu-ai/lobu |
| Language | TypeScript |
| Stars | 223 ★ / 31 forks (Sep 23, 2026; 162 in June)[1] |
| License | Apache-2.0 (header as of this review)[1] |
| Created | July 2025 |
| Creator | @buremba / @bu7emba |
Product Overview
Three documented uses: (1) add shared context to an agent you already run, (2) run persistent Lobu specialists, (3) CLI/TypeScript SDK against the same tools.[1]
The older "OpenClaw for teams" story still shows up in cloud marketing ("Serverless OpenClaw") and channel list. Treat that as a runtime option on top of the context layer, not the only product.[3]
Key capabilities
| Capability | Description |
|---|---|
| Shared memory | Append-only events linked to entities; permission-aware recall.[1] |
| MCP into existing agents | Claude Code, Codex, OpenCode, ChatGPT, Cursor without a Lobu loop.[1] |
| MCP proxy | Gateway handles OAuth and injects scoped tokens; workers should not see raw secrets.[2] |
| Channels | Slack, Telegram, WhatsApp, Discord, Teams, Google Chat, web, REST API.[1][4] |
| Scale to zero | Cloud workers billed only while active.[3] |
| OpenClaw-compatible files | Skills, IDENTITY.md, SOUL.md, USER.md still documented where the OpenClaw runtime is used.[1] |
A useful evaluation is npx @lobu/cli@latest connect claude-code, attaching one source, and asking a permission-scoped recall question. That was not executed here.
Technical Architecture
Slack/Telegram/WhatsApp/Discord/Teams/API/MCP clients
→ Gateway (secrets, MCP proxy, approvals)
→ Worker (optional Lobu specialist or just-bash)
→ Postgres (embedded default) / your DB
| Aspect | Detail |
|---|---|
| Deployment | Embedded Postgres local default; Docker; Kubernetes Helm.[1] |
| State | Event log + entities; Postgres + pgvector path still documented.[1] |
| Isolation | Gateway HTTP proxy; Linux systemd-run + IPAddressDeny=any / IPAddressAllow=127.0.0.1. just-bash is not a hostile-code VM.[2][1] |
| Secrets | lobu_secret_<uuid> placeholders swapped at 127.0.0.1:8118.[2] |
| Egress | Default WORKER_ALLOWED_DOMAINS unset means no access. LLM-judged egress is optional and fails closed without a model.[2] |
| Approvals | Destructive MCP calls need in-thread approval unless pre-approved in lobu.config.ts.[1] |
Mac app and Chrome extension download links remain on the README.[1]
Strengths
- Shared, permissioned memory across harnesses you already run.[1]
- Credential brokering that aims to keep tokens off workers.[2]
- Honest just-bash limitation in the current README.[1]
- Apache-2.0 self-host plus a usage-billed cloud with the same codebase claim.[3]
- Channel coverage for Slack, Telegram, WhatsApp, Discord, Teams, API.[4]
Cautions
- Do not treat just-bash as hostile-code isolation. Pair with a real sandbox for untrusted code.[1]
- Star count is still small (223). No independent production reviews found in this pass.
- Effectively a small-maintainer project; bus factor remains a concern for enterprise adoption.
- Cloud marketing still says "every agent runs in its own sandbox" — read that against the just-bash README caveat.[3][1]
- Fewer chat platforms than vanilla OpenClaw's long tail.
Pricing & Licensing
| Tier | Price (Sep 23, 2026) | Includes |
|---|---|---|
| Self-hosted | Free | Full features, Apache-2.0.[1] |
| Lobu Cloud | Usage-based | $0.000463/vCPU-min + $0.000231/GB-min + $0.15/GB-mo storage; per-second metering, scale-to-zero, no minimums.[3] |
Idle agents cost $0 on the cloud page. Hidden costs if self-hosting: your cluster or VM, plus LLM APIs. Funding is not publicly disclosed.
Competitive Positioning
Vs. OpenClaw
| Aspect | Lobu | OpenClaw |
|---|---|---|
| Job | Shared org context + optional runtime | Personal/self-hosted agent |
| MCP | Proxied, secrets isolated | Direct from agent |
| Network | Gateway + documented Linux IP deny | No built-in isolation |
| just-bash | Explicitly not a hostile VM | N/A |
Direct competitors
| Competitor | Differentiation |
|---|---|
| Tensol | Managed OpenClaw; Lobu is self-host or optional cloud |
| NanoClaw | Simpler container isolation |
| LaunchClaw | Hosted; Lobu is Apache-2.0 |
Vs. Tembo
Tembo runs coding agents in isolated cloud or licensed self-hosted environments with review and previews.[5] Lobu supplies shared organizational context and an MCP control plane. Complementary: Lobu for governed memory, Tembo for untrusted-code execution. No native integration is documented on tembo.io.
Disclosure: Ry Walker is Tembo's co-founder and CEO.
When to choose Lobu
- Choose Lobu when: Several agents must share governed company state.
- Choose Tembo when: You need isolated coding-agent sessions and PR review.
- Choose OpenClaw when: You want a single personal agent with maximum channels.
- Choose Tensol when: You want managed OpenClaw without running infra.
Ideal Customer Profile
Best fit:
- Teams that already run Claude Code/Codex and need shared memory
- Slack/Telegram deployments that need secret brokering
- Operators willing to read the security guide, not just the homepage sandbox line
Poor fit:
- Anyone treating just-bash as a VM
- Individual users wanting a one-click personal agent
- Organizations that need a large independent vendor-backed support org
Viability Assessment
| Factor | Assessment |
|---|---|
| Financial Health | Not publicly disclosed; commercial cloud meters published rates |
| Market Position | Niche context layer |
| Innovation Pace | Positioning shifted materially since June (context layer + MCP-first) |
| Community | 223 stars (Sep 23, 2026) |
| Long-term Outlook | Uncertain; architecture is interesting, independent validation is thin |
What Developers Say
No independent Hacker News or Reddit review was opened for this refresh. Absence of discussion is not proof of non-use.
Assessment
Use Lobu when several agents must share governed company state. Pair it with a real sandbox (Tembo, Vercel Sandbox, or equivalent) for untrusted code. Do not buy it as a drop-in VM isolation layer.
Recommended for: Teams that need permissioned shared memory across existing harnesses, self-hosted or via the metered cloud.
Not recommended for: Hostile-code isolation, or buyers who need a large support organization.
Outlook: The September README is more honest about just-bash than the June isolation story. Watch whether MCP-into-existing-agents converts into production write-ups.
Research by Ry Walker Research • methodology