Skip to content
Open Core · Self-Hosted · SaaS-Ready

Ship software
by describing it.

Frontal Codes is a local-first AI agent platform. Describe your goal in plain language — Frontal plans it, dispatches coding agents to isolated git worktrees, validates acceptance criteria beyond green tests, and merges deterministically. With budgets, circuit breakers, event-sourced memory, and one-click rollback.

Star on GitHub
$ frontal-codes # public release coming soon
Frontal Codes workspace preview showing live agent activity, kanban mini-board, budget meter, and throughput chart

Built on battle-tested foundations

FastAPI Vue 3 Pi Engine Docker ArangoDB Git tree-sitter
The problem · The Frontal way

AI agents are powerful. Untamed, they're chaos.

Three failure modes every team hits — and how Frontal turns each into a controlled, observable pipeline.

The problem

Agents forget what they learned

Every task starts from scratch. Decisions made last week are gone — so they get re-discovered, re-debated, and re-broken.

Parallel work corrupts each other

Two agents touch the same files. Merge conflicts. Half-applied refactors. Nobody knows what "done" means.

"Tests passed" ≠ "what I meant"

Green checks feel great — until you realize the feature doesn't actually do the thing you asked for. Unit tests can't read your mind.

The Frontal way

Event-sourced memory graph + context packs

Every decision, constraint, contract, and code symbol is an append-only event. Agents see what was decided before their task — never re-discover, never repeat mistakes.

Git worktree isolation · Bernstein-safe scheduling

Each task runs in its own worktree + Docker sandbox. Overlapping scopes serialize; disjoint scopes run fully parallel — provably safe by Bernstein's conditions.

Acceptance criteria validated before merge

You approve human-readable acceptance criteria with the plan. Frontal checks them against the actual behavior — beyond just running tests — before anything reaches main.

Features

One platform. Every layer of the pipeline.

From intake to merge — Frontal is the full orchestration loop, not another wrapper around an LLM.

AI Agent Management

Spawn specialized coding agents on demand. The orchestrator decides role, model tier, tool allowlist, and context pack per task — never authored by hand.

Learn more

Voice Assistant Built-in

Speak your goal. A dedicated voice microservice (STT → LLM → TTS, WebSocket + Telegram transports) drives the same pipeline hands-free.

Learn more

Telegram Integration

Approve plans, get notified, and command agents from anywhere. Telegram is a first-class control surface, not an afterthought.

Learn more

Context Engine with Memory

Decisions, constraints, contracts, and code symbols persist across sessions and tasks. Agents see what was decided BEFORE their task — never re-discover, never repeat mistakes.

See architecture

Git Worktree Isolation

Every task runs in its own worktree + Docker sandbox. Bernstein's conditions serialize overlapping scopes; disjoint tasks run fully in parallel. No more merge hell.

See architecture

Deterministic Merge & Rollback

Trunk-locked merges, one rebase-repair attempt, HMAC-chained event log as source of truth. One click reverts any merge with a new commit — history is never rewritten.

See architecture
How it works

From idea to merged code. Zero babysitting.

Four stages, exactly one human gate. Everything else is observable and reversible.

01

Describe

Tell Frontal what you want, in your own language. A short clarification dialogue refines the goal into a canonical English PRD.

02

Approve

Review the decomposed plan: epics, atomic task cards, acceptance criteria, and a pre-flight cost estimate. One click — your only gate.

03

Execute

Frontal dispatches coding agents to isolated worktrees. Watch the dual-layer activity feed: plain-language narration up top, raw events below.

04

Validate & Merge

Acceptance criteria are checked beyond green tests. Live preview the running app. Merge with one click, roll back just as easily.

Live demo

From prompt to merge in one terminal.

A real Frontal run, condensed. Every line is an actual event from the pipeline — narrated in plain language up top, raw JSON-RPC underneath.

frontal · run
0
TOTAL TOKENS USED
0
AGENTS RIGHT NOW
0
TASKS MERGED TODAY
Manual vs Frontal

Same feature. A different universe.

Building “Stripe checkout on the cart page” — by hand versus described to Frontal. One developer typing alone, or one command and a swarm of agents in parallel.

← drag to compare →
By hand ~22 hours
webhook.py checkout.vue test_checkout.py
1# TODO: verify signature properly
2def handle_webhook(request):
3    payload = request.body
4    sig = request.headers.get('Stripe-Signature')
5    # FIXME: signature keeps failing...
6    try:
7        event = stripe.Webhook.construct_event(
8            payload, sig, ENDPOINT_SECRET
9        )
10    except ValueError:
11        return HttpResponse('Invalid payload', status=400)
12    # ... still debugging signature ...
1<template>
2  <button :disabled="loading" @click="checkout">
3    Pay with Stripe
4  </button>
5</template>
6 
7<script setup>
8import { ref } from 'vue'
9import { loadStripe } from '@stripe/stripe-js'
10 
11const loading = ref(false)
12const checkout = async () => {
13  // TODO: implement properly
1import pytest
2from .webhook import handle_webhook
3 
4 
5# FIXME: can't get test cards to work...
6def test_successful_checkout():
7    response = client.post('/webhook', data=VALID_PAYLOAD)
8    assert response.status_code == 200
9 
10def test_invalid_signature():
11    # this keeps failing, why??
12    pass # TODO
Python · UTF-8 · Lv 1, Kol 1 00:00
22 hours
total effort
$880
labor · $40/hr
47 files
touched
With Frontal 3 min 12 sec
frontal · run
$
[00:24] ✓ Plan approved — 4 task cards created
[agent:stripe-api]
[agent:cart-ui]
[agent:e2e-tests]
[02:14] stripe-api → webhook handler
[02:14] cart-ui → checkout button
[02:14] e2e-tests → test fixtures
[02:18] ✓ stripe-api done
[02:18] ✓ cart-ui done
[02:18] ✓ e2e-tests 12 tests green
[02:47] ✓ Acceptance validated — visitor can complete checkout
[03:12] ⭙ Merged to main · $0.18
192 sec
wall-clock
$0.18
gateway-metered
12 files
touched

575× faster. · 4,888× cheaper.

Two ways to run it

Open core. Or let us run it for you.

The engine is open-core by design — the public release is on the roadmap. The same engine, managed, is Frontal Cloud. Same pipeline — pick your tradeoff.

Self-Hosted · Open Core

Self-host the full engine

  • Full orchestration pipeline, no feature gates
  • Local encrypted secrets vault
  • Bring your own model keys (GLM, MiniMax, OpenAI-compatible)
  • Community Discord + GitHub issues
$ frontal-codes # public release coming soon
Read the Docs →
Pricing

Start free. Scale when ready.

Same engine, every tier. Pay only when you want us to run it for you.

Open Source
$0
forever · self-hosted

Self-host the entire orchestration pipeline. No feature gates, no telemetry.

  • Full pipeline · self-hosted
  • Unlimited agents & worktrees
  • Bring-your-own model keys
  • Local encrypted vault
  • Community support
View on GitHub
Enterprise
Custom
annual · talk to us

For teams that need air-gapped, SSO, audit trails, and a real SLA.

  • Everything in Pro
  • SSO + SCIM + SOC 2 (roadmap)
  • On-prem / air-gapped option
  • Audit log export
  • Dedicated support + SLA
Talk to us
Architecture

The pipeline, end to end.

Every box is a real subsystem. Green nodes are on the hot path; the memory graph feeds back into every future run.

Goal → Intake → Plan Review Gate → Decompose → Worktrees × N
Docker Sandboxes · default-deny egress Watchdog + Repair Loop · ping → inspect → repair → takeover Acceptance Validation · beyond green tests Trunk-Lock Merge · one rebase repair attempt Context Engine · memory graph (ArangoDB · rebuildable view)
EVENT LOG

HMAC-chained, append-only. The single source of truth — ArangoDB is a derived view, rebuildable from here.

MODEL GATEWAY

OpenAI-compatible endpoint with per-provider circuit breakers and tier failover. Provider keys never reach agents.

BUDGET

Warns at 80%, pauses at 100%. Fed by a single metering point in the gateway.

Roadmap

Shipping next.

No fake testimonials — here's what we're actually building. Public, versioned, and tracked in the repo's IMPLEMENTATION-PLAN.md.

Voice in Turkish (locale boundary expansion) In progress · 78%
Mobile companion app · plan approvals on the go Design · 42%
Plugin marketplace · third-party MCP servers RFC open · 25%
GitHub PR publishing · branch-based review flows Beta · 64%
Multi-repo orchestration · cross-repo task graphs Research · 12%
FAQ

Questions, answered.

Do I need to give Frontal my code?
No. Self-hosted mode never leaves your machine. Cloud mode encrypts everything at rest and only accesses your repos when you explicitly link them.
Which AI providers are supported?
Frontal ships with built-in support for GLM, MiniMax, and any OpenAI-compatible endpoint. The Model Gateway handles per-provider circuit breakers and failover automatically.
Can I run it on my own infrastructure?
Yes. The core runs locally with Docker + ArangoDB. Enterprise tier supports air-gapped deployments for regulated environments.
What's "context engine" actually?
An event-sourced memory graph: every decision, constraint, and code symbol is stored as an append-only event. ArangoDB is a rebuildable view — losing the DB never loses memory. Agents get a budgeted context pack per task.
How are agents isolated?
Each task gets its own git worktree AND its own Docker container with default-deny network egress. Agents literally cannot see each other's filesystem. Overlapping task scopes are serialized by Bernstein's conditions; disjoint scopes run fully in parallel.
Is it production-ready?
See PROGRESS.md in the repo. Core pipeline works end-to-end — including real-engine contract tests that drive the full scenario (create → intake → plan → approve → real engine writes code → Docker-sandboxed pytest → acceptance validation → merge → live preview → rollback). Some Phase 9+ features are still in active development.
Ready to ship?

Describe your goal.
Approve the plan.
Watch it merge.

Frontal Codes isn't on sale yet. Join the waitlist — be first in line when early access opens.

No spam — one email when early access opens.