Self-hosting AgentLasso
AgentLasso's core is Apache-2.0: you can run it on your own infrastructure. This guide covers what you need, what works without which keys, and what doesn't work outside the hosted service yet.
Just want to look around?
npm run demoruns the whole app locally on fixed mock data, with no accounts, keys or database. Everything below is for a real install.
What you need
- Node.js ≥ 20.19 or ≥ 22.12. Older versions fail at runtime with a
util.styleTexterror rather than at install time. - A Supabase project (the free tier is fine): Postgres, auth and the API layer.
- Optional: an Anthropic API key for AI intent classification, and a scheduler for the background classification job.
1. Install
2. Create the database
- Create a project at supabase.com.
- Apply the migrations in
supabase/migrations/in filename order. With the Supabase CLI: Or paste each file into the Supabase SQL editor, oldest first. - Fill in the Supabase section of
.env(Settings → API in Supabase). KeepSUPABASE_SERVICE_ROLE_KEYsecret: it bypasses row-level security. - In Supabase → Authentication → URL Configuration, add your app's URL
(e.g.
http://localhost:8080, the dev server's default) to the redirect URLs, so email confirmation links come back to your install.
The migrations create a demo template project ("Acme Support Agent"). Every new account gets its own copy, so a first-time user sees a populated app. The template's API key is randomized by a migration, so the key that appears in the repo's history doesn't work on your install.
3. Run it
Sign up with email and password, then open Settings for your project's
API key and a ready-to-run curl command to send your first trace.
Which features need what
Without ANTHROPIC_API_KEY, traces the rules can't place wait (marked
awaiting_llm), and the Semantic Agent Map shows how many. Add a key later and
the next run classifies them.
4. Schedule the background job (optional)
POST /api/v1/sync-cluster classifies waiting traces in batches. Call it on a
schedule (every 15 minutes is reasonable) with
Authorization: Bearer <LOVABLE_CRON_SECRET>. If your fork is on GitHub, the
included .github/workflows/sync-cluster.yml does this; set the
AGENTLASSO_APP_URL and LOVABLE_CRON_SECRET repository secrets.
The first few traces of a new project are classified immediately on ingest, so you don't need the scheduler just to try things out.
Deploying
npm run build produces a Cloudflare Workers build (the build config's
cloudflare-module preset). Set the variables from .env as Worker
environment variables and secrets.
Other targets (a plain Node server, Docker) aren't supported out of the box yet: the build configuration only offers Cloudflare and a Lovable-internal format. Contributions welcome.
Not available self-hosted (yet)
- AI test generation and the Live Sandbox's built-in demo agent call
Lovable's AI gateway (
LOVABLE_API_KEY), which only exists on Lovable-hosted deployments. Self-hosted, they show an explanation instead. Connect your own agent in Settings to use the Live Sandbox. - "Continue with Google" goes through Lovable's OAuth broker, so it's hidden on self-hosted installs. Email sign-in works.
Security checklist
- Never commit
.env; it's in.gitignore. SUPABASE_SERVICE_ROLE_KEY,ANTHROPIC_API_KEYandLOVABLE_CRON_SECRETare secrets: set them server-side only.- Leave
AGENT_ENDPOINT_ALLOW_PRIVATEunset if untrusted users can sign up: it lets them make your server call addresses on its own network. - Found a vulnerability? See SECURITY.md.