The product

What is
Habenula?

habenula · huh-BEN-yuh-luh · noun. Brain region, from the Latin habena, "reins" — a hub for value-based decision-making; the mind's brake.

What we enforce, how each guarantee is built, and what it connects to — in one place.

Quick start →

In plain terms

An agent that acts, with you still in charge.

An agent is an AI that doesn't just talk — it acts: it sends email, spends money, changes files, posts as you. That's the useful part, and the part worth being careful about.

Habenula sits between your agent and the real world — and it isn't the AI. The model does the thinking; Habenula is a separate layer that decides what's actually allowed to happen, and the model can't overrule it or talk its way past it.

So before your agent does anything that matters, Habenula checks with you, keeps a record you can read yourself, and stops everything the moment you say so — an agent that gets things done without handing over the keys.

Why Habenula

What you get.

  • Enterprise-style governance, without the enterprise. The governance large organizations are building themselves, packaged as a product to be runnable by one person.
  • Independence you keep. Precise policies, custom to you, across a wide range of vendors and models.
  • Guards that check the exact action. Who is acting, what they want to do, and to which resource — not a generic "approve this?" prompt.
  • Trust backed by the security community, not the model. Everything you need to run it is open source, in one repository.

What it's built around

Six guarantees, enforced by the system.

Not features you configure and hope hold. Properties of how Habenula is built.

01

Nothing skips the check

Every action runs one path: the call is classified, checked against your policy, and written to the audit log before it can execute. An unrecognized tool isn't run on a guess — it's held for you. There is no second route to a provider. The check is deterministic: same inputs, same decision, every time.

02

The model never sees a credential

Your OAuth tokens are held encrypted and resolved only at the instant a tool runs. The model's context can't leak what it never receives.

03

Every action is on a tamper-evident record

The audit log is append-only and hash-chained: each entry carries the hash of the one before it, so altering any line breaks every link after it. You don't take our word for its integrity — habenula log verify recomputes the chain on your own machine. Entries are written before the tool runs, so a failure is recorded, never hidden.

04

No grant outlives its reason

Every grant is one-time or timed: allow a call once, or for a duration you choose (30 minutes by default, up to 30 days). It expires on its own. There is no standing "always allow"; anything not granted is denied.

05

Spending has a hard ceiling

You set the caps in dollars, per session and per month. A call that would cross a cap is held until you approve that specific order. The agent cannot raise its own limit.

06

The kill switch is real

One command deletes every grant, so everything is denied again, and clears held calls in a single transaction. Your connected services stay connected: no signing in again to resume.

We publish what isn't done as plainly as what is. This is an early release: one session at a time, an API that trusts only your own machine. Every limit is stated with the same prominence as every capability.

Integrations

Your agent, plugged into your world.

Habenula models every integration itself, so it can check the exact action, which a generic MCP server can't offer. Try it on the sandbox inbox and sandbox storefront first, then connect the real thing.

Available now

Gmail Google Calendar Slack Outlook Mail GitHub

This first set is small, but it proves the governance model. A much larger catalog is on the way. Want a tool sooner? Tell us which to prioritize (hello@habenula.ai), or build your own. The entire integration layer is open source. We would love to see your custom integrations.

Open source · quick start

Run it in one command.

Everything that holds your credentials, decides what your agent may do and records what it did is open source under AGPL v3. The audit-log verifier is MIT, so anyone can check the records independently.

Run it as a container on any Docker host or from npm. Self-hosting on your own Cloudflare account follows on the same code.

One command

$ npx habenula up

Runs locally — no account, no credentials handed over. Add your own model key to start a conversation.

Or build from source

$ git clone https://github.com/habenula-ai/habenula-oss

Keep reading