What is OAP?

Open Agent Primitives (OAP) is a secure way to run enterprise AI agents. A primitive is a basic building block that agents rely on, whatever they do; OAP ships a working implementation of each, and agents are composed from them. It runs in your own Kubernetes cluster on the models you choose. Defining an agent is easy — a prompt, some tools, a loop. Operating one safely is the hard part, and that's what OAP is for: an agent's identity, authorization, tools, memory, and channels are first-class, governed things rather than an afterthought.

The premise

The model is not a trust boundary. A capable agent will be asked to touch real systems — repositories, dashboards, customer data — and the interesting questions aren't "can it call a tool" but "whose credentials does it use, may it do this to this resource, who approves the risky steps, and what did it actually do." OAP answers those with six composable primitives.

The six primitives

  • Agent definition — an agent is a reviewable template (AgentClass) and a disposable instance (AgentSession), not a process.
  • Safe tools — an agent can only do what was written down: sandboxed CLI tools and MCP servers, validated against a toolspec.
  • Identity & credentials — an agent acts as itself or on your behalf, with named credentials resolved by need.
  • Authorization — every action is checked against a graph: can this subject do this, to this resource, right now?
  • Channels & continuity — agents are reached where teams already work; threads continue and approvals live in-channel.
  • Memory & knowledge — an agent remembers within reason: an authorized, searchable store with a knowledge-graph layer.

Each is designed around specific threats from the OWASP Agentic Top 10.

Where to next

  • Install OAP — bring up the platform, on your Mac or on a cluster.
  • Your first agent — define an agent and talk to it in a few minutes.