Skip to content
HN On Hacker News ↗

GitHub - theguysudo/ENZO: Self-hosted AI workspace with agents, skills, and tools (Gmail, Calendar) that runs entirely on your own provider API keys (BYOK). Bring your own keys — Groq, OpenRouter, NVIDIA, Hugging Face, Google AI.

▲ 16 points • 13 comments • by theguysudo • 3w ago • HN discussion ↗

Pangram verdict · v3.3

We believe that this entire text is AI.

99 %

AI likelihood · overall

AI
0% human-written 100% AI-generated
SEGMENTS · HUMAN 0 of 1
SEGMENTS · AI 1 of 1
WORD COUNT 1,643
PEAK AI % 99% · §1
Analyzed
Sep 20
backend: pangram/v3.3
Segments scanned
1 windows
avg 1643 words each
Distribution
0 / 100%
human / AI fraction
Verdict
AI
Pangram v3.3

Article text · 1,643 words · 1 segments analyzed

Human AI-generated
§1 AI · 99%

Quickstart · Live demo · What's inside · Security · What's new · Usage guide · Changelog Chat with 300+ models. Build agents that write their own operating manuals. Research, generate code, run it all — on your keys, on your infrastructure. When you send a message, the request goes from your browser through ENZO to the provider you picked, and you pay that provider their normal price. Nothing sits in between taking a cut. There is no ENZO account, no usage meter, no subscription. What's inside Inside ENZO Count What it gives you Models in one catalog 300+ across 9 providers, health-checked live Injectable agent skills 74 bundled domain playbooks the agent loop pulls in per run Self-drafting agents 2-pass builder plain-English task in, operating manual out CI pipeline stages 7 including a black-box security pentest on every push Pentest assertions 44 auth bypass, IDOR, hostile payloads, stream integrity Unit + security tests 298 agent, vault, crypto and model suites TypeScript (strict) ~44,000 lines one language, strict mode throughout Releases 5 v1.0.0 → v1.4.0, everything in the changelog Quickstart git clone https://github.com/theguysudo/ENZO.git cd enzo docker compose up -d # → http://localhost:5001 That's the whole install. No accounts, no mandatory env, no database server. Open the app, press Login, and pick any provider: Provider What you need Free tier OpenRouter API key many free models Google AI Studio API key generous free tier NVIDIA NIM API key free credits Groq, HuggingFace, Cloudflare, Gemini API key / OAuth varies Keys are saved encrypted in your browser (passphrase-protected vault, with a recovery file you can download). You can wipe them anytime from the Vault. On a fresh self-hosted instance the first live-validated key you paste claims the instance — it's written to the container .env and sealed into the enzo-memory volume, so every server-side feature (agents, skills, memory) unlocks immediately and survives restarts. No master key to configure, no setup wizard — paste a working key and go. (Pre-seed a provider key in compose env instead if you'd rather not have the claim window at all; the threat model states this trade plainly.) TipTry it hosted first: https://enzo-hub.duckdns.org — the same app, running on our infrastructure. This repo is exactly that code, minus Google sign-in (self-hosted login is just your provider keys) with a trimmed default theme set for a small download. Run on Google Colab — zero install Don't want the local hassle — or want ENZO reachable from any device? The Colab notebook does the whole setup for you: it clones this repo, installs the dependencies, builds the UI and boots the server, then hands you a URL. Click the button — the notebook opens in Colab (a free Google account is enough). Run all cells (Runtime → Run all, or Ctrl/⌘ + F9) — install + build takes ~4–5 min the first time; every cell is idempotent, so a re-run reuses what's already there instead of starting over. Take your URL — the last cell prints two links: a Colab link that works in the browser you're already in, and a Cloudflare tunnel link that works from your phone or any other device (free, no account). The tunnel URL changes each session; the Colab link is bound to your session. Stays up for the whole session. The notebook arms two disconnect-prevention mechanisms before handing you the URL: a keep-alive that resets Colab's ~90-minute idle timer every 60 seconds while the tab is open, and a watchdog thread that pings the server every 5 minutes and restarts it automatically if it ever dies. Free Colab caps a session at ~12 hours, so a 6-hour run fits comfortably; when a session does end, one click on Run all brings everything back. NoteThe notebook runs on Google's hardware, so Colab's terms apply while you're there — but your model keys stay yours: paste any provider key after boot, exactly like self-hosting, and nothing is ever stored on our side. When the Colab session ends, everything on the VM is gone. Six surfaces, one workspace Surface What it does Terminal Streaming chat with 300+ models — normal, thinking, research and coding modes — with a live ECG-style health trace in the toolbar that flatlines red the moment the catalog is unreachable Model marketplace One unified catalog across all 9 providers — cards now carry the platform's own cover art and a research panel with real download counts, licences and benchmarks Music player Search any song and play it in the marketplace — keyless, no YouTube API key — with a 5-band equalizer that actually re-shapes the audio Agent builder Describe a task in plain English; ENZO drafts the agent's full operating manual, and the agent keeps training itself on your activity from then on Research mode A deep-research loop that writes its own queries, reads what it finds, and decides when it's done — under hard budgets so it can't burn your key Code-gen Writes a coding project, boots it, previews it live, and tells you when it's broken Vault Every key sealed in the browser, attached per-request, wipeable in one click How the agent builder works Pass 1 — analysis. A two-pass drafter reads the domain of your task ("an agent that researches MUN country positions") and derives what the manual needs to cover: tacit knowledge, decision heuristics, edge cases. The race. When a draft needs a model, ~10 free candidates from your own providers fire simultaneously — the first to answer wins, stragglers are aborted, and a brain-health scoreboard reorders future races by which models actually deliver. Dead or rate-limited free-tier models can no longer collapse a draft. Honest provenance. Every agent records which model actually drafted it — and says so plainly when nothing was reachable. It doesn't stop. A per-agent neural layer folds in domain-matched platform activity on a 90-second cadence, distills lessons into memory, and injects a live NEURAL FOCUS block into every run. Watch it in the agent's Neural tab. Why ENZO stands out Most "AI workspaces" hold your keys, meter your usage, or need a subscription to exist. ENZO is built the other way around: ENZO Hosted AI apps (ChatGPT, Poe, …) Typical self-hosted AI tools Who pays the model you, directly to the provider the vendor (plus markup) you Where API keys live your browser, AES-256-GCM sealed under a non-extractable key vendor's servers server-side env/config Server reads your keys hosted mode: never — relay-only, CI-enforced. Self-hosted: only the key you explicitly claim, for scheduled agents — stated in the threat model yes usually yes Middleman fee none subscription / per-seat none Install docker compose up -d, zero config none (it's hosted) often multi-service setup Agents improve themselves neural layer learns from your activity no no Security testing in CI black-box pentest, 44 asserts, every push opaque rarely (Competitor column is about the category, not specific products — details vary.) Security The full threat model is written down — checkable, with the code that makes each claim true — in docs/SECURITY.md. The short version: Keys are sealed in your browser with AES-256-GCM under a non-extractable WebCrypto key. It can be used to decrypt your keys while never being copied — no JavaScript can export its bytes, ours or an attacker's. Optional passphrase mode re-seals everything under PBKDF2-SHA256 (600,000 iterations) and deletes the device key entirely. One module touches key storage, and CI enforces it. A pipeline stage greps the frontend for any raw localStorage key read and fails the build on a hit — a missed key-access site is a red build, never a production bug. Every push runs a 44-assertion black-box pentest against a booted server — auth bypass, hostile payloads, IDOR, stream integrity — plus a keyless-boot proof: the server must start with zero provider keys. That's the BYOK guarantee, tested, not promised. The limits are stated up front. Self-hosted mode stores the first key you claim in the container .env (sealed in the memory volume) so scheduled agents can run while your browser is closed — that trade is documented, not hidden. docs/SECURITY.md covers what's protected, what isn't, and why. What's new in v1.4.0 In-chat file converter — attach a PDF, spreadsheet, CSV, JSON, TXT or Markdown file in the terminal chat and it's parsed to real text/rows in your browser (files never leave the device; only the reasoning step uses your own key, like normal chat). The agent extracts, merges, or cross-converts — and CSV / Excel download buttons appear right on the reply. Built for research papers: "extract every table and merge into one CSV" now works end to end, and scanned PDFs report their missing text layer instead of failing. Run it on Google Colab — one click on the Open In Colab button (see Run on Google Colab): the notebook clones, installs, builds and boots ENZO on Google's hardware, hands you a URL for your browser plus a tunnel URL for your phone, and arms a keep-alive + watchdog so it stays up for 6+ hours. Self-healing Docker pulls — the container now verifies its dependencies on every start and installs anything missing before the server boots (ENZO_AUTO_INSTALL=0 to skip). A pulled image can't boot broken. What's new in v1.3.0 (previous) Music player — search any song and play it straight from the marketplace, keyless (no YouTube API key, no quota): a collapsed corner pill expands into a full player card — vinyl disc hero, queue walking, shuffle/loop/like, keyboard controls. For You turns your own listening history (kept device-local) into song seeds through your own provider key. Real equalizer — a 5-band Web Audio EQ (bass / low-mid / mid / presence / air, ±12 dB, preamp, five presets) that genuinely re-shapes the frequency response when you opt in. Enhance starts off — normal playback is untouched. Tracks the enhancer can't stream fall back to the YouTube engine automatically; playback never breaks.