Golem 1.6 · Agents, Tools, and Artifacts

Agents that never fail.
Policies that never bend.

Deploy agents, their tools, and their artifacts to one durable runtime. State persists automatically, every tool call executes exactly once, and the host enforces every policy — whoever, or whatever, wrote the code.

Golem thinker — stone figure in contemplation
Ziverge
Golem Social
WarpMind
Seeta AI Assistant
JournAI
Johnethel LMS
One runtime

Deploy agents, their tools, and their artifacts.

Agents

Typed, durable agents in six SDKs. Streaming methods, read-only methods, reflection, and state that survives anything.

Tools

Typed tools with host-enforced middleware, a built-in toolkit — shell, files, git, Node, npm, TypeScript, web fetch — and MCP in both directions.

Artifacts

The apps, pages, and files agents ship to people — served by Golem, backed by the agent, with login and resumable streams built in.

The harness chooses what an agent does. The runtime decides what it can do.

Code-first

Agents are code, not prompts.

Typed agents in TypeScript, Effect, Rust, Go, Scala, or MoonBit. State survives crashes and redeploys. Tool calls never fire twice. Your code — and the host — decide what's allowed.

orders-agent.ts
export const Orders = defineAgent({
  name: 'Orders',
  id: { customerId: z.string() },
  http: http.mount('/orders/{customerId}'),
  config: { systemPrompt: z.string() },
  methods: {
    handle: method({
      input: { request: z.string(), orderId: z.string() },
      returns: z.object({ resolved: z.boolean() }),
    }),
  },
})

export const OrdersImpl = Orders.implement({
  init: () => ({ history: [] as Message[] }),
  methods: {
    async handle({ request, orderId }) {
      // No DB writes — this push survives crashes, deploys, host migrations
      this.history.push({ role: 'user', content: request })

      // LLM sees full conversation; system prompt comes from typed config
      const outcome = await llm.run({
        prompt: this.config.systemPrompt, history: this.history,
        tools: [cancelOrder, changeAddress], context: { orderId },
      })
      this.history.push({ role: 'assistant', content: outcome.message })

      // Refunds aren't in the LLM's toolset — agent code gates them via HITL
      if (outcome.needsRefund) {
        // This await can sit for days at zero cost — no queue, no cron, no state table
        const webhook = createWebhook()
        await notifyApprover(webhook.getUrl(), outcome)
        const { approved } = (await webhook).json()
        if (approved) {
          // Crash, retry, restart — still one charge. No silent double-charges.
          const result = await refundOrder({ orderId, amount: outcome.refundAmount })
          this.history.push({ role: 'tool', content: JSON.stringify(result) })
        }
      }
      return { resolved: true }
    },
  },
})
Business coding agents

A coding agent, entirely in Golem.

The coding agents that matter most are the ones business users never see: the support bot that writes a script to reconcile an account, the assistant that builds the report from three systems.

On Golem, the shell, files, git, Node, npm, and TypeScript run inside the sandbox as isolated tool calls — under a path policy the agent can't bypass and a permission card that names the only hosts it may reach. No Linux VM to boot, sync, or pay for. Kill the server mid-task and the agent picks up where it stopped.

Harness inside or outside the sandbox — your choice. The guarantees come from the host, not from where the loop runs.

Read the 1.6 announcement →
Built-in toolkit
  • bash
  • read-file
  • write-file
  • edit-file
  • ls
  • grep
  • git
  • node
  • npm
  • npx
  • tsc
  • web-fetch
  • path-policy

Automatically persists state.

State changes and effects are captured automatically, without serialization, state machines, or annotations. Agents suspend for days or weeks at zero compute and zero memory cost, resuming with the same memory, locals, and call stack.

Treat memory as durable.

Executes transactionally.

Code keeps running exactly once through any interruption, as if nothing happened. A tool call that crashed mid-execution completes; a workflow paused for days picks up where it stopped. This is transactional code execution.

Ship code that runs exactly once.

Enforces every policy.

Every agent and every tool call runs in its own WebAssembly instance — its own memory, no system calls. Authority comes from permission cards the runtime mints: they narrow, never widen, and revocation cascades. Tool middleware runs in the host on every call, secrets are opaque handles, and every decision is journaled.

Turn policies into guarantees.

Artifacts

Agents ship things people use.

Front-ends, reports, live output — served by the same runtime that runs the agent, from the same deployment, under the same authority, with the same audit trail.

  • HTTP routers

    Mount any Fetch-compatible framework, and publish OpenAPI.

  • Static assets

    Versioned with the deployment, served without waking an agent.

  • Live files

    Agents publish what they write — reports, builds, workspaces.

  • Front-end login

    OAuth2 with PKCE for single-page apps, tokens issued by Golem.

  • Durable Streams

    Stream to the browser; a reload picks up where it left off.

  • Subdomains

    A real URL from the first golem deploy, locally and in the cloud.

router.ts
export const AppRouter =
  defineHttpRouter('AppRouter')
    .mount('/app')
    .implement((req) => app.fetch(req))
Why not LangChain?

LangChain leaves you the hard parts.

Tool calls firing twice. State lost mid-node. SQL checkpointers under load. These aren't problems LangChain solves — they're runtime problems. Golem solves them as runtime guarantees.

AI Framework
Golem Runtime
Why it matters
AI Framework
Agents share host resources; tenant isolation depends on developer-enforced discipline
Golem Runtime
Each agent owns its own memory, filesystem, and environment
Why it matters
Cross-tenant leaks become structurally impossible
AI Framework
Durability is opt-in and coarse — recovery restarts from last boundary, losing in-flight state
Golem Runtime
No checkpoints, steps, or annotations — the whole agent resumes mid-execution, after any failure or suspension
Why it matters
No state is ever lost to failure or suspension
AI Framework
Auto-retry only works for idempotent tools; the rest require developer-managed safety logic
Golem Runtime
Agent logic and tools — internal or external — execute durably with exactly-once semantics
Why it matters
Infrastructure failures never cause partial or duplicate work
AI Framework
Authority enforced by developer-written code and LLM prompts; both fail when their authors do
Golem Runtime
Authority carried by permission cards the runtime mints — code can only do what its cards and imports allow
Why it matters
Buggy or malicious code can't exceed what it was granted
AI Framework
Guardrails run in-process; generated code can route around them
Golem Runtime
Tool middleware enforced by the host on every call
Why it matters
Policies hold even for code the model wrote
AI Framework
Waits, retries, and HITL require explicit state-machine code at framework boundaries
Golem Runtime
Any flow is just code — suspension, retries, and resumption are runtime behaviors
Why it matters
No state-machine code to write or maintain

Runtimes deliver what frameworks can't even promise.

10,000+
Active agents per node
2 ms
Agent cold start
1 MB
Min sandbox memory
0 CPU/RAM
Idle resource cost
Bring your stack

Your libraries. Our runtime.

Bring your favorite LLM SDKs, your tool libraries, your utilities — anything that's just code. They run on Golem, and your agent logic and tool primitives inherit the runtime's guarantees, without modification.

Use Golem's lightweight SDKs only when you want runtime-specific features: durability hooks, forking, rollbacks, agent and tool discovery. MCP servers you import inherit the same durability and middleware. Frameworks that bring their own runtime aren't officially supported today.

The full package

Bundled into the runtime.

MCP, both directions
Export agents and tools; import any MCP server durably
Built-in toolkit
Shell, files, git, Node, npm, TypeScript, web fetch — in the sandbox
Tool middleware
Policies and guardrails, enforced by the host on every call
Permission cards
Runtime-minted authority that narrows, never widens
First-class secrets
Opaque handles; reveal only where granted, always journaled
Artifact hosting
HTTP routers, static and live files, PKCE login
Durable Streams
Resumable streams to any client, protocol-compatible URLs
Read-only methods
Enforced at runtime, cached at the HTTP edge
Tool-calling protocols
MCP, HTTP, RPC — all exactly-once
Webhook primitives
Incoming events like HITL become awaitable promises
Scheduled execution
Durable timers and scheduled invocations at zero idle cost
User-defined quotas
Rate, capacity, concurrency — throttle, reject, or terminate
OpenTelemetry built-in
Every step traced, every metric auto-emitted
Complete audit log
Every action and authorization decision, recorded and replayable
Sandboxed by construction
Every agent and tool call runs in its own WebAssembly instance
Model-agnostic
Any model via HTTP — routing stays in your code
Open source. Your cloud. Your language.

Run it where you want. Write it how you like.

BUSL‑1.1 → Apache‑2.0

The runtime source is auditable, the WASM components are inspectable, and the license transitions to Apache‑2.0 — staying out of your way today, fully permissive tomorrow.

Your cloud.

Run Golem where you run everything else — on a laptop, in Docker, in Kubernetes, on any cloud, or on-prem.

Your language.

Same runtime, same capabilities, same guarantees, same operational behavior across supported languages.

TypeScript Strongest surface
Effect Effect-native TypeScript
Rust Substrate-credible
Go Idiomatic, generics-first
Scala Effects-friendly
MoonBit Small WASM

Built by the wizards behind ZIO — the open-source effect system running in production at companies across fintech, ad tech, and AI infrastructure for the better part of a decade.

In their own words

From teams shipping on Golem.

"I tried Akka event sourcing and Step Functions first. What I love about Golem is clean code — durable state and automatic retry built in."

Peter Kotula
Peter Kotula
Software Engineer
Building Golem Social

"I crashed a running agent mid-test — its .schedule() reminder still fired on time. Golem's durability isn't bolted on; it's the runtime."

Rahul Joshi
Rahul Joshi
Full-Stack AI Developer
Building WarpMind

"Like AWS Lambda, but the function has memory across invocations and durable reminders. Durability is invisible — exactly how infrastructure should feel."

Seeta Ramayya Vadali
Seeta Vadali
Senior Consultant
Building Seeta AI

"For JournAI, I modeled log analysis as durable agents. Golem's guarantees around state, retries, and recovery let me focus on the logic, not the infrastructure."

Daniele Torelli
Daniele Torelli
Senior Software Engineer
Building JournAI

"Tried Temporal, Dapr, Restate, and Fermyon Spin. Golem gives me what I'd given up on finding: code-level customizability with no-code-level operational simplicity."

Samuel Iyeh
Samuel Iyeh
AI Software Engineer
Building Johnethel LMS

Crash your first agent in five minutes.
Watch it come back.

Scaffold a durable agent, run it locally, kill the process at any line, and watch it resume exactly where it stopped.

# Install: download from github.com/golemcloud/golem/releases
# Templates: ts | effect | rust | go | scala | moonbit
golem new --template ts --component-name example:counter --yes my-agent
cd my-agent && golem build
golem repl