<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Paperclip - Open-Source Orchestration Platform for Teams of AI Agents at Work]]></title><description><![CDATA[<p dir="auto"><strong>Paperclip</strong> - Open-Source Orchestration Platform for Teams of AI Agents at Work</p>
<hr />
<ul>
<li><strong>Main Page</strong>: <a href="https://paperclip.ing" target="_blank" rel="noopener noreferrer nofollow ugc">https://paperclip.ing</a></li>
<li><strong>Git</strong>: <a href="https://github.com/paperclipai/paperclip" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/paperclipai/paperclip</a></li>
<li><strong>Licence</strong>: MIT</li>
<li><strong>Dockerfile</strong>: <a href="https://github.com/paperclipai/paperclip/blob/master/Dockerfile" target="_blank" rel="noopener noreferrer nofollow ugc">Yes</a> - Official image at <a href="http://ghcr.io/paperclipai/paperclip" target="_blank" rel="noopener noreferrer nofollow ugc">ghcr.io/paperclipai/paperclip</a></li>
<li><strong>Docker-compose</strong>: <a href="https://github.com/paperclipai/paperclip/blob/master/docs/deploy/docker.md" target="_blank" rel="noopener noreferrer nofollow ugc">Yes</a> - Generated via <code>npx paperclipai onboard</code> CLI (Paperclip server, PostgreSQL, Redis, optional Qdrant); deployment docs included</li>
<li><strong>Demo</strong>: No public demo — <a href="https://paperclip.ing/blog/" target="_blank" rel="noopener noreferrer nofollow ugc">live demo video on the Paperclip blog</a>; can try without installing via <code>npx paperclipai</code> (no Paperclip account required)</li>
</ul>
<hr />
<ul>
<li><strong>Summary</strong>:<br />
• Open-source app (74k+ GitHub stars) for managing AI agents at work — "if OpenClaw is an employee, Paperclip is the company" — bringing your own agents (OpenClaw, Claude Code, Codex, Cursor, Bash, HTTP, and local agents like Gemini, OpenCode, Grok Build) into a single control plane<br />
• Models companies with org charts, roles, reporting lines, goals, budgets, and approval gates so you can assign work to agents and track progress and costs from one dashboard<br />
• Node.js server + React UI; runs with an embedded PostgreSQL database or your own, supports background-service installs on Linux/macOS, and includes governance features like audit trails, approval gates, and budget limits
<ul>
<li>OIDC Currently possible via plugin more info <a href="https://github.com/paperclipai/paperclip/issues/3028#issuecomment-5793283951" target="_blank" rel="noopener noreferrer nofollow ugc">here</a></li>
</ul>
</li>
</ul>
<hr />
<ul>
<li><strong>Notes</strong>:<br />
• Perfect for teams wanting to run "autonomous AI companies" on their own infrastructure — MIT licensed, fully self-hosted, 100% of data stays on your infra<br />
• Requires bring-your-own agent runtimes and API keys to be useful, and the multi-service stack (server, Postgres, Redis) makes it more involved to deploy than single-binary apps</li>
</ul>
<hr />
<ul>
<li><strong>Alternative to / Libhunt link</strong>:</li>
<li><strong>Screenshots</strong>: <a href="https://paperclip.ing/blog/" target="_blank" rel="noopener noreferrer nofollow ugc">live demo video</a></li>
</ul>
<p dir="auto"><img src="/assets/uploads/files/1790259387482-d34965cf-f261-4f47-a7df-5c5f68126a21-image-resized.jpeg" alt="image.jpeg" class=" img-fluid img-markdown" width="1600" height="1150" /></p>
<p dir="auto"><img src="/assets/uploads/files/1790259491010-487ddc7e-567b-4b6b-90c3-bbe863a9de89-image-resized.jpeg" alt="image.jpeg" class=" img-fluid img-markdown" width="1912" height="1107" /></p>
]]></description><link>https://forum.cloudron.io/topic/16008/paperclip-open-source-orchestration-platform-for-teams-of-ai-agents-at-work</link><generator>RSS for Node</generator><lastBuildDate>Thu, 01 Oct 2026 05:40:36 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/16008.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 24 Sep 2026 14:18:24 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Paperclip - Open-Source Orchestration Platform for Teams of AI Agents at Work on Mon, 28 Sep 2026 21:58:33 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/teiluj" aria-label="Profile: Teiluj">@<bdi>Teiluj</bdi></a> <a href="/post/130117">said</a>:</p>
<p dir="auto">Thanks for considering packaging paperclip.</p>
</blockquote>
<p dir="auto">We have created a package for Paperclip and have it running but are waiting to hear from upstream before publishing it.</p>
]]></description><link>https://forum.cloudron.io/post/130151</link><guid isPermaLink="true">https://forum.cloudron.io/post/130151</guid><dc:creator><![CDATA[LoudLemur]]></dc:creator><pubDate>Mon, 28 Sep 2026 21:58:33 GMT</pubDate></item><item><title><![CDATA[Reply to Paperclip - Open-Source Orchestration Platform for Teams of AI Agents at Work on Mon, 28 Sep 2026 09:07:33 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/loudlemur" aria-label="Profile: loudlemur">@<bdi>loudlemur</bdi></a> Thanks for considering packaging paperclip.</p>
]]></description><link>https://forum.cloudron.io/post/130117</link><guid isPermaLink="true">https://forum.cloudron.io/post/130117</guid><dc:creator><![CDATA[Teiluj]]></dc:creator><pubDate>Mon, 28 Sep 2026 09:07:33 GMT</pubDate></item><item><title><![CDATA[Reply to Paperclip - Open-Source Orchestration Platform for Teams of AI Agents at Work on Thu, 24 Sep 2026 18:34:01 GMT]]></title><description><![CDATA[<p dir="auto">Thank you for the request, <a class="plugin-mentions-user plugin-mentions-a" href="/user/teiluj" aria-label="Profile: Teiluj">@<bdi>Teiluj</bdi></a>. We like Paperclip and we are going to package it as a community app.</p>
<p dir="auto">Before we do so, here are some concerns which people who might want to use a Paperclip package may like to read, because this app is not like most on the store.</p>
<p dir="auto"><strong>What concerns us</strong></p>
<ul>
<li><strong>Agents run inside the app.</strong> Paperclip starts Claude Code, Codex and similar tools as processes in its own container, and upstream hands them the server's full environment. On Cloudron that includes the database credentials, and the key that encrypts every stored secret is a readable file. An agent that reads a hostile ticket or repository could take over the whole Paperclip instance.</li>
<li><strong>Upstream's sandbox cannot run here.</strong> It relies on Linux namespaces, which Cloudron app containers do not allow.</li>
<li><strong>The internal network is reachable.</strong> Any app container can reach the shared database servers and other apps directly, which also bypasses proxyAuth. An unconfined agent would be a foothold inside the server, not just inside Paperclip.</li>
<li><strong>Sign-in is email and password only.</strong> There is no OIDC yet (it is an open pull request upstream, not a plugin), and the server sends no email at all, so there is no password reset.</li>
<li><strong>It moves fast.</strong> Releases are roughly weekly, and one recent release carried 49 database migrations.</li>
</ul>
<p dir="auto">One correction to the post above: Paperclip does not use Redis or Qdrant. It needs only PostgreSQL, which the Cloudron addon provides.</p>
<p dir="auto"><strong>How we intend to handle it</strong></p>
<ul>
<li>Agents run as a separate, unprivileged user, started through a narrow sudo rule with a clean environment. They cannot read the database credentials, the encryption key or the server's memory.</li>
<li>A firewall inside the container, matched on that user for both IPv4 and IPv6, blocks the internal network and outbound mail. The internet, DNS and Paperclip's own API stay open.</li>
<li>Process and file-size limits apply to the agent user.</li>
<li>Telemetry is off by default, and so are Paperclip's own database dumps, because Cloudron already backs up PostgreSQL.</li>
</ul>
<p dir="auto">We have tested this design on a test Cloudron. The agent user was refused on every database and every other app, saw no secrets, and still reached the internet.</p>
<p dir="auto"><strong>Advantages</strong></p>
<ul>
<li>You can run local agents without handing them the server.</li>
<li>It works on stock Cloudron. It needs only the net_admin capability, which Cloudron offers to apps: no Docker socket and no privileged container.</li>
<li>The listing will say plainly what an agent can and cannot reach.</li>
</ul>
<p dir="auto"><strong>Drawbacks</strong></p>
<ul>
<li>All agents share one user, so one agent can read another's workspace.</li>
<li>Agents can still reach the internet, so anything an agent can read, it can send out. For untrusted input, a remote sandbox or an agent in its own app (OpenClaw and Hermes Agent are already in the store) remains the better choice.</li>
<li>An agent can still fill the disk.</li>
<li>Board users can run any command in the app, so treat them as administrators.</li>
<li>There is no SSO and no password reset until upstream adds them.</li>
<li>Updates to the application (but perhaps not the package) will be frequent.</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/129975</link><guid isPermaLink="true">https://forum.cloudron.io/post/129975</guid><dc:creator><![CDATA[LoudLemur]]></dc:creator><pubDate>Thu, 24 Sep 2026 18:34:01 GMT</pubDate></item></channel></rss>