Arkloop
干净、强大、属于你的 AI Agent 平台 --AI agents, without the clutter.
Ask AI about Arkloop
Powered by Claude · Grounded in docs
I know everything about Arkloop. Ask me about installation, configuration, usage, or troubleshooting.
0/500
Reviews
Documentation
Open-source / Clean / Powerful — Your AI Agent Platform
Arkloop is a design-focused open-source AI Agent platform. Multi-model routing, sandboxed execution, persistent memory — a clean desktop app that works out of the box.
Download
Download the latest version from GitHub Releases, supporting macOS, Linux, and Windows.
The desktop app bundles the full runtime — no Docker, no configuration. Just open and use. Automatic updates via GitHub Releases.
CLI via Homebrew
Homebrew installs the Arkloop CLI only:
brew install qqqqqf-q/arkloop/arkloop
ark web
macOS: app blocked (Move to Trash)
Do not click Move to Trash when macOS warns that Arkloop cannot be verified.
-
Choose Done or close the dialog.

-
Open System Settings → Privacy & Security. Under Security, find Open Anyway next to the Arkloop message and click it.

-
When the confirmation dialog appears, choose Open Anyway again.

Features
Arkloop does what other AI chat tools do — multi-model support, tool calling, code execution, memory — but we focus on doing it cleanly:
- Multi-Model Routing — OpenAI, Anthropic, and any compatible API; priority-based automatic routing with rate limit handling
- Sandboxed Execution — Code runs in Firecracker microVMs or Docker containers with strict resource limits
- Persistent Memory — System constraints, long-term facts, and session context preserved across conversations
- Prompt Injection Protection — Semantic-level scanning that detects and blocks injection attacks
- Channel Integration — Telegram integration with media handling and group context
- Custom Personas — Independent system prompts, tool sets, and behavior configs; Lua scripting supported
- MCP / ACP — Model Context Protocol and Agent Communication Protocol support
- Skill Ecosystem — Import skills from ClawHub, compatible with OpenClaw SKILL.md format
Full documentation at docs.
Contributing
We welcome contributions of all kinds.
Even if you're not a developer, just a regular user — if anything feels off while using it, even a bit of spacing, a color, a tiny detail, or a big-picture direction — please open an issue. We take every UX detail seriously, and your feedback makes the experience better for everyone.
See CONTRIBUTING.md for commit conventions and development workflow.
Sponsors
Thanks to the following friends for their support, keeping Arkloop going:
- @Jinnkunn — Bought me a domain
- @jeck — Treated me to an iced Americano
- @chuichui — Covered my AI costs for two weeks
Contributors
If you can, give us a Star

Architecture
| Service | Stack | Role |
|---|---|---|
| API | Go | Authentication, RBAC, resource management, audit logging |
| Gateway | Go | Reverse proxy, rate limiting, risk scoring |
| Worker | Go | Job execution, LLM routing, tool dispatch, agent loop |
| Sandbox | Go | Code execution isolation |
| Desktop | Electron + Go | Native desktop app with embedded sidecar |
| Web | React / TypeScript | User interface |
| Console | React / TypeScript | Admin dashboard |
Infrastructure: PostgreSQL, Redis, SeaweedFS (or filesystem), OpenViking (vector memory).
Development
bin/ci-local quick # Quick local CI
bin/ci-local integration # Go integration tests
bin/ci-local full # Full check
Self-Hosting
The self-hosting deployment path is still in development. While included in the current release, availability is not guaranteed. We are not focusing on this during the Alpha phase. We plan to provide full server deployment support once the desktop version stabilizes.
Star History
Security
To report vulnerabilities, please email qingf622@outlook.com instead of opening a public issue. See SECURITY.md for our disclosure policy.
License
Licensed under the Arkloop License, a modified Apache License 2.0 with additional conditions:
- Multi-tenant restriction — Source code may not be used to operate a multi-tenant SaaS without written authorization.
- Brand protection — LOGO and copyright information in the frontend components must not be removed or modified.
