Open-source control plane for Claude Code. Your devices run
claude; Forge routes the work, gates it, and keeps the receipts. The server never holds your Claude credentials.
Status: alpha. Breaking changes across v0.x.
Three boundaries hold the shape:
- Control plane vs. runtime. The server queues jobs and streams events; your machines run Claude. A server compromise leaks no Claude credentials — they never leave your box.
- Two principals, one policy layer. A user (JWT) and a device (long-lived, revocable) are separate principals; every access goes through the same checks.
- Core does not know the plugin exists. A project designates plugins; each device resolves
its own set and installs them. Nothing in this repo can gate that one —
SidCorp-co/forge-pluginships the CLI, the session hooks and the driver skill on its own clock.
The driver skill, the forge CLI and the session hooks live in a second repository on its own
clock. The CLI is not forge-runner — it carries its own HTTP client and its own declared route
table, and reaches REST with a Bearer PAT. This is the surface those three reach core through, the
one thing in it that carries a version, and the place an agent can pick the wrong tool:
The agent's surface, the data plane and where both are going: docs/proposals/destination/ — one set, measured, with its own coverage stated.
git clone https://github.com/SidCorp-co/forge.git && cd forge
cp .env.example .env
docker compose up -dAPI http://localhost:8080 · dashboard http://localhost:3000. Then pair a device:
curl <core-url>/install.sh | sh and forge-runner login --code <code>.
Full walkthrough: docs/quickstart.md.
| Package | Role |
|---|---|
packages/core/ |
Control plane — Hono, Drizzle, pg-boss, WebSocket, MCP |
packages/web-v2/ |
Next.js dashboard — kanban, replay, pipeline health, devices |
packages/runner/ |
forge-runner — the Rust device agent |
packages/contracts/ |
Types and registries shared across apps |
Vision · Quickstart · Architecture · Proposals · Decisions · Governance · Changelog
CONTRIBUTING.md is the front door; GOVERNANCE.md says who
reviews, merges and releases. Trunk-based: one main, branches under a day, feature flags absorb
what is in flight. Significant changes are argued in
docs/proposals/destination/, and the decisions behind the rules are
in docs/adr/.
Security vulnerabilities: never a public issue — use private reporting.
Apache-2.0 © Forge contributors.