Skip to main content
Tilde Cloud can provision a complete OpenBot installation from a title and a unique slug. The caller must be a system administrator or an administrator of the owning organization.
The request creates or reconciles:
  • a dedicated Tilde team named openbot-<slug>;
  • an instance-only agent API key and OpenBot OIDC audience;
  • separate Vercel control and agent projects;
  • a persistent Vercel Sandbox used as the writable OpenBot Computer;
  • project-scoped Vercel OIDC for AI Gateway, Sandbox, and VCR access;
  • a deterministic openbot-<slug>-control.vercel.app hostname; and
  • a non-interactive OpenBot initialization and production deployment command.
The response has status: "provisioning" and includes the team ID, hostname, deployment URL, Vercel project names, Sandbox name, bootstrap command ID, and public OIDC registration. A repeated request with the same organization and slug reconciles the deterministic resources. A slug already owned by another organization is rejected.
Custom trytilde-fs.com and trytilde-dev-fs.com hostnames are a follow-up. Provisioning currently uses the Vercel project domain so DNS does not block a working installation.

Source control and credentials

Hosted instances use OpenBot’s LocalGitProvider. The writable checkout and its bare file:// origin both remain on the persistent Sandbox filesystem; no GitHub account or GitHub token is required. Tilde’s Vercel account token remains exclusively in the Tilde deployment worker. It is never passed to the Sandbox, Git repository, OpenBot SOPS document, or tenant project environment. Deployed agents use project OIDC for AI Gateway, while OpenBot sends content-addressed prebuilt releases through its team-scoped Tilde capability. Runtime configuration accepts user-owned model, agent, and generated Computer values. Tilde derives the API key, organization, team, hosted-instance identity, OAuth metadata, public origin, and Computer identity from the authenticated instance record rather than trusting caller-supplied values.

Hosted inference billing

Tilde Cloud forwards the non-secret hosted-billing marker to the agent runtime through the managed release configuration allowlist. Vercel tokens and static Gateway credentials remain excluded. OpenBot enables metering only for Tilde-managed project OIDC; direct owner Gateway-key and Codex subscription paths disable it. Before every Gateway model call, OpenBot reserves organization AI credits and prepares a worker- and generation-fenced AgentRun effect. It persists the Gateway generation for crash recovery. The authoritative generation receipt commits system or fallback cost and releases a BYOK reservation. BYOK still reserves first because Vercel may fall back to charged system credentials and requires Gateway credits for that fallback. An organization with zero Tilde AI credits cannot start a Gateway call, including a BYOK call. If a provider result is planned, uncertain, or reconciled without a recoverable model response, OpenBot does not repeat it. The old run fails safely, and a later owner message creates a new run. Hosted cost budgets use the authoritative receipt after each call, so max_cost_microusd can overshoot by the final call; the organization credit balance remains protected by pre-call reservation.

Automatic memory

OpenBot automatic memory is shipped and defaults off. Set OPENBOT_AUTOMATIC_MEMORY_MODE to personal, personal_plus_agent, or team, or use an AGENT_<ID>_AUTOMATIC_MEMORY_MODE override. Only personal_plus_agent creates a lifecycle-owned bank. Its Agent Resource Bundle assigns the stable same-team memory-catcher ChatKit agent as synthesizer; omission preserves a current or server default, while disabling the bank removes that lifecycle-owned resource. Memory Catcher uses the installation’s selected inference provider, including managed project OIDC, and owns no memory bank itself. Before a billed call it validates the exact current prompt chunk and unexpired worker lease with Tilde, then uses a durable AgentRun effect for reservation and authoritative settlement. Failed credit commit or BYOK release remains retryable without repeating provider inference. Its bank-bound tools require the current batch ID, complete evidence IDs, and fresh lease owner for every mutation and completion, so synthesis cannot recursively retain itself or reuse a stale claim.

Managed release API

After building .vercel/output, OpenBot creates a release for either control or agents, uploads each unique SHA-1 file through Tilde, finalizes the release, and polls it until ready or failed. The release API never accepts a Vercel project ID from the caller. Tilde resolves the control or agent project from the authenticated hosted-instance record. Slugs must be lowercase DNS labels containing 3–48 letters, digits, or single hyphens. Titles must contain 1–100 characters.