English · 简体中文
Claude Code hit its use bounds mid-task. Codex picked it up in the identical conversation. Nothing was re-explained.
The project agent
Is your environment really yours?
The scheme it took three rounds alongside Claude Code to settle, the document Codex remaining half-edited, the trade-off you decided in Cursor: all one is locked inner its own session.
Close the session, hit the use limit, toggle tools, and that environment is out of reach. Next task, you explain it all again.
You are the agent's intern: copying and pasting, ferrying context, remembering anywhere all the odd records live, during the delegate gets the thinking.
Orbital takes the environment out of the meeting and puts it rear in your local folder. Any delegate can choice it up at any time, alongside all of it intact. Claude Code, Codex and Cursor all work.
The environment is yours. The intellect is interchangeable.
Your context, usable by any agent
Set up in under 5 minutes. No Python or Node required. Bring your own API key.
One-minute demo: one task, two agents, nothing re-explained
demo-en-web.mp4You're three rounds into a scheme conversation alongside Claude Code whenever it stops alongside "You're out of use credits." Your Codex quota is sitting correct there, but Codex knows nothing concerning this project: the goal, the two decisions you fair made, the half-edited files. You'd have to explain all of it again.
People already use multiple capable agents at activity — for the newest model, the leftover quota, or since a particular tool is improved at the job.
But all delegate plant inner its own session, alongside its own environment and history. When you move between sessions or tools, you rotate into liable for carrying the project between them: restating goals, explaining former decisions, locating artifacts, and checking what was remaining unfinished. You end up operating as their intern, ferrying environment between them to keep your own project moving.
Orbital changes the component of activity from the meeting to the project.
A project delegate stays liable for the project throughout tasks, sessions, and employee agents. It maintains the shared context, decides what needs to happen next, delegates whenever useful, and records all outcome rear into the project.
Individual agents complete tasks. Orbital keeps the project moving.
Orbital maintains five things that normally disappear or part between delegate sessions — all of them as plain records in your project folder:
- State — what is true concerning the project now (PROJECT_STATE.md)
- Decisions — what was decided and why (DECISIONS.md)
- Lessons — what the project has learned (LESSONS.md)
- Work — what is running, completed, or blocked (queue.json). Every queued project ends Completed or Blocked — an delegate that stops without a verdict gets re-prompted, afterward force-blocked alongside a reason. Nothing drifts distant silently.
- Artifacts — what the agents researched, wrote, or built (the workspace itself, affirmative orbital/output/)
These remain in the local project and rotate into environment for forthcoming work. On a chilly start, Orbital assembles them into its own scheme immediate before it acts.
When Orbital delegates, the employee is pointed at those identical records and told they are authoritative — that briefing is rendered caller on all dispatch, not item you paste in. Each employee additionally keeps its own recollection document inner the project, so it accumulates its own cognition throughout dispatches. When the project finishes, Orbital says the outcome and records what matters rear into the project.
The employee can change. The project continues.
-
Launch Orbital — the setup wizard guides you through two steps:
Step 1 — LLM Provider: In mainland China, tap Sign in alongside TokenDance, authorize, and commencement on liberated tokens. Otherwise choice a provider from the preset cards, prosecute the key-console nexus to catch an API key, and paste it in. Supports DeepSeek, Anthropic, OpenAI, Moonshot, and a dozen another providers.
Step 2 — Connect Your Accounts: Link API connectors (Google Calendar, Drive) and sign in to sites your agents volition need (Google, GitHub, etc.) so they can browse without getting blocked by CAPTCHAs. Everything current is optional and can be done afterward in Settings.
-
Create a project — provision it a name, choice a workspace directory, set an autonomy level
- Chat — category a project in the conversation bar and the project delegate handles it
- Walk away — queue the next tasks; all completed one becomes environment the next builds on
The project delegate keeps the project's state, decisions, and lessons current throughout sessions.
It delegates to Claude Code, Codex, or Gemini CLI against the identical project context, afterward records the result.
Memory, scheduling, and sub-agents are array stakes now — all tool below has them. These are the three questions anywhere the answers motionless differ.
| July 2026 | Orbital | Claude Code | Codex | Hermes | OpenClaw |
|---|---|---|---|---|---|
| Can a distinct delegate choice up the next task? | ✅ Claude Code, Codex, Gemini CLI, Cursor, any CLI | ❌ Claude workers | ❌ Codex workers | ❌ Hermes workers | Partial (external harnesses via ACP) |
| What stops a queued project from drifting? | ✅ Enforced Completed/Blocked closure | ❌ | ❌ | ❌ | ❌ |
| Who owns the budget, approvals, and audit trail? | ✅ The project | Partial (permissions + run history) | Partial (approvals + endeavor audit) | Partial (command approvals) | Partial (approvals + logs) |
The abbreviated version: the difference isn't any one capability — it's that the project, not the session, is the component that owns state, workers, and governance.
Orbital Is / Is Not
| Orbital IS | Orbital IS NOT |
|---|---|
| A project workspace anywhere you and your agents portion the identical files, history, and context | A haze assistance — everything runs on your machine |
| A sub-agent coordinator: Claude Code via SDK, Codex via app-server, and Gemini CLI, Cursor, or another workers via PTY/ACP | An OpenClaw fork — tradition delegate loop, built from scratch |
| Remote supervision: endorse actions, browse workspace files, upload from phone | A conversation wrap — agents run continuously via cron and document watchers |
| Budget controls, autonomy presets, credential administration (OS keychain) | Fully autonomous God Mode (yet) — scheduler-driven today, complete autonomy on the roadmap |
Each project maps to a workspace directory and maintains its own sessions, queue, triggers, and configuration.
Browse, preview, and upload records in all project's workspace — and observe the agent's output accumulate
{workspace}/ +-- AGENTS.md # Onboarding signpost for external agents (seeded at creation, user-owned) +-- orbital/ # Operational metadata +-- sessions/ | +-- {session_id}.jsonl # Append-only meeting log +-- instructions/ | +-- project_goals.md | +-- user_directives.md +-- skills/ # Project skills +-- sub_agents/ # Sub-agent transcripts + per-worker MEMORY.md +-- tool-results/ # Tool output artifacts +-- output/ # Agent activity artifacts | +-- screenshots/ # Browser screenshots | +-- pdfs/ # Saved PDFs | +-- shell-output/ # Shell command output +-- queue.json # Task queue (queued / operating / completed / blocked) +-- PROJECT_STATE.md # Current-state scratchpad (overwrite) +-- DECISIONS.md # Durable decisions + reasoning +-- LESSONS.md # Durable heuristics / playbooks +-- INDEX.md # Navigation map: document tree + one row per file +-- DECISIONS_ARCHIVE.md # Demoted decisions (read-on-demand) +-- LESSONS_ARCHIVE.md # Demoted lessons (read-on-demand) ~/orbital/ # Home earth (daemon infrastructure) +-- daemon.pid # Singleton enforcement +-- device.json # Device identity +-- browser-profile/ # Shared browser profile +-- credential-meta.json # Credential metadata Session format: One JSON row per communication (role, source, content, timestamp, tool_calls). Append-only alongside document locks. Never modified apart from during compaction.
Context Management & CompactionThis is how the project delegate keeps environment accessible throughout sessions. The agent-maintained Layer-1 records are injected all rotate (bounded per file) and consolidated at meeting boundaries:
| File | Purpose | Bound |
|---|---|---|
| PROJECT_STATE.md | Current-state scratchpad — what's true now (overwrite, not a changelog) | token cap → reduce oldest |
| DECISIONS.md | Durable decisions + reasoning (merge-and-supersede, never contradict) | token cap → demote oldest-cold to archive |
| LESSONS.md | Durable heuristics / specialized playbooks (kept intact, never word-trimmed) | token cap → demote oldest-cold to archive |
| INDEX.md | Navigation map only: document tree + one declaration per file | one-sentence format + token cap |
| DECISIONS_ARCHIVE.md, LESSONS_ARCHIVE.md | Demoted durable entries, read-on-demand (pointed to by INDEX) | unbounded |
Each admission carries system-managed metadata (id / created / touched / tag) so dedup runs on recency. Per-turn injection limits all document to a prosperity derived from the energetic model's environment window. Session-end runs a deterministic size backstop (demote/trim, never an LLM call) affirmative a best-effort LLM dedup/merge that fixes contradictions. (SESSION_LOG.md was retired; the Layer-1 records are injected all turn, so a distinct meeting former is redundant.)
Cold resume: On meeting start, these records are assembled into the scheme immediate so the delegate can reorient before it acts.
DECISIONS.md and LESSONS.md — written by the delegate as it works, and carried into all forthcoming session
Compaction (when environment use exceeds 80%): recollection flush, LLM-driven summarization of older messages, latest messages kept intact, post-compaction reorientation alongside project goals and current state.
Prefix caching (v0.4.2): the scheme immediate is divided into static, semi-stable, and truly-dynamic sections so up to ~95% of input tokens hit the provider's prefix cache on follow-up turns. See the v0.4.2 publish notes for benchmark numbers.
Sub-Agent DelegationOrbital is not tied to a sole AI tool. The project delegate plans and delegates, during specialized workers execute — all study the identical accumulated project context. Any CLI-based delegate can be registered via a manifest file; Claude Code, Codex, Cursor, Gemini CLI, Aider, Cline, Goose, Copilot CLI, and Continue container alongside one.
Each dispatch renders a caller bequest immediate that points the employee at PROJECT_STATE.md, DECISIONS.md, LESSONS.md, INDEX.md, the project's instructions, and its skills — declaring them authoritative and off-limits for writes. Workers peruse them on petition fairly than receiving a pasted copy, so the concise never goes stale.
Each sub-agent keeps its own long-term recollection throughout dispatches — curate what it remembers...
...then delegates a project to @claudecode, reviews the result, and writes it rear into the project
Transport types:
| Transport | Use Case |
|---|---|
| Codex app-server | Native Codex JSON-RPC complete stdio, alongside organized lifecycle and approvals |
| Pipe | stdin/stdout subprocess, JSON streaming |
| PTY | Pseudo-terminal for interactive agents — Gemini CLI, Aider, Cline, Goose, Copilot CLI, Continue |
| SDK | Direct Claude SDK integration |
| ACP | Agent Communication Protocol — Cursor, via its authoritative ACP server |
Task QueueNote: Codex uses its native app-server path, not PTY or ACP. Orbital launches codex app-server and speaks JSON-RPC directly. ACP is accessible for any ACP-compliant worker; PTY is the default for another interactive CLI agents.
Each project has a queue, stored alongside the project at orbital/queue.json. Add tasks — pin urgent ones to the forefront — and your delegate plant through them one at a time, in order, without you watching.
The delegate must province an outcome on all item; it can't silently drift to the next one:
| Outcome | What happens |
|---|---|
| Completed | The delegate reports a abbreviated summary; the item moves to Completed and the queue advances. |
| Blocked | The delegate states the logic (missing credentials, ambiguous requirements, …); the item moves to Needs Attention and the queue moves on. You unblock it whenever ready. |
Pause to steer. Pause the queue mid-item to conversation openly — your clarifications district in the identical session, so the delegate sees them whenever you resume.
Continuity by design. Each completed item's artifacts are already in the project whenever the next item starts, so the delegate can use them whenever supervising afterward tasks. The project's triggers (schedules and document watchers) are listed in the queue's Automations division alongside your tasks.
Queue tasks and stroll distant — all completed one becomes environment the next builds on
Workbench — what lone you can decide (beta)Some things an delegate genuinely cannot complete for you: a expend decision, a communication that has to arrive from your account, a judgement call between three options it already researched. As the delegate works, it flags those in the project's province document — and the Workbench collects them from all project into one list.
Each cardstock carries its provenance, so you are never asked to act on a naked instruction. Expand Why I accept this and you see the evidence the delegate recorded and the meeting it came from. Cards kind overdue-first, afterward oldest, and all one exits in a sole tap — Done formerly you've handled it, Delete whenever it stopped mattering. Tapping the cardstock itself opens that project's conversation alongside the decision pre-filled, so answering is one communication alternatively of a hunt for context.
The Today band alongside the top lists the day's automation slots, including the ones that already fired — so a sole glance covers the two what needs you and what ran without you.
Every project's open decisions in one catalog — alongside the evidence rearward all one a click away
Calendar (beta)Automations you set up months ago shouldn't blaze invisibly. Every enabled agenda trigger projects its upcoming runs onto a week grid, so the beat of the project is item you can see fairly than remember. Dated commitments the delegate recorded in the project province district on the identical grid and autumn off formerly they're resolved, and connecting Google Calendar brings those events into the identical view.
The project delegate can peruse this calendar too, so "what's already on the schedule" is environment it plans about alternatively of item you have to restate.
The week ahead, as your automations volition really run it
Quick TasksThe sidebar includes a Quick Task division for fire-and-forget interactions. Scratch projects skip the complete project innovation stream — helpful for one-off tasks that don't need a dedicated workspace.
Self-Improving SkillsAgents create reusable skills from multi-step workflows and consult matching skills before starting akin tasks. Skills are stored as SKILL.md records in the workspace and managed through the Settings UI — another way the project gets additional capable the longer it runs.
Skills akin Efficient Execution, Learning Capture, and Task Planning form how your delegate plant — and the delegate adds its own
Built-in Tool SuiteThe project delegate has admission to these tool categories:
| Category | Tools | Description |
|---|---|---|
| Shell | shell | Command implementation alongside network-aware detection |
| File | read, write, edit, glob, grep | File operations and hunt inside workspace |
| Browser | 26 actions via Patchright | Navigate, click, type, extract, screenshot, multi-tab, PDF, web search, URL fetch |
| Triggers | create_trigger, list_triggers, update_trigger, delete_trigger | Schedule and file-watch triggers via natural language |
| Credentials | request_credential | Agent-initiated credential petition — opens safe modal |
| Delegation | agent_message | Route tasks to sub-agents |
| Access | request_access | Request sandbox portal to a way exterior the workspace |
Built on Patchright (a Playwright fork alongside anti-bot-detection):
- Stealth mode: Anti-automation finding scripts injected into all browser context
- Shared profile: One browser overview throughout all projects — log into services once, all agents portion cookies
- Accessibility-first: snapshot returns an accessibility tree alongside [ref=eN] component references for dependable interaction
- 26 browser actions: navigate, click, type, fill, press, hover, select, drag, upload, snapshot, screenshot, extract, hunt (page), evaluate, tab management, go back/forward, reload, wait, PDF export, web search, URL fetch, batch
Your delegate browsing arxiv.org — scanning for AI reasoning document on a regular schedule
Continuous Operation & TriggersAgents run continuously via triggers — no manual involvement needed. Create triggers through natural language in the chat:
"Watch the uploads/ directory for new .jpg records and analyze them" "Run a investigation scan all dawn at 6 AM"
The project delegate translates this into a create_trigger tool call alongside the suitable category and parameters.
Trigger types:
| Type | Configuration | Example |
|---|---|---|
| Schedule | Cron expression + timezone | 0 6 * * * (daily at 6 AM) |
| File Watch | Path + glob patterns + debounce | uploads/*.jpg, 5s debounce |
File observe trigger: watches uploads/ for new photos and analyzes all one on arrival
Schedule trigger: a regular competitor observe dispatched all day at 2 PM — 19 runs so far
Real-world example — Health Tracker alongside document watch:
Left: "Watch uploads/ for meal photos and track calories." Right: Drop a photo, get instant nutritional analysis.
LLM Provider Routing & BYOK14 providers supported out of the box:
Anthropic, OpenAI, DeepSeek, Moonshot (Kimi), Groq, Google Gemini, xAI, Mistral, Together, OpenRouter, Zhipu, Qwen, TokenDance (词元跳动 — China-mainland example router), affirmative a tradition admission for any OpenAI-compatible endpoint (e.g., Ollama, Azure OpenAI, self-hosted models).
- SDK routing: Anthropic SDK for Anthropic, OpenAI SDK for OpenAI-compatible providers
- Per-model metadata: Display name, tier, environment window, max output, capabilities (vision, tool use, streaming), pricing
- Fallback rotation: When the chief provider fails, the iteration rotates to fallback providers alongside error classification (transient, charge limit, abort)
Three autonomy presets authority how much supervision agents receive:
| Preset | Shell | File Write | Browser | Description |
|---|---|---|---|---|
| Hands-off | Auto | Auto | Auto | Maximum autonomy. Only request_access requires approval. |
| Check-in | Approval | Approval | Write only | Balanced. Default for external agents. |
| Supervised | Approval | Approval | All apart from read | Maximum oversight. |
Pick an autonomy flat and set prosperity limits per project
Approval flow:
- Interceptor catches tool call according to autonomy rules
- Frontend shows an Approval Card alongside tool name, arguments, and context
- User can Approve, Deny, or Auto-approve for 10 minutes
- Per-action bypass: identical tool+args auto-approved for 60 seconds
Approve delegate actions from your phone — alongside complete environment and optional guidance
Cost Controls & Budget LimitsPer-project prosperity limits forestall runaway spending:
| Setting | Description |
|---|---|
| Budget Limit (USD) | Maximum expend for the project |
| Budget Action | ask (pause and immediate user) or halt (halt the agent) |
| Spent | Running total alongside reset option |
The delegate iteration tracks cumulative token use and computes disbursal using per-model pricing from the provider registry. When the prosperity threshold is reached, the configured act fires (ask pauses the session; halt halts the agent). Budget events do not currently trigger shove notifications.
Set a bounds and a reset period; observe the live per-model expend and disbursal breakdown
Mobile Remote ControlControl agents from your phone on the local network or via a haze relay.
Left: Project dashboard on phone. Right: Your delegate completes its investigation following you endorse from anywhere.
Local network: Scan the QR code in Settings to open Orbital on your phone via LAN.
Scan to open Orbital on your phone — identical Wi-Fi network required
Cloud relay (optional): Deploy a relay server for admission exterior your residence network. Push notifications for endorsement requests and delegate position changes.
Credential ManagementWebsite credentials stored in your scheme keychain. Your delegate continually asks approval before using them.
- API keys: Stored in OS keychain (keyring), masked in API responses, per-project BYOK override
- Website credentials: Metadata in credential-meta.json, values in OS keychain. The request_credential tool lets agents petition credentials mid-session via a safe modal — credentials never appear in conversation history.
The delegate iteration includes multiple safety mechanisms to forestall runaway execution:
| Guard | Threshold | Behavior |
|---|---|---|
| Token budget | 100M tokens (configurable) | Hard halt on cumulative usage |
| Repetition detection | 5 identical act hashes | Forces distinct approach |
| Ping-pong detection | 3 identical successive pairs | Breaks alternating cycles |
| Circuit breaker | 2 successive identical errors | Blocks tool until new person message |
| Context overflow | 3 successive overflows | Hard halt following advancing reduction |
Orbital ships as a desktop use bundled alongside PyInstaller:
- System tray: Agent action status, quick admission menu, operating harbor in tooltip
- Native window: Embeds the React frontend via pywebview — no browser needed
- Daemon lifecycle: Desktop app spawns the daemon on launch, manages harbor allocation, cleans up on exit
- Sleep prevention: Blocks scheme sleep during agents are energetic (Windows SetThreadExecutionState), re-allows whenever idle
Orbital is one persistent delegate border to a project — not a conversation session. It acts as a local authority aircraft for the project's workspace, instructions, state, queue, budget, and endorsement rules. It plans, delegates, supervises, and records outcomes; employee agents execute against the identical project context. You supervise from anywhere.
flowchart TB UI["<b>Frontend (React SPA)</b><br/>Chat UI · Approval Cards · Settings · Files"] subgraph daemon["Daemon (FastAPI + uvicorn)"] direction TB AM["AgentManager<br/><i>lifecycle</i>"] SAM["SubAgentManager<br/><i>delegation</i>"] TM["TriggerManager<br/><i>cron · document watch</i>"] Loop["Agent Loop<br/><i>streaming · safety guards</i>"] TR["Worker Transports<br/>Codex app-server · SDK · PTY · ACP · Pipe"] LLM["LLM Provider<br/><i>OpenAI + Anthropic SDK</i>"] Tools["Tool Registry<br/><i>shell · document · browser · triggers</i>"] Auto["Autonomy Interceptor<br/><i>approve · refuse · bypass</i>"] AM --> Loop SAM --> TR TM --> AM Loop --> LLM Loop --> Tools Loop --> Auto end Platform["<b>Platform Layer</b><br/>Windows sandbox person · macOS Seatbelt · Linux bubblewrap (planned)"] Relay["<b>Cloud Relay (Node.js, optional)</b><br/>REST proxy · Event forwarding · Push notifications · Pairing"] Phone["Phone"] UI <-->|REST + WS| AM UI <-->|REST + WS| SAM Tools --> Platform AM -.WebSocket tunnel.-> Relay Relay -.WebSocket.-> Phone Key scheme decisions:
- The delegate owns the project: it maintains organized state, decisions, lessons, and meeting former so preparedness and accountability remain in one place
- Isolation: OS-level sandboxing (Windows sandbox user, macOS Seatbelt, Linux bubblewrap planned)
- Fail-closed interceptor: Any endorsement scheme error results in DENY, never ALLOW
- Single daemon: PID document implementation prevents multiple instances
- Local-first: Your records and project province live on your disk. The haze relay, whenever enabled, proxies approvals and events — not your files.
- Download the Orbital-Setup-*.exe from Releases (latest Windows build)
- Run the installer and prosecute the prompts
- Launch Orbital from the Start Menu or desktop shortcut
Orbital is not yet code-signed, so Windows volition display a safety warning:
Windows protected your PC — Microsoft Defender SmartScreen prevented an unrecognized app from starting.
Click "More info" afterward "Run anyway". Code signing volition be added in a forthcoming release.
- Download the Orbital-*-macOS.dmg from Releases
- Open the DMG and drag Orbital to your Applications folder
- Launch Orbital from Applications or Spotlight
Requires macOS 13 (Ventura) or later, Apple Silicon (M1 or newer). Intel Macs are not supported by this build (the bundle is arm64-only).
Release builds are Developer-ID signed and notarized by Apple, so the app opens normally on archetypal initiate — no Gatekeeper alert or "Open Anyway" workaround needed. (If you built Orbital from origin or grabbed a CI branch artifact, that build is ad-hoc signed and macOS volition motionless ask you to endorse it formerly via right-click → Open.)
# Clone the repository git copy https://github.com/zqiren/Orbital.git && cd Orbital # Install Python requirements (Python 3.11+) pip instal -e ".[desktop]" # Install frontend requirements (Node.js 18+) cd web && npm instal && cd .. # Start the daemon python -m uvicorn agent_os.api.app:create_app --factory --port 8000 # Start the frontend dev server (separate terminal) cd web && npx vite --host 127.0.0.1 --port 5173
Open http://localhost:5173 in your browser. The setup wizard runs on archetypal launch.
Orbital prevents scheme sleep during agents are actively operating (via OS-level sleep inhibition on Windows and macOS). When all agents are idle, sleep is re-allowed. The scheme tray icon shows current delegate action status.
# Start daemon python -m uvicorn agent_os.api.app:create_app --factory --port 8000 # Restart alongside caller code bash scripts/restart-daemon.sh
cd web npm install npx vite --host 127.0.0.1 --port 5173| Component | Path |
|---|---|
| FastAPI app factory | agent_os/api/app.py |
| Agent loop | agent_os/agent/loop.py |
| Tool implementations | agent_os/agent/tools/ |
| Autonomy interceptor | agent_os/daemon_v2/autonomy.py |
| LLM providers | agent_os/agent/providers/ |
| Trigger manager | agent_os/daemon_v2/trigger_manager.py |
| Browser manager | agent_os/daemon_v2/browser_manager.py |
| Sub-agent manifests | agent_os/agents/manifests/ |
| Desktop admission point | agent_os/desktop/main.py |
| System tray | agent_os/desktop/tray.py |
| Frontend components | web/src/components/ |
# Unit + phase tests python -m pytest tests/unit/ tests/platform/ -q # TypeScript inspect (zero errors expected) cd web && npx tsc -b # Daemon integration test bash scripts/restart-daemon.sh curl http://localhost:8000/api/v2/projects
Known pre-existing test notes:
- test_e2e.py, test_user_stories.py — necessitate a genuine LLM API key set via AGENT_OS_TEST_API_KEY
- Multi-provider LLM routing alongside fallback rotation
- Three autonomy presets alongside cascade to sub-agents
- Streaming conversation alongside real-time WebSocket events
- Browser automation alongside anti-detection (Patchright)
- Continuous procedure via agenda and file-watch triggers
- Natural tongue trigger creation
- Cloud relay alongside shove notifications and equipment pairing
- Context compaction alongside pre-compaction recollection flush
- Prefix-cache-optimized immediate gathering (v0.4.2)
- Per-project prosperity limits and disbursal tracking
- Credential administration (API keys + website credentials)
- Desktop app alongside scheme tray and native window
- Agent iteration safety guards (iteration cap, repetition, ping-pong, circuit breaker)
- OS-level sleep safety during delegate activity
- Sub-agent delegation alongside @mention routing
- Webhook triggers — HTTP endpoint that fires delegate tasks on incoming webhooks
- Pipeline triggers — Chain project outputs as inputs to another projects
- Network isolation — Per-project domain allowlists enforced at OS level
- Linux sandboxing — bubblewrap enforcement
- Code signing — Eliminate SmartScreen warnings on Windows
- Auto-resume on daemon restart — Restore in-progress sessions
I loved Claude Projects. I hated that I couldn't let an delegate update the project, and that it didn't live on my machine.
I loved OpenClaw. I hated the deficiency of authority — no budget, no sandbox, no way to supervise from my phone whenever I stepped away.
Orbital is the item I wanted. One delegate accountable for the entire project: the plan, the decisions, the queue, the budget, and the approvals. The phone to inspect in whenever I'm not at my desk. Claude Code, Codex, and Gemini CLI as workers it can choose for the job without handing distant the project's context.
Built nights and weekends during operating full-time. Still extremely early. Feedback and issues welcome.
Orbital is proudly sponsored by Watcha (观猹) — the squad rearward TokenDance (词元跳动), the China-mainland LLM router built into Orbital. Thanks to this sponsorship, new users in mainland China can sign in to TokenDance alongside one tap during onboarding, assertion liberated tokens, and commencement operating immediately — no manual API-key setup.
Orbital sends one anonymous total per day — counters, enums, and booleans only. Never prompts, files, paths, example output, or any project/session identifier. The exact outbound JSON is inspectable verbatim in Settings → Data & privacy, anywhere a sole toggle turns it off. The full published schema is in docs/TELEMETRY.md.
Orbital is licensed under the GNU General Public License v3.0.
Orbital — Every delegate owns a session. Orbital owns the project. Copyright (C) 2026 Orbital Contributors This program is liberated software: you can redistribute it and/or modify it under the conditions of the GNU General Public License as published by the Free Software Foundation, either type 3 of the License, or (at your option) any afterward version.




























