How Open SWE Improves Developer Productivity with Self-Hosted AI Coding Agents

Open SWE is an open-source framework that deploys self-hosting internal coding agents to automate bug fixes, feature requests, and code reviews through sandboxed execution and deterministic middleware.

Open SWE gives engineering teams a production-ready infrastructure for autonomous coding agents. By combining the Deep Agents framework with isolated cloud sandboxes and a curated toolset, it eliminates repetitive manual steps while maintaining strict safety boundaries.

Composable Deep Agents Architecture

Open SWE builds on the Deep Agents framework via create_deep_agent in agent/server.py. This architecture allows teams to reuse upstream improvements while customizing orchestration, tools, and prompts for specific repositories.

The agent initializes with repository-specific conventions from AGENTS.md and a sandbox description, ensuring the LLM receives proper context from the first turn without expensive discovery calls.

Isolated Cloud Sandboxes for Safe Execution

Every task executes in its own sandbox—a fresh remote Linux VM with full shell access to the target repository but zero production permissions. The sandbox factory in agent/utils/sandbox.py supports multiple providers including Modal, Daytona, LangSmith, Runloop, and local environments.

Key safety features include:

  • Automatic recreation if sandboxes become unreachable
  • Parallel execution via is_thread_active and queue_message_for_thread in agent/webapp.py, allowing multiple threads to run simultaneously with dedicated sandboxes

Curated Toolset for Reliable Agent Actions

Instead of overwhelming the LLM with hundreds of generic APIs, Open SWE provides approximately 15 focused tools covering essential dev-ops actions. Tool definitions reside in agent/tools/:

  • execute – Run shell commands inside the sandbox
  • fetch_url – Convert web pages to markdown
  • commit_and_open_pr – Commit changes and open a draft PR (see agent/tools/commit_and_open_pr.py)
  • linear_comment – Post updates to Linear tickets
  • slack_thread_reply – Respond in originating Slack threads

This focused approach enables faster tool selection reasoning and more reliable output compared to broad tool libraries.

Context Engineering with AGENTS.md

When webhooks arrive from Slack, Linear, or GitHub, the agent receives a rich prompt combining repository-level rules from AGENTS.md with full issue or thread history. The process_* functions in agent/webapp.py handle these webhooks, building deterministic thread IDs via generate_thread_id_from_issue for Linear integration.

This pre-hydrated context eliminates the need for the model to discover information through additional tool calls, significantly reducing latency and token consumption.

Deterministic Orchestration via Middleware

Open SWE employs two orchestration layers to ensure predictable execution:

Subagents: The Deep Agents task tool spawns child agents, enabling parallel subtasks such as linting while the main agent writes code.

Deterministic Middleware: Middleware in agent/middleware/*.py wraps every model step:

  • check_message_queue_before_model – Pulls queued messages (e.g., follow-up Slack replies) into the next model turn
  • open_pr_if_needed – Guarantees PR creation even if the LLM forgets to call the tool (see agent/middleware/open_pr.py)
  • ToolErrorMiddleware – Catches tool failures and surfaces them as structured messages (see agent/middleware/tool_error_handler.py)

These hooks ensure workflows complete successfully regardless of LLM inconsistencies.

Multi-Platform Invocation Surfaces

Open SWE integrates with three primary entry points, all implemented in agent/webapp.py:

Slack: Mention @openswe in any thread. The process_slack_mention function resolves the repository via get_slack_repo_config and launches a thread-specific run.

Linear: Comment @openswe on a ticket; the webhook builds a deterministic thread ID from the issue ID, preserving state across follow-up comments.

GitHub: Tag @openswe in PR comments; the agent reacts, fetches new comments via helpers in agent/utils/github_comments.py, and updates the same branch.

Because LangGraph thread IDs are reused across platforms, state persists across follow-up messages, allowing developers to ask clarification questions without restarting the entire run.

Automatic PR Creation and Feedback Loops

When the agent completes its task, it invokes commit_and_open_pr from agent/tools/commit_and_open_pr.py, which:

  1. Commits all changes inside the sandbox
  2. Pushes to a new branch on the target repository
  3. Opens a draft PR and returns the URL

The open_pr_if_needed middleware in agent/middleware/open_pr.py provides a hard safety net, ensuring PR creation occurs even if the LLM neglects to call the tool. The PR URL is automatically posted back to the originating platform via linear_comment, slack_thread_reply, or GitHub reactions, completing the feedback loop.

Extensibility Through Plug-in Architecture

Open SWE supports customization through environment variables and modular components:

Sandbox Providers: Set SANDBOX_TYPE to switch between Modal, Daytona, LangSmith, Runloop, or local sandboxes via the factory in agent/utils/sandbox.py.

Custom Middleware: Add new hooks to agent/middleware/__init__.py to enforce organizational policies such as code-owner approvals or extra CI checks.

Tool Customization: Extend the curated toolset by adding new modules to agent/tools/ following existing patterns.

This plug-and-play design allows teams to adapt Open SWE to existing infrastructure without forking the core codebase.

Practical Code Examples

Trigger the Agent from Slack


# Slack webhook payload arrives → process_slack_mention()

# (simplified excerpt from agent/webapp.py)

event_data = {
    "channel_id": "C123456",
    "thread_ts": "1698234567.000200",
    "event_ts": "1698234567.001000",
    "user_id": "U7890",
    "text": "@openswe implement feature X",
    "bot_user_id": "B1111",
}
repo_cfg = await get_slack_repo_config(event_data["text"], event_data["channel_id"], event_data["thread_ts"])

# Launch a LangGraph thread that runs the Deep Agent

await process_slack_mention(event_data, repo_cfg)

The function extracts the repo, creates a deterministic thread ID (generate_thread_id_from_slack_thread), builds a prompt that includes the Slack conversation, and starts a run (langgraph_client.runs.create).

Create a Sandbox (Default LangSmith)

from agent.utils.sandbox import create_sandbox

sandbox = create_sandbox()        # SANDBOX_TYPE defaults to "langsmith"

# sandbox now implements SandboxBackendProtocol (e.g., execute, upload, download)

Switch to a different provider simply by setting SANDBOX_TYPE=modal and the factory will call create_modal_sandbox (see agent/utils/sandbox.py).

Commit and Open a PR from Inside the Agent


# Inside the agent's tool implementation (agent/tools/commit_and_open_pr.py)

await commit_and_open_pr(
    branch_name="openswe/feature-123",
    commit_message="Implement feature 123",
    repo_config={"owner": "myorg", "name": "myrepo"},
    sandbox_backend=sandbox,
)

The tool runs git add ., creates a commit, pushes the branch, and calls the GitHub API to open a draft PR.

Middleware that Forces CI Before PR Merge


# agent/middleware/ci_check.py

class CICheckMiddleware:
    async def before_model(self, state, **kwargs):
        # Run CI inside the sandbox; block if failures

        result = await state["sandbox"].execute("make test")
        if result.exit_code != 0:
            raise Exception("CI failed – aborting PR creation")
        return state

Add it to the middleware stack in agent/server.py to guarantee every run passes CI before a PR is opened.

Summary

Open SWE improves developer productivity by automating the entire coding task lifecycle while maintaining strict safety and reliability standards. Key takeaways include:

  • Self-hosting architecture gives teams full control over their internal coding agents without vendor lock-in
  • Isolated sandboxes ensure safe execution with automatic recreation and support for multiple providers (Modal, Daytona, LangSmith, Runloop)
  • Deterministic middleware guarantees critical actions like PR creation occur even when LLMs behave unpredictably
  • Curated toolsets reduce reasoning complexity and improve reliability compared to generic API access
  • Multi-platform integration allows developers to trigger agents directly from Slack, Linear, or GitHub while preserving conversation state across follow-ups

By eliminating manual PR creation, reducing context-switching between tools, and enforcing safety boundaries through sandboxed execution, Open SWE enables engineering teams to resolve issues and ship features significantly faster.

Frequently Asked Questions

What is Open SWE and how does it differ from other coding agents?

Open SWE is an open-source framework for self-hosting internal coding agents that integrates with existing engineering workflows through Slack, Linear, and GitHub. Unlike managed services or generic AI coding tools, Open SWE provides deterministic middleware, isolated sandbox environments, and full control over the agent's toolset and orchestration, making it suitable for enterprise security requirements.

How does Open SWE ensure code safety and prevent production incidents?

Open SWE executes all tasks in isolated cloud sandboxes—fresh Linux VMs with no production permissions—using the factory pattern in agent/utils/sandbox.py. If a sandbox becomes unreachable, it is automatically recreated. Additionally, deterministic middleware in agent/middleware/open_pr.py ensures that pull requests are only created after successful execution, and custom middleware can enforce CI checks before any code reaches the repository.

Can Open SWE integrate with existing project management tools?

Yes, Open SWE provides native webhook handlers for Slack, Linear, and GitHub in agent/webapp.py. The system preserves conversation state across platforms using deterministic thread IDs, allowing developers to trigger agents via @openswe mentions in Slack threads, Linear comments, or GitHub PR discussions. Each integration automatically feeds context into the agent's prompt, including full ticket history and repository-specific conventions from AGENTS.md.

Is it possible to customize the tools and middleware in Open SWE?

Absolutely. Open SWE uses a pluggable architecture where you can set SANDBOX_TYPE to switch between Modal, Daytona, LangSmith, Runloop, or local sandboxes via the factory in agent/utils/sandbox.py. New tools can be added to agent/tools/ following existing patterns, and custom middleware can be registered in agent/middleware/__init__.py to enforce organizational policies such as code-owner approvals or extra CI checks.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →