Why I built Poka — an open-source, local-first alternative to cloud AI agents with governed tool approvals, multi-model support, and a sandboxed browser runtime.
tags:
As autonomous AI agents continue to evolve, most of the industry is heading in one clear direction: closed cloud platforms.
Services like OpenAI Operator, Claude Cowork, Manus, and Meta Muse promise seamless agentic workflows. But they also require you to surrender:
- Your Data Sovereignty: Conversation history, sensitive files, and execution logs live on remote corporate servers.
- Your API Keys & Secrets: Credential management is completely opaque.
- Execution Safety: Agents often execute arbitrary shell actions or web tasks in environments you cannot inspect or audit. I wanted something different: a sovereign, inspectable, self-hosted personal AI agent workspace where you retain absolute ownership over your data, credentials, and execution environment. That is why I created Poka.
🌟 What is Poka?
Poka is an open-source, local-first personal AI agent platform built with Next.js 15 (React 19), FastAPI, SQLite, and Docker/Playwright.
It combines multi-model conversations, an action gateway with human-in-the-loop approvals, external app connectors, and an optional sandboxed desktop runtime into one unified workspace.
💡 The Core Pillars
1. 🛡️ Governed Action Gateway (Deny-by-Default)
The biggest hazard of autonomous agents is letting them run unvetted terminal commands, script executions, or file modifications.
Poka implements a governed action gateway:
- Low-risk operations (workspace reads, web search) execute automatically and are recorded in a tamper-resistant audit trail.
-
High-risk operations (shell execution, writing files, sending OS keystrokes) automatically pause execution and prompt for explicit user approval.
You can inspect the exact payload, command, or script before the agent is permitted to run it.
### 2. 🔒 Absolute Privacy & Local-First Storage - All conversations, assistant personas, artifacts, and logs reside in a local SQLite database (
~/.poka). - Provider API keys and secret tokens are encrypted with 256-bit Fernet keys at rest.
- Browser authentication uses server-enforced
HttpOnlysession cookies — no master tokens are ever exposed to the frontend JavaScript runtime. ### 3. 🤖 Universal Multi-Model Support (Cloud & Local) Poka isn't tied to any single AI provider. You can switch between models on the fly: - Cloud Providers: OpenAI, Anthropic Claude, DeepSeek, Groq, Mistral.
- Local Inference Engines: Connect directly to Ollama, vLLM, or LM Studio via OpenAI-compatible endpoints with zero external network leakage.
- Multiple protocols supported: standard
/chat/completions, streaming/responses, and direct prediction endpoints. ### 4. 🖥️ Sandboxed Computer Automation Need the agent to navigate the web or automate desktop workflows? - Docker / Playwright Sandbox: Runs an assistant-scoped container with a 30 FPS display stream, virtual input, read-only root filesystems, and dropped Linux capabilities.
-
Windows Desktop Agent: Includes a dedicated agent script for remote PowerShell execution and native Windows GUI automation with DPAPI token security.
### 5. 🔌 Ecosystem Connectors & Keyless Search -
Keyless Web Search: Real-time web browsing via a built-in You.com MCP adapter (
/search <query>) that works out-of-the-box without requiring an API key.

Top comments (0)