# QM: features, protocols, quickstart

## TL;DR

QM is a self-hosted agent harness for organisations, published by the yc-software GitHub organisation under the MIT license. Each person and each Slack or web room gets its own scoped memory, files and sandbox, and Pi, OpenCode, Codex or Claude Code can drive the core. It includes swarms of worker sessions. It suits small companies deploying one shared agent.

## Key facts

| Field | Value |
| --- | --- |
| Type | Platform |
| Languages / SDKs | TypeScript |
| License | MIT |
| Pricing model | Open source, free |
| Orchestration pattern | Swarm |
| GitHub stars | 15,291 (as of 2026-09-30) |
| GitHub forks | 1,888 |
| Last push | 2026-09-30 |
| Latest release | v0.1.13 |
| Repository | [yc-software/qm](https://github.com/yc-software/qm) |
| Website | [x.com](https://x.com/qm__dev) |
| Documentation | [github.com](https://github.com/yc-software/qm/blob/HEAD/docs/getting-started.md) |
| Last verified | 2026-09-30 |

## Key features

- Personal and shared scopes: each person and each room has its own memory, files, keychain view, permissions, crons, web apps and durable sandbox, and the same identity works in Slack and on the web. ([source](https://github.com/yc-software/qm/blob/HEAD/README.md))
- A choice of agent harness and model per deployment: Pi, OpenCode, Codex and Claude Code all run on the same core. ([source](https://github.com/yc-software/qm/blob/HEAD/README.md))
- Swarms: a session can spawn a pool of worker sessions through POST /v1/swarm, each with its own durable transcript, blank computer and JSON context, and members exchange durable messages addressed to chosen peers or all. ([source](https://github.com/yc-software/qm/blob/HEAD/docs/swarms.md))
- Persistent subagent sessions: a `sessions` tool opens child sessions for delegated tasks, sends attributed messages between related sessions and returns results to the parent; a session tree allows at most ten pending or running runs. ([source](https://github.com/yc-software/qm/blob/HEAD/docs/persistent-subagent-sessions.md))
- Org-wide security posture (Strict, Auto or Dangerous): Strict pauses every harness tool call for human approval, and a predeclared command policy applies under every posture. ([source](https://github.com/yc-software/qm/blob/HEAD/README.md))
- Administrators register HTTP MCP servers, with shared or per-user credentials, and control which tools agents may call. ([source](https://github.com/yc-software/qm/blob/HEAD/docs/mcp-connectors.md))
- Background work: crons, watches and inbound webhooks run while users are away. ([source](https://github.com/yc-software/qm/blob/HEAD/README.md))
- Deployment directory and `qm` CLI: `qm init` creates a deployment for Fly.io or AWS in the operator's own account and generates a deploy skill for a coding agent to follow. ([source](https://github.com/yc-software/qm/blob/HEAD/docs/getting-started.md))

## Architecture and orchestration pattern

Pattern: Swarm.

QM has a headless core (Fastify on Node, run as TypeScript) that handles the HTTP API, identity, policy and scheduling, and an agent loop that calls one of the supported harnesses. Postgres holds sessions, memory and the queue; without `SESSION_STORE=postgres` sessions live in process memory and are lost on restart. Each scope has a durable sandbox reached through a small fixed tool surface whose main tool is `execute`. The web UI, admin panel and portal are separate services, and Slack is an optional in-process plugin.

There are two ways to use more than one agent. Swarms treat ordinary QM sessions as members: the initiating session is the root, workers get their own blank computers, transcripts and character JSON, and the swarm API lets them discover peers and send durable messages to chosen audiences. Persistent subagent sessions let an agent open child sessions for delegated tasks and message related sessions; the docs mark that feature as off by default behind a feature flag. Many people working with one shared agent in a channel is the other sense of the word multiplayer in the README.

Memory is a built-in notebook scoped per person or room, which can be routed to external memory providers by scope. Everything company-specific lives in a deployment directory that the CLI validates and deploys.

### Human in the loop

Under the Strict posture every harness tool call pauses for human approval; the default Auto posture blocks private-network access and can use a content screener, and Dangerous removes posture-based approval gates. A predeclared command policy with approval rules and hard denials for actions such as recursive deletes applies under all three. Swarm worker transcripts are read-only for ordinary messages in the web UI, but the requesting human can allow or deny their pending approvals there. Flagged external content needs release approval.

### Harnesses it can drive

- Claude Code ([evidence](https://github.com/yc-software/qm/blob/HEAD/README.md))
- Codex ([evidence](https://github.com/yc-software/qm/blob/HEAD/README.md))
- OpenCode ([evidence](https://github.com/yc-software/qm/blob/HEAD/README.md))

## Protocols

| Protocol | Support | Evidence | Note |
| --- | --- | --- | --- |
| MCP | Yes (checked 2026-09-30) | [link](https://github.com/yc-software/qm/blob/HEAD/docs/mcp-connectors.md) | Client: administrators register HTTP MCP servers through the admin API, which sets the outbound destination and the tools available to agents, with shared or per-user credentials; no MCP server mode was found. |
| A2A | Unknown (checked 2026-09-30) | — | Not found in README or docs pages read; GitHub code search for a2a matched only unrelated strings in UI and lockfile files, and agent2agent returned nothing. |
| AG-UI | Unknown (checked 2026-09-30) | — | Not found in README or docs; GitHub code search for ag-ui matched only a package-lock file in the web UI, and QM is not in the AG-UI README integration list. |

## Best for

- A small company that wants one shared agent in Slack and on the web, with per-person and per-room scopes and admin-set security posture.
- Choosing among Claude Code, Codex, OpenCode and Pi as the harness behind the same deployment. ([shortlist](https://multiagentguide.top/best/coding-agents.md))
- Self-hosting an agent platform in your own Fly.io or AWS account with your own model keys. ([shortlist](https://multiagentguide.top/best/self-hosted-local.md))
- Fanning a task out to a pool of worker sessions that coordinate through durable messages (swarms).

## Not for

- Teams that want to accept pull requests to the core as code; CONTRIBUTING asks for human-written proposals in adrs/ instead.
- Anyone needing a stable 1.x release; the latest tagged release is v0.1.13 and the swarm and subagent features are gated or newly documented.
- Environments without Postgres and a sandbox backend, which swarms require.

## Quickstart

```sh
npm exec --yes --package=@yc-software/qm@latest -- qm init . --org <slug> --target <fly-or-aws>
```

Install not yet verified by this site.

```bash
# In an empty, organization-owned private repository (Node.js >= 24.15)
npm exec --yes --package=@yc-software/qm@latest -- \
  qm init . --org <slug> --target <fly-or-aws>
npm install

# qm init writes deployment.md and .codex/skills/deploy-qm/.
# Hand that skill to a coding agent; it confirms the cloud account and billing,
# sets up web sign-in and connectors, deploys and runs live checks.

# Validate and plan from a source checkout when you customise QM itself
node cli/bin/qm.ts check --config <deployment-dir>/qm.config.jsonc
node cli/bin/qm.ts plan --config <deployment-dir>/qm.config.jsonc --build-from .
```

### Common pitfalls

- Requires Node.js 24.15 or newer (package engines and README badge).
- Set `DATABASE_URL` and `SESSION_STORE=postgres`; otherwise sessions are kept in memory and vanish on restart.
- Choose Fly.io or AWS before `qm init`; changing provider means initialising a new empty directory. Each deployment runs in your own cloud account and no deployment CI is generated.
- Sign-in defaults to a built-in email one-time-link broker that needs a Resend key or SMTP credentials.
- Swarms need Postgres session and run stores plus a sandbox backend (`SANDBOX_RESOURCES_ENABLED=true`) and are unavailable with mixed memory/Postgres stores. Persistent subagents and responsive_spine are off until enabled per actor scope.
- Per-user MCP credentials need `CONNECTOR_SECRET_KEY` for encrypted keychain storage.

Official quickstart: https://github.com/yc-software/qm/blob/HEAD/docs/getting-started.md

## Pros

- Scoped memory, files, sandbox and permissions per person and per room, so one deployment can serve a whole team without sharing everything. ([source](https://github.com/yc-software/qm/blob/HEAD/README.md))
- The harness is swappable between Pi, OpenCode, Codex and Claude Code without changing the deployment. ([source](https://github.com/yc-software/qm/blob/HEAD/README.md))
- Swarm workers and persistent subagent sessions are durable, keep separate transcripts and enforce budgets and scope authorization. ([source](https://github.com/yc-software/qm/blob/HEAD/docs/swarms.md))
- An org picks a security posture with a Strict mode that pauses every tool call for approval. ([source](https://github.com/yc-software/qm/blob/HEAD/README.md))
- MIT-licensed and runs in the operator's own cloud account with the operator's own model keys. ([source](https://github.com/yc-software/qm/blob/HEAD/README.md))

## Cons

- The latest tagged release is v0.1.13, so the project is pre-1.0. ([source](https://github.com/yc-software/qm/releases/tag/v0.1.13))
- Persistent subagent sessions and responsive_spine default to off and are enabled per actor scope through feature flags. ([source](https://github.com/yc-software/qm/blob/HEAD/docs/persistent-subagent-sessions.md))
- Swarms are unavailable with mixed memory and Postgres stores and need a configured sandbox backend. ([source](https://github.com/yc-software/qm/blob/HEAD/docs/swarms.md))
- CONTRIBUTING asks for feature proposals as human-written text in adrs/ rather than code pull requests. ([source](https://github.com/yc-software/qm/blob/HEAD/CONTRIBUTING.md))
- The README lists Fly.io and AWS as deployment targets and says the repository has no production deployment workflow. ([source](https://github.com/yc-software/qm/blob/HEAD/docs/getting-started.md))

## Alternatives

- [OpenClaw](https://multiagentguide.top/tools/openclaw.md)
- [Paperclip](https://multiagentguide.top/tools/paperclip.md)
- [Hermes Agent](https://multiagentguide.top/tools/hermes-agent.md)
- [LobeHub](https://multiagentguide.top/tools/lobehub.md)
- [Buzz](https://multiagentguide.top/tools/buzz.md)

## FAQ

### Does QM support MCP?

Yes as a client. Administrators register HTTP MCP servers and choose shared or per-user credentials. No MCP server mode was found in the sources read.

### Which coding harnesses can drive QM?

The README says Pi, OpenCode, Codex and Claude Code all drive the same core, so a deployment is not tied to one vendor.

### What does multiplayer mean in QM?

Several people share one agent in Slack channels, group messages and projects while each person also keeps an isolated personal workspace. Running several agents is a separate feature: swarms of worker sessions and persistent subagent sessions.

### Is QM free?

The code is MIT-licensed and you run it in your own cloud account with your own model keys. The README also points to a third-party hosted version that is not run by the project, and no paid hosted product from the project was found.

## Sources

- [QM repository README](https://github.com/yc-software/qm/blob/HEAD/README.md)
- [Docs: Getting started (deploy QM)](https://github.com/yc-software/qm/blob/HEAD/docs/getting-started.md)
- [Docs: Agent swarms](https://github.com/yc-software/qm/blob/HEAD/docs/swarms.md)
- [Docs: Persistent subagent sessions](https://github.com/yc-software/qm/blob/HEAD/docs/persistent-subagent-sessions.md)
- [Docs: MCP connector credentials](https://github.com/yc-software/qm/blob/HEAD/docs/mcp-connectors.md)
- [CONTRIBUTING.md](https://github.com/yc-software/qm/blob/HEAD/CONTRIBUTING.md)
- [Release v0.1.13](https://github.com/yc-software/qm/releases/tag/v0.1.13)
- [QM X account (GitHub homepage field)](https://x.com/qm__dev)

## Unknown fields

protocols.a2a and protocols.agui: searched README, docs pages and GitHub code search; no documented support. homepage is the X account listed in GitHub's homepage field; the project has no separate website or docs site, so docs_url points to the repository's getting-started doc.

Corrections or removal requests: support@multiagentguide.top

---

Data as of 2026-09-30. Not affiliated with listed projects. HTML version: https://multiagentguide.top/tools/qm
