Astron talks to its model through a single server-side abstraction, keeps tools in a registry, and persists every run. Swapping a provider or adding a tool does not mean rewriting the product.
A tool declares its schema, its risk level, and its handler. The runtime does the rest: streaming the activity, persisting the call, and enforcing approval when the risk is high.
web_search: {
risk: 'low',
schema: {
name: 'web_search',
description: 'Search the public web through DuckDuckGo.',
parameters: {
type: 'object',
properties: { query: { type: 'string' } },
required: ['query'],
},
},
async handler(args, ctx) {
const res = await duckduckgoSearch(args.query);
if (!res.ok) return { ok: false, error: res.reason };
return { ok: true, data: res, sources: res.results };
},
}Architecture
Server-sent events carry text, activity, tool calls, sources, artifacts, approvals, completion, and errors as separate typed events, so the interface never has to guess run state from prose.
Users, workspaces, memberships, conversations, messages, agent runs, run steps, tool calls, approvals, search sources, artifacts, files, repositories, connectors, credentials, tasks, automations, memories, usage events, and audit logs.
Every request resolves the session server-side and verifies workspace membership before any query runs. Hidden interface controls are never treated as security.
SSRF protection on page fetching, path traversal prevention on archives, secret redaction in logs, tool allowlists, and confirmation for sensitive actions.
An abort signal travels from the browser through the route handler to the upstream request, and the partial answer is preserved.
Create a workspace, name your coworker, and give it something you have been putting off.
Get Astron