Local-first
The core binds to 127.0.0.1 and wants a bearer token on every request except a health check. State lives as files in your own data folder. Legion is a personal tool: it is not built to be exposed to a network or shared between users.
Install on Windows PowerShell
git clone https://github.com/dnh33/legion.git; cd legion; .\setup.cmd Hand it to an AI agent paste this
Install Legion on this computer. Fetch https://getlegion.xyz/install.md and follow it exactly. Check the requirements first and tell me what you are about to run, and ask me before anything it does not list. When it is installed, check that it starts and tell me what you saw. For a coding agent that can run commands on your machine. It reads install.md (also as llms.txt), checks your setup, and is told to ask you before it installs.
Windows 10 and 11 are the main target. The installer is unsigned, so SmartScreen may warn. macOS and Linux work from a dev install. Needs Node.js 20.10+, git and a Claude Code login.
A desktop app that runs several Claude agents side by side, with approval cards, rooms and a shared memory. MIT licensed, and young: version 0.2.0.
What it is
Legion is a desktop app for running several Claude agents from one place. Each agent has its own persona, model policy, approval mode and working directory, and can start a cloud Ubuntu VM on boat.dev when a task calls for one. Claude Code and Cowork can drive it too, over MCP.
127.0.0.1 does the work. An Electron window sits on top.
Step 1
Twelve wait in the rail, thirteen once BSV mode is on. Each has its own persona, model policy and approval mode.
Step 2
Tool calls stream into the thread as they happen. Several bots can work at once, and Zealot can hand work to the others.
Step 3
Per bot, choose ask, auto-edits or full. In the first two a risky call stops at a card you answer with A or D; full never asks, and Builder ships as full.
Step 4
Notes a bot writes after touching the web, a shell or an outside tool wait in your Inbox until you accept them.
The muster
Each ships with its own persona and an animated bust. They are ordinary agents: edit their prompts, models and approval modes like any other, or delete the ones you do not want (all but Zealot). The Assayer stays hidden until BSV mode is on, so you see twelve until then.
Lead
Lead agent of the Legion.
Its bust is the Relic, the mascot. It leans in while you type, thinks, hacks, waits for your approval, celebrates, winces at errors and sleeps when nothing happens.
Coding
Coding and building. Prefers its VM for risky work.
Research
Research and reading.
Review
Hostile review and security audit.
Docs
Documentation.
Memory
Notes and memory hygiene. Flags and proposes; it cannot delete Library notes.
Watch
Watch duty and alerts.
Infra
Infrastructure, CI and deploys.
Debugging
Debugging.
Craft
Craft and mentoring.
Drafts
Message drafts. Briefed to draft only, never to send.
BSV
BSV development. Hidden until BSV mode is on.
3D
Blender work through the Blender bridge.
Why it differs
The core binds to 127.0.0.1 and wants a bearer token on every request except a health check. State lives as files in your own data folder. Legion is a personal tool: it is not built to be exposed to a network or shared between users.
Every agent runs on a Claude model through the Claude Agent SDK. Legion's own code never reads, copies or stores your Claude credentials. Auto routing picks Sonnet or Opus per task, and retries once on Opus after most Sonnet failures or turn-limit hits. Other providers are not supported.
Per agent, choose ask, auto-edits or full. In ask and auto-edits modes, risky calls show up as Allow or Deny cards in the thread; full never asks. A run that touched outside content (the web, a shell, an outside tool) counts as tainted, and what it writes to the Library waits in your Inbox until you accept it. A bot that reads config.json cannot approve its own request: the admin secret exists only in memory.
Limits are written down: a program running as your own user can still attack Legion. Read the threat model.
A room is a group chat of two to six bots plus you. A message wakes bots by one of four strategies (mention, manager, round-robin, all). Guards for hops, budget, cycles and @everyone stop loops, and you can freeze and resume a room. Bots can propose a room, but creating one waits for an Allow card only you can answer.
The Lattice is a shared knowledge graph the bots use as long-term memory: search, neighbours, paths, recall, lint, Markdown vault import and export. The Library adds trust levels and the Inbox. There are no model calls and no embeddings in any of it.
Optional, through your own boat.dev account. An agent can start, use and stop its own Ubuntu VM, and you get a live preview and an Open desktop link. Idle VMs stop after 15 minutes by default. Without a key, agents simply work locally.
Claude Code connects over HTTP; Cowork and Claude Desktop use a stdio bridge. Nine tools cover listing agents and models, creating an agent, running and continuing tasks, checking status, cancelling, driving a VM and listing recent tasks. Agent runs started this way sit under an ask ceiling, and the MCP token cannot approve cards or change settings. The VM tool is the exception: it has no Legion card, so treat the token like a password.
claude mcp add --transport http legion http://127.0.0.1:4747/mcp \
--header "Authorization: Bearer <token>" The app
Real screenshots of Legion 0.2.0, not mock-ups: different bots, moods, cards and both themes. The tasks, notes and room are demo content, not a real workspace. Nothing is edited. Click any picture to open it full size.
The lead hands work to the others, and a room puts several bots in one conversation with you.
Each bust reacts to what its bot is doing: celebrating a finished task, wincing at a failure, standing by.
In ask and auto-edits modes, risky calls stop at a card only you can answer. The bust turns amber and waits. Full mode never asks, and Builder ships as full.
Bots keep long-term notes in a graph. What they write after touching outside content waits for you.
An optional switch, off by default and fixed to testnet. It reveals the Assayer and loads a read-only knowledge pack.
Hooking it up to Claude Code, picking a model, running commands from the composer.
The amber "boat.dev key missing" card in the right-hand panel is what the Computer card says until you add a key. The model picker lists the models of the account the capture ran under. Both are shown as the app shows them. The capture ran on a different local port from the default 4747, so the port in a snippet may differ from the one on this page.
Status
Legion is young. Here is what is done, what is built but not yet proven, and what it does not do.
The core is built and covered by automated tests: agents, approvals, rooms, the Library and Lattice, and the Windows setup script. The test suite makes no network calls and no real Claude calls, so it says nothing about how your own setup behaves.
Other model providers: Codex or ChatGPT may be added later, which is a possibility and not a feature. Signed installers and prebuilt releases: today you install from source.
Instructions
claude, then /login. A Claude subscription or an API key is required..cmd files.If you use a coding agent that can run commands, give it the address of this site and ask it to install Legion. It will find install.md, a plain-Markdown procedure written for agents: check that Node, git and Claude Code are present and ask you to confirm you are signed in, clone the source, show what setup would do, ask you before installing, then check that Legion starts and report what it saw. It is told not to touch your credentials, not to use admin rights and to stop and ask when a step fails. The same text is at llms.txt and llms-full.txt.
Open PowerShell and run the command from the top of this page. It clones the source and starts setup:
git clone https://github.com/dnh33/legion.git; cd legion; .\setup.cmd Setup installs Legion for your user in %LOCALAPPDATA%\Programs\Legion. No admin rights are needed. It copies the source there, installs dependencies, builds the app and adds Legion shortcuts to the Desktop and Start menu. If you already have the source, double-click setup.cmd or run:
powershell -ExecutionPolicy Bypass -File scripts\setup.ps1 -InstallDir "C:\Some\Folder" installs somewhere else.-DryRun shows what would happen without changing anything.-Yes asks no questions: it stops a running Legion, installs and launches.Launch from the shortcuts, or start-legion.cmd in the install folder. uninstall.cmd in the install folder removes the install and the shortcuts and keeps your data in %USERPROFILE%\.legion; add /purge to delete that too.
These work from a dev install:
git clone https://github.com/dnh33/legion.git
cd legion
npm ci
npm start # builds, then opens the desktop app npm run core runs the headless core alone, which is enough for the MCP integration.
On first launch Legion creates config.json in its data folder with a fresh auth token. Open Doctor in the title bar, or type /doctor. It checks your Node version, config, Claude sign-in, boat.dev key and workspace folder, and tells you how to fix anything that fails. For agent VMs, create a boat.dev API key and put it in config.json as "boat": { "apiKey": "…" }, or set BOAT_API_KEY.
FAQ
Not for Legion itself, but you do need a Claude subscription or an API key. By default Legion uses whichever account Claude Code is signed in to on your machine. If you would rather pay by API key, switch the setting and provide one.
No. Every agent runs on a Claude model through the Claude Agent SDK. Other providers are a possible later addition, not a feature.
Legion itself is MIT licensed. Your Claude usage is billed under your own plan or API key, and Anthropic's terms say what your plan allows. VMs are optional, belong to boat.dev and cost money while they run; Legion stops idle ones after a set time.
It depends on the approval mode you pick. ask puts risky tool calls behind a card, full removes the prompts for that agent. Agents can run code on your machine, so use a VM for untrusted work. Legion's own checks do not stop a program that already runs as your user. The security policy lists the limits.
Legion's state is files in your data folder. Your prompts go to Claude through the Agent SDK, as they would from Claude Code, and to boat.dev only if you turn on a VM for an agent. Tools you approve can reach further: a web fetch, or an MCP server you add, talks to whatever it is pointed at.
No. It is a personal tool for your own machine. Do not put it behind a shared endpoint or pass your subscription through it to someone else.
An optional toggle, off by default and fixed to testnet. It shows the Assayer bot, loads a read-only BSV knowledge pack and can run a read-only status check of a wallet on your computer. Legion has no spend tool in this version.
From a dev install, yes. Windows 10 and 11 are the primary target and the only place the setup script runs.