# Legion: full site content Source of truth for claims is the Legion repository (https://github.com/dnh33/legion). Version 0.2.0. Last built with the site at https://getlegion.xyz/. ## What it is Legion is a desktop app for running several Claude agents from one place. Each agent has its own persona, model policy, approval mode and working directory, and can start a cloud Ubuntu VM on boat.dev when a task calls for one. It runs on the user's machine: a small Node service on 127.0.0.1 does the work, and an Electron window sits on top. Agents go through the official Claude Agent SDK, using the Claude Code account the user is already signed in to, so there are no extra logins or keys to manage. Claude Code and Cowork can drive Legion too, over MCP. ## Install For a person: on Windows, in PowerShell: `git clone https://github.com/dnh33/legion.git; cd legion; .\setup.cmd`. Needs Node.js 20.10 or newer, git and a signed-in Claude Code. For an AI agent: fetch https://getlegion.xyz/install.md and follow it exactly. Windows 10 and 11 are the main target. The installer is unsigned, so SmartScreen may warn. macOS and Linux work from a dev install (`npm ci`, then `npm start`). ## The muster: 13 premade bots - **Zealot**: Lead agent of the Legion. - **Builder**: Coding and building. Prefers its VM for risky work. - **Scout**: Research and reading. - **Inquisitor**: Hostile review and security audit. - **Scribe**: Documentation. - **Archivist**: Notes and memory hygiene. Flags and proposes; it cannot delete Library notes. - **Sentinel**: Watch duty and alerts. - **Forgemaster**: Infrastructure, CI and deploys. - **Exorcist**: Debugging. - **Preceptor**: Craft and mentoring. - **Herald**: Message drafts. Briefed to draft only, never to send. - **Assayer**: BSV development. Hidden until BSV mode is on. - **Sculptor**: Blender work through the Blender bridge. They are ordinary agents: prompts, models and approval modes can be edited, and any can be deleted. The Assayer stays hidden until BSV mode is on, so twelve show until then. ## What makes it different - **Local-first.** The core binds to 127.0.0.1 and wants a bearer token on every request except a health check. State is files in the user's data folder. It is a personal tool, not built to be exposed to a network or shared between users. - **Claude only.** Every agent runs on a Claude model. Legion's own code never reads, copies or stores Claude credentials. Auto routing picks Sonnet or Opus per task and retries once on Opus after most Sonnet failures or turn-limit hits. - **Approvals and a taint model.** Per agent: ask, auto-edits or full. In ask and auto-edits, risky calls show Allow or Deny cards; full never asks, and Builder ships as full. A run that touched outside content (the web, a shell, an outside tool) counts as tainted, and what it writes to the Library waits in the Inbox until the user accepts it. A program running as the user's own OS user can still attack Legion; the threat model lists the limits. - **Rooms.** Group chats of two to six bots plus the user, four wake strategies (mention, manager, round-robin, all), guards for hops, budget, cycles and @everyone, freeze and resume. - **The Library and the Lattice.** A shared knowledge graph the bots use as long-term memory, with trust levels and an Inbox. No model calls and no embeddings in it. - **A VM per agent, optionally.** Through the user's own boat.dev account; idle VMs stop after 15 minutes by default. - **MCP.** Claude Code connects over HTTP; Cowork and Claude Desktop use a stdio bridge. Nine tools. Agent runs started this way sit under an ask ceiling. The VM tool has no Legion approval card, so the MCP token is a password. ## Status (version 0.2.0) - Built and tested: the core (agents, approvals, rooms, Library and Lattice, the Windows setup script) is covered by automated tests that make no network calls and no real Claude calls. - Built, not yet proven: the Blender bridge (off by default, not tried on a real Blender); BSV mode (read-only today, testnet, off by default; a testnet spend tool, mainnet later and off by default, is being finished and has not been verified with real funds); the installer (unsigned, not yet run on a wide range of Windows machines). - Not here: other model providers (Codex or ChatGPT may come later; a possibility, not a feature); signed installers and prebuilt releases. ## FAQ - **Do I need an API key?** Not for Legion itself, but a Claude subscription or API key is required. By default Legion uses the account Claude Code is signed in to. - **Other models?** No. Claude only. - **Cost?** Legion is MIT licensed. Claude usage is billed under the user's own plan or key. boat.dev VMs are optional, separate, and cost money while they run. - **Safe to give agents a shell?** Depends on the approval mode. Use a VM for untrusted work. See https://github.com/dnh33/legion/blob/main/SECURITY.md. - **Does anything leave the computer?** State is local files. Prompts go to Claude through the Agent SDK, and to boat.dev only if a VM is on for an agent. Tools the user approves can reach further. - **Host it for others?** No. Personal tool for one machine. - **macOS or Linux?** From a dev install. Windows 10 and 11 are primary. ## Links - Repository: https://github.com/dnh33/legion - Licence (MIT): https://github.com/dnh33/legion/blob/main/LICENSE - Security policy: https://github.com/dnh33/legion/blob/main/SECURITY.md - Credits: https://getlegion.xyz/credits.html - Made by @hypercoiner: https://x.com/hypercoiner - Not affiliated with or endorsed by Anthropic or boat.dev.