# Legion: full site content Source of truth for claims is the Legion repository (https://github.com/dnh33/legion). Version 0.2.5-h. Site: https://getlegion.xyz/. ## What it is Legion is a desktop app for running several Claude agents from one place. Each agent has its own persona, model policy, approval mode and working directory, and can start a cloud Ubuntu VM on boat.dev when a task calls for one. It runs on the user's machine: a small Node service on 127.0.0.1 does the work, and an Electron window sits on top. Agents go through the official Claude Agent SDK, using the Claude sign-in the user already has or an API key. Claude Code and Cowork can drive Legion too, over MCP. ## Install For a person, one line. Windows, in PowerShell: `irm https://getlegion.xyz | iex`. macOS and Linux, in a terminal: `curl -fsSL https://getlegion.xyz | sh`. The Windows script downloads the latest release from GitHub Releases over HTTPS, checks it against the release's SHA-256 and runs Legion's setup; the package is not code-signed, so SmartScreen may warn. The macOS and Linux script needs git and Node.js 22.12 or newer, builds Legion from the release tag in `~/.local/share/legion` and adds a `legion` command in `~/.local/bin`; no sudo. Read the scripts first: https://getlegion.xyz/install.ps1 and https://getlegion.xyz/install.sh. Manual download: https://github.com/dnh33/legion/releases/latest. From source, on Windows, in PowerShell: `git clone https://github.com/dnh33/legion.git; cd legion; .\setup.cmd`. Needs git, Node.js 22.12 or newer (setup can fetch it after asking) and a Claude sign-in or API key. A prebuilt package for Windows x64 needs no Node, no Git and no npm; the command above is the source route. For an AI agent: fetch https://getlegion.xyz/install.md and follow it exactly. Windows 10 and 11 are the main target. The installer is unsigned, so SmartScreen may warn. macOS and Linux work from a dev install (`npm ci`, then `npm start`). ## The muster: 13 premade bots - **Zealot**: Lead agent. Plans the task and hands the work to the other bots. - **Builder**: Coding and building. Prefers its VM for risky work. - **Scout**: Research and reading. - **Inquisitor**: Hostile review and security audit. - **Scribe**: Documentation. - **Archivist**: Notes and memory hygiene. Flags and proposes; it cannot delete Library notes. - **Sentinel**: Watch duty: checks what you point it at and reports. Scheduled runs are planned. - **Forgemaster**: Infrastructure, CI and deploys. - **Exorcist**: Debugging. - **Preceptor**: Craft and mentoring. - **Herald**: Drafts messages. It can read the web, and it never sends or submits forms. - **Assayer**: BSV development. Hidden until BSV mode is on. - **Sculptor**: Blender work: headless on your computer first, in a cloud VM when you want it isolated. They are ordinary agents: prompts, models and approval modes can be edited, and any except Zealot can be deleted. The Assayer stays hidden until BSV mode is on, so twelve show until then. ## What makes it different - **Local-first.** The core answers only your own computer: it checks where each request came from and needs a secret token on every request except a health check. Your work is plain files in your data folder. It is a personal tool, not built to sit on a network or be shared between people. - **Built around Claude.** Every agent runs on a Claude model by default, the full-featured path. OpenRouter ships and is on by default, and any other OpenAI-compatible endpoint can be added, with Legion's own tools, not Claude Code's. Legion's own code never reads, copies or stores Claude credentials. Auto routing picks Sonnet or Opus per task and retries once on Opus after most Sonnet failures or turn-limit hits. - **Approvals and a taint model.** Per agent: ask, auto-edits or full. In ask and auto-edits, risky calls show Allow or Deny cards; full never asks, and Builder ships as full. A run that touched outside content (the web, a shell, an outside tool) counts as tainted, and what it writes to the Library waits in the Inbox until the user accepts it. A program running as the user's own OS user can still attack Legion; the threat model lists the limits. - **Rooms.** Group chats of two to six bots plus the user, four wake strategies (mention, manager, round-robin, all), guards for hops, budget, cycles and @everyone, freeze and resume. - **The Library and the Lattice.** A shared knowledge graph the bots use as long-term memory, with trust levels and an Inbox. No model calls and no embeddings in it. - **Projects.** Group tasks, rooms, notes and agents per project, with project instructions; notes can be scoped to a project; only the user controls a project; MCP has read-only project tools. The project board (work items per project in columns, agent access, project notes and a board digest carried into each agent run) is built and on by default. - **For developers and contributors.** The source includes a test harness with stand-ins for the model, the wallet and Blender. It is a development tool, not part of what Legion does for the user. - **Open source.** Legion is open source under the Apache 2.0 licence. - **Blender (the Sculptor, built).** The Sculptor writes Python scripts that run in Blender. Three places: this computer, headless (default when Blender is found; needs Blender 4.2 or newer; Legion checks the script, but that is a filter, not a sandbox, so every script shows an approval card first); a cloud VM on boat.dev (the isolated option); or the user's own open Blender through an add-on (official Blender MCP add-on needs Blender 5.1 or newer; the community add-on works with older versions; Legion backs the scene up before the first live script). If Blender is missing, Settings can fetch one pinned official portable Blender (5.2.2 LTS, Windows x64, about 386 MB, SHA-256 checked before unpacking, only after the user presses the button and approves a card showing the address, size and hash) or link to blender.org/download; Legion never installs Blender silently. A one-time chooser asks where scripts should run. Optional and off by default: both add-on backends at once, and Poly Haven asset downloads (an approval card per download, the run becomes tainted, files stay in the task folder, each asset source off until enabled). Output: allow-listed file types within size limits; .blend files are quarantined, not opened automatically. Not done: a tested sculpt-brush recipe. - **Updates only on request.** An in-app updater checks GitHub releases on launch and every twelve hours, downloads only after a click, installs only when Legion is idle, and rolls back if the new version does not start. The manifest is signed and checked against a public key built into the app; the repository is public. Installing automatically when idle is off by default. A release that fails its first start is offered again after a week, or straight away with Retry. - **A VM per agent, optionally.** Through the user's own boat.dev account; idle VMs stop after 15 minutes by default. - **MCP.** Claude Code connects over HTTP; Cowork and Claude Desktop use a stdio bridge. A small set of tools, including read-only project tools. Agent runs started this way sit under an ask ceiling. The VM tool has no Legion approval card, so the MCP token is a password. ## Status (version 0.2.5-h) - Built and tested: agents, approvals and the taint model, rooms, Projects, the Library and Lattice, MCP, the local-only core, the read-only BSV pack, and OpenRouter. Covered by automated tests that make no network calls and no real Claude calls. - Built and covered by tests against stand-ins, never run end to end on a real machine: the browser tool (Edge or Chrome already on the PC, off by default) and the BSV spend tool. Built and tested: the project board (on by default), Blender, the cloud VM and the in-app updater. - Built: the BSV spend tool (testnet and mainnet capability; mainnet hard-off behind a natively confirmed switch; a spend needs an Arm and the wallet's own prompt); Blender. OpenAI, Ollama, LM Studio and vLLM are built into the provider core but shown in the app as next release. - Next: live runs of the BSV spend tool and the browser tool on a real Windows PC. Then a knowledge-graph audit button, scheduled Sentinel runs (nothing runs on a timer today), and an optional lighter package. Signed installers are planned, with no release assigned. Command-line agents such as Codex are not offered: their own tools would run outside Legion's approval cards. ## FAQ - **Do I need an API key?** Not for Legion itself. A Claude sign-in (subscription) or an API key is required. By default Legion uses the account Claude Code is signed in to. - **Other models?** For OpenAI-compatible models, yes: an agent can run on an endpoint you configure. OpenRouter ships and is on by default; OpenAI, Ollama, LM Studio and vLLM are built into the core but shown in the app as next release; any custom URL works now. Claude stays the default and the full-featured path. A provider agent gets Legion's own tools, not Claude Code's, plus the same Library and working memory. A continued task summarises older turns rather than resuming a native session. Command-line agents are not offered. - **BSV mode?** Optional, off by default: the Assayer, a read-only pack of 163 notes and 727 links, and wallet status. The spend tool is built. - **Cost?** Legion is Apache-2.0 licensed. Claude usage is billed under the user's own plan or key. boat.dev VMs are optional, separate, and cost money while they run. - **What stops an agent running a shell command?** It depends on the approval mode. Use a VM for untrusted work. See https://github.com/dnh33/legion/blob/main/SECURITY.md. - **Does anything leave the computer?** State is local files. Prompts go to Claude through the Agent SDK, and to boat.dev only if a VM is on for an agent. Tools the user approves can reach further. - **Host it for others?** No. Personal tool for one machine. - **macOS or Linux?** From a dev install. Windows 10 and 11 are primary. ## Links - Repository: https://github.com/dnh33/legion - Licence (Apache-2.0): https://github.com/dnh33/legion/blob/main/LICENSE - Security policy: https://github.com/dnh33/legion/blob/main/SECURITY.md - Credits: https://getlegion.xyz/credits.html - Made by @hypercoiner: https://x.com/hypercoiner - Not affiliated with or endorsed by Anthropic or boat.dev.