LIFEHUBBER
Choose theme

AI Resources

Paperclip

GitHub stars: 98.8K GitHub forks: 16.7K Declared license: MIT: MIT Last pushed October 8, 2026: Pushed today
Stats from GitHub

Paperclip is a self-hosted server and dashboard for coordinating AI agents through assigned tasks, company goals, budgets, and approvals.

Agents bring their own models and runtimes. Paperclip tracks their work and scheduled runs through adapters for tools such as Claude Code, Codex, and HTTP agents. Use this as a first read, not a recommendation. Open the original project before trusting details like terms, limits, privacy, cost, setup, or safety.

What it is

A task system around existing agents

Issues connect assigned work to a company, project, goal, and parent task, with comments, documents, and attachments kept alongside it.

Why it stands out

Work and spending in the same dashboard

Operators can follow scheduled runs, review pending decisions, and inspect recorded costs by company, agent, or project.

Availability

Open-source and self-hosted

The current installation guide requires Node.js 24.11 or newer. A common local setup uses embedded PostgreSQL; agent runtimes and authentication need their own setup.

Why it matters

What makes it useful

When several agents contribute to one project, a task needs an owner and a place to leave partial progress. Paperclip's issue guide describes checking out work before starting, recording progress in comments, and identifying blockers so another person or agent can pick up the thread.

Notable points

What stands out

The cost guide separates monthly company and agent budgets from lifetime project spending caps. The current README qualifies enforcement: it uses recorded spend, and reporting delays or work already running can delay a stop. A dashboard budget is therefore not a guarantee that a provider invoice will stay below that amount.

Before using

What to review

The Codex adapter guide says a managed agent home inherits the host's Codex login by default; a configured per-agent API key takes precedence. That choice changes which account the agent uses.

The repository publishes security advisories. An April advisory reports inherited Gmail-connector access through a Paperclip-managed Codex runtime for version 2026.403.0, and a July advisory reports a local-trusted deployment attack for versions below 0.3.1. Neither lists a patched version; these reports alone do not establish the status of a current installation.

The v2026.1001.0 release changes native and legacy agent execution to full-auto defaults when explicit restrictive settings are absent. Paperclip's controller approvals are separate from runtime tool permissions. The current Codex guide scopes its approval and sandbox bypass to the classic CLI engine; the ACP path keeps its writable-workspace sandbox with network access by default. Review the actual engine and permission configuration before scheduling work.

Check the server's retained task records, attachments, runtime credentials and outputs, who can access them, and your backup and deletion arrangements. Local installation data persists after the command exits. The publisher distinguishes trusted-local loopback use from authenticated network deployments; choose the authentication and network boundary for the intended users.

The README says first-party usage telemetry is enabled by default and documents opt-out settings, including PAPERCLIP_TELEMETRY_DISABLED=1 or DO_NOT_TRACK=1. Its description excludes issue content, prompts and secrets from those events; that is the publisher's stated boundary. Separately configured OpenTelemetry trace export is an opt-in observability path.

Review what scheduled heartbeats and adapter tools can do with the supplied accounts. Company decisions, spend records and a successful connection probe do not by themselves restrict every file, command or provider action.

Company export packages are not full-instance backups. The export guide's history omissions need a separate retention plan; the README also warns that package exports can retain plain environment values and local paths even when referenced secrets are omitted.

Reader fit

Who may find it relevant

People coordinating several agents on continuing projects may find the task, schedule, cost and decision records useful. Operating it requires configuring the server and each agent runtime. Someone who only needs one interactive assistant has less need for company and scheduled-task administration. Builders connecting a Codex runtime can use the adapter's Test Environment check for the command, working directory, authentication, and a hello probe before scheduling runs. This checks the connection; a successful probe does not show that an assigned task has been completed.

Editorial note

Why LifeHubber lists it

We include Paperclip for people coordinating continuing agent work because it makes recovery from a stranded run part of the tracked task. Recovery actions preserve the original assignee and record the evidence, recovery owner, wake policy and resolution; unsafe or exhausted retries are escalated to the board. That gives operators a place to follow what happened to interrupted work instead of losing that explanation in a silent reassignment.

Source links

Source materials

Reader note

Before relying on this entry

LifeHubber lists entries to help readers inspect AI projects, not to endorse them or prove they are safe, suitable, accurate, maintained, or right for a specific use. We do not verify every entry in depth. Before relying on anything listed, review the original materials, terms, privacy practices, limits, and risks that matter for your situation.

Advertisements

Advertisements

For project maintainers

Listed here? You can use the badge.

If you maintain a project with a current LifeHubber listing, you may add the optional “Listed on LifeHubber AI Resources” badge to its README, docs, or website. No introduction or permission request is needed.

See what’s moving