decocms

studio

Built by decocms โ€ข 354 stars

What is studio?

Open-source control plane for your AI agents. Connect tools, hire agents, track every token and dollar

How to use studio?

1. Install a compatible MCP client (like Claude Desktop). 2. Open your configuration settings. 3. Add studio using the following command: npx @modelcontextprotocol/studio 4. Restart the client and verify the new tools are active.
๐Ÿ›ก๏ธ Scoped (Restricted)
npx @modelcontextprotocol/studio --scope restricted
๐Ÿ”“ Unrestricted Access
npx @modelcontextprotocol/studio

Key Features

Native MCP Protocol Support
Real-time Tool Activation & Execution
Verified High-performance Implementation
Secure Resource & Context Handling

Optimized Use Cases

Extending AI models with custom local capabilities
Automating system workflows via natural language
Connecting external data sources to LLM context windows

studio FAQ

Q

Is studio safe?

Yes, studio follows the standardized Model Context Protocol security patterns and only executes tools with explicit user-granted permissions.

Q

Is studio up to date?

studio is currently active in the registry with 354 stars on GitHub, indicating its reliability and community support.

Q

Are there any limits for studio?

Usage limits depend on the specific implementation of the MCP server and your system resources. Refer to the official documentation below for technical details.

Official Documentation

View on GitHub
<h1 align="center">deco Studio</h1> <p align="center"> <em>Open-source ยท TypeScript-first ยท Deploy anywhere</em><br/><br/> <b>Open-source private AI workspace for organizations.</b> </p> <p align="center"> <a href="https://docs.decocms.com/">Docs</a> ยท <a href="https://decocms.com/discord">Discord</a> ยท <a href="https://decocms.com/studio">decocms.com/studio</a> </p>

TL;DR: Your team needs a secure internal vibecoding platform. You just found it. Configure agents with team context. Connect private MCPs once โ€” share capabilities, not credentials. Keep the model layer interchangeable. Roll out across the organization with SSO, RBAC, audit logs, and cost controls โ€” all through one MCP endpoint. Local-first. Self-host or use the cloud.


What is deco Studio?

Studio packages the infrastructure behind an internal AI rollout: model routing, MCP authentication, agent configuration, SSO, RBAC, audit logs, and usage accounting. Your teams get chat. You keep control.

Under the hood it's one control plane for your AI agents โ€” one MCP endpoint for all your agents, tools, and models. Agents package context, tools, and policy into something you publish to the organization. Connections give them governed access to your systems โ€” GitHub, Slack, Postgres, Sentry, anything that speaks MCP โ€” with tokens stored in an encrypted vault. Models stay interchangeable: OpenRouter or direct providers, chosen per agent and per tool.

Start with one team. Standardize approved models, tools, and context. Expand across the organization without copying secrets or rebuilding the platform. Install locally and it stays private; sync to the cloud for remote access, team roles, and shared billing.

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                             Clients                             โ”‚
โ”‚            Cursor ยท Claude ยท VS Code ยท Custom Agents            โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                            โ”‚
                            โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                           DECO STUDIO                           โ”‚
โ”‚      Agents ยท Connections ยท Models ยท Vault ยท Observability      โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                            โ”‚
                            โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                       Tools & MCP Servers                       โ”‚
โ”‚       GitHub ยท Slack ยท Postgres ยท OpenRouter ยท Your APIs        โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Quick Start

bunx decostudio

Or clone and run from source:

git clone https://github.com/decocms/studio.git
bun install
bun run dev

runs at http://localhost:4000 (client) with API routes proxied to the Bun server


What you get

Agents

Package context, tools, and policy into an agent. Define instructions, add skills and files, grant approved MCP access, choose a model policy, then publish the agent to the organization. Each agent is its own MCP endpoint โ€” callable from Cursor, Claude Desktop, your own code, or another agent. Agents compose, and every action is tracked with cost attribution.

Connections

Connect private systems once, securely. Register MCP servers at the organization level through a web UI with one-click OAuth โ€” no JSON configs. Tokens live in the encrypted vault, and you grant tool-level access by organization, role, or agent. Share MCP capabilities โ€” not credentials.

As tool surfaces grow, Studio exposes Virtual MCPs โ€” one endpoint, different strategies for which tools to surface:

  • Full-context: expose everything (simple, deterministic, good for small toolsets)
  • Smart selection: narrow the toolset before execution
  • Code execution: load tools on demand in a sandbox

Models

Keep the AI layer interchangeable. Use OpenRouter or connect Anthropic, OpenAI, Google, or any compatible provider directly โ€” the best model for each agent and tool, behind one router. For coding work, engineers can link their own Claude Code or Codex session and use the subscription already authenticated on their machine.

Projects

Projects bring agents and connections together around a goal. The project's UI adapts to what's inside โ€” add a content agent and a CMS connection, the sidebar shows content management; add an analytics agent and a database, it shows dashboards and queries. The UI you see is the UI that's relevant for operating that project.

Observability

Account for every model and tool call. Trace the user, agent, model, tools, latency, errors, tokens, and cost for every thread. Break usage down by agent, connection, organization, or teammate โ€” one dashboard.

From your desktop to your org

Localbunx decostudio on your desktop. Embedded PostgreSQL. Private.
CloudLog in to studio.decocms.com. Control local projects from any browser.
TeamInvite people. SSO and role-based access. Shared connections. Cost attribution.
EnterpriseSelf-hosted. Organization isolation, tool-scoped API keys, audit logs. Your infra, your rules.

Core Capabilities

CapabilityWhat it does
AgentsPackage context, tools, and policy into publishable agents with cost attribution
ConnectionsRoute MCP traffic through one governed endpoint with auth, proxy, and encrypted token vault
ModelsInterchangeable AI layer โ€” OpenRouter or direct providers, model policy per agent
ProjectsOrganize agents and connections around goals with an adaptive UI
Virtual MCPsCompose and expose governed toolsets as new MCP endpoints
ObservabilityTraces, costs, errors, and latency per user, agent, and connection โ€” one dashboard
Access ControlSSO + RBAC via Better Auth โ€” OAuth 2.1 and tool-scoped API keys per workspace/project
Multi-tenancyOrganization/project isolation for config, credentials, policies, and audit logs
Event BusPub/sub between connections with scheduled/cron delivery and at-least-once guarantees
BindingsCapability contracts so tools target interfaces, not specific implementations
StoreDiscover and install agents, tools, and templates

Define Tools

Type-safe, audited, observable, callable via MCP.

import { z } from "zod";
import { defineTool } from "~/core/define-tool";

export const CONNECTION_CREATE = defineTool({
  name: "CONNECTION_CREATE",
  description: "Create a new MCP connection",
  inputSchema: z.object({
    name: z.string(),
    connection: z.object({
      type: z.enum(["HTTP", "SSE", "WebSocket"]),
      url: z.string().url(),
      token: z.string().optional(),
    }),
  }),
  outputSchema: z.object({
    id: z.string(),
    scope: z.enum(["workspace", "project"]),
  }),
  handler: async (input, ctx) => {
    await ctx.access.check();
    const conn = await ctx.storage.connections.create({
      projectId: ctx.project?.id ?? null,
      ...input,
      createdById: ctx.auth.user!.id,
    });
    return { id: conn.id, scope: conn.projectId ? "project" : "workspace" };
  },
});

Every tool call gets input/output validation, access control, audit logging, and OpenTelemetry traces automatically.


Project Structure

โ”œโ”€โ”€ apps/
โ”‚   โ”œโ”€โ”€ mesh/                # Full-stack deco Studio (Hono API + Vite/React)
โ”‚   โ”‚   โ”œโ”€โ”€ src/
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ api/         # Hono HTTP + MCP proxy routes
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ auth/        # Better Auth (OAuth + API keys)
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ core/        # StudioContext, AccessControl, defineTool
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ tools/       # Built-in MCP management tools
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ storage/     # Kysely DB adapters
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ event-bus/   # Pub/sub event delivery system
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ encryption/  # Token vault & credential management
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ observability/  # OpenTelemetry tracing & metrics
โ”‚   โ”‚   โ”‚   โ””โ”€โ”€ web/         # React 19 admin UI
โ”‚   โ”‚   โ””โ”€โ”€ migrations/      # Kysely database migrations
โ”‚   โ””โ”€โ”€ docs/                # Astro documentation site
โ”‚
โ””โ”€โ”€ packages/
    โ”œโ”€โ”€ bindings/            # Core MCP bindings and connection abstractions
    โ”œโ”€โ”€ runtime/             # MCP proxy, OAuth, and runtime utilities
    โ”œโ”€โ”€ ui/                  # Shared React components (shadcn-based)
    โ”œโ”€โ”€ std/                 # Isomorphic async primitives (sleep, retry, backoff)
    โ”œโ”€โ”€ sandbox/             # Isolated per-agent containerized environments
    โ”œโ”€โ”€ mesh-sdk/            # SDK for external apps integrating with Studio
    โ””โ”€โ”€ create-deco/         # Project scaffolding (npm create deco)

Development

bun install          # Install dependencies
bun run dev          # Run dev server (client + API)
bun test             # Run tests
bun run check        # Type check
bun run lint         # Lint
bun run fmt          # Format

Studio commands (from apps/mesh/)

bun run dev:client     # Vite dev server (port 4000)
bun run dev:server     # Hono server with hot reload
bun run migrate        # Run database migrations

Worktrees

dev:worktree routes http://<WORKTREE_SLUG>.localhost via Caddy โ€” useful for running multiple workspaces without port conflicts.

# One-time setup
brew install caddy && caddy start

# Start
WORKTREE_SLUG=my-feature bun run dev:worktree

# Conductor adapter (sets WORKTREE_SLUG from CONDUCTOR_WORKSPACE_NAME)
bun run dev:conductor

Deploy Anywhere

# Docker (embedded PostgreSQL)
docker compose -f deploy/docker-compose/docker-compose.yml up

# Docker (PostgreSQL)
docker compose -f deploy/docker-compose/docker-compose.postgres.yml up

# Bun
bun run build:client && bun run build:server && bun run start

# Kubernetes (Helm)
helm install deco-studio oci://ghcr.io/decocms/chart-deco-studio --version <version> -n deco-studio --create-namespace

No vendor lock-in. Runs on Docker, Kubernetes, AWS, GCP, or local runtimes.

What you need to run it

TierFootprint
LaptopNothing. One process, embedded PostgreSQL.
DockerThe published image. Bring PostgreSQL or use the embedded one.
Production (Helm)PostgreSQL you bring, plus optional NATS (event bus wake-up), ClickHouse + OTel Collector (traces and analytics), and the sandbox operator (isolated agent environments on Kubernetes). Your identity provider, your model keys, your storage.

Production topology

graph TB
    clients["MCP clients โ€” Cursor ยท Claude ยท VS Code ยท your code"]

    clients -->|"one MCP endpoint ยท SSO ยท RBAC ยท audit"| api

    subgraph k8s ["Kubernetes (Helm)"]
        api["Studio API + Admin UI"]
        api --> sandbox["Agent sandboxes<br/>(sandbox-operator)"]
        api -->|"notify"| nats["NATS"]
        api -->|"traces ยท costs"| otel["OTel Collector"]
        nats -->|"wake"| worker["Workers<br/>event bus ยท schedules"]
        otel --> ch[("ClickHouse")]
    end

    pg[("PostgreSQL")]
    api --> pg
    worker --> pg

    subgraph upstream ["Models & tools"]
        models["Anthropic ยท OpenAI<br/>OpenRouter ยท Ollama"]
        mcps["GitHub ยท Slack ยท Postgres<br/>your MCP servers"]
    end

    api -->|"model routing ยท vaulted credentials"| upstream

Every box is optional except Studio and PostgreSQL โ€” start small, turn on the rest as the rollout grows.


Tech Stack

LayerTech
RuntimeBun / Node
LanguageTypeScript + Zod
FrameworkHono (API) + Vite + React 19
DatabaseKysely โ†’ embedded PostgreSQL / PostgreSQL
AuthBetter Auth (OAuth 2.1 + API keys)
ObservabilityOpenTelemetry
UIReact 19 + Tailwind v4 + shadcn
ProtocolModel Context Protocol (MCP)

Roadmap

  • Agent marketplace โ€” discover, hire, and compose agents
  • Declarative planning engine
  • Cost analytics and spend caps
  • Remote access from any browser
  • Live tracing debugger
  • Workflow orchestration with guardrails

License

MIT โ€” see LICENSE.md.

Questions? builders@decocms.com


Contributing

bun run fmt      # Format
bun run lint     # Lint
bun test         # Test

See AGENTS.md for coding guidelines.


<div align="center"> <sub>Made with care by the <a href="https://decocms.com">deco</a> community</sub> </div>

Global Ranking

-
Trust ScoreMCPHub Index

Based on codebase health & activity.

Manual Config

{ "mcpServers": { "studio": { "command": "npx", "args": ["studio"] } } }