The protocol + runtime for agentic work.
Vibe-coding speed. Production-grade safety.
Point Floom at your OpenAPI spec or GitHub repo. Every surface your users can reach, generated from the same source of truth.
This is Floom's uuid app running in this page. Every call hits the real POST /api/run.
A clever prompt is not a product. Real apps need auth, secrets, run history, rate limits, observability, and durable state. Building all that yourself is weeks of plumbing.
Six production-grade layers, one config. Ingest a spec, get MCP + HTTP + CLI + Web + Share, each with auth, secrets, runs, and a renderer. Deploy is docker run.
MIT licensed, single binary, 30-second self-host. No lock-in, no SaaS dependency for your critical path. Run it on a $5 VPS, a laptop, or a cluster.
Each one has a real endpoint, a real renderer, and a real test. No placeholders.
Point at OpenAPI URL or GitHub repo. Floom resolves operations, infers schemas, builds the app.
Sandboxed execution. Sync + job queue for >30s runs. Per-app concurrency caps. Retries + DLQ.
Encrypted at rest, scoped per app + per creator. Never in logs. Rotatable without redeploy.
Per-session state. KV, file-scoped, app-scoped. Survives container restart. TTL-aware.
Every call logged: inputs, outputs, duration, client, status. Full replay + diff across runs.
Auto-generated form from schema. Custom renderers for bespoke UIs. Mobile-first by default.
Paste into Claude Desktop → Settings → Developer → Edit Config. That's it.
Single image. Single command. No extra services required for a development instance.
Fork the repo, mount your own apps directory, override the renderer. Full guide.
Read the self-host guide →Helm chart for K8s, Postgres replacement for SQLite, Redis for the job queue. Cloud tier handles it.
Floom Cloud →Six Cloud-tier additions in the next two quarters. Vote on what lands first.
Floom grew out of shipping seven weekend projects and realizing the same plumbing kept getting rewritten. Open source from day one; MIT licensed because lock-in is a bug.
The protocol + runtime for agentic work. MIT licensed.
The protocol + runtime for agentic work.
Vibe-coding speed. Production-grade safety.
Prompt ≠ product. Real apps need auth, secrets, runs, rate limits.
Six layers, one config. Ingest → MCP + HTTP + CLI + Web + Share.
MIT licensed. Single binary. 30-second self-host.
OpenAPI → app.
Sandboxed, queued.
Encrypted at rest.
Per-session KV.
Every call logged.
Auto form from schema.
Browse the Store, or jump back into Studio.
Full landing sections (Why · Layers · Apps · MCP · Self-host · Roadmap · Built-by · Footer) render identically below the fold for both anon and logged-in users. Logged-in dashboard tiles above replace the Proof row.