Skip to content

Repository files navigation

orchestra.ai

Open-Source Visual Node-Based Engine for Building AI Automations & Multi-Agent Workflows

License: MIT Next.js Phase Status Tests CI/CD


orchestra.ai Visual Node Engine Canvas Screenshot

🌐 Live Demo

Try orchestra.ai live on Vercel: https://orchestra-ai.vercel.app
> Note: Shared demo environment. Register your own free account to create, test, and save custom workflows.


📌 Overview

orchestra.ai is an open-source visual workflow automation platform purpose-built for AI agents and multi-node orchestration. It combines the visual drag-and-drop simplicity of tools like Zapier and n8n with an engine built specifically for LLMs, sandboxed code execution, and real-time DAG execution tracking.

Connect user inputs, AI models, custom scripts, external webhooks, and structured outputs seamlessly on a unified interactive canvas.


✨ Feature Highlights

Feature Description
🎨 Visual Canvas Editor Interactive drag-and-drop workflow builder powered by React Flow, complete with custom dynamic nodes, snap-to-grid edge connectors, zoom/pan controls, and minimap navigation.
🧩 5 Core Node Types
  • ⚡ Trigger Node: Initiates DAG execution via manual user invocation (inbound webhook endpoints planned).
  • 🧠 AI Engine Node: Google Gemini support active today with BYOK AES-256 encryption; OpenAI & Anthropic planned (schema-ready).
  • 💻 Data Processor Node: Executes custom JavaScript transformation snippets in a safe, sandboxed environment.
  • 🌐 Integration Node: Executes HTTP REST calls (GET/POST/PUT/DELETE) with dynamic variable template substitution.
  • 🖥️ Output Node: Captures and renders final structured output payloads and execution summaries.
🔐 BYOK Architecture "Bring Your Own Key" system ensuring user API keys are encrypted at rest using industry-standard AES-256 GCM before database storage.
⚡ Background Orchestration Asynchronous, resilient job queue architecture powered by Inngest to prevent serverless execution timeouts during multi-LLM chaining.
🛡️ Sandboxed Code Execution Isolated JavaScript evaluation powered by isolated-vm with strict execution timeouts, memory limits, and zero host environment access.
📊 Live Execution Tracking Real-time visual node status feedback (Pending, Running, Success, Failed), topological DAG sorting, and automatic cycle detection.

⚖️ Comparison Matrix

Feature / Capability orchestra.ai n8n Zapier
AI-Native DAG Chaining 🟢 Purpose-built LLM context flow 🟡 Added via AI node extensions 🔴 Basic linear step actions
Open Source 🟢 MIT License 🟡 Fair-code / Sustainable License 🔴 Proprietary
BYOK Pricing Model 🟢 Bring Your Own Key (Zero Markup) 🟡 Self-host or Tiered Cloud 🔴 Task-based Tiered Billing
Background Execution Queue 🟢 Inngest Async Queues 🟢 Bull / Redis Workers 🟢 Proprietary Task Queue
Sandboxed Execution 🟢 isolated-vm (Memory & Time Capped) 🟢 Standard Node VM 🟡 Limited Code By Zapier

🛡️ Security Architecture & Disclosure

  • BYOK API Key Encryption: User LLM provider keys are encrypted at rest using AES-256-GCM with unique initialization vectors (iv) before database storage. Keys are decrypted strictly in-memory during node execution steps.
  • Sandboxed Code Execution: JavaScript transformation scripts inside Data Processor nodes run in an isolated V8 isolated-vm isolate with strict resource bounds (128MB memory ceiling, 5-second execution timeout, and zero access to host environment or Node.js global APIs).
  • Responsible Vulnerability Disclosure: If you discover a security vulnerability, please report it privately via GitHub Security Advisories rather than opening a public issue.

🛠️ Tech Stack

Category Technologies
Framework & Language Next.js 14 (App Router), TypeScript (Strict Mode)
Styling & UI Tailwind CSS, Shadcn UI, Lucide Icons, Framer Motion
Workflow & Canvas React Flow 11, Zustand (State Management)
Database & ORM PostgreSQL (Neon), Prisma ORM 5
Async Architecture & Security Inngest (Background Queue), isolated-vm (Sandbox), AES-256 Encryption
Testing Suite Vitest (Unit & Integration), Playwright (End-to-End)

🚀 Getting Started

Follow these steps to set up orchestra.ai locally on your machine.

1. Clone & Install Dependencies

git clone https://github.com/junaidahmeddev/orchestra-ai.git
cd orchestra-ai
npm install

2. Environment Variables Setup

Create a .env.local file in the project root:

cp .env.example .env.local

Configure the required environment variables inside .env.local:

# ── Database (Neon PostgreSQL) ────────────────────────────────
DATABASE_URL="postgresql://user:password@ep-host.neon.tech/neondb?sslmode=require"

# ── NextAuth Authentication ───────────────────────────────────
# Generate with: openssl rand -base64 32
NEXTAUTH_SECRET="your-nextauth-secret-key"
NEXTAUTH_URL="http://localhost:3000"

# ── AES-256 Encryption Key (32-byte hex) ─────────────────────
# Generate with: openssl rand -hex 32
ENCRYPTION_KEY="your-32-byte-hex-encryption-key"

# ── Inngest (Background Job Queue) ────────────────────────────
INNGEST_EVENT_KEY="your-inngest-event-key"
INNGEST_SIGNING_KEY="your-inngest-signing-key"

3. Database Migration

Push the Prisma schema to your PostgreSQL database:

npx prisma db push

(Optional) Launch Prisma Studio to inspect your database models:

npm run prisma:studio

4. Run Development Server

Standard Single Terminal Command:

npm run dev

Open http://localhost:3000 with your browser to explore orchestra.ai.

Dual Terminal Command (Recommended for Inngest Background Jobs):

  • Terminal 1 (Next.js Application):
    npm run dev
  • Terminal 2 (Inngest Local Dev Server):
    npx inngest-cli@latest dev
    Access the Inngest Developer Dashboard at http://127.0.0.1:8288.

🧪 Testing Suite (Phase 8 Summary)

We maintain a rigorous 3-layer automated testing architecture ensuring stability across DAG calculations, database authorization, and user workflows:

  • 🔬 Unit Tests (Vitest): Validates pure graph execution algorithms (topologicalSort), AES-256 encryption/decryption, and memory-capped isolated-vm sandbox evaluation.
  • 🔌 Integration Tests (Vitest + Prisma Mocks): Verifies backend API endpoints, credential authentication routes (/api/auth/register), and workflow CRUD operations.
  • 🎭 End-to-End Tests (Playwright): Tests real browser interactions including login, canvas creation, dynamic node addition, connector edge linking, and state persistence.

Test Runner Commands

# Run all Unit & Integration tests (Vitest)
npm test

# Run Unit tests in interactive watch mode
npm run test:watch

# Run Playwright End-to-End tests
npm run test:e2e

📁 Architecture & Project Structure

orchestra-ai/
├── prisma/
│   └── schema.prisma             # PostgreSQL schema & Prisma models
├── src/
│   ├── app/                      # Next.js 14 App Router
│   │   ├── (auth)/               # Login & Registration pages
│   │   ├── (dashboard)/          # Workflow listing & Canvas editor
│   │   └── api/                  # REST API Endpoints & Route Handlers
│   │       ├── auth/             # Registration & NextAuth handlers
│   │       ├── api-keys/         # Encrypted LLM key endpoints
│   │       ├── inngest/          # Inngest background queue webhook
│   │       └── workflows/        # Workflow CRUD & Execution handlers
│   ├── components/               # UI & Visual Canvas Components
│   │   ├── canvas/               # React Flow canvas, node palette & sidebars
│   │   │   └── nodes/            # 5 Custom Node React components
│   │   └── ui/                   # Shadcn UI reusable components
│   ├── lib/                      # Core Engine & Utilities
│   │   ├── db.ts                 # Prisma client singleton
│   │   ├── encryption.ts         # AES-256 GCM encryption helpers
│   │   └── engine/               # DAG Execution Engine
│   │       ├── topologicalSort.ts # Cycle detection & execution ordering
│   │       ├── executor.ts       # Main graph runner logic
│   │       └── nodeHandlers/     # Individual node logic handlers
│   ├── store/                    # Zustand canvas state management
│   └── types/                    # Shared TypeScript interfaces
├── e2e/                          # Playwright End-to-End specs
├── scripts/                      # Utility & encryption test scripts
├── package.json
└── README.md

🗺️ Development Roadmap

  • Phase 0 — Project Scaffold & Next.js Setup
  • Phase 1 — Database Design & Prisma Schema (Neon PostgreSQL)
  • Phase 2 — Authentication System (NextAuth.js Credentials Provider)
  • Phase 3 — Workflow CRUD Engine (API Routes & Security Guards)
  • Phase 4 — Visual Canvas Editor (React Flow + Zustand State Slices)
  • Phase 5 — DAG Execution Engine (Topological Sorting & Cycle Detection)
  • Phase 6 — Inngest Background Execution & isolated-vm Sandbox
  • Phase 7 — Encrypted API Key Storage (AES-256) & Gemini Integration
  • Phase 8 — Comprehensive Testing Suite (30 Unit/Integration Tests + Playwright E2E)
  • Phase 9 — Production Deployment & Documentation (Vercel + Neon + Inngest)
  • Phase 10 — Pre-Built Workflow Templates & Multi-LLM Extensions
    • 1-Click Pre-Built Canvas Workflow Templates (Customer Complaint Auto-Responder & Meeting Notes Extractor)
    • Multi-Provider LLM Integration Wrappers (OpenAI GPT-4o & Anthropic Claude 3.5)
    • Inbound Automated Webhook Trigger Endpoints & Cron Scheduler

📄 License & Contributing


Made with ❤️ by the orchestra.ai Open-Source Team.

About

Open-source, visual node-based tool for building AI automations and multi-agent workflows — no code required.

Topics

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages