Try orchestra.ai live on Vercel: https://orchestra-ai.vercel.app
> Note: Shared demo environment. Register your own free account to create, test, and save custom workflows.
orchestra.ai is an open-source visual workflow automation platform purpose-built for AI agents and multi-node orchestration. It combines the visual drag-and-drop simplicity of tools like Zapier and n8n with an engine built specifically for LLMs, sandboxed code execution, and real-time DAG execution tracking.
Connect user inputs, AI models, custom scripts, external webhooks, and structured outputs seamlessly on a unified interactive canvas.
| Feature | Description |
|---|---|
| 🎨 Visual Canvas Editor | Interactive drag-and-drop workflow builder powered by React Flow, complete with custom dynamic nodes, snap-to-grid edge connectors, zoom/pan controls, and minimap navigation. |
| 🧩 5 Core Node Types |
|
| 🔐 BYOK Architecture | "Bring Your Own Key" system ensuring user API keys are encrypted at rest using industry-standard AES-256 GCM before database storage. |
| ⚡ Background Orchestration | Asynchronous, resilient job queue architecture powered by Inngest to prevent serverless execution timeouts during multi-LLM chaining. |
| 🛡️ Sandboxed Code Execution | Isolated JavaScript evaluation powered by isolated-vm with strict execution timeouts, memory limits, and zero host environment access. |
| 📊 Live Execution Tracking | Real-time visual node status feedback (Pending, Running, Success, Failed), topological DAG sorting, and automatic cycle detection. |
| Feature / Capability | orchestra.ai | n8n | Zapier |
|---|---|---|---|
| AI-Native DAG Chaining | 🟢 Purpose-built LLM context flow | 🟡 Added via AI node extensions | 🔴 Basic linear step actions |
| Open Source | 🟢 MIT License | 🟡 Fair-code / Sustainable License | 🔴 Proprietary |
| BYOK Pricing Model | 🟢 Bring Your Own Key (Zero Markup) | 🟡 Self-host or Tiered Cloud | 🔴 Task-based Tiered Billing |
| Background Execution Queue | 🟢 Inngest Async Queues | 🟢 Bull / Redis Workers | 🟢 Proprietary Task Queue |
| Sandboxed Execution | 🟢 isolated-vm (Memory & Time Capped) |
🟢 Standard Node VM | 🟡 Limited Code By Zapier |
- BYOK API Key Encryption: User LLM provider keys are encrypted at rest using AES-256-GCM with unique initialization vectors (
iv) before database storage. Keys are decrypted strictly in-memory during node execution steps. - Sandboxed Code Execution: JavaScript transformation scripts inside Data Processor nodes run in an isolated V8
isolated-vmisolate with strict resource bounds (128MB memory ceiling, 5-second execution timeout, and zero access to host environment or Node.js global APIs). - Responsible Vulnerability Disclosure: If you discover a security vulnerability, please report it privately via GitHub Security Advisories rather than opening a public issue.
| Category | Technologies |
|---|---|
| Framework & Language | Next.js 14 (App Router), TypeScript (Strict Mode) |
| Styling & UI | Tailwind CSS, Shadcn UI, Lucide Icons, Framer Motion |
| Workflow & Canvas | React Flow 11, Zustand (State Management) |
| Database & ORM | PostgreSQL (Neon), Prisma ORM 5 |
| Async Architecture & Security | Inngest (Background Queue), isolated-vm (Sandbox), AES-256 Encryption |
| Testing Suite | Vitest (Unit & Integration), Playwright (End-to-End) |
Follow these steps to set up orchestra.ai locally on your machine.
git clone https://github.com/junaidahmeddev/orchestra-ai.git
cd orchestra-ai
npm installCreate a .env.local file in the project root:
cp .env.example .env.localConfigure the required environment variables inside .env.local:
# ── Database (Neon PostgreSQL) ────────────────────────────────
DATABASE_URL="postgresql://user:password@ep-host.neon.tech/neondb?sslmode=require"
# ── NextAuth Authentication ───────────────────────────────────
# Generate with: openssl rand -base64 32
NEXTAUTH_SECRET="your-nextauth-secret-key"
NEXTAUTH_URL="http://localhost:3000"
# ── AES-256 Encryption Key (32-byte hex) ─────────────────────
# Generate with: openssl rand -hex 32
ENCRYPTION_KEY="your-32-byte-hex-encryption-key"
# ── Inngest (Background Job Queue) ────────────────────────────
INNGEST_EVENT_KEY="your-inngest-event-key"
INNGEST_SIGNING_KEY="your-inngest-signing-key"Push the Prisma schema to your PostgreSQL database:
npx prisma db push(Optional) Launch Prisma Studio to inspect your database models:
npm run prisma:studioStandard Single Terminal Command:
npm run devOpen http://localhost:3000 with your browser to explore orchestra.ai.
Dual Terminal Command (Recommended for Inngest Background Jobs):
- Terminal 1 (Next.js Application):
npm run dev
- Terminal 2 (Inngest Local Dev Server):
Access the Inngest Developer Dashboard at
npx inngest-cli@latest dev
http://127.0.0.1:8288.
We maintain a rigorous 3-layer automated testing architecture ensuring stability across DAG calculations, database authorization, and user workflows:
- 🔬 Unit Tests (Vitest): Validates pure graph execution algorithms (
topologicalSort), AES-256 encryption/decryption, and memory-cappedisolated-vmsandbox evaluation. - 🔌 Integration Tests (Vitest + Prisma Mocks): Verifies backend API endpoints, credential authentication routes (
/api/auth/register), and workflow CRUD operations. - 🎭 End-to-End Tests (Playwright): Tests real browser interactions including login, canvas creation, dynamic node addition, connector edge linking, and state persistence.
# Run all Unit & Integration tests (Vitest)
npm test
# Run Unit tests in interactive watch mode
npm run test:watch
# Run Playwright End-to-End tests
npm run test:e2eorchestra-ai/
├── prisma/
│ └── schema.prisma # PostgreSQL schema & Prisma models
├── src/
│ ├── app/ # Next.js 14 App Router
│ │ ├── (auth)/ # Login & Registration pages
│ │ ├── (dashboard)/ # Workflow listing & Canvas editor
│ │ └── api/ # REST API Endpoints & Route Handlers
│ │ ├── auth/ # Registration & NextAuth handlers
│ │ ├── api-keys/ # Encrypted LLM key endpoints
│ │ ├── inngest/ # Inngest background queue webhook
│ │ └── workflows/ # Workflow CRUD & Execution handlers
│ ├── components/ # UI & Visual Canvas Components
│ │ ├── canvas/ # React Flow canvas, node palette & sidebars
│ │ │ └── nodes/ # 5 Custom Node React components
│ │ └── ui/ # Shadcn UI reusable components
│ ├── lib/ # Core Engine & Utilities
│ │ ├── db.ts # Prisma client singleton
│ │ ├── encryption.ts # AES-256 GCM encryption helpers
│ │ └── engine/ # DAG Execution Engine
│ │ ├── topologicalSort.ts # Cycle detection & execution ordering
│ │ ├── executor.ts # Main graph runner logic
│ │ └── nodeHandlers/ # Individual node logic handlers
│ ├── store/ # Zustand canvas state management
│ └── types/ # Shared TypeScript interfaces
├── e2e/ # Playwright End-to-End specs
├── scripts/ # Utility & encryption test scripts
├── package.json
└── README.md
- Phase 0 — Project Scaffold & Next.js Setup
- Phase 1 — Database Design & Prisma Schema (Neon PostgreSQL)
- Phase 2 — Authentication System (NextAuth.js Credentials Provider)
- Phase 3 — Workflow CRUD Engine (API Routes & Security Guards)
- Phase 4 — Visual Canvas Editor (React Flow + Zustand State Slices)
- Phase 5 — DAG Execution Engine (Topological Sorting & Cycle Detection)
- Phase 6 — Inngest Background Execution &
isolated-vmSandbox - Phase 7 — Encrypted API Key Storage (AES-256) & Gemini Integration
- Phase 8 — Comprehensive Testing Suite (30 Unit/Integration Tests + Playwright E2E)
- Phase 9 — Production Deployment & Documentation (Vercel + Neon + Inngest)
- Phase 10 — Pre-Built Workflow Templates & Multi-LLM Extensions
- 1-Click Pre-Built Canvas Workflow Templates (Customer Complaint Auto-Responder & Meeting Notes Extractor)
- Multi-Provider LLM Integration Wrappers (OpenAI GPT-4o & Anthropic Claude 3.5)
- Inbound Automated Webhook Trigger Endpoints & Cron Scheduler
- License: Released under the MIT License.
- Contributing: Contributions are welcome! Please read our Contributing Guidelines before submitting pull requests.
Made with ❤️ by the orchestra.ai Open-Source Team.
