Moltis
Self-hosted persistent AI agent server in Rust with sandboxed execution
A top-tier self-hosted agent server that matches cloud features while keeping keys local. Demands CLI comfort and server upkeep, but for technical privacy-minded users it's a rare find with unmatched multi-channel automation and runtime extensibility.
Verified 5d ago · liveness 74/100 · cite: rightaichoice.com/tools/moltis
- Developers wanting a self-hosted AI agent server with full control over data and execution
- Privacy-focused users who want to avoid cloud lock-in and keep keys local
- Power users needing multi-channel automation via Telegram, Discord, Slack, and more
- Teams looking for an on-premise assistant with sandboxed execution and no plugin supply-chain risk
- Users who prefer a fully managed, zero-setup cloud service with no server maintenance
- Non-technical users uncomfortable with command-line interface and server configuration
- Those needing a large plugin marketplace or a wide ecosystem of pre-built integrations
We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.
- Honest verdict, not marketing
- Real pros & cons from real users
- Attributed quotes with receipts
3 free scans · no card needed
Skip Moltis if you aren't comfortable with CLI and server management, need a fully managed cloud assistant with zero setup, or expect a large plugin marketplace with pre-built integrations.
You'll need your own hardware or a VPS, plus Docker or another sandbox runtime — that's an infrastructure cost not included in the $0 price tag.
Moltis is free and open-source, so the cost is your own infrastructure and time. That makes it a bargain for technical users compared to cloud assistants like OpenAI's ChatGPT Plus ($20/mo) or Anthropic's Claude Pro ($20/mo). But you trade that savings for ops burden — no one else manages the server for you.
In short
Moltis — Self-hosted persistent AI agent server in Rust with sandboxed execution. Best for Developers wanting a self-hosted AI agent server with full control over data and execution, Privacy-focused users who want to avoid cloud lock-in and keep keys local, Power users needing multi-channel automation via Telegram, Discord, Slack, and more. Free to use.
What's new in Moltis
Checked 3 days agoAcross the latest 8 updates: 8 changelog entries.
Moltis 20260830.01: Drop DMI sysfs masks, make object schemas OpenAI-safe, validate sandbox image requests
Drops DMI sysfs masks on arm64 Docker daemons, makes object schemas OpenAI-safe, and validates sandbox image requests.
Moltis 20260827.01: Fix Fastmail MCP OAuth scope, allow replacing preferred models
Fixes Fastmail MCP OAuth scope registration and enables replacing preferred models for providers.
Moltis 20260826.01: Preserve delivered channel context, validate Brave search parameters
Fixes cron to preserve delivered channel context and validates Brave search parameters in tools.
Moltis 20260824.01: WhatsApp Markdown, memory fixes, Browserless v2 support, Obscura stealth by default
Renders Markdown in WhatsApp outbound, bounds embedding batches, supports Browserless v2, and enables Obscura stealth by default.
Moltis 20260820.01: Harden release checks, require auth for vault unlock, more WhatsApp fixes
Hardens transient integration checks, requires authentication for vault unlock/recovery, and improves WhatsApp reply handling.
Moltis 20260818.06: Managed Files library, MiniMax Code ACP agent, Slack reactions, zvec memory backend
Adds managed Files library, MiniMax Code ACP agent, Slack reaction triggers and live task cards, Nostr NIP-29 support, and zvec vector memory backend.
Moltis 20260818.08: Remove broken star history chart, fix gateway heartbeat patch
Removes broken star history chart, keeps core service methods within size limit, and treats heartbeat.update params as a patch.
Moltis 20260818.10: Add GPT-5.6 Luna routing coverage, fix Apple Container status
Adds routing for GPT-5.6 Luna, fixes Apple Container status parsing and sandbox resource limits, and preserves Responses routing for explicit endpoints.
What people actually say about Moltis — is it worth it?
We ran a structured research pass across product reviews, community discussions, and post-purchase forum threads to surface the patterns vendors won't publish themselves. Below: the recurring strengths, the hidden costs people mention most, and the cohort that consistently regrets adopting this tool.
72 mentions across 5 sources (Hacker News, YouTube, Bluesky, GitHub, Lemmy) · researched Jul 14, 2026.
- +Polished, not full of half-baked features like competitors.
- +One-command installation: three steps from zero to chat.
- +Sandboxed execution with Docker or Apple Containers for security.
- +Persistent memory with vector and full-text search.
- +Multi-provider LLM support: 20+ cloud and local models.
- −Sandbox restrictions cannot be disabled, limiting some use cases.
- −Self-modifying skills raise security concerns among community.
- −Voice and scheduling features lack extensive real-world feedback.
- −Small community means slower support and fewer integrations.
- −No mobile app or managed cloud tier available.
- • Self-hosting costs: hardware, electricity, bandwidth for local LLMs if not using cloud APIs.
Viability Score
How well maintained and how widely used is Moltis? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this
Last calculated: September 2026
How we score →Key Features
- Single binary server, no runtime dependencies
- Persistent memory with hybrid vector + full-text search
- Natural-language cron scheduling
- SSRF-protected web browsing with sandboxed browser sessions
- CalDAV calendar integration for events and reminders
- Voice input/output with cloud and local TTS/STT providers
- Multi-channel messaging: Telegram, WhatsApp, Discord, Slack, Matrix, Nostr, Teams
- Runtime creation of skills, hooks, and MCP tools
- Webhook triggers for GitHub PRs, Stripe payments, and more
- OAuth zero-config for GitHub Copilot, OpenAI Codex, Kimi Code
- Encryption-at-rest vault for API keys and secrets
- Passkeys (WebAuthn), token, and password authentication
- Sandboxed execution via Docker, Podman, Apple Containers, or WASM
- GraphQL API and JSON-RPC for custom integrations
- OpenClaw import for one-click migration
About Moltis
Moltis is an open-source, self-hosted AI agent server that runs as a single Rust binary. No dependencies, no runtime, just download and run on your Mac, Raspberry Pi, or any server. It's built for developers and privacy-conscious users who want full control over their data and execution, without cloud lock-in. Install in 60 seconds with a curl command, then configure via web UI at localhost:13131—paste your provider key, pick a model, and start chatting from any channel. The agent persists context across sessions, handles recurring tasks, and extends itself dynamically. Out of the box, Moltis connects to Telegram, WhatsApp, Discord, Slack, Matrix, Nostr, and Teams—one agent across every frontend. It supports 20+ LLM providers including Anthropic, OpenAI, Gemini, Mistral, DeepSeek, and local models via Ollama or LM Studio. Voice input/output works with cloud and local TTS/STT providers. Security is baked in: keys and private data stay on your machine, sandboxed execution (Docker, Podman, Apple Containers, WASM) prevents filesystem access without approval, and SSRF-protected browsing blocks loopback IPs. Recent updates add GPT-5.6 model support and MiniMax Code ACP agent, full read-only OpenClaw import for one-click migration, webhook triggers (GitHub PRs, Stripe payments), and a configurable Slack API base URL. The changelog also notes security hardening: vault unlock now requires authentication, and WhatsApp treats replies as addressing the bot. An iOS companion app is coming soon. Moltis isn't a chatbot wrapper—it's a serious agent server for technical users. Expect CLI comfort and manual configuration. If you prefer a managed, zero-setup cloud service, alternatives like ChatGPT or Claude exist, but you'll sacrifice local control and multi-channel reach. For those who value data sovereignty and are willing to handle ops, Moltis delivers capability few tools match.
Behind the Verdict
We'd reach for Moltis when you're tired of cloud assistants that hold your data hostage. Single binary, no dependencies—the install is genuinely one command. The sandboxing is the differentiator: your AI can't rummage through your files unless you approve. In practice, that means you can run it on hardware you own and still sleep at night. Where it bites: this is not a plug-and-play app. You'll live in the terminal, edit TOML configs, and debug API keys. If the phrase 'production-ready' makes you check for a managed console, Moltis will test your patience. The web UI is fine, but the real power is in the GraphQL API and CLI. Compared to OpenClaw, Moltis feels more finished. The import tool brings over conversations, skills, and settings in one click—that's a low-risk migration path. Community reports note it's more stable and performant out of the box, with guardrails like SSRF protection already enabled. Watch out for the upkeep. You're running a server 24/7; updates come fast and you need to track them. The changelog shows security patches landing every few weeks—that's good, but it means you must stay on top of releases. For a home lab, fine. For a busy team, budget time for maintenance. Niche? Yes. But if you want local-first AI with genuine autonomy—scheduling, browsing, coding, messaging—Moltis is the rare tool that delivers without a catch. Just be honest about your willingness to manage it.
Researching Moltis? Get your full AI stack in 60 seconds.
Free, no signup — tell us your goal and get tools matched to your budget & existing stack.
Real-world workflow fit
Concrete scenarios for the personas Moltis actually fits — and what changes day-one when you adopt it.
Install Moltis on a Mac Mini, connect Telegram, and use it to manage daily standup reminders via natural-language cron.
Outcome: You get a persistent assistant that reminds you of tasks each morning, summarizes web pages on demand, and never leaks your API keys.
Deploy Moltis on a Raspberry Pi, connect Signal, and use it to manage calendar events via CalDAV without sending data to the cloud.
Outcome: Your calendar and messages stay local, and you can message the agent securely from your phone.
Run Moltis on a shared server, connect Slack, and set up webhook triggers to post updates on GitHub PRs.
Outcome: The team gets automated alerts and can extend the agent with custom skills without supply-chain risk.
Use Cases
- Schedule recurring cron jobs using natural language, like 'remind me daily to check logs'.
- Browse and summarize web pages with SSRF protection.
- Manage your calendar via CalDAV, adding events and reminders.
- Send and receive messages across Telegram, WhatsApp, Discord, Slack, Matrix, Nostr, and Teams.
- Extend the agent's capabilities at runtime by creating custom skills, hooks, or MCP tools.
- Automate workflows via webhooks, e.g., trigger on GitHub PRs or Stripe payments.
- Run a local assistant that remembers context across sessions for research or personal tasks.
Models Under the Hood
as of 2026-08-27
Limitations
- As a self-hosted solution, Moltis requires users to manage their own infrastructure (server, Docker, networking).
- Setup involves CLI commands and configuration, which may be a barrier for beginners.
- While it supports many LLM providers, each requires an API key or local model setup.
- The OpenClaw import is read-only, so changes made in Moltis won't sync back.
- There's no official mobile app yet (iOS is coming soon), and support is community-driven rather than a commercial team.
as of 2026-08-21
Verification history
We have re-verified Moltis 6 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
Free to cite with attribution — this page re-verifies continuously.
12-month cost
Project the real annual outlay, including the implied monthly cost when only an annual tier is published.
Vendor list price only. Add-on usage, seat overages, and contract minimums are surfaced under Hidden costs & gotchas.
Plans compared
For each published Moltis tier: who it actually fits, and what it adds vs. the previous tier. Cross-reference the cost calculator above for projected annual outlay.
Self-hosted
$0/mo
Ideal for
Technical individuals and teams who want full control over their AI agent and data, are comfortable with CLI and server management, and prefer a free open-source solution over paid managed services.
What this tier adds
This is the only tier currently offered. It's free and includes all features: multi-channel, memory, sandboxing, and no feature paywalls.
Where the pricing makes sense
The company stage and team size where Moltis's pricing actually pencils out — and where peers do it cheaper.
Moltis is free and open-source, so the cost is your own infrastructure and time. That makes it a bargain for technical users compared to cloud assistants like OpenAI's ChatGPT Plus ($20/mo) or Anthropic's Claude Pro ($20/mo). But you trade that savings for ops burden — no one else manages the server for you.
Setup time & first value
How long it actually takes to get something useful out of Moltis — broken out by persona, not the marketing-page minute.
Installation is a single curl command and takes minutes, but configuration (adding provider keys, setting up sandbox, connecting channels) can take 15–30 minutes for a technical user. Non-technical users may spend an hour or more on initial setup.
Switching to or from Moltis
How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.
- →From OpenClaw: One-click import read-only — brings over conversations, skills, and settings.
- →From a cloud assistant: Copy-paste your key memories and recurring tasks into Moltis, then configure channels.
- ↗To OpenClaw: Manual export of skills and settings; no automated path.
- ↗To a cloud service like ChatGPT: Manual copy of conversations or use the API to extract memory.
Integrations
Resources & Guides
Tutorials & Learning
Official links
Featured Head-to-Head Comparisons
Moltis vs Sublime Security
Moltis and Sublime Security serve entirely different needs. Moltis is a free, self-hosted AI agent for developers who want full control, multi-channel automation, and privacy. Sublime Security is a commercial email security platform for enterprise security teams battling advanced phishing and BEC. Choose Moltis if you need a programmable assistant; pick Sublime if you need to protect your organization from email attacks.
Moltis vs Push Security
If your priority is securing your organization against browser-based attacks and controlling employee AI tool usage, Push Security is the clear choice. If you need a self-hosted, private AI assistant for personal automation across messaging channels, Moltis delivers unmatched flexibility and data control. They solve fundamentally different problems—choose based on whether you're defending an enterprise or running your own agent.
Moltis vs Audioeye
If you need a self-hosted AI agent that automates tasks across messaging channels and keeps data private, Moltis is the clear choice – it’s free and developer-friendly. If you must achieve web accessibility compliance quickly and reduce legal risk, AudioEye provides a managed turnkey solution with expert audits. They solve completely different problems, so the right pick depends on your priority: data control vs. compliance automation.
Popular in Local & On-Device AI
Unsloth
Run and fine-tune LLMs locally on your own hardware with Unsloth — fast, memory-efficient, no cloud needed.
Cortex.cpp
Run 123+ open-source models locally or connect online APIs in one free, open-source desktop app
Frequently Asked Questions
Best-of guides
Used Moltis? Help shape our editorial sentiment research.


