umadev
Open-source Rust CLI that turns your logged-in local coding agents into an eight-role dev team with governance and audit packs.
If you already pay for Claude Code, Codex, OpenCode, Grok Build, or Kimi Code, UmaDev adds what those tools structurally cannot give themselves: a second opinion. Single-writer execution plus independent read-only cross-review by six specialist roles catches the mistakes a model grading its own homework misses, and the 113 checks plus 90-point gate plus proof-pack.zip and scorecard.html are genuinely useful when someone else has to sign off. Recent releases hardened exactly the right things: secrets no longer leak into base-CLI child processes (v1.1.0), and resume/write-intent handling no longer mislabels fix requests as read-only (v1.0.73). Skip it if you want magic-button prototyping —
Verified 6d ago · liveness 68/100 · cite: rightaichoice.com/tools/umadev
- Solo developers who want a full AI dev team without hand-running multiple agent sessions
- Small teams that need governance, audit trails and compliance evidence for AI-generated code
- Developers already paying for Claude Code, Codex, OpenCode, Grok Build or Kimi Code who want added structure
- Engineers shipping production apps where a 90-point quality gate beats raw generation speed
- Anyone wanting a fully autonomous agent with zero human confirmation gates — two gates always pause
- Teams that need a hosted, managed platform holding model API keys — UmaDev is local-CLI only
- Users who want an IDE plugin — this is a standalone TUI/CLI tool
We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.
- Honest verdict, not marketing
- Real pros & cons from real users
- Attributed quotes with receipts
3 free scans · no card needed
Skip UmaDev if you want a zero-gate, fully autonomous agent or an IDE plugin — two human confirmation gates always pause, and it runs only as a standalone TUI/CLI on top of a base CLI you already installed and logged in.
UmaDev itself is MIT-licensed and free, but the base CLI it drives still bills you at the vendor's own rates — Claude Code, Codex, Kimi Code and the rest are separate subscriptions you keep paying.
UmaDev is MIT-licensed and costs nothing to install; the money you spend is whatever your base CLI already charges (Claude Code, Codex, OpenCode, Grok Build or Kimi Code subscriptions). That places it under hosted agent platforms that bundle orchestration into a per-seat or usage fee, and it means cost scales with how much base-CLI inference you actually drive. For a solo dev already paying for one base CLI, the marginal cost of adding UmaDev's governance layer is near zero; for a small team,
In short
umadev — Open-source Rust CLI that turns your logged-in local coding agents into an eight-role dev team with governance and audit packs. Best for Solo developers who want a full AI dev team without hand-running multiple agent sessions, Small teams that need governance, audit trails and compliance evidence for AI-generated code, Developers already paying for Claude Code, Codex, OpenCode, Grok Build or Kimi Code who want added structure. Free to use.
What's new in umadev
Checked 6 days agoAcross the latest 4 updates: 4 changelog entries.
v1.1.1: npm release channel migrated to @umatech scope; self-updater fixed
All published npm packages moved to the @umatech scope (main package umadev → @umatech/umadev, command name unchanged), and the updater now points at the new name so it no longer misreports an old install as current.
v1.1.0: supply-chain hardening, five-lens bug review, interaction robustness
Base-CLI child processes no longer inherit publishing credentials (NPM_TOKEN, signing certs, UMADEV_* are scrubbed), opencode's loopback password uses an OS CSPRNG, and headless Guarded sandbox requests escalate by trust tier instead of being silently auto-approved.
v1.0.73: resume state machine closed; write intent no longer misread as read-only; review failures bounded
/continue, /tasks resume and natural-language continue share one persistent migration restoring plan, cursor, evidence and requirements; explicit fix/write/commit requests keep write semantics through intent timeouts, and rate limits or base stops settle only the current in-memor
v1.0.72: system-wide hardening of state, knowledge, resident sessions and release chain
Status, progress and permission queries now read host facts without side effects, resident rounds get hard time/token/event/tool-call caps, and all five base CLIs start regardless of CLI version with private capabilities safely downgraded per source evidence.
What people actually say about umadev — is it worth it?
We scanned public community sources for umadev on Jul 1, 2026 and could not establish that the discussion we found is about this tool rather than something else sharing its name. Our own analysis of that scan says the posts were off-subject. Rather than publish a sentiment score built on the wrong subject, we publish nothing here and re-run the scan.
Viability Score
How well maintained and how widely used is umadev? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this
Last calculated: October 2026
How we score →Key Features
- Orchestrates five local CLI bases: Claude Code, Codex, OpenCode, Grok Build, Kimi Code
- Vendor-protocol driving for Claude Code, Codex and OpenCode; official ACP v1 for Grok Build and Kimi Code
- Eight expert dev roles: product, architecture, design, frontend, backend, QA, security, DevOps
- Single-writer main session with independent read-only fork cross-review
- Five task modes: Chat, Explain, QuickEdit, Debug, Build — small fixes skip the heavy pipeline
- 34 formal clauses and 113 content governance checks enforced per run
- Configurable quality gate (default 90 points) with skip list
- Two human-in-the-loop confirmation gates, including for preview and irreversible actions
- Visible DAG plan in .umadev/plan.json with live steering via /plan (skip, veto, add, up, down)
- Project memory across sessions: facts, pitfalls, validated experience, run notes
- Local hybrid RAG retrieval: BM25 + optional local vector model + HyDE, degrading to BM25 alone
- repo-map parsing of symbols and import edges for task-scoped context injection
- Auditable delivery pack: output/ design docs, .umadev/audit/ proof files (runtime-proof.json, deploy-proof.json), release/ handoff
- Trust gradients (plan / guarded / auto) with confirmation required for push and deploy
- MCP server mode exposing governance to other tools and CI
About umadev
UmaDev is an MIT-licensed, Rust-based CLI that does not ship a model and does not hold your API keys. Instead it drives five first-class local CLI bases you already have installed and logged in: Claude Code, Codex, and OpenCode through their vendor-specific protocols, and Grok Build and Kimi Code through their official ACP v1 interfaces with isolated vendor config. Version 1.1.1 (2026-08-26) moved all npm packages to the @umatech scope, so the install command is now `npm i -g @umatech/umadev`. You can also skip npm entirely and use the native installer, which downloads a checked platform binary and needs neither Node nor sudo. The routing layer decides first: Chat, Explain, QuickEdit, Debug, or Build. A one-line fix does not trigger the heavy pipeline, while a real build expands into clarification, research, docs, frontend, backend, quality gate, and delivery, with a visible dependency DAG written to .umadev/plan.json that you can steer mid-run via /plan (skip, veto, add, reorder). Review is deliberately separated from writing: the main session is the only writer, and product, architecture, design, QA, security, and DevOps roles review in fresh read-only fork sessions, with structured findings folded back into the same plan. Governance is enforced per run: 34 formal clauses, 113 content governance checks, and a default 90-point quality gate with a configurable skip list, plus two human confirmation gates that cannot be scripted past, including for preview and irreversible actions. A plan/guarded/auto trust gradient controls how much runs unattended, while push and deploy always ask. Project memory accumulates facts, pitfalls, and validated experience across sessions, retrieved through local hybrid RAG (BM25 plus optional local semantic search plus HyDE), and repo-map parsing of symbols and import edges keeps context injection task-scoped. Delivery leaves an auditable pack: output/ design docs, .umadev/audit/ runtime and deploy proofs, and release/ with scorecard and PR body. Fit: solo developers and small teams who want structured delivery, audit trails, and compliance evidence without handing their codebase to a hosted agent platform.
Behind the Verdict
UmaDev's central design choice is that it owns no model. It adapts five first-class local CLI bases — Claude Code, Codex, and OpenCode via vendor protocols, Grok Build and Kimi Code via official ACP v1 — and reads the model and reasoning effort your base already has configured, without forcing a --model flag. No CLI version whitelist: version numbers are used only for diagnostics, and specific capabilities are negotiated live at runtime, with private capabilities safely downgraded per documented evidence. That is a meaningfully different posture from an agent runner that pins a model version and freezes your upgrade path. The team model is the second distinguishing piece. The main session is the single writer; the eight roles (product, architecture, UI/UX, frontend, backend, QA, security, DevOps) review in fresh read-only fork sessions and hand results back only through the plan and a shared team blackboard. That prevents two agents from editing the trunk simultaneously and it prevents the writing model from grading itself. The routing layer matches spend to task: Chat carries only stable identity and language context, Explain adds bounded code context, QuickEdit does fast small edits, Debug focuses on errors/logs/related files, and only Build expands the full nine-stage chain (research → docs → doc confirmation → execution plan → frontend → preview confirmation → backend → quality gate → delivery). Governance is concrete rather than aspirational: 34 formal clauses, 113 content governance checks, a 90-point default threshold with skip_checks, two human gates that cannot be scripted around, and three trust levels (plan / guarded / auto) with push and deploy always requiring confirmation. Delivery artifacts are meant to survive scrutiny — output/ holds the team blackboard outputs (PRD, architecture, UI/UX, OpenAPI, execution plan, open decisions); .umadev/audit/ holds runtime-proof.json, deploy-proof.json, contract reconciliation and security review; release/ holds review reports, scorecard, proof pack and PR body. Where it gets uncomfortable is friction by design. The two human confirmation gates always pause, so anyone expecting a zero-touch autonomous agent will be disappointed. It is a standalone TUI/CLI, not an IDE plugin. It requires a supported base CLI already installed and logged in locally; it does not install, update, or perform interactive logins for your base, and it never auto-launches OAuth or opens a browser. Documentation is candid about install pitfalls: on Linux you should avoid sudo global npm installs because a root-owned prefix will break your base CLIs' own updates too — use a user-owned prefix, npx, or the native installer. Since v1.1.1 all published packages live under the @umatech scope (npm i -g @umatech/umadev), and the docs warn that some third-party mirrors may still cache the withdrawn malicious 1.0.74, so use the official npm registry. The engineering signal over the last two months is largely adversarial
Researching umadev? Get your full AI stack in 60 seconds.
Free, no signup — tell us your goal and get tools matched to your budget & existing stack.
Real-world workflow fit
Concrete scenarios for the personas umadev actually fits — and what changes day-one when you adopt it.
Runs `umadev init` in an empty repo, launches the TUI, and types a one-paragraph description of a course-booking app; UmaDev routes it to Build, writes a dependency DAG to .umadev/plan.json, and pauses at the documentation confirmation gate.
Outcome: A visible plan with PRD, architecture and UI/UX drafts, a preview to approve, backend implementation, a 90-point quality gate, and output/, .umadev/audit/ and release/ artifacts to review.
Drives Codex through a compliance-sensitive feature, then exports proof-pack.zip and scorecard.html from release/ so a non-technical stakeholder can see what was checked.
Outcome: The client receives contract reconciliation, runtime-proof.json and deploy-proof.json alongside the code, rather than an assurance that the AI 'finished'.
Instead of opening separate Claude Code and OpenCode sessions, switches the base with one config change mid-project; UmaDev carries the conversation summary, current plan, team blackboard, project facts and run state across the switch.
Outcome: The build resumes at the same cursor with the same evidence instead of restarting, and review findings from earlier roles stay attached to the plan.
Use Cases
- Take a single prompt for a course-booking app and get a visible plan, PRD, architecture, UI/UX, frontend, backend, quality gate and delivery proof
- Generate an auditable delivery package for a client project, including compliance mapping and a scorecard
- Run governance rules inside CI by exposing UmaDev as an MCP server so every AI-generated change is checked
- Automate repetitive CRUD work while keeping human approval at the documentation and preview gates
- Onboard new developers using UmaDev's structured documentation outputs and accumulated project memory
- Keep a multi-session build coherent across context compaction, session resume and switching between base CLIs
Limitations
- UmaDev does not provide models or API keys; it adapts five first-class local CLIs (Claude Code, Codex, OpenCode via vendor-specific protocols; Grok Build and Kimi Code via official ACP v1) and those bases use their own models and their own login.
- It does not install, update, or run interactive logins for your base CLI — you must have one installed and logged in first, and it never auto-launches OAuth or opens a browser.
- The full build chain plus eight roles is intended for substantial tasks; smaller work routes through Chat/Explain/QuickEdit/Debug paths.
- Installation requires care: avoid sudo global npm installs on Linux because a root-owned npm prefix will also break updates to your base CLIs, and the docs warn some third-party mirrors may still cache the withdrawn malicious 1.0.74 — use the official npm registry.
- Supported binaries cover macOS (Apple Silicon/Intel), Linux (x86_64/ARM64, glibc ≥ 2.31 or musl), and Windows x86_64; Windows on ARM runs the x64 binary through the system compatibility layer, and Kimi Code on Windows also needs Git Bash.
as of 2026-10-02
Verification history
We have re-verified umadev 9 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-checked, vendor evidence unchanged
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
Showing the 6 most recent of 9 verification passes.
Free to cite with attribution — this page re-verifies continuously.
12-month cost
Project the real annual outlay, including the implied monthly cost when only an annual tier is published.
Vendor list price only. Add-on usage, seat overages, and contract minimums are surfaced under Hidden costs & gotchas.
Plans compared
For each published umadev tier: who it actually fits, and what it adds vs. the previous tier. Cross-reference the cost calculator above for projected annual outlay.
Free (open source, MIT License)
$0
Ideal for
Solo developers and small teams that already pay for a local base CLI and want routing, governance and audit output without a new subscription.
What this tier adds
Starting tier — full 8-role orchestration across 5 local CLI bases, 34 clauses, 113 checks, 90-point gate, DAG plan and audit pack, all at $0 for UmaDev itself.
Where the pricing makes sense
The company stage and team size where umadev's pricing actually pencils out — and where peers do it cheaper.
UmaDev is MIT-licensed and costs nothing to install; the money you spend is whatever your base CLI already charges (Claude Code, Codex, OpenCode, Grok Build or Kimi Code subscriptions). That places it under hosted agent platforms that bundle orchestration into a per-seat or usage fee, and it means cost scales with how much base-CLI inference you actually drive. For a solo dev already paying for one base CLI, the marginal cost of adding UmaDev's governance layer is near zero; for a small team,
Setup time & first value
How long it actually takes to get something useful out of umadev — broken out by persona, not the marketing-page minute.
Solo dev on a base CLI they already use: minutes — install via `npm i -g @umatech/umadev` (or the native installer), run `umadev init`, then `umadev`, and the first routed task starts. Native/source installs that want semantic retrieval need the local vector model supplied separately via UMADEV_EMBED_MODEL_DIR. Small teams: add time for agreeing on the `[quality] threshold` and `skip_checks` in
Switching to or from umadev
How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.
- →From raw Claude Code / Codex sessions: keep the same logged-in base CLI, install UmaDev over it, and run `umadev init` in the repo so routing and governance apply without changing your subscription.
- →From a previous flat npm `umadev` install: reinstall as `npm i -g @umatech/umadev` and run `umadev update` — v1.1.1 repointed the updater, so older installs may have reported themselves as already current.
- →From sudo/root-owned global npm installs: run `umadev doctor`, which detects root-owned install dirs or npm caches and prints the repair commands.
- →From a hand-rolled multi-agent script: move plan state into .umadev/plan.json and let /plan handle skip, veto, add and reorder instead of scripting session handoffs.
- ↗To a plain base CLI: stop invoking UmaDev and run Claude Code, Codex or OpenCode directly — artifacts in output/, .umadev/audit/ and release/ are plain files you keep.
Integrations
Resources & Guides
Tutorials & Learning
YouTube returned 6 videos for “umadev”, and we withheld 6: 6 could not be judged, because “umadev” is a single word that other videos use for other things. We are showing none, because we could not prove any of them are about umadev.
Official links
Tools that pair well with umadev
Common stack mates teams adopt alongside umadev, with the specific reason each pairing earns its keep.
OpenHands
Open-source platform for autonomous coding agents that fix bugs, review PRs, and automate engineering workflows.
Poolside AI
Open-weight agentic coding models — Laguna XS 2.1 (33B) and Laguna S 2.1 (118B) — built for code that cannot leave your security boundary.
Imbue
Imbue is an open AI lab publishing modular, open-source coding-agent tools you run and inspect yourself.
Featured Head-to-Head Comparisons
Umadev vs Bito
Bito is the right choice for engineering teams who need system-wide context across multiple repositories and deep integrations with Jira, Slack, and IDEs like Cursor. UmaDev is better for solo developers or small teams who want a free, open-source, local AI development pipeline with built-in quality gates and audit trails. If you're a large enterprise, pick Bito; if you're an individual tinkerer, pick UmaDev.
Umadev vs Cognition Ai
Choose Cognition AI if you're an enterprise team needing autonomous end-to-end engineering with a financial guarantee and cross-platform support. Choose umadev if you're a solo developer or small team wanting an open-source, audit-driven AI team that enforces quality gates and compliance — all locally for free. Both are powerful, but they serve opposite ends of the control-vs-autonomy spectrum.
Umadev vs Poolside Ai
Choose Poolside AI if you're an enterprise in a regulated industry needing on-prem, custom models with full governance. Choose umaDev if you're a solo developer or small team wanting a free, open-source, structured AI development workflow with quality gates and audit trails, running on your existing CLI tools.
Alternatives to umadev
View allOpenHands
Open-source platform for autonomous coding agents that fix bugs, review PRs, and automate engineering workflows.
Poolside AI
Open-weight agentic coding models — Laguna XS 2.1 (33B) and Laguna S 2.1 (118B) — built for code that cannot leave your security boundary.
Frequently Asked Questions
Best-of guides
Used umadev? Help shape our editorial sentiment research.