Stuga

dev.stugav0.1.10Updated Oct 2, 2026

Agent edits await review by default in a self-hosted workspace for documents and databases.

VerifiedStreamable HTTPWeb executableDatabasesKnowledge & MemoryProductivity & Workflow

Overview

AI-generated overview

Stuga is a self-hosted workspace for documents and databases where an AI assistant's edits arrive as tracked changes that a person reviews and accepts.

What it does
Agents connect over MCP to a self-hosted node holding collaborative documents and SQLite-backed databases. Their writes arrive as tracked changes that wait for a person to accept or reject by default, though an owner or admin can let AI edits apply directly. Each run records the agent, the person it acts for, the client and model, and every change, and agents can query which passages they wrote. Documents support real-time editing, comments and version history, and databases offer typed tables, saved views and read-only SQL.
When to use it
Worth adding when a team wants an AI assistant to work inside shared documents and tables but keep a human in the loop before changes land. Suited to self-hosted setups where review, attribution and audit of agent edits matter more than instant application.
Requirements
A self-hosted Stuga node reached over streamable HTTP at your node's address. Install on an Apple silicon Mac with macOS 13 or later, or with Docker on x86-64 or arm64; the node runs as one Node.js process with Postgres including pgvector and pg_search. Create an account and workspace, then connect agents through browser sign-in or an API key. No AI key is needed on the node because each agent brings its own model.
Before you install
Agents can change documents and databases, so review settings decide whether edits land immediately or wait. Sign-in scopes an app to chosen workspaces and to read-only or read-and-suggest access, and API keys can be confined to folders, made read-only or given an expiry; revoke access when no longer needed. Renaming, moving, deleting, sharing and the review setting stay with people. Every MCP call, reads included, is recorded in the audit log, and the node makes outbound requests only for…

Installation

In SourceWeft

  1. Open Stuga in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "stuga": {
      "type": "http",
      "url": "https://{stuga_host}/mcp"
    }
  }
}

README

[Image]

Stuga

AI suggests. You decide.

Self-hosted documents and databases where edits from Claude Code, Codex or any MCP client arrive as tracked changes and, by default, land only when a person accepts them. Use it on your own or with your team.

Download for Mac (Apple silicon, macOS 13+) · Install with Docker

Install, then create your account and workspace and connect an agent. Help for people using Stuga: stuga.dev/docs.

[Claude Code's edits to a document arriving as tracked changes, accepted and rejected one by one]

How agent edits work

  • Review by default. An agent's changes wait for a person, who is notified and accepts or rejects each one in the document or table. Nothing lands on a timer.
  • Nobody is blocked. Collaborators never see pending agent text and keep editing. The agent carries on, and its later reads include its own pending edits.
  • Or apply at once. The owner of a document or database, or a workspace admin, can choose Let AI edits apply directly. Changes then land at once, recorded, attributed and revertible.
  • A run per session. Each run records the agent, the person it acts for, the client and model it reported, and every change. Review AI edits lists the runs that need someone.
  • Who wrote this? An agent can ask a document which passages agents wrote and whether a person accepted them.
  • Instructions that stack. The workspace, folders, documents and databases can each carry instructions for agents. They advise the model; permissions and review decide what a write does.

[Claude Code's changes to a table waiting as proposals, then accepted]

What's in it

  • Documents written together. Real-time editing (Tiptap over a Yjs CRDT) with presence, comments, @mentions and version history.
  • Databases with SQL. Typed tables beside your documents, each database its own SQLite file, with saved views, row pages and CSV import. Agents, Ask and the REST API run read-only SQL on them.
  • Search that follows permissions. Keyword (BM25, pg_search) and semantic (pgvector) search in one SQL statement, with access checked inside it. Chinese and Japanese are split into words.
  • Built-in AI, off until set up. A co-author and a table assistant, whose edits are reviewed like an agent's, and Ask, which cites sources. OpenAI, Anthropic, Gemini, DeepSeek and more, or Ollama.
  • Sharing and sign-in. Workspaces, folders, per-document sharing, groups and guests. People join by invite link and sign in with a password or your OpenID Connect provider.
  • Import and export. A Notion export, or a zipped Obsidian vault or folder of Markdown, becomes a workspace; a workspace exports as one .stuga.zip of Markdown, JSON Lines and its files.

[The built-in co-author's edits arriving as suggestions, accepted and rejected one by one]

Connect your agents

Agents connect over MCP. Settings → Your AI agents gives the setup for Claude Code, Claude Desktop, Codex, Antigravity, Cursor, VS Code, Kiro, Goose, LM Studio, DeepSeek Harness and Pi, with your node's address filled in, and the URL any other MCP client needs (docs/agents.md). Each agent brings its own model, so the node needs no AI key.

  • Scoped sign-in. Most clients sign in through the browser, where you tick the workspaces an app may use and choose Read only or Read and suggest changes. Revoke ends its access.
  • Narrow keys. A client without sign-in uses an API key, which can be confined to folders, made read-only or given an expiry.
  • Content only. Agents change documents and databases. Renaming, moving, deleting, sharing and the review setting stay with people.
  • Full audit. Every MCP call, reads included, is in the workspace's audit log. An event feed and signed webhooks report what changed.

Your data

Stuga sends no telemetry, and nothing reaches us unless a node admin turns on remote access. The node makes outbound requests only for features in use, such as an AI provider, and asks GitHub once a day for the list of releases unless a node admin turns that off. docs/privacy.md lists what the node sends and stores.

Install

  • A Mac with Apple silicon, on macOS 13 or later: open Stuga.pkg. It carries its own Postgres and Node.js (docs/install/macos.md).

  • Docker on x86-64 or arm64, such as a Linux server or a NAS: install.sh starts Postgres and the node with Compose (docs/install/docker.md):

    sh
    curl -fsSL https://github.com/stuga-dev/stuga/releases/latest/download/install.sh | bash

A node is one Node.js process and Postgres with pgvector and pg_search; people open it in a browser. It backs itself up every day by default and before every upgrade (docs/operations.md). docs/getting-started.md walks through the first hour.

Questions and feedback

Ask a question or share an idea in Discussions; report a bug as an issue.

Contributing

Issues and pull requests are welcome. CONTRIBUTING.md covers running Stuga from source, the tests and the conventions, and RELEASING.md how a release is cut. Contributions are accepted under a Contributor License Agreement (CLA.md); a bot asks on your first pull request. Report a vulnerability privately, as SECURITY.md describes.

License

AGPL-3.0-only, except integrations/, which is MIT; copyright notice in NOTICE. If you modify Stuga and offer it to others over a network, you share your changes under the same terms. The name and logo are not covered by the license: TRADEMARKS.md says how you may use them.

Source: README.md at commit 0c0a0b3

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.10LatestOct 2, 2026