NOIR
Get started

Mental model

Understand the seven pieces of a Noir agent and which parts belong to your application.

Noir is the reliability boundary around an agent, not the intelligence provider inside it. Your code supplies behavior and providers. Noir supplies common execution semantics for messages, effects, approvals, retries, and delivery.

The one-file shape

noir({
  model,
  channels,
  connectors,
  database,
  memory,
  sandbox,
  plugins,
})

Each field answers one question:

FieldResponsibilityOwned by
modelgenerate decisions and tool callsyour model provider
channelsreceive and deliver messagesyour provider accounts
connectorsexpose named external systemsyour clients and credentials
databasepersist the runtime inbox, history, approvals, checkpoints, and outboxyour database
memoryrecall and store long-term factsyour adapter and memory vendor
sandboxprovide an owned working environmentyour driver or local process
pluginsadd tools, policy, hooks, routes, and lifecycleyour selected modules

All except model and channels are optional in the provider-native authoring mode. In handler mode, the model is optional too because your existing framework can own the loop.

The execution boundary

An inbound provider event becomes a normalized InboundEvent. Noir deduplicates it, derives a conversation key, serializes work for that conversation, and gives the turn a stable execution ID. Successful tool steps can be checkpointed. Outbound messages enter an outbox before the channel sends them.

That boundary provides an answer to the hard failure case: the process may stop after an external provider accepts a request but before local state records success. Noir can replay its own work, but an external write must also receive the stable idempotency key available in ToolContext or noir.executionId.

Connectors, resources, and plugins

These concepts are deliberately distinct:

  • A connector is a named external system. Its tools become name.tool, and it may expose a client, health check, or close hook.
  • Memory and sandbox are first-class resources because they shape nearly every turn and have ownership scopes.
  • A plugin adds an optional behavior bundle: tools, policy, prompts, services, routes, hooks, health, and lifecycle.
  • A standalone tool is the escape hatch for one function that does not justify a connector or plugin.

The ownership rule

You own the source, provider accounts, credentials, data, deployment, prompts, model selection, tools, and policies. Noir owns the semantics it promises inside your process: event identity, leases, retries, approval binding, checkpoint reuse, output bounds, and delivery settlement.

The result is self-hosted in the literal sense. Removing Noir leaves ordinary TypeScript adapters and provider clients in your repository; there is no remote project to export.

On this page