The Operating System for Agentic Work
The LLM is the kernel.
The browser is the API.
RookeryOS runs autonomous AI agents as isolated, dual-container pods — replacing hundreds of brittle SaaS connectors with a real browser, secured by human-in-the-loop authentication and an encrypted session vault.

The foundation for AgentWorks Studio AI Agent Pods.
One base. Every industry.
Specialty pods, built on a common core
Each pod is a domain expert running on the same Agent Work Studio runtime — so a new vertical inherits voice, messaging, and browser tooling for free.
Tidemark
User Pod
The operator cockpit — navigate, direct, and watch your agent fleet work in real time.
Contractor Pod
Project Management
Bids, schedules, and job sites — an agent that runs the back office of a trades business.
Dental Practice Pod
Patient Management
Scheduling, recalls, and patient comms handled end-to-end inside the practice software.
Financial Advisor Pod
Portfolio Management
Portfolio reporting, client outreach, and compliance — driven through real advisory tools.
The problem
The API economy doesn't scale to agents
Traditional agent platforms demand a dedicated connector for every service. It is an unsustainable treadmill of maintenance, security risk, and silent failure.
API connectors to build and maintain across 25 industries
A different, brittle auth flow for every single service
APIs change without notice and agents fail silently
Thousands of raw API keys to store — a security liability
RookeryOS replaces the connector treadmill with the most stable API in existence: the web itself.
How it works
Six ideas that make agents durable
The Browser is the Universal API
Instead of maintaining 335+ fragile SaaS connectors, agents operate a real browser. If a human can use a website, a RookeryOS agent can too — and websites stay backwards-compatible for decades.
Human-in-the-Loop Authentication
When an agent hits a login wall, it pauses and a human steps in over a live noVNC stream to handle 2FA or captchas. The session is captured once — no developer tokens, no stored API keys.
Encrypted Cookie Vault
Authenticated sessions are encrypted with AES-256-GCM using per-tenant keys held in a managed secret store, then injected automatically so agents skip the login next time.
Dual-Container Isolation
Each agent runs as two containers — a Kernel that never touches the browser and a Sidecar that never runs agent logic — communicating over the local Chrome DevTools Protocol in under 100ms.
Lighthouse Knowledge Layer
A state-driven knowledge system answers from an indexed source of truth before ever calling the model — cutting token usage and eliminating hallucination on known facts.
Zero-Trust by Design
Five security layers — transport, container, network, data, and application — with namespace isolation, hardened images, RBAC, and free-tier pods physically separated from production.
Human-in-the-loop
Login walls, solved once
When an agent meets 2FA or a captcha, it doesn't fail — it pauses and hands off to a person over a live browser stream. The session is captured, encrypted, and reused.
- 1A login detector identifies the auth page from the live DOM.
- 2The agent pauses and alerts a human co-pilot over noVNC.
- 3The human handles 2FA or the captcha natively in the stream.
- 4The session is captured and sealed in the AES-256-GCM Cookie Vault.
- 5The agent resumes — and future visits skip the login entirely.
One pod · Two containers
The platform
A complete operating system, not a script runner
Hudson Gateway
The KernelThe agent execution engine — orchestrates LLM calls, tools, memory, and the terminal sandbox. Never runs browser code.
Sidecar (Eye/Hand)
The BrowserA headless Chromium with a noVNC view and DOM-distillation service, controlled by the kernel over the local DevTools Protocol.
Lighthouse
Knowledge LayerSub-100ms document registry, semantic vector search, and an index-first reasoner that checks knowledge before the model.
Cookie Vault
Session SecurityPer-tenant AES-256-GCM encryption of browser sessions, captured after human authentication and injected on demand.
Sonar
Voice EngineLocal speech-to-text and text-to-speech over WebRTC for sub-second, low-cost voice — no cloud voice APIs.
Navigator
Free TierPhysically isolated, ephemeral assessment pods in a dedicated namespace with strict resource and lifetime limits.
Why browser-first
Resilient where wrappers are brittle
See agentic work in action
RookeryOS powers AgentWorks Studio AI Agent Pods. Reach out for a walkthrough or early access.
