Skip to content
Rookery OS

The Operating System for Agentic Work

The LLM is the kernel.
The browser is the API.

RookeryOS runs autonomous AI agents as isolated, dual-container pods — replacing hundreds of brittle SaaS connectors with a real browser, secured by human-in-the-loop authentication and an encrypted session vault.

The RookeryOS pod stack — specialty pods for Tidemark, contractors, dental practices, and financial advisors built on the Agent Work Studio runtime and the Rookery OS base.

The foundation for AgentWorks Studio AI Agent Pods.

335+
SaaS API connectors replaced
<100ms
In-pod browser latency (CDP)
<300ms
End-to-end voice latency
AES-256
GCM-encrypted session vault

One base. Every industry.

Specialty pods, built on a common core

Each pod is a domain expert running on the same Agent Work Studio runtime — so a new vertical inherits voice, messaging, and browser tooling for free.

Tidemark

User Pod

The operator cockpit — navigate, direct, and watch your agent fleet work in real time.

Contractor Pod

Project Management

Bids, schedules, and job sites — an agent that runs the back office of a trades business.

Dental Practice Pod

Patient Management

Scheduling, recalls, and patient comms handled end-to-end inside the practice software.

Financial Advisor Pod

Portfolio Management

Portfolio reporting, client outreach, and compliance — driven through real advisory tools.

Core communication services
Industry Agent Expert
Bridge & Other Tools
Answer Phone
Send SMS
Track Email

The problem

The API economy doesn't scale to agents

Traditional agent platforms demand a dedicated connector for every service. It is an unsustainable treadmill of maintenance, security risk, and silent failure.

335+

API connectors to build and maintain across 25 industries

OAuth

A different, brittle auth flow for every single service

Schema drift

APIs change without notice and agents fail silently

Key sprawl

Thousands of raw API keys to store — a security liability

RookeryOS replaces the connector treadmill with the most stable API in existence: the web itself.

How it works

Six ideas that make agents durable

The Browser is the Universal API

Instead of maintaining 335+ fragile SaaS connectors, agents operate a real browser. If a human can use a website, a RookeryOS agent can too — and websites stay backwards-compatible for decades.

Human-in-the-Loop Authentication

When an agent hits a login wall, it pauses and a human steps in over a live noVNC stream to handle 2FA or captchas. The session is captured once — no developer tokens, no stored API keys.

Encrypted Cookie Vault

Authenticated sessions are encrypted with AES-256-GCM using per-tenant keys held in a managed secret store, then injected automatically so agents skip the login next time.

Dual-Container Isolation

Each agent runs as two containers — a Kernel that never touches the browser and a Sidecar that never runs agent logic — communicating over the local Chrome DevTools Protocol in under 100ms.

Lighthouse Knowledge Layer

A state-driven knowledge system answers from an indexed source of truth before ever calling the model — cutting token usage and eliminating hallucination on known facts.

Zero-Trust by Design

Five security layers — transport, container, network, data, and application — with namespace isolation, hardened images, RBAC, and free-tier pods physically separated from production.

Human-in-the-loop

Login walls, solved once

When an agent meets 2FA or a captcha, it doesn't fail — it pauses and hands off to a person over a live browser stream. The session is captured, encrypted, and reused.

  • 1A login detector identifies the auth page from the live DOM.
  • 2The agent pauses and alerts a human co-pilot over noVNC.
  • 3The human handles 2FA or the captcha natively in the stream.
  • 4The session is captured and sealed in the AES-256-GCM Cookie Vault.
  • 5The agent resumes — and future visits skip the login entirely.

One pod · Two containers

Kernel
Agent logic, tools, memory. Never runs the browser.
CDP
<100ms
Sidecar
Headless Chromium + noVNC. Never runs agent logic.
Shared pod network · encrypted Cookie Vault · 10Gi workspace

The platform

A complete operating system, not a script runner

Hudson Gateway

The Kernel

The agent execution engine — orchestrates LLM calls, tools, memory, and the terminal sandbox. Never runs browser code.

Sidecar (Eye/Hand)

The Browser

A headless Chromium with a noVNC view and DOM-distillation service, controlled by the kernel over the local DevTools Protocol.

Lighthouse

Knowledge Layer

Sub-100ms document registry, semantic vector search, and an index-first reasoner that checks knowledge before the model.

Cookie Vault

Session Security

Per-tenant AES-256-GCM encryption of browser sessions, captured after human authentication and injected on demand.

Sonar

Voice Engine

Local speech-to-text and text-to-speech over WebRTC for sub-second, low-cost voice — no cloud voice APIs.

Navigator

Free Tier

Physically isolated, ephemeral assessment pods in a dedicated namespace with strict resource and lifetime limits.

Why browser-first

Resilient where wrappers are brittle

Zero connectors to build — if a human can browse it, the agent can use it.
No stored API keys — humans handle 2FA; the agent saves an encrypted session.
Resilient to UI change — the model adapts where rigid schemas break.
No vendor API fees or rate limits — you pay for compute, not connectors.

See agentic work in action

RookeryOS powers AgentWorks Studio AI Agent Pods. Reach out for a walkthrough or early access.