Open Agent SDK (Rust)
Build AI agents in Rust using your own hardware
What you can build:
- Copy editors that analyze manuscripts and track writing patterns
- Git commit generators that write meaningful commit messages
- Market analyzers that research competitors and summarize findings
- Code reviewers, data analysts, research assistants, and more
Why local?
- No API costs - use your hardware, not OpenAI's
- Privacy - your data never leaves your machine
- Control - pick your model (Qwen, Llama, Mistral, etc.)
How fast? From zero to working agent in under 5 minutes. Rust-native performance (zero-cost abstractions, no GC), fearless concurrency, with 390 active tests.
Overview
Open Agent SDK (Rust) provides a clean, streaming API for working with OpenAI-compatible local model servers. 100% feature parity with the Python SDK—complete with transport-boundary-safe SSE streaming, tool call aggregation, hooks, and automatic tool execution—built on Tokio for high-performance async I/O.
Supported Providers
Supported (OpenAI-Compatible Endpoints)
- LM Studio -
http://localhost:1234/v1 - Ollama -
http://localhost:11434/v1 - llama.cpp server - OpenAI-compatible mode
- vLLM - OpenAI-compatible API
- Text Generation WebUI - OpenAI extension
- Any OpenAI-compatible local endpoint
- Local gateways proxying cloud models - e.g., Ollama or custom gateways that route to cloud providers
Note on LM Studio: LM Studio is particularly well-tested with this SDK and provides reliable OpenAI-compatible API support. If you're looking for a user-friendly local model server with excellent compatibility, LM Studio is highly recommended.
Not Supported (Use Official SDKs)
- Claude/OpenAI direct - Use their official SDKs, unless you proxy through a local OpenAI-compatible gateway
- Cloud provider SDKs - Bedrock, Vertex, Azure, etc. (proxied via local gateway is fine)
Quick Start
Installation
[]
= "0.7.0"
= { = "1", = ["full"] }
= "0.3"
= "1.0"
For development:
Simple Query (LM Studio)
use ;
use StreamExt;
async
Multi-Turn Conversation (Ollama)
use ;
async
Function Calling with Tools
Define tools using the builder pattern for clean, type-safe function calling:
use ;
use json;
async
Advanced: Manual Tool Execution
For custom execution logic or result interception:
// Disable auto-execution
let options = builder
.system_prompt
.model
.base_url
.tool
.auto_execute_tools // Manual mode
.build?;
let mut client = new?;
client.send.await?;
while let Some = client.receive.await?
Key Features:
- Automatic execution - Tools run automatically with safety limits
- Type-safe schemas - Automatic JSON schema generation from parameters
- OpenAI-compatible - Works with any OpenAI function calling endpoint
- Clean builder API - Fluent API for tool definition
- Hook integration - PreToolUse/PostToolUse hooks work in both modes
See examples/calculator_tools.rs and examples/auto_execution_demo.rs for complete examples.
Multimodal Vision Support
Send images alongside text to vision-capable models like llava, qwen-vl, or minicpm-v. The SDK handles OpenAI Vision API formatting automatically.
Simple Image + Text
use ;
// From URL
let msg = user_with_image?;
client.send_message.await?;
// From local file path (NEW!)
let msg = new;
client.send_message.await?;
// From base64 data
let msg = user_with_base64_image?;
client.send_message.await?;
// Control detail level for token costs
let msg = user_with_image_detail?;
client.send_message.await?;
Supported Image Sources:
ImageBlock::from_url(url)- HTTPS/HTTP URLs or data URIs (e.g.,data:image/png;base64,...)ImageBlock::from_file_path(path)- Local filesystem (automatically encodes as base64)- Supports:
.jpg,.jpeg,.png,.gif,.webp,.bmp,.svg - MIME type inferred from file extension
- File is read and encoded automatically
- Supports:
ImageBlock::from_base64(data, mime)- Manual base64 with explicit MIME type
Token Cost Management
Control image processing costs using ImageDetail levels:
ImageDetail::Low- Lower resolution (typically more cost-effective)ImageDetail::High- Higher resolution (typically more detailed analysis)ImageDetail::Auto- Model decides (balanced default)
⚠️ Token Costs Vary by Model:
OpenAI's Vision API uses ~85 tokens (Low) and variable tokens based on dimensions (High), but local models may have completely different token costs—or no token costs for images at all. The ImageDetail setting may even be ignored by some models.
Always benchmark your specific model instead of relying on OpenAI's published values for capacity planning.
Complex Multi-Image Messages
use ;
let msg = new;
Key Features:
send_message()API - Send pre-built messages with images viaclient.send_message(msg).await?- Automatic serialization - Images converted to OpenAI Vision API format
- Multiple sources - URLs, local file paths, or base64 data
- Backward compatible - Text-only messages still work with
send("text") - Data URIs supported - Base64-encoded images transmitted seamlessly
- Token cost control - Choose detail level based on use case
See examples/vision_example.rs for comprehensive working examples including local file paths.
Context Management
Local models have fixed context windows (typically 8k-32k tokens). The SDK provides utilities for manual history management—no silent mutations, you stay in control.
Token Estimation & Truncation
use ;
let mut client = new?;
// Long conversation...
for i in 0..50
// Check token usage
let tokens = estimate_tokens;
println!;
// Check if approaching limit (margin = 0.8 means warn at 80% of limit)
if is_approaching_limit
// Manually truncate when needed
if tokens > 28000
Recommended Patterns
1. Stateless Agents (Best for single-task agents):
// Process each task independently - no history accumulation
for task in tasks
2. Manual Truncation (At natural breakpoints):
use truncate_messages;
let mut client = new?;
for task in tasks
3. External Memory (RAG-lite for research agents):
// Store important facts in database, keep conversation context small
let mut database = new;
let mut client = new?;
client.send.await?;
// Save response to database
database.insert;
// Clear history, query database when needed
let truncated = truncate_messages;
*client.history_mut = truncated;
Why Manual?
The SDK intentionally does not auto-compact history because:
- Domain-specific needs: Copy editors need different strategies than research agents
- Token accuracy varies: Each model family has different tokenizers
- Risk of breaking context: Silently removing messages could break tool chains
- Natural limits exist: Compaction doesn't bypass model context windows
See examples/context_management.rs for complete patterns and usage.
Lifecycle Hooks
Monitor and control agent behavior at key execution points with zero-cost Rust hooks.
Quick Example
use ;
// Security gate - block dangerous operations
let hooks = new
.add_pre_tool_use
.add_post_tool_use;
// Register hooks in AgentOptions
let options = builder
.system_prompt
.model
.base_url
.hooks
.build?;
let mut client = new?;
Hook Types
PreToolUse - Fires before tool execution
- Block operations: Return
Some(HookDecision::block(reason)) - Modify inputs: Return
Some(HookDecision::modify_input(json!({}), reason)) - Allow: Return
Some(HookDecision::continue_())
PostToolUse - Fires after the tool completes and before the final result is committed
- Observational (tool already executed)
- Use for audit logging, metrics, result validation
- Return
NoneorSome(HookDecision::...)
Every hook event exposes history as Vec<serde_json::Value>, with one structured
JSON object per internal Message (role plus typed content blocks). Prompt and
pre-tool snapshots contain history up to that lifecycle point; post-tool snapshots
also include the completed tool call and its unmodified result.
UserPromptSubmit - Fires before sending prompt to API
- Block prompts: Return
Some(HookDecision::block(reason)) - Modify prompts: Return
Some(HookDecision::modify_prompt(text, reason)) - Allow: Return
Some(HookDecision::continue_())
Common Patterns
Pattern 1: Redirect to Sandbox
hooks.add_pre_tool_use
Pattern 2: Compliance Audit Log
let audit_log = new;
let log_clone = audit_log.clone;
// Note: add_post_tool_use consumes and returns Hooks (builder pattern) — always rebind
let hooks = hooks.add_post_tool_use;
Hook Execution Flow
- Hooks run sequentially in the order registered
- First non-None decision wins (short-circuit behavior)
- Hooks run inline on async runtime (spawn tasks for heavy work)
- Works with both Client and query() function
See examples/hooks_example.rs and examples/multi_tool_agent.rs for comprehensive patterns.
Interrupt Capability
Cancel long-running operations cleanly without corrupting client state. Perfect for timeouts, user cancellations, or conditional interruptions.
Interrupt Quick Example
use ;
use ;
async
Common Interrupt Patterns
1. Conditional Interruption
let mut full_text = Stringnew;
while let Some = client.receive.await?
2. Concurrent Cancellation
use Ordering;
let interrupt_handle = client.interrupt_handle;
let cancel_task = spawn;
while let Some = client.receive.await?
cancel_task.await?;
How It Works
When you call client.interrupt():
- Atomic signal - A thread-safe flag tells the receive loop to stop
- Stream cleanup -
receive()observes the flag, drops the active stream, and returnsOk(None) - Clean history - Partial manual responses are discarded instead of committing incomplete assistant messages
- Idempotent - Safe to call multiple times
- Cross-task safe -
interrupt_handle()lets another task cancel without locking theClient
See examples/interrupt_demo.rs for comprehensive patterns.
Practical Examples
Example agents demonstrating real-world usage:
Git Commit Agent
Analyzes your staged git changes and writes professional commit messages following conventional commit format.
# Stage your changes
# Run the agent
# Output:
# Found staged changes in 3 file(s)
# Analyzing changes and generating commit message...
#
# Suggested commit message:
# feat(auth): Add OAuth2 integration with refresh tokens
#
# - Implement token refresh mechanism
# - Add secure cookie storage for tokens
# - Update login flow to support OAuth2 providers
Features:
- Analyzes diff to determine commit type (feat/fix/docs/etc)
- Writes clear, descriptive commit messages
- Follows conventional commit standards
Log Analyzer Agent
examples/log_analyzer_agent.rs
Intelligently analyzes application logs to identify patterns, errors, and provide actionable insights.
# Analyze a log file
Features:
- Automatic error pattern detection
- Time-based analysis (peak error times)
- Root cause suggestions
- Supports multiple log formats
Why These Examples?
These agents demonstrate:
- Practical Value: Solve real problems developers face daily
- Tool Integration: Show how to integrate with system commands (git, file I/O)
- Structured Output: Parse and format LLM responses for actionable results
- Privacy-First: Keep your code and logs local while getting AI assistance
Why Not Just Use OpenAI Client?
Without open-agent-sdk (raw reqwest):
use Client;
let client = new;
let response = client
.post
.json
.send
.await?;
// Complex parsing of SSE chunks
// Extract delta content
// Handle tool calls manually
// Track conversation state yourself
With open-agent-sdk:
use ;
let options = builder
.system_prompt
.model
.base_url
.build?;
let mut stream = query.await?;
// Clean message types (TextBlock, ToolUseBlock)
// Automatic streaming and tool call handling
Value: Familiar patterns + Less boilerplate + Rust performance
Why Rust?
Performance: Zero-cost abstractions mean no runtime overhead. Streaming responses with Tokio delivers throughput comparable to C/C++ while maintaining memory safety.
Safety: Compile-time guarantees prevent data races, null pointer dereferences, and buffer overflows. Your agents won't crash from memory issues.
Concurrency: Fearless concurrency with async/await lets you run multiple agents or handle hundreds of concurrent requests without fear of race conditions.
Production Ready: Strong type system catches bugs at compile time. Comprehensive error handling with Result types. No surprises in production.
Small Binaries: Standalone executables under 10MB. Deploy anywhere without runtime dependencies.
API Reference
AgentOptions
builder
.system_prompt // System prompt
.model // Model name (required)
.base_url // OpenAI-compatible endpoint (required)
.tool // Add a single tool for function calling
.tools // Add multiple tools at once
.hooks // Lifecycle hooks for monitoring/control
.auto_execute_tools // Enable automatic tool execution
.max_tool_iterations // Max tool calls per query in auto mode
.max_tokens // Tokens to generate (unset: omitted, server decides); getter returns Option<u32>
.max_turns // Max conversation turns (default: 1)
.temperature // Sampling temperature (default: 0.7)
.timeout // Request timeout in seconds (default: 60)
.api_key // API key (default: "not-needed")
.build?
query()
Simple single-turn query function.
pub async
Returns a stream yielding ContentBlock items. Use futures::StreamExt to iterate.
Client
Multi-turn conversation client with tool monitoring.
let mut client = new?;
client.send.await?;
while let Some = client.receive.await?
Additional Client methods:
// Send a pre-built Message (e.g., with images)
client.send_message.await?;
// Access the AgentOptions this client was created with
let opts = client.options;
// Clear conversation history (resets to system prompt only)
client.clear_history;
// Look up a registered tool by name
if let Some = client.get_tool
// Obtain a shareable interrupt handle (Arc<AtomicBool>) for use across tasks
let handle = client.interrupt_handle;
MessageRole
Who sent a message. Used when constructing Message values directly.
use MessageRole;
System // Establishes context and instructions
User // Input from the human or calling application
Assistant // Response from the AI model
Tool // Results from tool/function execution
Message
Pre-built message values (for client.send_message()). Convenience constructors:
use ;
// Build a message manually (any role)
new // Convenience constructors — all return Self (infallible):
user // Vision constructors — return Result<Self>:
user_with_image
Message Types
ContentBlock::Text(TextBlock)- Text content from modelContentBlock::Image(ImageBlock)- Image content (for vision models)ContentBlock::ToolUse(ToolUseBlock)- Tool calls from modelContentBlock::ToolResult(ToolResultBlock)- Tool execution results
Tool System
use tool;
let my_tool = tool
.param
.build;
For full JSON Schema control, use .schema() instead of chaining .param() calls:
let my_tool = tool
.schema
.build;
ToolBuilder
The tool() function returns a ToolBuilder for fluent construction of tool definitions:
use ;
let t: Tool = tool
.param
.build;
Provider Configuration
Helper types and functions for mapping provider names to their default endpoints:
use ;
// get_base_url(provider: Option<Provider>, fallback: Option<&str>) -> String
let url = get_base_url; // http://localhost:1234/v1
let url_with_fallback = get_base_url;
// get_model(fallback: Option<&str>, prefer_env: bool) -> Option<String>
let model = get_model; // use provided model
let env_model = get_model; // prefer OPEN_AGENT_MODEL env var
OpenAI Wire Types
Low-level serialization types matching the OpenAI API request format, exported for callers that need to construct raw payloads:
use ;
OpenAIContent and OpenAIContentPart are used internally by the SDK when serializing messages to the OpenAI-compatible format. They are exported for advanced use cases where callers need to inspect or construct raw request content.
Error and Result Types
use ;
Error is the SDK's unified error type, covering HTTP errors, parse failures, configuration errors, and I/O errors. Result<T> is an alias for std::result::Result<T, Error>.
Newtype Wrappers
Strong-typed wrappers used internally by AgentOptions and exported for external use:
use ;
Retry Module
Exponential-backoff retry utilities, exported as a public module:
use ;
// Configure retry behavior (builder pattern)
let config = default // 3 attempts, exponential backoff
.max_attempts
.initial_delay_ms
.max_delay_ms
.backoff_multiplier;
// Retry any async operation
let result = retry_with_backoff.await?;
// Retry only transient failures; anything else fails on the first attempt
let result = retry_with_backoff_conditional.await?;
// Check if an SDK error is worth retrying
let retryable = is_retryable_error;
is_retryable_error treats network errors, timeouts, and stream errors as transient. API
errors are classified on Error::status_code(), which reads the status Error::Api carries as
structured data; the retryable set is 408, 429, 500, 502, 503, 504, 529. Everything else —
including API errors raised without a status — is non-retryable, so a 400 Bad Request fails
immediately rather than burning the full attempt budget.
use Error;
let err = api_status; // status: Some(429)
assert_eq!;
let err = api; // status: None
assert_eq!;
Prelude Import
For convenience, import the most commonly used types at once:
use *;
Hook Name Constants
String constants for hook event types are exported for use in custom registries:
use ;
Context Utilities
use ;
// Estimate tokens in message history (character-based approximation)
let tokens = estimate_tokens;
// Check if approaching a context limit (margin=0.8 means 80% of limit)
let near_limit = is_approaching_limit;
// Truncate history, keeping the last N messages (preserve_system=true keeps system prompt)
let truncated = truncate_messages;
Recommended Models
Local models (LM Studio, Ollama, llama.cpp):
- GPT-OSS-120B - Best in class for speed and quality
- Qwen 3 30B - Excellent instruction following, good for most tasks
- GPT-OSS-20B - Solid all-around performance
- Mistral 7B - Fast and efficient for simple agents
Cloud-proxied via local gateway:
- kimi-k2:1t-cloud - Tested and working via Ollama gateway
- deepseek-v3.1:671b-cloud - High-quality reasoning model
- qwen3-coder:480b-cloud - Code-focused models
Project Structure
open-agent-sdk-rust/
├── src/
│ ├── client.rs # Public client module docs/imports and fragment orchestration
│ ├── client/ # Query, send, send_message, setup, streaming, receive, history, state, and tests
│ ├── config.rs # Provider helpers (Provider, get_base_url, get_model)
│ ├── context.rs # Token estimation and truncation
│ ├── error.rs # Error types
│ ├── hooks.rs # Public lifecycle-hook module orchestration
│ ├── hooks/ # Hook events, decisions, handlers, registry, and tests
│ ├── lib.rs # Public exports and prelude module
│ ├── retry.rs # Retry logic with exponential backoff
│ ├── tools.rs # Public tool module orchestration
│ ├── tools/ # Tool, schema, builder, handler, factory, and tests
│ ├── types.rs # Public core-type module orchestration
│ ├── types/ # Options, messages, images, wire types, validated newtypes, and tests
│ ├── utils.rs # SSE parsing and tool call aggregation
│ └── utils/ # Utility unit tests
├── examples/
│ ├── simple_query.rs # Basic streaming query
│ ├── calculator_tools.rs # Function calling (manual mode)
│ ├── auto_execution_demo.rs # Automatic tool execution
│ ├── multi_tool_agent.rs # Production agent with 5 tools and hooks
│ ├── hooks_example.rs # Lifecycle hooks patterns
│ ├── context_management.rs # Context management patterns
│ ├── interrupt_demo.rs # Interrupt capability patterns
│ ├── git_commit_agent.rs # Production: Git commit generator
│ ├── log_analyzer_agent.rs # Production: Log analyzer
│ ├── advanced_patterns.rs # Retry logic and concurrent requests
│ ├── vision_example.rs # Multimodal: URLs, local files, base64
│ ├── vision_api_demo.rs # Vision API walkthrough
│ └── test_tool_serialization.rs # Tool call serialization verification
├── benches/
│ └── performance.rs # Criterion benchmarks (token estimation, history ops)
├── tests/
│ ├── integration_tests.rs # Core integration tests
│ ├── advanced_integration_test.rs
│ ├── auto_execution_test.rs
│ ├── backward_compatibility_test.rs
│ ├── client_image_serialization_test.rs
│ ├── debug_logging_test.rs
│ ├── defensive_validation_test.rs
│ ├── edge_cases_test.rs
│ ├── hooks_history_snapshot_test.rs
│ ├── hooks_integration_test.rs
│ ├── image_serialization_test.rs
│ ├── package_manifest_test.rs # Package exclusion coverage (CLAUDE.md, .markdownlint.json)
│ ├── ci_workflow_policy_test.rs # GitHub CI runner, coverage, and security policy guards
│ ├── security_bypass_test.rs
│ ├── send_message_test.rs # Manual-mode history regression (v0.6.2)
│ ├── source_file_size_test.rs # Repository Rust hard-limit guard
│ └── tool_call_content_test.rs # Tool call serialization tests
├── .github/
│ ├── dependabot.yml # Grouped weekly Cargo dependency updates
│ └── workflows/
│ ├── ci.yml # GitHub CI (fmt, clippy, MSRV, Linux/macOS stable + beta matrix, security audit, docs, LLVM Tarpaulin coverage, benchmarks)
│ └── scheduled-audit.yml # Scheduled dependency audit
├── .markdownlint.json # Markdown lint rules (disable MD013, allow duplicate sibling headings)
├── Cargo.toml
├── Cargo.lock
├── CHANGELOG.md
└── README.md
Examples
Production Agents
git_commit_agent.rs– Analyzes git diffs and writes professional commit messageslog_analyzer_agent.rs– Parses logs, finds patterns, suggests fixesmulti_tool_agent.rs– Complete production setup with 5 tools, hooks, and auto-execution
Core SDK Usage
simple_query.rs– Minimal streaming query (simplest quickstart)calculator_tools.rs– Manual tool execution patternauto_execution_demo.rs– Automatic tool execution patternvision_example.rs– Multimodal image support (URLs, local files, base64)vision_api_demo.rs– Vision API walkthrough with token cost noteshooks_example.rs– Lifecycle hooks patterns (security gates, audit logging)context_management.rs– Manual history management patternsinterrupt_demo.rs– Interrupt capability patterns (timeout, conditional, concurrent)advanced_patterns.rs– Retry logic and concurrent request handlingtest_tool_serialization.rs– Verifies tool call serialization (seeexamples/test_tool_serialization.rs)
Documentation
- API Documentation
- Python SDK - Reference implementation
- Examples - Comprehensive usage examples
Testing
# Run all tests
# Run with output
# Run specific test
# Mutation sweep (must report zero survivors)
Test Coverage:
- 124 unit tests (lib)
- 113 active integration tests across 22 test files (12 additional tests are
#[ignore]d by default)- Hooks integration tests
- Auto-execution tests
- Image serialization tests
- Defensive validation tests
- Backward compatibility tests
- Advanced integration tests
- Edge cases, security bypass, debug logging, send message, tool call content tests
- Streaming, retry classification, and
max_tokensregression tests
- 153 active doctests (17 additional doctests are
ignored)
Total: 390 active unit, integration, and documentation tests
Mutation testing is part of the gate, not an optional extra: a green suite proves the tests ran, not that they would notice if the code were wrong. CI runs the full sweep on every push. To run the same check before each commit:
The hook runs cargo fmt --check, cargo clippy --all-targets -- -D warnings, cargo test,
and a cargo mutants --in-diff sweep scoped to the staged Rust changes.
Requirements
- Rust 1.85+
- Tokio 1.50+ (async runtime)
- serde, serde_json (serialization)
- reqwest (HTTP client)
- futures, tokio-stream (async streams)
- eventsource-stream (SSE parsing)
- async-trait (async trait support)
- thiserror 2.0 + anyhow 1.0.103+ (error handling)
- log 0.4.29+ (logging)
- base64 0.23 (multimodal image encoding)
- wiremock 0.6 (dev-only: HTTP mocking for streaming and wire-format tests)
- cargo-mutants 27.1.0 (dev-only: mutation testing gate)
- rand (retry jitter)
License
MIT License - see LICENSE for details.
Acknowledgments
- Rust port of open-agent-sdk Python library
- API design inspired by claude-agent-sdk
- Built for local/open-source LLM enthusiasts
Repository Hosting
GitHub is the canonical repository and CI/release host. Any family Gitea copy is a passive Git mirror and does not run a separate required Actions pipeline.
Status: v0.7.0 - end-of-stream flushing for servers that omit finish_reason, structured Error::Api with status-based retry classification, no implicit max_tokens cap, a mandatory mutation-testing gate, plus transport-boundary-safe SSE streaming, complete structured hook history, source-size architecture guards, Rust 1.85-compatible dependencies, GitHub-hosted Linux/macOS CI, non-locking cancellation, and multimodal image support
Star this repo if you're building AI agents with local models in Rust!