Devplane

Local-first · One binary · MIT OR Apache-2.0

Let the agent work.
Know when it is done.

Devplane tells you when an agent's work is actually done. Run any agent that speaks the Agent Client Protocol in its own worktree, verify its change with your own checks run outside the agent, see the weakened tests first, and keep the record of who decided what while you were not looking.

It sits on top of your tools: the spec is your spec tool’s folder, the checks are your commands, the isolation is git worktree. Delete Devplane and the project still builds.

curl -LsSf https://github.com/hupe1980/devplane/releases/latest/download/devplane-installer.sh | sh

macOS (Apple Silicon) and Linux. Windows through npm install -g devplane; anything else with cargo install. Every platform.

$ devplane change start "password reset" --spec specs/142-password-reset
$ devplane change show c-3f9a
password reset  c-3f9a
  state      ✓ verified
  gates      `check` exited zero against the working tree as it stands
  branch     change/password-reset-3f9a1c
  spec       specs/142-password-reset at 3f9a1c40b7e2d518 over 4 documents
  tasks      11 ticked · 9 seen by a passing check
$ devplane change offer c-3f9a
A change open in the Devplane workbench: verified against the working tree, with one check weakened beside it, its lifecycle, six views and evidence
The review leads with a check the agent weakened — a skipped test — before anything else

The loop

  1. SpecifyThe spec you already write — Spec Kit, OpenSpec, Kiro, or plain Markdown.
  2. Start a changeAn isolated worktree, any ACP agent, the tasks you chose. One prompt to several repositories if you like.
  3. SuperviseQuestions, permissions and red checks, across every project, most urgent first.
  4. VerifyYour own check passed against the tree exactly as it stands — or it is not verified.
  5. Review and offerWeakened checks read first, then a pull request with a certificate anyone can re-run.

What it does

A workbench, not a dashboard

Laid out like your editor: a palette on ⌘K, an activity bar, tabs, a bottom panel. A change opens as a document with six views — Overview, Tasks, Review, Gates, Ledger, Agent — and the review is a file tree beside the diff, walked with j/k.

The workbench

Verified means verified

Your committed gate, run by Devplane rather than the agent, against a digest of the working tree — uncommitted files included, hashed byte for byte. Touch one file and it is stale. Only the gate that defines done can make a change verified.

Verified done

Weakened checks first

A skipped test, a removed assertion, a test that asserts nothing, a loosened tolerance, an edited CI file: read before anything is green, and the offer waits until you have. Your spec folder — Spec Kit, OpenSpec, Kiro — says what was asked for.

Review before you merge

Any ACP agent, and the ones you already run

Drives Claude Code, Codex, GitHub Copilot, OpenCode and Gemini CLI, or any agent you name in one file. Watches the sessions you started yourself, and says which ones it cannot see.

Driving agents

Devplane never approves

It can refuse a tool call and put one in front of you; it cannot approve one. Rules use Claude Code’s syntax, reach through shell tricks, and fail closed when the file will not load. An agent cannot answer its own permission.

Permissions

Who decided

Every decision is on the record with its authority — a person, a rule, a timer, nobody, or Devplane doing what your project wrote down. “Refused” is not an answer; “refused by Bash(rm *)” is.

The decision log

Principles

Local-first

No account, no cloud relay, no telemetry of our own. Loopback only, with a token in a file only you can read. Nothing starts unless you start it.

On top, never the only way in

Plain files your agents read without Devplane: the spec folder, your gate commands, git worktree, AGENTS.md.

Documented interfaces only

Hooks, OpenTelemetry, the session roster, the Agent Client Protocol. No transcript scraping.

The model is never the authority

Gates, policy and the inbox are functions of trusted inputs. None of them calls a model.

Evidence over claims

An agent saying it is done is an input. Exit codes against a tree digest are the verdict, and a stranger can re-run them.

Try it on the machine you already have

One binary. It finds your running sessions on the first run.

curl -LsSf https://github.com/hupe1980/devplane/releases/latest/download/devplane-installer.sh | sh && devplane ls

Quickstart Read the docs