LaunchedEditorial Listing

Pizza Bot

Amazon · Pizza Bot: Open-Source Inbox for Background AI Agents

Open Pizza Bot

Pizza Bot is a free, open-source (Apache 2.0) app from Amazon for running long AI agent tasks in the background. You start, schedule, or trigger a task by webhook, and results land in an email-style inbox with Unread and Action queues for review and approvals. It suits technical users who want local-first, model-agnostic background agents they control.

PricingFree
Setupmedium
Runs onDesktop · Web · Self-hosted
Open sourceYes
DocsYes
CategoryProductivity
Open SourceBackground AgentsInboxLocal-FirstModel-AgnosticHuman-in-the-LoopMCPLangGraph

Best for

Developers and technical users who want to hand long-running tasks to agents, review results and approvals later in an inbox, and keep data and model choice under their own control

Not ideal for

Non-technical users who want a hosted assistant, teams that need vendor support or an SLA, and anyone who needs agents to keep working without running their own always-on machine

Who it's for

Developers and technical users who want local-first background agents with an inbox for results and approvals

Capabilities

  • Inbox with All, Unread, and Action queues, plus folders for organizing threads
  • Tasks start manually, on cron schedules from the Automations screen, or from secret-protected webhooks
  • Checkpointed runs (LangGraph with SQLite) that survive client disconnects and keep going when you switch conversations
  • Built-in tools to list, read, write, edit, and search files in its own scratch space and in folders you grant
  • Sandboxed JavaScript interpreter with no network or filesystem access
  • Browser automation through a bundled Playwright MCP plugin
  • Skills (SKILL.md) that run as tool-scoped specialist subagents, with transcripts and tool calls shown in the Activity panel
  • Per-tool approval gates with approve, edit, or reject decisions
  • Model providers: Amazon Bedrock, Anthropic, Google Gemini, OpenAI, OpenRouter, and Ollama, with custom base URLs for compatible endpoints
  • MCP servers, Agent Skills, and plugins that bundle both
  • Explicit folder grants, read-only by default, with no default access to your home directory
  • Electron desktop app for macOS, Windows, and Linux, plus a browser client, terminal CLI, and standalone backend for Docker, Compose, or Kubernetes

Limitations

  • A community project with no AWS support or service-level agreement
  • Young: v1.0.0 shipped on September 8, 2026, and the authors say its skill and MCP ecosystem is not yet as rich as the one used inside Amazon
  • Agents run only while the api-server process is running. Quitting the desktop app stops its embedded server and ends that server's runs, so always-on work needs a machine or server that stays up
  • MCP servers and plugins run as trusted code with your user's permissions
  • A data root supports one backend process on local storage and cannot be shared across replicas or hosts
  • The API listener serves plain HTTP; remote access needs a reverse proxy with TLS or an SSH or VPN tunnel
  • Only the macOS builds are signed, so Windows and Linux may ask you to confirm the install, and on Linux without a compatible secret store, saved provider keys may not be meaningfully encrypted
  • No hosted version is offered; you supply and pay for your own model provider

Use cases

  • Starting a research or writing task, closing the window, and reviewing the result in Unread later
  • Scheduling a daily briefing or report as a cron automation
  • Kicking off an agent run from another system through a webhook trigger
  • Letting an agent work through files in a granted project folder, with a skill that requires approval before it writes
  • Running the backend on an always-on server and connecting from the desktop app, browser, or CLI

Our take

Pizza Bot is built for work that takes long enough that you do not want to watch it. The inbox, with finished work in Unread and approvals in Action, plus cron and webhook triggers, makes background agents easier to manage than a stack of chat tabs. Its SECURITY.md also spells out its data and network boundaries in detail. It is still a young community project, though, with no AWS support and a thin extension ecosystem, and always-on use means running and securing your own backend. It suits technical users comfortable with that more than teams looking for a supported product.

Who should use it

Developers and technical users who want to delegate long-running or scheduled tasks and review results later, people who want local-first agents with their choice of provider, and teams willing to run a small backend themselves.

Who should skip it

Users who want a hosted, zero-maintenance assistant, teams that need vendor support or an SLA, and anyone who is not comfortable reviewing the MCP servers and plugins they install.

Strengths

  • Free and open source under Apache 2.0
  • Inbox model with Unread and Action queues suits long, asynchronous tasks
  • Cron and webhook triggers start work without an open conversation
  • Bring your own provider, including Bedrock and local models through Ollama
  • Local-first: data stays on your machine, localhost binding by default, no telemetry

Weaknesses

  • No AWS support or SLA
  • Young project with a small extension ecosystem
  • Always-on work requires running your own backend
  • MCP servers and plugins run with your user's permissions

Pizza Bot pricing

Open Source

Free

  • Apache 2.0 desktop app, browser client, CLI, and backend
  • Bring your own model provider or local model

Note: Pizza Bot is free. Costs come from the model provider you connect and any server you run the backend on.

Technical specs

Available models

Amazon BedrockAnthropicGoogle GeminiOpenAI (and OpenAI-compatible endpoints)OpenRouterOllama (local models)

Where Pizza Bot excels

Asynchronous research and drafting

You start the task and move on. The result lands in Unread, and any decision the agent needs lands in Action instead of blocking a chat window.

Scheduled and event-driven agent runs

Cron automations and secret-protected webhooks start tasks without an open conversation, and checkpointed runs survive disconnects.

Controlled file work

Folder grants are explicit and read-only by default, and skills can require approval, with the option to edit arguments, before a tool runs.

Pizza Bot vs. competitors

Pizza Bot vs. OpenClaw

OpenClaw is a self-hosted assistant you talk to through messaging apps such as Telegram, WhatsApp, and Slack. Pizza Bot is organized around an inbox of background tasks with Unread and Action queues rather than chat channels.

Pizza Bot vs. Hermes Agent

Hermes Agent is a self-hosted agent from Nous Research focused on persistent memory and learning skills from experience. Pizza Bot focuses on asynchronous task delivery, with triggers, checkpointed runs, and per-tool approvals surfaced in an inbox.

Pizza Bot vs. Paperclip

Paperclip orchestrates coding and other agents you already use as a company with budgets and an org chart. Pizza Bot is the agent itself, with its own runtime, tools, and skills, delivered through an inbox.

Pizza Bot vs. Claude Cowork

Claude Cowork is Anthropic's hosted task-execution feature inside the Claude app, tied to paid Claude plans. Pizza Bot is free, local-first, and works with several model providers, but you run it yourself.

Frequently asked questions

What is Pizza Bot?

Pizza Bot is an open-source app for running AI agents in the background. You start, schedule, or webhook-trigger a task, and finished work appears in an Unread queue while tasks that need approval or an answer wait in an Action queue.

Is Pizza Bot an AWS service?

No. It was developed at Amazon and released under Apache 2.0 on September 10, 2026, but AWS describes it as a community project with no AWS support or service-level agreement.

Which models does Pizza Bot support?

Amazon Bedrock, Anthropic, Google Gemini, OpenAI, OpenRouter, and Ollama for local models. OpenAI and Anthropic also accept custom base URLs for compatible endpoints.

Does Pizza Bot keep working when I close the app?

Runs continue when you switch conversations, reload, or a client disconnects, as long as the api-server process keeps running. Quitting the desktop app stops the server it started and ends its runs, though checkpoints mean you lose only the step in progress. For work that should run while your laptop is off, run the standalone backend on an always-on machine or server.

Can Pizza Bot be self-hosted?

Yes. Besides the desktop app, the standalone backend can run on a server with Docker, Compose, or Kubernetes and serve the browser client, the CLI, or a remote desktop app. Non-localhost binding requires a bearer token and an origin allowlist.

Why is it called Pizza Bot?

The name comes from Amazon's two-pizza teams, the idea of small, autonomous teams.

Integrations & fit

Amazon BedrockAnthropicGoogle GeminiOpenAIOpenRouterOllamaMCPPlaywrightDockerKubernetes
Good fit forSolo / individual, Startup / small team
Pricing modelFree· No cost to start
See pricing on Pizza Bot →

Alternatives to consider

About Pizza Bot

Pizza Bot changes where you wait for an agent. Instead of watching a chat window, you start a task and move on. Finished work lands in Unread, and tasks that need a decision or approval wait in Action. All keeps the full history, and folders organize threads without hiding them from those queues. Tasks can be started by hand, on a cron schedule from the Automations screen, or by a webhook protected by its own secret. The runtime is built on DeepAgents and LangGraph, with checkpoints in SQLite, so a run survives a client disconnect. The agent can list, read, write, edit, and search files in its own scratch space and in folders you grant, run code in a sandboxed JavaScript interpreter with no network or filesystem access, drive a browser through the bundled Playwright MCP plugin, and keep optional long-term memory. Skills (SKILL.md files) become specialist subagents with scoped tool access, and you can follow each one's transcript and tool calls in the Activity panel. A skill can require approval for specific tools, and the approval card lets you approve, edit the arguments, or reject. You bring your own model: Amazon Bedrock, Anthropic, Google Gemini, OpenAI, OpenRouter, or Ollama, with custom base URLs for OpenAI- and Anthropic-compatible endpoints. It ships as an Electron desktop app for macOS, Windows, and Linux, and the same backend serves a browser client, a terminal CLI, and standalone deployments with Docker, Compose, or Kubernetes. Data stays in a local folder (~/.pizza-bot-oss by default), the server binds to localhost unless you configure a token and allowed origins, and the project includes no telemetry. The tradeoffs are maturity and scope. AWS released it on September 10, 2026 as a community project with no AWS support or SLA, and its authors say its skill and MCP ecosystem is still young. Agents run only while the api-server process is running, and quitting the desktop app stops the server it started, so always-on work needs a machine that stays up. MCP servers and plugins run as trusted code with your user's permissions.

Updates from Pizza Bot

New Featurev1.1.0 adds a configurable tool call limit

Pizza Bot 1.1.0 added a configurable tool call limit and fixed desktop sidecar startup and crash reporting.

LaunchAWS open-sources Pizza Bot

AWS introduced Pizza Bot on the AWS Open Source Blog as an Apache 2.0 inbox for AI agents that work in the background, developed at Amazon and released as a community project.

Are you the founder? Claim this listing →