Meet adam, a production-shaped starting point for eve agents, with observability, evals, dependency automation, and a 95% coverage gate already wired together.
adam gives your agent memory, document search, and chat history on Upstash Redis, sends
its logs and AI traces to PostHog and Braintrust, and runs lint, type checks, tests, and
a real eve build in CI. You fork it and delete what you do not need, instead of
assembling it a second time.
The button asks for two values and shows a demo card for a live deployment, where conversations are recorded. Deploy to Vercel explains both.
Quick start · Configuration · Observability · Capabilities · Contributing · eve docs
The button above clones the repository and asks for two values: BRAINTRUST_API_KEY and
POSTHOG_PROJECT_TOKEN. The build fails until both are set. The PostHog host defaults
to the US address, https://us.i.posthog.com: set POSTHOG_HOST for a project in
another region.
Redis needs no value typed in: the button creates an Upstash Redis store from the
Vercel Marketplace, which sets KV_REST_API_URL and KV_REST_API_TOKEN on the
project. At that step the form asks you to choose a plan and a region for the store. A
team that has not added the Upstash integration before may also be asked to
accept its terms.
The model asks for nothing: it runs through the Vercel AI Gateway, which a Vercel deployment reaches with its own project credentials and bills to the team's AI Gateway credits.
See Configuration for what each value is.
A deployed copy is closed: until you add a sign-in provider or set
ALLOW_ANONYMOUS_ACCESS=true, it answers only the project's own deployments and its
Vercel team. To let people in, register a
Sign in with Vercel app on your team and
set its client ID as VERCEL_APP_CLIENT_ID. Anyone who signs in is then a named user
with their own memory and chat history, and pnpm connect <url> signs in from a
terminal and opens eve's client. It takes no vendor account, no secret, and no package;
the cost is that only someone with a Vercel account can sign in. A signed-in user's
conversations are traced in full, like every conversation.
Signing in is access, not only an identity. A signed-in caller can run commands in the
agent's sandbox, read and write files there, fetch web pages, and spend the model
budget, and an app admits any Vercel account unless you restrict it to your team.
Decide who may sign in, and set a spend limit, first.
ALLOW_ANONYMOUS_ACCESS=true opens a deployment to anyone instead, or as well: a
visitor who does not sign in can chat and has none of those tools, and a signed-in
caller keeps the shell, file, and web-fetch tools. See
Sign-in and
Anonymous access before opening it.
The button also shows a demo card for a live deployment of this repository at https://adam-umber.vercel.app, which has been opened that way. It has no chat page in the browser: the page at that address shows eve's status and the terminal connect command. Chat with it from eve's terminal client, without signing in:
npx eve remote connect --url https://adam-umber.vercel.app- Conversations are recorded. Your messages and the model's replies are sent in full to Braintrust and PostHog, so do not type anything private.
- Without signing in, you can chat, and nothing else. The agent remembers what you tell it within a session and can search the deployment's shared document index. It has no shell, file, or web tools for a visitor who does not sign in, and it takes 20 messages a minute from one address.
- A caller who signs in with Vercel gets more. They get the sandbox shell, the file tools, and web fetch, with their own memory and chat history.
- It runs under a spend limit. When the limit is used up, the demo can be unavailable.
Requires Node.js 24.x and pnpm 12.x.
Click Use this template above, or clone it:
git clone https://github.com/ahcarpenter/adam.git
cd adam
pnpm installFill in the environment - startup validates every variable, in every mode:
cp env.example .env.localEvery variable without a default must be filled: the Upstash Redis URL and token (under
the UPSTASH_REDIS_REST_ names or the Vercel Marketplace's KV_REST_API_ names),
BRAINTRUST_API_KEY, and POSTHOG_PROJECT_TOKEN (or the Vercel Marketplace's
NEXT_PUBLIC_POSTHOG_PROJECT_TOKEN and NEXT_PUBLIC_POSTHOG_HOST). See
Configuration for the full table.
The model runs through the Vercel AI Gateway, so a local run also needs a gateway
credential, which startup does not check. The simplest is an AI Gateway API key: set
AI_GATEWAY_API_KEY in .env.local. A linked Vercel project works too.
Model access covers both paths, and what a Vercel
team needs before the first call.
Then start the agent:
# TUI at http://127.0.0.1:2000
pnpm dev- Agent runtime - eve with the AI SDK, the model routed through the Vercel AI Gateway: no provider key, and one optional, validated variable to change the model.
- Memory, RAG, and chat history - Upstash Redis via AgentKit, plus per-caller rate limiting and a tool cache. See Capabilities.
- Sign-in - optional Sign in with Vercel, verified with eve's own OIDC verifier, and a terminal helper that signs in through the browser. Off until a deployment sets one public value. A signed-in caller gets the agent's tools, not only an identity. See Sign-in.
- Observability - structured winston logs to PostHog, AI traces to Braintrust and PostHog LLM analytics, OTel metrics to any OTLP collector. The design, the three alerts worth paging on, and how to verify the pipeline are in docs/observability.md.
- Quality gates in CI - Biome, Prettier,
tsc, a realeve build, Knip, and Vitest at 95% project and patch coverage through Codecov. - Dependency automation - Renovate, with the eve/AgentKit contract pairing already
encoded so a bump cannot silently break
eve build. - Evals - deterministic eval suites under
evals/, reporting to their own Braintrust project.
- Fails fast, everywhere. An incomplete environment stops the process at module load - in local dev too, not only in production.
- Instrumentation cannot take down the agent. Every hook runs inside
neverThrow. eve 0.68 already logs a thrown hook and carries on with the turn, so the wrapper is a precaution there. - Signals earn their place. Each metric and log line maps to a question on-call actually has to answer; cardinality stays in logs and traces, not in metric labels.
- CI builds, not just typechecks.
tscdoes not run eve's compiler, so CI runseve build- otherwise extension contract breaks are invisible until deploy. - The reasoning is written down. Comments and docs say why a decision was made, not what the line does.
pnpm dev # eve dev (TUI at http://127.0.0.1:2000)
pnpm build # eve build
pnpm typecheck # tsc
pnpm lint # biome lint --write . (auto-fix)
pnpm lint:check # biome lint . (no writes)
pnpm lint:ci # biome ci . (lint + format, CI mode)
pnpm format # biome check --write + prettier --write (md/yml/css)
pnpm format:check # biome check + prettier --check
pnpm test # vitest run
pnpm test:coverage # vitest run --coverage (95% thresholds)
pnpm eval # eve eval
pnpm connect <url> # sign in with Vercel, then open eve's client on a deployed agent
pnpm knip # dead code / unused dependency scan
pnpm build also prepares the agent's sandbox, as eve 0.68 does on every build. Off
Vercel, eve picks Docker when the Docker daemon answers within about 5 seconds, and
otherwise falls back to microsandbox (Apple Silicon macOS, or Linux with KVM) or else
just-bash, neither of which adam installs, so the build fails.
Either have Docker running, or run pnpm build --skip-sandbox-prewarm for a
compile-only check, which is what CI runs. Do not deploy output built that way: it may
not be able to start its sandbox.
- Configuration - environment variables and one-time setup
- Observability design - signals, alerts, verification
- Upstash capabilities - memory, RAG, rate limiting, tool cache
- Spec, plan, and task history
- eve documentation
Contributions are welcome - see CONTRIBUTING.md to get started, and SUPPORT.md for where to ask questions.
This project follows the Contributor Covenant. Security vulnerabilities go through SECURITY.md, never the issue tracker.
MIT - see LICENSE.