Fungi architecture
How Teams, Agents, Computers and Apps fit together, and where their work runs.
Fungi is a workspace for people and AI Agents. A Team owns its members, Agents, Computers, Apps and bill. You reach that workspace through the Hub, Fungi’s account and product server.
The resources you work with
Section titled “The resources you work with”| Resource | Responsibility |
|---|---|
| Team | Membership, shared resources, permissions and billing administration |
| Agent | Accepted work, conversations and their saved history |
| Computer | Workspace files, commands, processes and port previews |
| App | A user interface and optional backend, using granted Team resources |
An Agent’s conversation is a Session. Starting another Session keeps the same Agent, attached Computers and Home choice. Grove shows those conversations; Inkcap and Shed work on the selected Computer’s files and processes.
An App Release captures one immutable version of its code and assets. The Team’s installation and grants decide which Release and resources it can use. Building a Release, publishing it and granting access are separate actions. Tourtois is the default dashboard and an ordinary forkable App, using the same grants as other Apps.
Where Fungi runs
Section titled “Where Fungi runs”celld runs the Hub and workload services on operator-managed hosts. It is a Workers-compatible runtime: services use Worker request handling and durable state owners. Each Team’s shard has a separate process, Unix user and network namespace on a shared kernel. An idle Team has no resident shard process.
Hosted Computers execute in Firecracker microVMs, which have their own guest kernel. Files persist independently of a running process. Sleeping a Computer stops its processes; waking it does not resume a stopped server.
Cloudflare supplies DNS and the public edge, email, AI Gateway, image and artifact services. The static marketing and documentation sites run there too. The Hub reaches those supplier services through a narrow edge service.
Identity and permission
Section titled “Identity and permission”People sign in on the Hub with an email code, magic link or GitHub. Better Auth owns accounts and sessions in PostgreSQL. Global Team storage owns Team handles and current membership; a signed-in account is checked against those facts before acting on a Team.
Each Team opens at <team>.fungi.computer. A one-time hand-off from the Hub
gives that host its own host-only session. Hub sign-out ends the Team sessions
linked to that browser session, leaving independent devices signed in. The
hostname selects the Team; it does not grant access.
App content runs on a separate App domain, apart from the Team host’s sign-in. The Hub supplies capabilities for the selected App Release and resource. The App receives the allowed operations, not Team or provider credentials. Guest execution reaches Team authority through the broker, which checks the granted actor, Team and operation.
Durable work
Section titled “Durable work”The owner of a record commits it before acknowledging acceptance. A saved prompt is accepted work; a reply or terminal outcome tells you whether that work finished. Live events notify clients, while the owning record remains the authority after a reconnect.
Team owners send versioned changes to resource owners through Post, durable addressed delivery. Delivery can remain pending after the Team’s change commits. Resource owners maintain local permission projections so ordinary execution stays within its admitted scope. Provider credentials remain with their custodian and are added only at the trusted provider request.
The modules behind the product
Section titled “The modules behind the product”| Module | Job |
|---|---|
| Shiitake | Agent Sessions, runs, saved history and client events |
| Mule | The model and tool execution loop |
| Mycelium | Acquires and releases the capabilities available to a run |
| Forage | Searches and describes those capabilities |
| Watchdog | Durable job execution and recovery |
| BirdDog | Addressed Agent work and replies |
| Carrier | Email delivery and the Post delivery module |
| Agar | Typed capabilities between an App and its host |
| Hypha | Computer and runtime-host communication |
| Corral | Optional Herdr activity reporting for Shiitake clients |
| Veil | Provider credential custody and egress policy |
| Parakeet, Caps, Stipe and Maosaico | Conversation UI, controls, visual tokens and layout |
These modules use Effect 4 internally. Public adapters expose ordinary Promise and stream interfaces where appropriate; an App uses the host’s granted SDK rather than calling private state owners.
The local Fungi CLI composes the Agent runtime on your machine. One Fungi account login supports hosted models and Team MCP; model billing and Computer authorization remain separate choices. Running a local Agent does not require operating the hosted Hub.