The Smarter Project v0.15.0 Documentation

Project Website Made with ❤️ by Contributors Forums Video Tutorials DockerHub ArtifactHub Contribute Donate AGPL-3 License

The Smarter Project is an open source, cloud-native platform and developer framework for building sophisticated AI applications without writing a single line of Python. An application that searches the web, queries your databases, calls your APIs, uses the tools of any MCP server, and defends itself against prompt injection and data leaks is described in one short YAML file, and deployed with one command.

Quick Start: up and running on your desktop in about 10 minutes

With Docker Desktop installed:

git clone https://github.com/smarter-sh/smarter-deploy.git
cd smarter-deploy
make            # creates a .env file. Add your credentials to it before continuing.
make init       # pulls the Docker containers and seeds the platform with test data
make run        # starts the platform

Then open http://localhost:9357/login/ and log in as admin@smarter.sh with password smarter (change it after your first login), and install the Smarter CLI.

See the Quick Start Guide for step-by-step instructions with screenshots.

No code. Just a manifest.

Until now, an AI application that combines retrieval, tool calling, and safety controls has been a software project: Python code for every API client, database query, and MCP session, glue code to route tool calls, and custom middleware to filter what goes in and out of the model. That code has to be written, tested, secured, and maintained by engineers, and every change to the application is a change to the code.

Smarter replaces all of it with a Smarter Manifest (SAM), a plain YAML file that declares what an application is, rather than programming how it works. Every Resource in Smarter, from an Account to an LLMClient to a Guardrail, is created the same way:

smarter apply -f my-ai-application.yaml

This changes who can build AI applications, and how fast:

  • No programming required. Prompt engineers, business analysts, and product managers can build, read, and change production AI applications themselves. The manifest is the application.

  • Sophistication is a list, not a project. Giving an application web search, a SQL database, an MCP server, or a prompt injection guardrail means adding one line to its manifest.

  • One way to do everything. There is no resource-specific SDK to learn and no API convention to memorize. If you can write one manifest, you can write them all.

  • Infrastructure as code for AI. Manifests are versioned, diffed, reviewed in pull requests, and deployed from CI/CD, like the rest of your infrastructure.

Every way to reach external data

An LLM is only as useful as the information it can get to. Smarter connects your AI applications to external data through every approach in use today. Each one is a Resource that you declare in a manifest, and none of them requires you to write code:

  • Remote APIs: an API Plugin calls your REST services, and authenticates with credentials that are stored as Secrets, which the model never sees.

  • Remote SQL: a SQL Plugin runs parameterized queries against your databases through a managed Connection.

  • MCP servers: an MCPClient gives your application the tools of any server in the Model Context Protocol ecosystem.

  • The web: a WebsearchPlugin searches the web and reads the pages it finds.

  • Expertise: a SkillPlugin packages instructions and reference material that teach a model how to do a specific job well.

  • Your own documents: a Vectorstore provides semantic search over the content that you load into it.

Governed from the first prompt

Instructions in a system prompt are requests, not controls. A Smarter Guardrail is a deterministic software control that inspects every message on its way to the model, and every reply on its way back. Guardrails moderate abusive and unsafe content, redact personal data and leaked secrets, and stop prompt injection, jailbreaks, and code injection from bad actors, whatever the model would have done. Like everything else in Smarter, a guardrail is declared in a manifest and added to an application by name, with no code. Every intervention is recorded, so each Prompt can be traced back through the guardrail checks, tool calls, and model connection that produced it, to the Account and budget that authorized it.

Contained by design

There is growing concern about AI agents that go rogue: agents that run code they were never meant to run, reach systems they were never meant to reach, and break out of the sandboxes that were supposed to contain them. Smarter was designed from the start on the assumption that a model will eventually try to do something it should not. It does not rely on the model to behave. It makes the dangerous actions impossible:

  • No code execution. Smarter never runs code written by a model, or by a third party, on its own servers. A SkillPlugin provides instructions, not programs, and Smarter rejects any MCPClient that would launch an MCP server as a local process. Remote MCP servers run on their own infrastructure, not on yours.

  • Nowhere to escape to. In production, Smarter runs on private VPC networks wherever possible, and Calico network policies on Kubernetes control which ports and services each workload can reach. Containers run as a non-root user. A model cannot open a connection that the network will not carry, so breaking out is not a matter of clever prompting. It is not technically possible.

  • Hardened outbound requests. When a plugin fetches a web page, it uses https on port 443 only, to public addresses only, with every redirect validated. A model cannot direct Smarter to reach your internal network or your cloud provider’s instance metadata.

  • Role-based access at every layer, from Kubernetes and the cloud account, to the Account and user, to each individual Resource. A model can use only the plugins, MCP clients, and connections that its manifest names, and a manifest can name only the Resources that its author is permitted to use.

  • Credentials the model never holds. API keys and passwords are stored as encrypted Secrets, and are applied by the platform when it makes a request. They never appear in a prompt.

  • Guardrails on both sides of the model, which stop prompt injection and jailbreaks on the way in, and stop leaked secrets and personal data on the way out.

  • Budgets and a complete audit trail. Every request is authorized against the account’s budget, and every prompt, tool call, and guardrail intervention is recorded in the Smarter Journal.

See Security for details.

Composed like an orchestra

These capabilities are designed to work together, and you conduct them from the manifest. A single LLMClient manifest combines a model from any provider with the plugins, MCP clients, and guardrails that it needs, simply by listing them by name. Each piece plays its own part, and Smarter handles the tool calling, authentication, guardrail enforcement, and auditing in between. For example, a research analyst can search the web, read PDF reports, and have its citations checked before they reach the user. A customer support agent can draft on-brand replies behind nine guardrails for safety and privacy. A data analyst can answer business questions in SQL, check syntax against the database’s own documentation over MCP, and never leak personal data. When one application is not enough, an Orchestrator coordinates several LLMClients in sequential, parallel, supervisor/worker, routing, and voting/debate workflows, and it too is just a manifest.

Smarter ships with built-in LLMClients like these, so that you can see the whole ensemble at work on a fresh installation, and then copy the manifests to start your own.

Built for teams

AI applications are built by teams, not individuals, so Smarter builds ownership and sharing into every Resource. Each LLMClient, Plugin, MCPClient, Guardrail, Secret, and Connection is owned by the person who created it, and is shared automatically with everyone in the same Account. Teammates can reuse each other’s plugins, MCP clients, and guardrails in their own manifests by name, without copying them, and credentials stay in Secrets rather than in anyone’s manifest. Resources that Smarter provides are shared with every account, so your team can start from a library of ready-made building blocks. Permissions are enforced by the platform itself, in every query, for the web console, the REST API, and the CLI alike, and usage is charged to the account’s budget, so it is always clear who built what, who can change it, and who is paying for it.

Runs at scale, on your infrastructure

Smarter runs wherever you do. Start with a single Docker container on your laptop, then go to production on Kubernetes with the Smarter Helm chart, where the application servers and background workers scale horizontally and automatically with demand. The same manifests that you wrote on your laptop run unchanged in a production cluster that serves your whole organization. There is no managed-service dependency and no vendor lock-in. You own the deployment, the data, and the infrastructure that it runs on.

At a glance

Usage

1. Create a Smarter manifest

This built-in LLMClient is a complete, governed AI application. It combines a SkillPlugin, an MCPClient, and four guardrails, and it contains no code.

Example Smarter Manifest
apiVersion: smarter.sh/v1
kind: LLMClient
metadata:
  description: "A business intelligence analyst that answers questions by writing SQL against the Stackademy data warehouse."
  name: data_analyst
  version: 1.0.0
  tags:
    - analytics
    - business-intelligence
    - sql
    - stackademy
  annotations:
    - smarter.sh/llmclient/use-case: text to SQL analytics
    - smarter.sh/llmclient/showcases: MCPClient, SkillPlugin, Guardrail
    - smarter.sh/llmclient/last-updated: 2026-09-30
    - smarter.sh/llmclient/owner: Lawrence McDaniel
spec:
  apiKey: null
  config:
    appAssistant: Quinn
    appBackgroundImageUrl: null
    appExamplePrompts:
    - Which five courses had the most enrollments last quarter?
    - What is our monthly revenue trend for this year?
    - Write the SQL to find students who enrolled in more than three courses.
    - How do I write a window function in PostgreSQL?
    appFileAttachment: false
    appInfoUrl: https://smarter.sh
    appLogoUrl: https://cdn.smarter.sh/images/logo/smarter-crop.png
    appName: Stackademy Data Analyst
    appPlaceholder: Ask a business question about Stackademy...
    appWelcomeMessage: Welcome! Ask me a business question, and I'll answer it with SQL against the Stackademy data warehouse.
    customDomain: null
    defaultMaxTokens: 2048
    defaultModel: gpt-4o-mini
    defaultSystemRole:
      You are a senior business intelligence analyst for Stackademy, an online learning
      company. Answer business questions by writing SQL against the Stackademy data
      warehouse, following the sql analyst skill that is provided to you. Show the SQL that
      you wrote, explain it in one or two sentences, and then answer the question in plain
      language. For general SQL questions, such as the syntax of a function, use DeepWiki
      to check the documentation of the relevant database project.

      Write read-only SELECT statements only. NEVER write INSERT, UPDATE, DELETE, DROP or
      other statements that change data. Aggregate personal data rather than listing
      individual students. If a question is ambiguous, such as "last quarter", state the
      assumption that you made.
    defaultTemperature: 0.0
    deployed: false
    dnsVerificationStatus: Verified
    provider: openai
    subdomain: null
  functions: []
  plugins:
    - sql_analyst
  mcpClients:
    - deepwiki
  guardrails:
    - code_injection_input
    - prompt_injection_keyword_input
    - pii_leak_output
    - secrets_leak_output

2. Apply the Manifest

smarter apply -f llmclient-data-analyst.yaml

3. Interact

Smarter Prompt Engineering Workbench Demo

Getting Started