The Smarter Project v0.15.0 Documentation
The Smarter Project is an open source, cloud-native platform and developer framework for building sophisticated AI applications without writing a single line of Python. An application that searches the web, queries your databases, calls your APIs, uses the tools of any MCP server, and defends itself against prompt injection and data leaks is described in one short YAML file, and deployed with one command.
Quick Start: up and running on your desktop in about 10 minutes
With Docker Desktop installed:
git clone https://github.com/smarter-sh/smarter-deploy.git
cd smarter-deploy
make # creates a .env file. Add your credentials to it before continuing.
make init # pulls the Docker containers and seeds the platform with test data
make run # starts the platform
Then open http://localhost:9357/login/ and log in as admin@smarter.sh with password
smarter (change it after your first login), and install the
Smarter CLI.
See the Quick Start Guide for step-by-step instructions with screenshots.
No code. Just a manifest.
Until now, an AI application that combines retrieval, tool calling, and safety controls has been a software project: Python code for every API client, database query, and MCP session, glue code to route tool calls, and custom middleware to filter what goes in and out of the model. That code has to be written, tested, secured, and maintained by engineers, and every change to the application is a change to the code.
Smarter replaces all of it with a Smarter Manifest (SAM), a plain YAML file that declares what an application is, rather than programming how it works. Every Resource in Smarter, from an Account to an LLMClient to a Guardrail, is created the same way:
smarter apply -f my-ai-application.yaml
This changes who can build AI applications, and how fast:
No programming required. Prompt engineers, business analysts, and product managers can build, read, and change production AI applications themselves. The manifest is the application.
Sophistication is a list, not a project. Giving an application web search, a SQL database, an MCP server, or a prompt injection guardrail means adding one line to its manifest.
One way to do everything. There is no resource-specific SDK to learn and no API convention to memorize. If you can write one manifest, you can write them all.
Infrastructure as code for AI. Manifests are versioned, diffed, reviewed in pull requests, and deployed from CI/CD, like the rest of your infrastructure.
Every way to reach external data
An LLM is only as useful as the information it can get to. Smarter connects your AI applications to external data through every approach in use today. Each one is a Resource that you declare in a manifest, and none of them requires you to write code:
Remote APIs: an API Plugin calls your REST services, and authenticates with credentials that are stored as Secrets, which the model never sees.
Remote SQL: a SQL Plugin runs parameterized queries against your databases through a managed Connection.
MCP servers: an MCPClient gives your application the tools of any server in the Model Context Protocol ecosystem.
The web: a WebsearchPlugin searches the web and reads the pages it finds.
Expertise: a SkillPlugin packages instructions and reference material that teach a model how to do a specific job well.
Your own documents: a Vectorstore provides semantic search over the content that you load into it.
Governed from the first prompt
Instructions in a system prompt are requests, not controls. A Smarter Guardrail is a deterministic software control that inspects every message on its way to the model, and every reply on its way back. Guardrails moderate abusive and unsafe content, redact personal data and leaked secrets, and stop prompt injection, jailbreaks, and code injection from bad actors, whatever the model would have done. Like everything else in Smarter, a guardrail is declared in a manifest and added to an application by name, with no code. Every intervention is recorded, so each Prompt can be traced back through the guardrail checks, tool calls, and model connection that produced it, to the Account and budget that authorized it.
Contained by design
There is growing concern about AI agents that go rogue: agents that run code they were never meant to run, reach systems they were never meant to reach, and break out of the sandboxes that were supposed to contain them. Smarter was designed from the start on the assumption that a model will eventually try to do something it should not. It does not rely on the model to behave. It makes the dangerous actions impossible:
No code execution. Smarter never runs code written by a model, or by a third party, on its own servers. A SkillPlugin provides instructions, not programs, and Smarter rejects any MCPClient that would launch an MCP server as a local process. Remote MCP servers run on their own infrastructure, not on yours.
Nowhere to escape to. In production, Smarter runs on private VPC networks wherever possible, and Calico network policies on Kubernetes control which ports and services each workload can reach. Containers run as a non-root user. A model cannot open a connection that the network will not carry, so breaking out is not a matter of clever prompting. It is not technically possible.
Hardened outbound requests. When a plugin fetches a web page, it uses https on port 443 only, to public addresses only, with every redirect validated. A model cannot direct Smarter to reach your internal network or your cloud provider’s instance metadata.
Role-based access at every layer, from Kubernetes and the cloud account, to the Account and user, to each individual Resource. A model can use only the plugins, MCP clients, and connections that its manifest names, and a manifest can name only the Resources that its author is permitted to use.
Credentials the model never holds. API keys and passwords are stored as encrypted Secrets, and are applied by the platform when it makes a request. They never appear in a prompt.
Guardrails on both sides of the model, which stop prompt injection and jailbreaks on the way in, and stop leaked secrets and personal data on the way out.
Budgets and a complete audit trail. Every request is authorized against the account’s budget, and every prompt, tool call, and guardrail intervention is recorded in the Smarter Journal.
See Security for details.
Composed like an orchestra
These capabilities are designed to work together, and you conduct them from the manifest. A single LLMClient manifest combines a model from any provider with the plugins, MCP clients, and guardrails that it needs, simply by listing them by name. Each piece plays its own part, and Smarter handles the tool calling, authentication, guardrail enforcement, and auditing in between. For example, a research analyst can search the web, read PDF reports, and have its citations checked before they reach the user. A customer support agent can draft on-brand replies behind nine guardrails for safety and privacy. A data analyst can answer business questions in SQL, check syntax against the database’s own documentation over MCP, and never leak personal data. When one application is not enough, an Orchestrator coordinates several LLMClients in sequential, parallel, supervisor/worker, routing, and voting/debate workflows, and it too is just a manifest.
Smarter ships with built-in LLMClients like these, so that you can see the whole ensemble at work on a fresh installation, and then copy the manifests to start your own.
Built for teams
AI applications are built by teams, not individuals, so Smarter builds ownership and sharing into every Resource. Each LLMClient, Plugin, MCPClient, Guardrail, Secret, and Connection is owned by the person who created it, and is shared automatically with everyone in the same Account. Teammates can reuse each other’s plugins, MCP clients, and guardrails in their own manifests by name, without copying them, and credentials stay in Secrets rather than in anyone’s manifest. Resources that Smarter provides are shared with every account, so your team can start from a library of ready-made building blocks. Permissions are enforced by the platform itself, in every query, for the web console, the REST API, and the CLI alike, and usage is charged to the account’s budget, so it is always clear who built what, who can change it, and who is paying for it.
Runs at scale, on your infrastructure
Smarter runs wherever you do. Start with a single Docker container on your laptop, then go to production on Kubernetes with the Smarter Helm chart, where the application servers and background workers scale horizontally and automatically with demand. The same manifests that you wrote on your laptop run unchanged in a production cluster that serves your whole organization. There is no managed-service dependency and no vendor lock-in. You own the deployment, the data, and the infrastructure that it runs on.
At a glance
Get started | Quick Start Guide | Prerequisites | Trouble Shooting & FAQ | Tutorial
Platform
A proxy server that gives secure, governed, auditable access to AI providers and resources, without exposing secrets or the underlying vendor accounts.
Build every AI resource with declarative YAML manifests, with no Python programming, much as you would with Kubernetes.
Manage resources with the web console, the REST API, and the command-line interface.
Built for teams: every resource has an owner, and is shared with everyone in the owner’s Account.
Runs at scale on Kubernetes, with automatic horizontal scaling of application servers and background workers.
Built-in logging, cost accounting, and security.
Knowledge and tools
MCPClients for the Model Context Protocol ecosystem.
Vectorstores for semantic search over your own content.
Trust and safety
Input and output Guardrails for moderation, self-harm, personal data, data subject requests, leaked secrets, profanity, fabricated citations, prompt injection, jailbreaks, and code injection.
End-to-end audit, from each Prompt back to the Account that authorized it.
Models and workflows
Works with many AI model providers, including OpenAI, Google AI, Meta AI, and DeepSeek, as well as self-hosted models with LLMHost.
Multi-agent workflows with Orchestrator.
A prompt engineering workbench for testing applications before you deploy them.
Developer framework
For when you do want to write code: built on Django, Django REST Framework, and Pydantic, and the same framework that Smarter itself is built on.
Automated AWS cloud infrastructure and Kubernetes management.
A React component that adds a Smarter chat to any web page.
Python SDK, NPM packages, and a VS Code extension.
Usage
1. Create a Smarter manifest
This built-in LLMClient is a complete, governed AI application. It combines a SkillPlugin, an MCPClient, and four guardrails, and it contains no code.
apiVersion: smarter.sh/v1
kind: LLMClient
metadata:
description: "A business intelligence analyst that answers questions by writing SQL against the Stackademy data warehouse."
name: data_analyst
version: 1.0.0
tags:
- analytics
- business-intelligence
- sql
- stackademy
annotations:
- smarter.sh/llmclient/use-case: text to SQL analytics
- smarter.sh/llmclient/showcases: MCPClient, SkillPlugin, Guardrail
- smarter.sh/llmclient/last-updated: 2026-09-30
- smarter.sh/llmclient/owner: Lawrence McDaniel
spec:
apiKey: null
config:
appAssistant: Quinn
appBackgroundImageUrl: null
appExamplePrompts:
- Which five courses had the most enrollments last quarter?
- What is our monthly revenue trend for this year?
- Write the SQL to find students who enrolled in more than three courses.
- How do I write a window function in PostgreSQL?
appFileAttachment: false
appInfoUrl: https://smarter.sh
appLogoUrl: https://cdn.smarter.sh/images/logo/smarter-crop.png
appName: Stackademy Data Analyst
appPlaceholder: Ask a business question about Stackademy...
appWelcomeMessage: Welcome! Ask me a business question, and I'll answer it with SQL against the Stackademy data warehouse.
customDomain: null
defaultMaxTokens: 2048
defaultModel: gpt-4o-mini
defaultSystemRole:
You are a senior business intelligence analyst for Stackademy, an online learning
company. Answer business questions by writing SQL against the Stackademy data
warehouse, following the sql analyst skill that is provided to you. Show the SQL that
you wrote, explain it in one or two sentences, and then answer the question in plain
language. For general SQL questions, such as the syntax of a function, use DeepWiki
to check the documentation of the relevant database project.
Write read-only SELECT statements only. NEVER write INSERT, UPDATE, DELETE, DROP or
other statements that change data. Aggregate personal data rather than listing
individual students. If a question is ambiguous, such as "last quarter", state the
assumption that you made.
defaultTemperature: 0.0
deployed: false
dnsVerificationStatus: Verified
provider: openai
subdomain: null
functions: []
plugins:
- sql_analyst
mcpClients:
- deepwiki
guardrails:
- code_injection_input
- prompt_injection_keyword_input
- pii_leak_output
- secrets_leak_output
2. Apply the Manifest
smarter apply -f llmclient-data-analyst.yaml
3. Interact
Getting Started
Table of Contents