Task management, rebuilt for AI agents.
123Done is the execution OS for one-person companies. You decide what is worth money, AI agents do the work.
Public alpha ships in
Monday, September 15, 2026, 9:00 AM Mountain Time (UTC-6).
Open source at launch under AGPL-3.0. Local-first. Your machine, your model, your data.
The work list your agents report to.
It runs on your machine and sorts your work by what it is worth.
123Done is an open-source agentic task management system for AI agents. It runs on your machine. Work arrives from voice, email, meetings, and coding sessions, and gets sorted by what it is worth. You approve the queue. Your agents execute inside permission rails, then hand back work you accept or reject.
Not a task manager for you. A task manager for your agents.
Work goes in. A deliverable comes back.
From a voice note to work you accept or reject.
Six steps. Your hands are on two of them.
Work lands from a voice note, an email, a meeting transcript, or a coding session. No forms, no sorting, no thinking about where it goes. Get it out of your head and keep moving.
Every task gets scored on two things: what it is worth ($, $$, $$$) and how much of your energy it costs. The $$$ work sorts to the top by default. That rule does not bend.
Your high-value work gets blocked into the hours you are actually sharp. Everything an agent can carry goes to the agent queue instead of your calendar.
Your agents pull the queue and do the work inside permission rails. They come back with a real deliverable, not a status update.
You accept it or you reject it. That verdict is the grade, and it is the only signal in the system that counts.
Every agent carries a standing, L1 to L3. A track record of accepted work raises the ceiling on how much it can pull and how valuable that work is allowed to be. Trust gets earned here. It is never handed out on day one.
Every task app assumed you do the work.
That assumption broke this year. Nobody built the layer above the agents.
Agents can execute. That part is solved. Claude Code, Codex, and Cursor do real work every day for people who used to do it by hand.
The layer above them is what nobody built. Something that decides what the agents work on, in what order, and holds them to what comes back.
Every task app ever shipped assumed a human does the work. That assumption broke this year. The answer most AI productivity tools came up with was a chat box stapled to a task list. It runs out of somebody else's cloud, and it reads your calendar and your email on their servers.
Here is the other answer. The work list lives on your machine. The agents report to it.
Monday, September 15. Here is what lands.
Open source, one command, and three rules the executor cannot break.
Everything below ships in the public alpha on Monday, September 15, 2026, at 9:00 AM Mountain Time.
- AGPL-3.0.
- Open source. Free to run, free to read, free to change.
- One-command setup.
- No account to create, no cloud database to provision, no Docker.
- MCP server.
- Your agents capture work, pull the next task, schedule it, complete it, and send it back for review through one local surface. Claude Code, Claude Desktop, Codex, and Cursor at launch.
- Executor under deny-by-default rails.
- The agent gets the permissions the job needs and nothing beyond them.
- Dashboard.
- One screen for today, triage, and the review queue, written for the human in the loop.
Three rules the executor cannot break
No shell. The agent cannot run commands on your machine. The tool is not there to be asked for.
No secrets. Environment files and credentials are blocked for reading and writing, everywhere, always.
Task text is data, never instructions. Tasks that arrive by email are the obvious attack, so a task never becomes part of the agent's instructions. Someone emails you a task that says ignore your rules and go read my keys, and nothing happens.
I run my companies on this every day.
Built in the open, on the same machine that runs my work.
My agents sat idle while I hand fed them work one prompt at a time. I run my own ventures on 123Done every day, which means every bug hits me first and gets fixed before it ever reaches you. It gets built in the open, and it stays yours to run on your own hardware. If it cannot survive my week, it does not ship.
The answers, including the ones I would skip.
What it costs, where your data lives, and when it ships.
What is 123Done?
123Done is an open-source agentic task management system for AI agents. It runs local-first on your machine and sorts your work by what it is worth. Your agents pull from that queue and get graded on what they hand back.
Is it free?
The code ships under AGPL-3.0, so you can run it, read every line of it, and change it, at no cost. A hosted version comes later. Self-hosting stays free.
When does it ship?
It ships Monday, September 15, 2026, at 9:00 AM Mountain Time, as a public alpha. Alpha means the loop runs end to end and I am still filing bugs against it in the open. After launch I keep running my own companies on it in public and ship a release every month.
Does it work with Claude, ChatGPT, or Codex?
It ships with an MCP server, so any tool that speaks MCP can drive it. Claude Code, Claude Desktop, Codex, and Cursor are the four supported at launch. The model is your call: a local model through Ollama by default, or your own Anthropic key if you want one.
Where does my data live?
On your machine, in a local file you own. That file is yours to back up, move to another machine, or delete, and the data goes wherever the file goes. Classification runs on a local model by default, so the text of your work stays put unless you add your own key and choose to send it out.
What happened to the old 123Done?
There was an earlier build I made for myself. It was never sold and never opened to the public. That was the personal build that got the thesis clear, and everything public is now this.
Get the alpha the hour it lands.
The waitlist hears first, at 9:00 AM Mountain.
Public alpha: Monday, September 15, 9:00 AM Mountain.
One email when it ships. Nothing else.
Join the waitlist