Quote, plan, buy, build, inspect and ship on one live model of your factory,
from a ten-person prototype shop to a rate-production line.
Start free · Self-host · Docs · API · MCP · Discord · Roadmap
Quote to cash. Quotes, orders, jobs and invoices on one record. |
Unfork your BOM. Multi-level BOMs, revisions and configuration. |
Traceability by default. Lot and serial genealogy, forwards and back. |
- Why Carbon
- Features
- Get Carbon
- API & MCP
- Architecture
- Tech Stack
- Monorepo
- Local Development
- Commands
- Security
- Contributing
- License
Legacy ERPs were built for accountants in the 1990s. We built Carbon after years of running manufacturing on off-the-shelf systems and finding that:
- Modern, API-first tooling didn't exist
- Vendor lock-in bordered on extortion
- There is no "perfect ERP", because every manufacturer is unique
So Carbon puts ERP, MRP, MES and QMS on one Postgres schema you can read, own and extend. Every stage, from CAD to cash, writes to the same record: no handoffs, no re-keying, no reconciliation.
Carbon is an open-source alternative to NetSuite, Epicor, SAP Business One, Plex, Odoo and ERPNext, built for discrete manufacturing: complex assembly, contract manufacturing, configure-to-order and high-mix, low-volume production. See all comparisons.
| ERP | Sales (quotes, orders, RMAs), purchasing, inventory, items, invoicing |
| MRP & Planning | Material requirements planning, demand forecasts, finite capacity scheduling |
| MES | Digital travelers, 3D assembly instructions, barcode/QR tracking, live labor |
| QMS | Inspections, FAI, non-conformances, CAPA, gauge calibration, risk register |
| Traceability | Serial and lot genealogy, forwards and back |
| Engineering | Nested BoMs, revisions, change orders, item supersession, product configurator |
| Accounting | GL, journals, multi-entity and multi-currency, Xero / QuickBooks sync |
| Workflows | No-code automation rules with full run history |
| Maintenance & Assets | Scheduled maintenance, fixed assets, kanban replenishment |
| API, Webhooks & MCP | 1,500+ typed API operations, served over HTTP and as a built-in MCP server |
| Custom Fields | Extend any record |
| Integrations | Onshape, SolidWorks, Paperless Parts, Linear, Jira, Slack, Ramp, Stripe, Zebra |
See the full roadmap for what's next.
Technical highlights
- Full-stack type safety, from the database to the UI
- Row-level security, multi-tenant by design
- Role- and attribute-based access control (Employee, Customer, Supplier)
- Realtime database subscriptions
- Unified auth and permissions across apps
- Dependency graph for operations
- Rust geometry service: STEP → GLB and assembly motion planning
| Carbon Cloud | The fastest way to start. Create a company, no call required. |
| Self-hosted | Run the whole stack on a single VPS, your own AWS account, or air-gapped. See the self-hosting guide. |
| Develop locally | Hack on the source: follow Local Development. |
Carbon is API-first. The Carbon API is the service layer, the same code the app runs when you click a button: 1,500+ operations across 15 modules, each validating its input, recalculating what depends on it and enforcing your permissions. Every operation is reachable two ways, with the same arguments:
- HTTP:
POST https://app.carbon.ms/api/v1/{module}/{operation}, with a published OpenAPI spec for generating a typed client in any language - MCP: as tools for Claude, ChatGPT, Cursor and other agents, scoped to the permissions of the key or signed-in user
Create a key under Settings → API Keys, then:
curl -X POST https://app.carbon.ms/api/v1/sales/getSalesOrders \
-H "Authorization: Bearer $CARBON_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "args": { "limit": 10 } }'Self-hosted, the same API is served by your ERP at /api/v1. For the rare case the service layer doesn't cover, the Data API exposes every table and view directly.
ERP and MES are React Router apps over a single Postgres database. Permissions (row-level security), computed totals and change events live in the database itself; background work runs through Inngest, which calls back into the ERP to execute jobs. The architecture guide follows one click all the way down.
| Layer | Technology |
|---|---|
| Apps | React Router 7 on Vite, TypeScript |
| UI | Tailwind 4, Radix, React Aria, TanStack Table and Query |
| Forms | Zod with @carbon/form |
| Database | Postgres with row-level security, PostgREST and Kysely |
| API | oRPC with OpenAPI, MCP server |
| AI | AI SDK (Anthropic, OpenAI) |
| Jobs & events | Inngest |
| Cache | Redis |
| 3D & CAD | three.js / react-three-fiber; Rust with OpenCASCADE and FCL |
| Documents | React PDF, React Email, TipTap |
| i18n | Lingui |
| Tooling | pnpm, Turborepo, Biome, Vitest |
| Docs | Next.js + Fumadocs |
| Hosting | AWS via SST, or self-hosted with Docker |
carbon
├── apps # ERP, MES and the Rust assembler
├── packages # shared TypeScript packages
├── crates # Rust crates behind the assembler (CAD conversion, collision, motion planning)
└── docs # docs.carbon.ms, with content and glossary as @carbon/content
| App | Description |
|---|---|
erp |
ERP: sales, purchasing, inventory, planning, quality, accounting |
mes |
MES: the shop floor app, run on tablets next to the machines |
assembler |
Rust geometry service: STEP → GLB and assembly motion planning |
academy |
Training |
starter |
Example app built on the API |
| Package | Description |
|---|---|
@carbon/database |
Schema, migrations, generated types and database clients |
@carbon/auth |
Authentication, RBAC, sessions, API keys and OAuth |
@carbon/api |
API contract: the generated operation manifest behind the Carbon API and MCP |
@carbon/react |
Shared UI components (Radix, React Aria, Tailwind) |
@carbon/form |
ValidatedForm and field components for zod + FormData |
@carbon/jobs |
Inngest background jobs: events, integrations, notifications, workflows |
@carbon/planning |
MRP and scheduling engines |
@carbon/documents |
PDFs, email templates, ZPL labels, QR and barcodes |
@carbon/printing |
Printer routing, label queue and ProxyBox delivery |
@carbon/viewer |
3D models and animated assembly instructions (react-three-fiber) |
@carbon/files |
File handling: images, HEIC, CAD formats |
@carbon/tiptap |
Rich-text editor extensions and components |
@carbon/onboarding |
Implementation Hub: guided company setup |
@carbon/notifications |
Notification event taxonomy shared by apps and jobs |
@carbon/workflows-core |
Community-licensed contracts for workflow triggers |
@carbon/locale |
Lingui i18n runtime for ERP and MES |
@carbon/lib |
Server utilities: event system, Inngest client, SMTP, Slack |
@carbon/kv |
Redis client and rate limiting |
@carbon/env |
Validated environment variables, secrets kept server-side |
@carbon/logger |
Isomorphic logger built on LogTape |
@carbon/utils |
Pure shared utilities (dates, precision, BOM, formatting) |
@carbon/stripe |
Stripe billing (Carbon Cloud only) |
@carbon/ee |
Enterprise features and integrations (commercial license) |
@carbon/checks |
Conformance checks that keep the codebase consistent |
@carbon/dev |
The crbn dev CLI: worktrees, Docker stacks, dev URLs |
@carbon/harness |
Harness for AI coding agents working on this repo |
@carbon/config |
Shared Vitest, TypeScript and Tailwind configuration |
Prerequisites: Docker, Node.js 22 and pnpm (via Corepack). On Windows, use WSL or Git Bash.
git clone https://github.com/crbnos/carbon.git && cd carbon
corepack enable && pnpm install
cp .env.example .env
pnpm devpnpm dev boots the whole backend in Docker (Postgres, PostgREST, auth, storage, realtime, Inngest, Redis and a mail catcher), applies migrations, generates types and starts the apps:
| Surface | URL |
|---|---|
| ERP | http://localhost:3000 |
| MES | http://localhost:3001 |
| API | http://localhost:54321 |
Sign in as test@carbon.ms: the dev stack seeds that user and skips the magic link. To fill a company with a full demo story (items, BOMs, orders, jobs, inspections, journals), seed one of the industry datasets (satellite, robotics, precision, motor):
pnpm db:seed:dev -- --email test@carbon.ms --dataset satelliteNo external accounts are needed to run locally. Email, Google/Microsoft sign-in, Stripe, PostHog and AI providers are all optional and configured in .env; see environment variables.
pnpm dev is shorthand for crbn up --no-portless. Run source ./setup.sh once to put crbn on your PATH and you get a separate, isolated stack per git worktree, so several branches can run side by side, each on its own HTTPS .dev URLs via portless:
crbn checkout -b feat/my-thing # new branch + worktree off HEAD
crbn up # boot this worktree's stack at erp.<branch>.dev
crbn checkout 760 # check out PR #760 into its own worktree
crbn status | down | reset # ports and health, stop, wipe and rebootThe full command reference is in the local development guide.
assembler is a Rust service (STEP → GLB + assembly motion planning) over C++ FCL and OpenCASCADE. ERP/MES run fine without it — set it up only if you need the 3D /convert and /plan endpoints.
-
Toolchain + native build deps (macOS):
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh # Rust, if not already installed brew install fcl cmake ninja draco # collision libs (+ libccd/eigen/octomap), build tools, Draco mesh compression
On Linux, install the equivalents from your package manager:
libfcl-dev libccd-dev libeigen3-dev liboctomap-dev libdraco-dev cmake ninja-buildplus a C/C++ toolchain../setup.shalready installs Draco on macOS. If yours lives outside the Homebrew keg (/opt/homebrew/opt/dracoon arm64), pointdraco-bridge's build at it withDRACO_PREFIX=/path/to/draco cargo build. -
Build OCCT once — a patched static OpenCASCADE, cached in
~/.cache/carbon-occt. Slow (~15–30 min) but one-time per machine; re-running is a no-op once cached:./apps/assembler/scripts/build-occt.sh
-
Build the service — seconds once OCCT is cached (
build.rsfinds it automatically):cargo build --release -p assembler
crbn up spawns the binary when it's present. Verify it's up with curl -sf "$ASSEMBLER_SERVICE_URL/health" (the URL is in your worktree's .env.local) or by watching the asm | lines in the crbn up output. Without the binary the rest of the stack still runs — only /convert and /plan are unavailable.
To restore a production database snapshot locally, use crbn restore. It handles both plain-text .backup and custom-format .dump archives, drops and rebuilds the public schema, realigns internal sequences, resets storage metadata, then applies any migrations the backup predates and regenerates types.
-
Export a backup of your production database with
pg_dump. -
Run it from your worktree root:
crbn restore /path/to/db_cluster.backup # …or for .dump archives: crbn restore /path/to/postgres_YYYYMMDD.dumpIt prompts before replacing the database. The stack must already be running (
crbn up) — a restore rewrites theauthandstorageschemas, which GoTrue and Storage build through their own migrations when those containers boot, socrbn restorerefuses rather than restore into an uninitialized stack.To also get local admin access, pass your production email — your account is upgraded to Admin in the companies it already belongs to and the password is reset locally:
crbn restore /path/to/backup.backup --admin-email you@example.com # Optional: set a custom local password (default: localpass) crbn restore /path/to/backup.backup --admin-email you@example.com --admin-password mypassUseful flags:
--no-scrub-emailskeeps real addresses (see the warning below),--mode prodrestores exactly as-is without localizing config/webhooks/integrations,--no-migrate/--no-regenskip the trailing steps,--yesskips the prompt.Emails are scrubbed by default — every address is rewritten to
@example.test(your--admin-emailis preserved so you can still log in). If you pass--no-scrub-emails, real production addresses will be present in the local DB; ensure local email sending is disabled or pointed at a sandbox (e.g. Mailpit) before triggering any email flows.Note:
storage.objectsis truncated by default, so a restore does not populate local file storage — kept rows would reference files that only exist in the source environment's backend. Pass--keep-storage-objectsto retain the metadata (and the backup's buckets) anyway; downloads will still 404, but the rows are there for work that needs realistic storage volume.
The underlying script, scripts/restore-database.sh, can still be invoked directly — it takes the same options as environment variables (SCRUB_EMAILS, ADMIN_EMAIL, ADMIN_PASSWORD, RESTORE_MODE), but note it defaults to not scrubbing emails and leaves the trailing pnpm db:migrate / pnpm db:types to you.
| Command | Description |
|---|---|
pnpm dev |
Boot the stack and apps on localhost |
pnpm db:migrate:new <name> |
Create a database migration |
pnpm db:migrate |
Apply pending migrations |
pnpm generate:types |
Regenerate database types after a migration |
pnpm db:seed:dev -- --dataset <key> |
Seed a demo company |
pnpm lint / pnpm test |
Biome lint / unit tests |
pnpm exec turbo run typecheck --filter=<pkg> |
Typecheck one package |
pnpm --filter <pkg> <cmd> |
Run a command in one workspace |
This project uses Biome for formatting and linting; install the VS Code extension for format-on-save.
Found a vulnerability? Please email support@carbon.ms instead of opening a public issue. We respond within 3 business days and credit reporters once a fix ships. The full policy is in SECURITY.md.
Security is enforced by the database, not left to application code:
- Tenant isolation in Postgres. Every table is scoped to a company and guarded by row-level security, so a query can only see its own company's rows.
- Granular permissions. Role-based access per module and action for employees, customers and suppliers, applied the same way in the app, the API and MCP.
- Scoped API keys. Keys carry explicit permissions, are stored only as hashes and are rate limited per key.
- Sign-in. Passkeys, SSO, and enforced two-factor authentication on the Business plan.
- Audit log. A record of who changed what and when, on the Business plan.
- Your perimeter. Self-host on a single server, in your own cloud account or fully air-gapped, for programs with ITAR or CMMC requirements.
We welcome contributions of all sizes. Read CONTRIBUTING.md to get started, and say hi in Discord. Good first issues are labelled good first issue.
Carbon is open core. Everything in this repository is licensed under AGPLv3, except the Enterprise files (packages/ee and any file whose name contains .ee.), which are under the Carbon Commercial License. See Licensing for what that means in practice.