English | 中文
AI Agent to generate web pages and safe APIs, AI generate UI once, API repeat everytime safely, quickly and stably.
Agent-to-API protocol and MVP demo: generate a simple task UI, tune an HTTP API request until it works,
then let users change filters, sort, and paging from the UI — which directly calls HTTP API
without going through the LLM again, no more token cost.
No SQL execution path. Writes or sensitive reads wait in the Admin approval queue.
- Node.js 18+
- Local APIJSONBoot-MultiDataSource (or compatible) at
http://localhost:8080
cd ~/a2api
cp .env.example .env
npm install
npm test
npm run build
npm run dev-
Client (Vite): http://localhost:5173
-
Admin (config approvals):
npm run dev:admin→ http://localhost:5174- Tables
Apply+Call: runadmin/sql/sys_Apply.sqlandsys_Call.sql, reload Access/Request. If Call logs say GET denied for LOGIN, runadmin/sql/patch_Call_access.sql(Access id 9003; 9002 is Apply). - Ordinary CRUD hits APIJSON HTTP directly; admin server only runs approve → Access/Request/Document/Chain
- Admin tabs: Apply · Call logs · Stats
- Tables
-
API (Hono): http://localhost:3000
Open the client URL. Use Login (top-right) to open the account menu and set AI Model / Base URL / API Key (APIAuto-style). Try chips such as List the latest 3 moments with authors, then change sort/page and click Query / Refresh — the right panel shows usedLlm: false and the exact APIJSON body.
Curated chat examples live in conversations/; project Agent skills in .cursor/skills/.
Optional: set OPENAI_API_KEY in .env to refine bootstrap with an LLM. Without it, built-in intent rules for User / Moment / Comment still work (English and Chinese phrases).
| Path | Role |
|---|---|
opendoubao |
Orchestrator + chat UI (Bootstrap) + bound filters (Steady-state) |
opendoubao-admin |
Config application approvals → write Access / Request / Document / Chain |
a2api/protocol |
A2API 0.1 envelopes, JSON Pointer helpers, validators, CRUD fixture tests |
a2api/runtime |
ApiJsonClient, HitlController, BoundExecutor |
Envelopes: { "version": "0.1", "<type>": { ... } }
proposeRequest— candidate APIJSON callreviseRequest/decision— edit / approve|rejectbindRequest— aftercode == 200, template +paramMapfor UI-driven callsrequestResult/status— outcomes
Read methods auto-execute. Non-sensitive post / put auto-execute with an audit row. Sensitive methods (default delete, override SENSITIVE_METHODS) wait for Admin Approve/Reject.
- Bootstrap (chat / AI or rules) — generate UI + propose APIJSON → validate → execute until success → emit
bindRequest - Steady-state (no LLM) — filter/sort/page →
BoundExecutormergesparamMapintobodyTemplate→POST {baseUrl}/{method}
Top tabs:
- UI — chat bootstrap + bound table/detail/charts
- Data — APIAuto-style HTTP debugger
- Admin — sensitive approval queue + audit trail (
auto_approved/ approved / rejected)
Also:
- Embed APIAuto — iframe
http://localhost:8080/api/index.html?send=true&type=JSON&url=...&json=...(share-link auto fill + send) - Open APIAuto in new window — same share URL in a new tab
Agent / console automation:
a2apiAgent.switchTab("data")
a2apiAgent.debug({
url: "http://localhost:8080/get",
json: { User: { id: 38710 } },
send: true, // builtin send
// useApiAuto: true, // or load iframe + auto send
})export APIJSON_BASE_URL=http://localhost:8080
# or edit .envEnsure the Demo schema is available on that server. Business layout tables are in opendoubao/sql/layout_demo_tables.sql (User / Moment / Comment plus Employee, Activity, Message, News, Notice, Blog, Article, Video, Music, Product, ShopOrder, Address, Category, …). After import, reload Access/Request. To add only categories, run opendoubao/sql/layout_demo_categories.sql; to add only addresses, run opendoubao/sql/layout_demo_address.sql (those pages also auto-import if the table is missing).
Writes (POST/PUT/DELETE): the Demo often requires a logged-in session (@role OWNER/LOGIN). The MVP still generates the request and shows the HITL Approve/Reject UI; if APIJSON returns "not logged in", log in via your Demo/APIAuto session cookies or relax Access for local testing. Reads work out of the box against the public Demo data.
npm test # protocol + runtime unit tests
npm run build # compile a2api + demo
npm run dev # API :3000 + Vite :5173
npm run typecheckCross-device sync via database tables or file import/export — see the design plan.
We are always looking for more developers to help implementing new features, fix bugs, etc.
Fork the project and send a pull request.
If you have any questions or suggestions, you can create an issue or send me an e-mail.








