Pauses on an external event, such as an approval or a mailbox message, and resumes in a new process, even in the other runtime. Completed work that was acknowledged is reused; a write with an unknown outcome stays blocked.
Agent programming language
Write agent programs that wait,
resume, and replay.
ALGAL is a programming language and VM for AI agent programs that wait for approval and leave receipts you can replay. When a run stops for an approval or a crash, it continues in a new process and reuses the work it already finished.
program route(email: text) -> text {
budget { max_agent_calls: 2 }
let intent = decide "What does this email need?" using email
as choice {
help: "Help with a problem",
sales: "Information before buying",
other: "Anything else"
}
return match intent.value {
help => generate "Draft a helpful support reply." using email,
sales => generate "Draft a concise sales reply." using email,
other => "Needs a human review."
}
}
- events
- 14
- cells
- 7 committed · 3 skipped
- effects
- 2 recorded
- outcome
- complete
- receipt
sha256:d22379d75489…- program
sha256:69a990085c0a…
program reply(email: text) -> text {
budget { max_agent_calls: 2 }
let intent = decide "What does this email need?" using email
as choice {
help: "Help with a problem",
sales: "Information before buying",
other: "Anything else"
}
let task = match intent.value {
help => "Draft a helpful support reply.",
sales => "Draft a concise sales reply.",
other => "Draft a clarifying question."
}
return generate task using email
}
- events
- 9
- cells
- 5 committed
- effects
- 2 recorded
- outcome
- complete
- receipt
sha256:8ccbed076231…- program
sha256:fa60e616cc9c…
import draft from "./draft.algal"
program inbox(sample: text, emails: json) -> json {
budget { max_agent_calls: 4 }
let preview = call draft using { email: sample, tone: "helpful" }
let replies = each draft over email in emails using { tone: "helpful" } max_items 3
return { preview: preview, replies: replies }
}
- events
- 31
- cells
- 25 committed
- effects
- 4 recorded
- outcome
- complete
- receipt
sha256:57896185e6aa…- program
sha256:7dad396424aa…
{
"contract": "algal.organism.v1",
"key": "organism:habitat-propose",
"name": "HabitatPropose",
"budgets": {
"maxAgentCalls": 4,
"maxContextBytes": 65536,
"maxDepth": 4,
"maxOutputBytes": 65536,
"maxSteps": 32,
"maxWork": 10000
},
"cells": [
{
"id": "goal",
"kind": "input",
"outputs": {
"text": {
"type": "text"
}
- events
- 10
- cells
- 7 committed
- effects
- 1 recorded
- outcome
- complete
- receipt
sha256:9072891c9150…- program
sha256:7f890428e915…
Each example is a run the site build executed with scripted model answers and then replay-checked. Nothing runs in your browser.
The idea
Software that
accumulates competence.
ALGAL is built on one bet: a computer can accumulate tested ways of acting, not only produce new answers or new code. A model proposes a procedure. ALGAL checks it and measures it on cases you declare, and the host decides whether to keep it. Those mechanisms work today. Whether kept procedures make later work measurably better is an open experiment.
LangGraph agents are Python or TypeScript code in your process. Temporal, Restate, and Inngest make workflow code durable through a server that keeps its history. An ALGAL program is typed data that the ALGAL VM runs, and each run leaves a receipt anyone can replay offline. LangGraph and Temporal are the mature choices today. Compare ALGAL with other tools.
Anatomy
Source you can read
compiles to a graph you can check.
You write .algal source. The compiler turns it into a typed manifest, which is inspected, hashed, and checked before anything runs.
program reply(email: text) -> text {
budget { max_agent_calls: 2 }
let intent = decide "What does this email need?" using email
as choice {
help: "Help with a problem",
sales: "Information before buying",
other: "Anything else"
}
let task = match intent.value {
help => "Draft a helpful support reply.",
sales => "Draft a concise sales reply.",
other => "Draft a clarifying question."
}
return generate task using email
}
The model classifies the email, a pure match picks the task, and the model drafts the reply.
Each model call sees only the context named after using.
matchThe site build compiles and runs this source. The compiler turns .algal into the algal.organism.v1 format, and both runtimes run the compiled manifest. The name nods to ALGOL, the algorithmic language.
Capabilities
Six things
a program can do.
Each capability below is defined in the v1 specs (algal.organism.v1, algal.process.v1, and algal.foundry.v1). Each is implemented, runs within declared limits, and can be inspected.
Durable slots, a content-addressed store, and semantic recall are built into the language, so a program's memory persists from one run to the next without a separate database.
Model judgment lives in its own typed cell. The cell declares the context the model may see, the output shape it must return, and its budget. Everything around it is pure dataflow.
A program can write its own successor as ordinary data. The spawn cell checks that manifest and runs it within the parent's limits.
A foundry scores candidate programs on cases you declare, and the host decides which to keep. Receipts record where each candidate came from, how it scored, and whether it was promoted.
Every run produces a receipt that replays bit-for-bit. You can verify it without the model, the original store, or credentials.
The habitat
Your host sets
the tools, models, and limits.
An ALGAL program, which the spec calls an organism, runs inside a habitat: the store, the function and tool registries, and the model executors your host application provides, all under limits the host sets.
The native Rust kernel and the TypeScript reference runtime execute the same manifest. A saved run can pause in one runtime and resume in the other on a shared local store.
The host attaches model executors the way you attach a device to a computer. A program declares what judgment it needs, but it cannot give itself access to a model or tool.
algal.organism.v1Typed cells, ports, and edges stored as data; a manifest carries no host code
17 cell kindsData input/const · pure fn/expr · model agent/decide/classifier · effect tool/gate/recall · composition organism/repeat/each/spawn · state store/load/slot
Built inContent-addressed store · durable slots · semantic recall · recorded compaction
Host-attachedModel executors, typed tools, and human approval gates. The host attaches them; a program cannot create them.
ReceiptsOne record per run, named by its content hash · replays bit-for-bit
Two runtimesNative Rust kernel · Bun/TypeScript reference · cross-runtime handoff
Receipts
Every run
can be replayed offline.
Each run leaves a receipt: a record, named by its content hash, that you can replay and inspect after the run ends.
- 01
Verify
Replay a run offline. Recorded effects stay fixed while the orchestration is recomputed bit-for-bit, with no model, store, or credentials needed.
algal verify receipt.json - 02
Diff
Compare two runs: which cells diverged, and where their work counts differ.
algal diff a.json b.json - 03
Diagnose
Map a recorded failure back to the source expression that produced it. This command is in the Bun CLI, run from a checkout.
bun cli.ts diagnose receipt.json --source main.algal
Replay shows that a run was internally consistent. It does not show that a model's answer is true, that a provider performed an operation, or that an external write with an unknown outcome happened exactly once.
Reproduction and selection
Programs write programs.
Your host picks which to keep.
An organism can emit a new manifest as data. spawn checks it and runs it within the parent's budgets. A generated program is a manifest, not host code. Foundries and the civilization loop measure candidates on cases you declare, and the host decides which to keep.
- 01 / proposeCandidate artifacts
Model-produced plans or manifests
- 02 / checkTyped programs with declared limits
Host compilation and checks
- 03 / measureEvaluation evidence
Declared cases and work limits
- 04 / selectKeep or promote
Host policy and recorded lineage
In one local on-device run, which is not published as replayable evidence, Apple Intelligence acted as the designer. An on-device model of about 3B parameters proposed plans, a host function compiled them into checked manifests, and candidates that passed their cases were kept. The whole civilization epoch stayed on the machine. Running it needs a Mac with Apple Intelligence and Xcode: on first use, --apple builds the separate Apple bridge, which is not part of the CLI package.
algal civ --live --apple --dir .algal/civ # an on-device epoch
algal civ-verify --dir .algal/civ # replay + audit it offline
Civilization workflows · Habitats and self-reproduction · Watch an organism propose a child on the tour
Proposing a program does not promote it. An organism cannot rewrite the runtime, grant itself permissions, or choose itself as the winner; the host decides what is accepted and what is kept. The lifecycle above is conceptual. It is not a recorded winning run or a promise that a candidate improves.
Get started
Install one binary.
Run your first program.
Download and verify a native prerelease. The built-in workbench needs no checkout, Bun, Cargo, credentials, or web server. Use a fresh directory for each demo.
Download the prerelease# Check the installed build and which model providers are available
algal doctor
# Start a VM process that waits for your decision
algal demo start ./my-review
algal demo inspect ./my-review
# my-review/report.html shows the exact command to approve or deny
# Crash the demo's own processes and check how they recover
algal demo prove ./crash-laboratorycrash-laboratory/proof.json records an approval that publishes once, a denial that publishes nothing, completed writes reused after a crash during a read, and a write with an unknown outcome that is not sent again. The decisions are fixtures; everything else, including the processes, journals, and verification, runs in the VM.
Status and limits
Know the limits
before you adopt it.
ALGAL fits local review queues, coding repairs checked by your own tests, reusable judgment pipelines, and run histories you need to inspect later. A single unstructured prompt may need less machinery, and Temporal, Restate, or Inngest, if you already run one, may meet your recovery needs.
ALGAL is an application VM prerelease. Its packages are unsigned and not notarized. Your host application stays responsible for tool permissions, confirming what happened when an external write's outcome is unknown, storage operations, and any OS isolation you need. Multi-tenant service use, moving a running process to another machine, and store-wide quotas are not built yet.
The adoption guide covers these limits before you connect a real system.