`_refresh_token_cache` rebuilt the bearer-token map in two steps, `clear()` then `update()`. Between them the dict a concurrent reader was already holding was empty, so a valid token landing in that window found zero candidates and got a 401. The refresh runs on a worker thread via `to_thread`, so the window is real rather than theoretical. Build the new map and rebind the name. The reader dereferences the global once and then holds a map that is complete — the previous one if it read early, the new one if it read late, never a half-built one. `app.state._token_cache` is rebound with it, because it was bound once at startup and would otherwise point at the abandoned dict. Ported from public `dev` (`984337b3`), with its test. The upstream test does not pin the fix: both of its concurrency cases pass against the pre-fix code, because landing a GIL switch inside a window a few bytecodes wide does not happen across 100 refreshes. They are kept as written and `TestRefreshLeavesTheReadersMapAlone` is added next to them, stating the same invariant at object level — a map a reader already holds is not mutated by a later refresh — which fails on the pre-fix code without depending on thread scheduling.
A self-hosted AI workspace for chat, agents, research, documents, email, notes, calendar, and local model workflows.
Quick Start · Setup Guide · Contributing · Roadmap
Quick Start
devis the default branch and gets the newest changes first. Usemainif you want the more curated branch.
git clone https://github.com/odysseus-dev/odysseus.git
cd odysseus
cp .env.example .env
docker compose up -d --build
Open http://localhost:7011 when the containers are healthy. The first admin password is printed in docker compose logs odysseus.
Native installs, GPU notes, Windows/macOS instructions, HTTPS, and configuration live in the setup guide.
Features
- Chat + Agents — local/API models, tools, MCP, files, shell, skills, and memory.
- Cookbook — hardware-aware model recommendations, downloads, and serving.
- Deep Research — multi-step web research with source reading and report generation.
- Compare — blind side-by-side model testing and synthesis.
- Documents — writing-first editor with AI edits, suggestions, Markdown, HTML, CSV, and syntax highlighting.
- Email — IMAP/SMTP inbox with triage, tags, summaries, reminders, and reply drafts.
- Notes, Tasks + Calendar — reminders, todos, scheduled agent tasks, and CalDAV sync.
- Extras — gallery/image editor, themes, uploads, web search, presets, sessions, and 2FA.
Demo
A full hover-to-play tour lives on the Odysseus landing page. Its source lives under website/.
Contributing
Help is welcome. The best entry points are fresh-install testing, provider setup bugs, mobile/editor polish, docs, and small focused refactors. See CONTRIBUTING.md and ROADMAP.md.
Security
Odysseus is a self-hosted workspace with powerful local tools. Keep auth enabled, keep private data out of Git, and do not expose raw model/service ports publicly.
- Keep
AUTH_ENABLED=truefor any network-accessible deployment. - Keep
LOCALHOST_BYPASS=falseoutside local development.
Deployment details are in the setup guide.
Star History
License
AGPL-3.0-or-later -- see LICENSE and ACKNOWLEDGMENTS.md.

