aicoded framework
An open Go framework for company web apps that AI assistants build, safe by construction.
Pre-release: no API is stable yet
Approve capabilities, not code
People who are not engineers now build the tools their teams need, with AI assistants. Nobody can review every line an assistant writes. This framework is built so that nobody has to: an app built from it states what it may do, and the framework and its checks hold it there.
- Every page is locked. A page with no access rule does not build, and rules are checked from the top of the path down before any code of the page runs.
- No passwords or keys in the app. The app reaches its database, files, mail and secrets through a local runner, never with credentials of its own.
- Safe output by default. Templates compile to type-checked Go with escaping that knows where each value lands, and forms are protected against cross-site requests.
- Every mistake comes with a fix. Generator, check and runner errors carry a code, the
file:line, a one-line fix and a docs link, so an assistant can repair its own work.
How it works
Pages are folders of HTML templates that aicoded generate compiles into Go. Building blocks give an app the viewer's identity, its own SQL database, file stores, mail, settings, secrets, telemetry and calls to other apps. The aicoded CLI comes with a local runner, a dev UI with logs, traces and caught mail, test personas, and a local MCP server for AI assistants. aicoded check runs the tests and the framework's own analyzers before anything ships.
Quick start
You need Go 1.25 or later and Chrome. In a checkout of the repository:
git clone https://github.com/AiCoded-Dev/framework
cd framework
make install # installs aicoded into $(go env GOPATH)/bin
aicoded init hello # creates the app hello in a new folder
cd hello
aicoded dev # runs it on your computer
Then open http://hello.localhost:8080/. Every new app carries an AGENTS.md with the rules for AI assistants, and aicoded explain <CODE> prints the page for any error.
Go module
import "aicoded.dev/framework/web"
The source, issues and security policy are on GitHub.