Plan
The mission is split into owned tasks before a single file is touched. Read-only. You see the plan, the blast radius and the estimated Fuel cost, and you approve it or you do not.
Talk in WebChat. Run agents. Compare models in Round Table. Brainstorm, inspect images, use voice, install MCP servers and skills, watch Fuel, and create API keys — without leaving Dulus.
Runs across
An agent that only executes is a liability. Every mission on Dulus Online runs through four stages, and the fourth one is what makes the other three safe to trust.
The mission is split into owned tasks before a single file is touched. Read-only. You see the plan, the blast radius and the estimated Fuel cost, and you approve it or you do not.
The agent uses its configured tools under the workspace permission policy. Risky actions can stop and ask before anything changes.
Checkpoints, tool results and tests let you inspect what changed instead of trusting a confident final message.
Fuel headers, ledger entries and durable artifacts make model usage and delivered work inspectable.
These are the surfaces already wired into the Dulus desktop shell. Each one keeps the agent, workspace and model within reach.
Streaming chat, model selection, checkpoints, attachments and tool activity in the primary workspace.
Runtime status, provider configuration and the controls that connect the desktop shell to the agent engine.
Several models work the same question in parallel, then a synthesizer turns their positions into one answer.
See and coordinate agent workers from the same shell instead of losing parallel work across terminals.
Turn one rough idea into competing approaches before committing the agent to a direction.
Bring images into the workflow for inspection, OCR and model-assisted visual work.
Speak to Dulus, transcribe locally when configured, and keep voice inside the same session.
Discover servers from registry, curated and community sources, then connect the tools you need.
Search open agent skills, inspect their source and install new behavior into Dulus.
Available balance, reserved balance, lifetime grants, lifetime spend and recent ledger entries.
Create, name and revoke dulus_sk_ credentials; copy Python, curl and Node examples immediately.
Authentication, runtime connection, models and product preferences in one predictable place.
Deposits credit an off-chain ledger; prompts do not create a blockchain transaction. Paid calls reserve first, settle from reported tokens and release the remainder.
| Plan | $DULUS / mo | ≈ USD | Launch offer |
|---|---|---|---|
| Sandbox | 0 | $0.00 | free |
| Starter | 1,000,000 | $34.08 | $29 |
| Pro | 3,000,000 | $102.24 | $79 |
| Enterprise | custom | — | let's talk |
$DULUS is a utility and community token. Its reference price is configuration, not a promise — the token floats, and nothing here is financial advice.
Monthly, cancel whenever. The open-source agent stays free forever — these plans buy hosted runtimes, metered inference and the shared workspace.
0$DULUS
$0.00 USD
A daily allowance based on the $DULUS held in your account.
1M$DULUS/mo
$34.08 USD
$29 /mo · launch offer
Your dedicated agent with memory and tools.
3M$DULUS/mo
$102.20 USD
$79 /mo · launch offer
More agents, more capacity and team control.
Custom
annual billing
Scope the runtime with us.
Need something bigger, on your own cloud, or with a signed DPA? Write to hello@dulus.ai and you will get a straight answer about what exists today and what does not.
Here is what is enforced today, and what is still on the way. We would rather lose a deal than win it on a claim we cannot back.
Auth0 proves identity. The control plane issues signed leases and checks access before a hosted model call reaches its provider.
Permission modes separate read-only planning from mutation. Risky tool calls can stop for explicit approval before execution.
API-key secrets are shown once and stored as a digest. A key cannot mint replacement keys, and revocation is scoped to its account.
Webhooks are signature-verified, deduplicated by event id and rejected outside a five-minute replay window. Retries are safe; a replayed payment cannot re-grant a subscription.
Desktop analytics is designed for operational metadata such as latency, token counts and error classes — not prompts, model output, tool arguments or credentials.
Dulus is not SOC 2 certified today. Enterprise requirements are scoped and verified individually; the site does not turn roadmap items into security claims.
dulus.ai is the open-source agent you install on your own machine — free forever, no account. dulus.online is the hosted version: runtimes we operate, inference we meter, a shared workspace with approvals and an audit trail. Same engine underneath. You can start free and move up, or never move at all.
No. Pay in USD by card and Fuel is credited automatically. Token deposits exist for people who prefer them and they settle through a verified on-chain flow. Your Fuel balance is denominated so that it does not move with the token price.
The control plane rejects the hosted model call before contacting the upstream provider. Top up Fuel, use an eligible free route, or switch to a provider you configure yourself.
Permission policy controls what tools may do. Read-only planning and approval-gated execution let you choose how much autonomy a workspace receives.
Not by us. We send your content to the model provider you selected, under that provider's terms, and we store what the workspace needs to function. Our own telemetry is metadata only and never contains prompts, outputs or tool arguments.
The agent core, providers, memory, tools, permissions, metering and payment settlement are in production and covered by tests. Dulus OS and the mobile shell are early. There are real paying customers, and not many of them yet — you would be early, and priced accordingly.
Open the command center, choose a model and see the same Fuel and API identity across the product.