Argus
Argus is a retrieval platform for AI agents offering web search, content extraction, URL recovery, and research workflows.
Search the Web (
search_web): Route searches across 14+ providers with multiple modes (discovery, research, recovery, grounding), configurable result counts, and multi-turn sessions viasession_id.Extract Content (
extract_content): Pull clean text from any URL using a 12-step fallback chain; supports authenticated extraction for paywalled sites.Recover URLs (
recover_url): Recover dead or moved URLs via Wayback Machine, archive.is, and search-based fallbacks.Recover Dead Articles (
recover_dead_article): Run a full workflow to recover a dead article, producing a local report with citations and provenance.Capture Sites (
capture_site): Crawl and capture important pages from an entire site with configurable page limits and a generated summary.Build Research Packs (
build_research_pack): Combine official documentation with external sources into a local research pack for a given topic.Expand Queries (
expand_links): Expand a search query with related links for broader discovery.AI-Synthesized Answers (
valyu_answer): Get AI-generated answers with citations via the Valyu Answer API.Provider Health & Budgets (
search_health,search_budgets): Monitor operational status and budget/credit usage across all integrated providers.Test Providers (
test_provider): Smoke-test a specific search provider to verify configuration.Cookie Health (
cookie_health): Check health of configured cookie domains used for authenticated extraction.Runtime Paths (
argus_paths): View resolved storage paths for corpus data, docs cache, research packs, and workflow state.
Integrates with Brave Search API as a core search provider, supporting automatic query routing, budget enforcement (tracking the 2,000 free monthly queries), health monitoring, and fallback coordination across multiple search modes including discovery, recovery, grounding, and research.
Integrates with self-hosted SearXNG metasearch engine instances as a privacy-focused search provider requiring no API key. Serves as a primary option in discovery and recovery search chains, with automatic fallback to commercial providers when results are insufficient.
Utilizes Tailscale networking to access remote authenticated extraction services for retrieving content from paywall-protected domains, enabling authenticated Playwright-based extraction as the first tier of its content extraction pipeline before falling back to local methods.
Argus
Retrieval platform for AI agents. Argus routes search across 14 providers, recovers dead URLs, captures important site content, builds local docs-plus-research packs, and persists everything with traceable local artifacts.
Features at a glance:
Topology-aware acquisition — Argus knows if it's on a residential IP or datacenter, routing search and extraction automatically to avoid blocks and minimize network hops.
14 providers, one API — free-first tier routing, budget-exhausted providers skipped automatically
Zero-key start —
pip install argus-searchgives you DuckDuckGo + Yahoo immediately, no accounts neededSearXNG self-host = 70+ engines — Google, Bing, Yahoo, Startpage, Ecosia, Qwant and more via one Docker container
12-step content extraction — returns full page text with quality gates, not just links
Opinionated retrieval workflows — recover dead articles, capture important pages from a site, and build local docs-plus-research packs
Argus-owned corpus storage — runtime data goes to a writable user data directory, not your repo checkout
Multi-turn sessions — pass
session_idfor conversational context across searchesScore attribution — optionally show which providers contributed to each fused RRF score
Usage dashboard — inspect provider budgets, recent query volume, and machine-level usage at
/dashboard4 search modes — discovery, research, recovery, grounding
Dead URL recovery —
/recover-urlwith Wayback Machine and archive fallbacks4 integration paths — HTTP API, CLI, MCP server, Python SDK
Built for AI agent builders, RAG pipelines, and ops teams who need reliable search, capture, and local evidence without stitching APIs together.
Status: beta. The retrieval workflows and corpus model are production-oriented, but still maturing.
Contents
Related MCP server: GroundRoute
Quickstart
Mode 1: Local CLI (zero config)
pip install argus-search && argus search -q "python web frameworks"That's it. DuckDuckGo handles the search — no accounts, no keys, no containers. You get unlimited free search from your laptop right now. Add API keys whenever you want more providers, or don't.
argus extract -u "https://example.com/article" # extract clean text from any URL
argus recover-article -u "https://example.com/dead-post"
argus capture-site -u "https://docs.example.com"
argus build-research-pack -t "example sdk" --official-url "https://docs.example.com"Works on any machine with Python 3.11+ — laptop, Mac Mini, Raspberry Pi, cloud VM. Nothing to host.
For MCP (Claude Code, Codex, OpenCode, Cursor, VS Code):
pipx install argus-search[mcp]
export ARGUS_MCP_STANDALONE=true # explicit development-only local broker
argus mcp init --global --client allThat writes native config for Claude Code, Codex CLI, OpenCode, and Cursor. Restart the client after configuration. For manual stdio setup:
{"mcpServers": {"argus": {"command": "argus", "args": ["mcp", "serve"], "env": {"ARGUS_MCP_STANDALONE": "true"}}}}Or install from the MCP Registry:
{
"mcpServers": {
"argus": {
"registryType": "pypi",
"identifier": "argus-search",
"runtimeHint": "uvx",
"env": {"ARGUS_MCP_STANDALONE": "true"}
}
}
}Standalone development needs no server or keys, but it must be explicitly enabled. Production MCP always delegates to an authenticated HTTP authority.
See MCP Client Setup for exact config files, verification commands, remote HTTP setup, and troubleshooting.
Mode 2: Full Stack Server
Got a Raspberry Pi running Pi-hole? A Mac Mini on your desk? An old laptop? That's enough to run the full stack — SearXNG (your own private search engine, disabled by default) plus local JS-rendering content extraction.
# Optional: tell Argus it has residential egress to optimize routing
export ARGUS_EGRESS_TYPE=residential
ARGUS_SEARXNG_ENABLED=true docker compose up -d # SearXNG + ArgusWhat you have | What you get |
Any machine with Python 3.11+ | DuckDuckGo + API providers (no server) |
Home server / old laptop (4GB+) | Everything — SearXNG, all providers, Crawl4AI, Obscura |
Mac Mini M1+ (8GB+) | Full stack with headroom |
Free cloud VM (1GB) | SearXNG + search providers (use residential workers for extraction) |
SearXNG takes 512MB of RAM and gives you a private Google-style search engine (disabled by default — set ARGUS_SEARXNG_ENABLED=true) that nobody can rate-limit, block, or charge for. It runs alongside Pi-hole on hardware millions of people already own.
Where Argus Writes Data
Argus code and Argus runtime data are different things.
Code lives wherever you install or clone Argus.
Runtime corpus data lives in a writable user data directory resolved by
platformdirs, or inARGUS_DATA_ROOTif you override it.
Inspect the exact paths on your machine:
argus pathsBy default Argus writes:
official docs cache under the resolved
docs/cache/research packs under
docs/research/workflow run state under
workflows/runs/versioned workflow snapshots under
snapshots/
This means Argus does not require a sibling ../docs-cache checkout. If you have an older docs-cache tree, import it once with:
argus corpus import-docs-cache -s /path/to/docs-cacheOpinionated Workflows
These workflows build local artifacts, not just transient JSON responses.
Recover A Dead Article
argus recover-article -u "https://example.com/old-post" -t "Example Post"Argus searches for recovery candidates, extracts the best result, saves the recovered sources locally, and writes a citation-backed report plus manifest.
Capture The Important Parts Of A Site
argus capture-site -u "https://docs.example.com"Argus stays on-domain, uses sitemap-assisted discovery plus heuristic link scoring, saves the important pages it finds, and writes a detailed summary with references.
Build A Docs + Research Pack
argus build-research-pack -t "example sdk"
argus build-research-pack -t "example sdk" --official-url "https://docs.example.com"Argus captures official docs into its local docs cache, adds non-official supporting sources from search, and writes a combined research pack with traceable artifacts.
Development
Repo development is pinned to Python 3.12. The package runtime floor remains Python 3.11, but contributors should use the uv workflow below so local verification matches CI and avoids accidentally using an older system interpreter.
uv sync --python 3.12 --extra dev --extra mcp
uv run pytest tests/ -v --tb=shortThe repo includes .python-version with 3.12 so uv, pyenv, and similar tools pick the right interpreter by default. More contributor guidance lives in CONTRIBUTING.md.
Providers
Provider | Credit type | Free capacity | Setup |
DuckDuckGo | Free (scraped) | Unlimited | None |
Yahoo | Free (scraped) | Unlimited | None — fragile, auto-skipped if broken |
SearXNG | Free (self-hosted, off by default) | Unlimited — 70+ engines¹ | Docker |
GitHub | Free (API) | Unlimited | None (token for higher rate limit) |
WolframAlpha | Free (API key) | 2,000 queries/month | |
Brave Search | Monthly recurring | 2,000 queries/month | |
Tavily | Monthly recurring | 1,000 queries/month | |
Exa | Monthly recurring | 1,000 queries/month | |
Linkup | Monthly recurring | 1,000 queries/month | |
Parallel AI | Monthly recurring | $5 credit with card on file, up to 5,000 searches/month | |
Serper | One-time signup | 2,500 credits | |
You.com | One-time signup | $20 credit | |
Valyu | One-time signup | $10 credit |
¹ SearXNG aggregates Google, Bing, Yahoo, Startpage, Ecosia, Qwant, Wikipedia, and 60+ more — all behind a single self-hosted endpoint. Run docker compose up -d on any machine with 512MB of free RAM.
² WolframAlpha returns computed answers (math, unit conversions, factual lookups), not web search results. It only activates in grounding and research modes. Queries it can't compute (general web searches) return empty — no error, no health penalty.
7,000+ free queries/month from recurring free-tier providers with API keys (WolframAlpha 2k + Brave 2k + Tavily 1k + Exa 1k + Linkup 1k), or up to 12,000+ when Parallel's monthly credit is available to an eligible account with a card on file. DuckDuckGo, Yahoo, and GitHub have no monthly cap. SearXNG is disabled by default (enable in .env). Routing priority: Tier 0 (free: SearXNG*, DuckDuckGo, Yahoo, GitHub, WolframAlpha) → Tier 1 (monthly recurring: Brave, Tavily, Exa, Linkup, Parallel) → Tier 3 (one-time: Serper, You.com, Valyu, SearchAPI). Budget-exhausted providers are skipped automatically.
HTTP API
All endpoints prefixed with /api. OpenAPI docs at http://localhost:8000/docs.
Local loopback calls can use the API without auth. Remote HTTP callers must send ARGUS_API_KEY as either Authorization: Bearer ... or X-API-Key: .... Privileged routes under /api/admin/* require ARGUS_ADMIN_API_KEY (or fall back to ARGUS_API_KEY if no separate admin key is configured).
# Search
curl -X POST http://localhost:8000/api/search \
-H "Content-Type: application/json" \
-d '{"query": "python web frameworks", "mode": "discovery", "max_results": 5}'
# Search with score attribution
curl -X POST http://localhost:8000/api/search \
-H "Content-Type: application/json" \
-d '{"query": "python web frameworks", "include_attribution": true}'
# Multi-turn search (conversational refinement)
curl -X POST http://localhost:8000/api/search \
-H "Content-Type: application/json" \
-d '{"query": "what about async?", "session_id": "my-session"}'
# Extract content from a working URL
curl -X POST http://localhost:8000/api/extract \
-H "Content-Type: application/json" \
-d '{"url": "https://example.com/article"}'
# Recover a dead or moved URL
curl -X POST http://localhost:8000/api/recover-url \
-H "Content-Type: application/json" \
-d '{"url": "https://example.com/old-page", "title": "Example Article"}'
# Network-free process liveness (container health target)
curl http://localhost:8000/api/live
# Public minimal startup and cached readiness
curl http://localhost:8000/api/startup
curl http://localhost:8000/api/ready
# Authenticated operator status, health compatibility, and budgets
curl -H "Authorization: Bearer $ARGUS_ADMIN_API_KEY" \
http://localhost:8000/api/admin/status
curl -H "Authorization: Bearer $ARGUS_ADMIN_API_KEY" \
http://localhost:8000/api/admin/budgets
curl -H "Authorization: Bearer $ARGUS_ADMIN_API_KEY" \
http://localhost:8000/api/admin/maya-outbox/status
curl -H "Authorization: Bearer $ARGUS_ADMIN_API_KEY" \
http://localhost:8000/api/admin/maya-outbox/dead-letters
# After correcting the cause of a permanent rejection:
curl -X POST -H "Authorization: Bearer $ARGUS_ADMIN_API_KEY" \
http://localhost:8000/api/admin/maya-outbox/DELIVERY_ID/recover/api/health remains a 200 liveness compatibility route. It intentionally
does not check PostgreSQL, providers, Maya, or the browser, so a dependency
outage cannot cause container restart storms. See
production operations for the canonical topology and
operator procedures, and operational status for endpoint semantics,
readiness classification, observation expiry, and safe telemetry.
Search modes
Mode | Use for | Example |
| Related pages, canonical sources | "Find the official docs for X" |
| Broad exploratory retrieval | "Latest approaches to Y?" |
| Finding moved/dead content | "This URL is 404" |
| Fact-checking with live sources | "Verify this claim about Z" |
Tier-based routing always applies first. Within each tier, the mode selects provider order.
Response format
{
"query": "python web frameworks",
"mode": "discovery",
"results": [
{
"url": "https://fastapi.tiangolo.com",
"title": "FastAPI",
"snippet": "Modern Python web framework",
"provider": "duckduckgo",
"score": 0.0164,
"score_attribution": {"duckduckgo": 0.0164},
"egress": "unknown",
"machine": null
}
],
"total_results": 1,
"cached": false,
"traces": [
{"provider": "duckduckgo", "status": "success", "results_count": 5, "latency_ms": 312}
]
}Each result includes url, title, snippet, domain, provider, and score. The traces array shows which providers were called and their outcomes.
When include_attribution is true, each result also includes
score_attribution: a provider-to-score map that decomposes the result's
Reciprocal Rank Fusion score. RRF is additive, so each provider's attribution is
exactly its own rank contribution, and the values sum to score. Attribution is
off by default and cached separately from non-attributed searches.
Budgets
{
"budgets": {
"brave": {"remaining": 1847, "monthly_usage": 153, "usage_count": 153, "exhausted": false},
"duckduckgo": {"remaining": 0, "monthly_usage": 0, "usage_count": 42, "exhausted": false}
},
"token_balances": {"jina": 9833638}
}Each provider tracks usage. Tier 1 (monthly) uses a 30-day rolling window; tier 3 (one-time) uses a lifetime counter that never resets. When a provider hits its budget, Argus skips it and moves to the next. Free providers (DuckDuckGo, GitHub) have no limit. SearXNG is free but disabled by default. Set ARGUS_*_MONTHLY_BUDGET_USD to enforce custom limits per provider.
Dashboard
Run the HTTP server and open /dashboard:
argus serve
# http://127.0.0.1:8000/dashboardThe dashboard shows provider budget burn, over-pace and exhausted providers, query volume for the last 30 days, usage by machine, and recent provider activity. Budget cards refresh automatically.
Set ARGUS_ADMIN_API_KEY to require dashboard login. If no admin key is set,
the dashboard is open to anyone who can reach the server, which is suitable only
for trusted local use.
For subpath deployment behind a reverse proxy, set ARGUS_ROOT_PATH to the
external path prefix:
ARGUS_ROOT_PATH=/argus argus serveThat makes dashboard redirects, links, and HTMX fragment URLs work when the
proxy serves Argus at a path such as https://khamel.com/argus/.
For direct public HTTPS, the repo includes a Caddy profile:
ARGUS_DOMAIN=argus.example.com ACME_EMAIL=you@example.com \
docker compose --profile proxy up -dFor an existing Authentik/nginx deployment, keep authentication at the proxy
layer and set ARGUS_ROOT_PATH to the public prefix.
Integration
CLI
argus search -q "python web framework" # zero-config, uses DuckDuckGo
argus search -q "python web framework" --mode research -n 20
argus search -q "python web framework" --free # free providers only (no paid API calls)
argus search -q "python web framework" --attribution # show per-provider score attribution
argus search -q "fastapi" --session my-session # multi-turn context
argus extract -u "https://example.com/article" # extract clean text
argus extract -u "https://example.com/article" -d nytimes.com # auth extraction
argus recover-url -u "https://dead.link" -t "Title"
argus doctor # full setup diagnostics
argus health # provider status
argus budgets # budget + token balances
argus mcp check # validate MCP setup
argus set-balance -s jina -b 9833638 # track token balance
argus test-provider -p brave # smoke-test a provider
argus serve # start API server
argus mcp serve # start MCP server
argus mcp init # add MCP config to projectAll commands support --json for structured output.
Pass session_id to any search call. Argus stores each query and extracted URL through the same SQLAlchemy repository used by the retrieval ledger (ARGUS_DB_URL, PostgreSQL in production and SQLite for direct local use). Reusing the same session_id gives the broker context from prior queries — follow-up searches are automatically refined using earlier conversation context. Sessions persist across restarts. Omit session_id for stateless, one-shot searches.
Legacy sessions from the former budget SQLite database can be reconciled without mutating the target first:
argus ledger reconcile-sessions \
--source sqlite:///argus_budgets.db \
--target "$ARGUS_DB_URL"
# Review source/imported/skipped/conflicting, then repeat with --apply.The import is idempotent: an identical existing session is skipped and a different session with the same ID is reported as conflicting.
MCP
MCP is a stateless protocol adapter over the authenticated HTTP API. It does not construct providers or a broker and does not own browser, database, budget, session, health, or outbox state. Configure the adapter process with:
export ARGUS_AUTHORITY_URL=http://argus-api:8000
export ARGUS_AUTHORITY_TOKEN=replace-with-a-scoped-caller-tokenOption A — Local adapter (stdio)
Install the adapter on the same machine as your MCP client:
{
"mcpServers": {
"argus": {
"command": "argus",
"args": ["mcp", "serve"]
}
}
}Use the full path if argus isn't on PATH: "/home/you/.local/bin/argus".
The adapter inherits ARGUS_AUTHORITY_URL and ARGUS_AUTHORITY_TOKEN from
the client process. To run a local broker instead, development environments
must explicitly set ARGUS_MCP_STANDALONE=true; production rejects it.
Works with Claude Code, Codex CLI, OpenCode, Cursor, and any stdio-based MCP client. Use argus mcp init --global --client all to write native client configs for the current machine.
Detailed client setup and verification commands live in docs/mcp-clients.md.
Option B — Remote MCP adapter (clients over Tailscale)
Run Argus on one machine, connect every client over the network. No local install on clients.
On the adapter host:
export ARGUS_API_KEY=replace-with-a-long-random-secret
export ARGUS_AUTHORITY_URL=http://argus-api:8000
export ARGUS_AUTHORITY_TOKEN="$ARGUS_API_KEY"
argus mcp serve --transport streamable-http --host YOUR_TAILSCALE_IP --port 8001Remote MCP credentials must also be valid scoped credentials at the HTTP
authority because the adapter forwards each authenticated bearer token
unchanged. For stdio, ARGUS_AUTHORITY_TOKEN is the caller credential.
To keep the HTTP API and remote MCP service running after reboot on a systemd host:
cat >mcp.env <<'EOF'
ARGUS_AUTHORITY_URL=http://argus-api:8000
ARGUS_AUTHORITY_TOKEN=replace-with-scoped-caller-token
ARGUS_API_KEY=replace-with-the-same-scoped-caller-token
EOF
chmod 600 mcp.env
ARGUS_MCP_ENV_FILE="$PWD/mcp.env" scripts/install-systemd.sh
systemctl status argus argus-mcp --no-pagerThe installer validates the minimal adapter environment, installs it as
root-only /etc/argus/mcp.env, then installs and starts both units. The MCP
unit never loads the authority's .env, provider vaults, database settings,
browser paths, or writable data volumes.
On each client:
Client | Config |
Claude Code |
|
OpenCode |
|
Cursor | Same as Claude Code — reads |
Codex CLI |
|
Gemini CLI |
|
Antigravity |
|
With Tailscale, <server> is your machine's Tailscale IP (e.g. 100.x.x.x). One server, every machine on your mesh gets search.
One-command provisioning:
# Load secrets, then push config to any machine:
eval $(secrets decrypt argus | grep -E 'ARGUS_REMOTE_URL|ARGUS_API_KEY' | sed 's/^/export /')
curl -s https://raw.githubusercontent.com/Khamel83/argus/main/scripts/provision-mcp-client.sh | bash -s local # this machine; uses local stdio if argus is installed
curl -s https://raw.githubusercontent.com/Khamel83/argus/main/scripts/provision-mcp-client.sh | bash -s user@100.x.x.x # remote machineThe script writes Claude/Cursor, Codex, and OpenCode configs on the target.
Local stdio does not require an MCP listener key, but the adapter still
requires its scoped ARGUS_AUTHORITY_TOKEN. Remote MCP mode requires
ARGUS_REMOTE_URL and ARGUS_API_KEY. Requires Python 3.
argus mcp init also generates configs automatically:
argus mcp init --global # local stdio adapter for Claude Code + OpenCode + Cursor
argus mcp init --client codex # local stdio for Codex (writes ~/.codex/config.toml)
argus mcp init --client opencode # local stdio for OpenCode
ARGUS_REMOTE_URL=http://argus.local:8271 ARGUS_API_KEY=... argus mcp init --global --client all
argus mcp init --client gemini # prints gemini mcp add command
argus mcp init --global --client all # everything aboveRelease Status
Pushing main does not publish PyPI. Package and MCP Registry publication happens through the GitHub publish workflow on release creation or manual dispatch. See docs/releasing.md for version sync, preflight checks, and publish verification.
Transports: stdio (default local adapter), sse (legacy remote), and
streamable-http (modern remote, "type":"http" in config). Remote MCP
transports require ARGUS_API_KEY; every transport delegates execution to
ARGUS_AUTHORITY_URL.
Available tools:
HTTP-backed stdio and remote MCP:
search_web,extract_content,recover_url,expand_links,search_health,search_budgets,recover_dead_article,capture_site, andbuild_research_packExplicit standalone development additionally exposes local-only
test_provider,cookie_health,valyu_answer, path/file tools, and resources. These are intentionally absent from production adapters.
search_web accepts free_only=true to restrict results to free (tier-0) providers only, and include_attribution=true to include per-provider score attribution in the Markdown response.
Using Argus from MCP vs HTTP
Two transports, one rule: agents use MCP, everything else uses HTTP.
MCP (
argus mcp serve) — a stateless authenticated adapter for AI harnesses that speak MCP natively. Core tools delegate to the HTTP authority:search_web,extract_content,recover_url,expand_links, and workflow starts. MCP restarts cannot fork accounting, sessions, health, or outbox state.HTTP (
POST /api/search,POST /api/extract,POST /api/workflows/...) — for scripts, cron jobs, and service integrations (including Maya). Send a scoped caller credential inAuthorization; body"caller"values are diagnostic labels and cannot override the authenticated identity.
The cross-service transport and role contract for the wider fleet (Maya / Hermes / Argus) is canonical in Maya's architecture documentation.
Python
Direct broker and extraction imports are a standalone development convenience. Production Python callers use the authenticated HTTP API so all execution and durable accounting remain in one authority.
from argus.broker.router import create_broker
from argus.models import SearchQuery, SearchMode
from argus.extraction import extract_url
broker = create_broker()
response = await broker.search(
SearchQuery(query="python web frameworks", mode=SearchMode.DISCOVERY, max_results=10),
compute_attribution=True,
)
for r in response.results:
print(f"{r.title}: {r.url} (score: {r.score:.3f})")
print(r.score_attribution)
content = await extract_url(response.results[0].url)
print(content.title)
print(content.text)Content Extraction
Argus tries up to twelve methods to extract content from any URL: auth extraction for paywalls, then local extractors (trafilatura, Crawl4AI, Obscura, Playwright, residential IP), then external APIs (Jina, Valyu Contents, Firecrawl, You.com, Wayback, archive.is). Each attempt is quality-checked for completeness and garbage output. See docs/providers.md for the full extractor comparison.
Completeness assessment runs automatically after every successful extraction. Argus scores five signals — trailing ellipsis, feed truncation markers ("Read more", WordPress RSS footers), mid-sentence endings, abrupt final paragraphs, and suspicious round word counts — and returns is_complete, completeness_confidence, and truncation_type alongside the text. When confidence is ≥ 85%, Argus continues trying the next extractor rather than returning a partial result; this means a trafilatura fetch that ends with "..." will automatically fall through to Playwright, Jina, Wayback, etc. Callers that already have text (e.g. RSS feed items) can use POST /api/assess-content to check completeness without triggering extraction.
Obscura (optional) is a lightweight Rust headless browser (~70MB binary, 30MB RAM) with built-in stealth mode — it sets navigator.webdriver=undefined, randomizes canvas/GPU/audio fingerprints per session, and blocks 3,520 tracker domains. This directly addresses bot detection on JS-heavy and anti-scraping sites that block standard Playwright/Chrome. No API key, no rate limit — fully local.
Two ways to use it:
Mode | Setup | What you get |
CLI extraction step | Install binary on | Argus auto-detects it; stealth browser as fallback step before Playwright |
CDP backend for Playwright | Run | Playwright uses Obscura as its browser engine — stealth + 30MB vs 200MB + DOM-to-Markdown output |
Install the binary: github.com/h4ckf0r0day/obscura/releases
Extract gets the full text of a working URL and tells you whether that text is complete. Recover-URL finds alternatives when a URL is dead, paywalled, or radically changed.
Architecture
Caller (CLI/HTTP/MCP/Python) → SearchBroker → tier-sorted providers → RRF ranking → response
↕ SessionStore (optional)
Extractor (on demand) → 12-step fallback chain with quality gatesModule | Responsibility |
| Tier-based routing, ranking, dedup, caching, health, budgets |
| Provider adapters (one per search API) |
| 12-step URL extraction fallback chain with quality gates |
| Multi-turn session store and query refinement |
| Authenticated production execution authority |
| HTTP caller in production; direct execution in development |
| Stateless MCP-to-HTTP adapter |
| Shared PostgreSQL authority state; SQLite standalone development |
| Cached readiness, typed dependency observations, process identity, bounded metrics |
Add new providers or extractors with a single adapter file. See CONTRIBUTING.md for the interface.
How a Query Works
query arrives → cache? → build provider queue → execute sequentially → RRF fuse → dedup → respondCache check.
SearchCachehashes the normalized query, mode, and whether attribution was requested (SHA256). Hit returns immediately with a TTL of 168 hours (7 days).Provider queue.
resolve_routing()takes the mode-specific preference list and stable-sorts by tier: tier 0 (free) first, tier 1 (monthly) next, tier 3 (one-time) last. Example for discovery mode:searxng → duckduckgo → yahoo → github → brave → exa → tavily → linkup → parallel → serper → you → valyuSequential execution with gates. Each provider is checked in order. Four gates must pass before an API call:
Config — is the provider enabled and configured (API key present)?
Health — has it failed 5+ consecutive times (triggers 60-minute cooldown)?
Budget — for tier 1+: is the budget exhausted? For tier 1 (monthly), pacing checks if the 7-day usage rate would drain the remaining budget in under a week — empty days bank headroom. For tier 3 (one-time), a lifetime counter gates access — exhaustion is the sole check.
Execute — the actual HTTP call. Successes reset failure counters; failures increment them.
RRF fusion. Results from all queried providers are merged using Reciprocal Rank Fusion (
k=60). Each result's score is the sum of1/(k + rank)across every provider that returned it. Results appearing in multiple providers rank higher.Dedup and truncate. URLs are normalized (stripped
www., tracking params likeutm_*, trailing slashes) and deduplicated. The merged list is truncated tomax_results(default 10).Cache and persist. The authority writes the final response to its in-memory cache and configured SQL repository (PostgreSQL in production, SQLite for standalone development). Search results and extractions include provenance metadata (
egress,machine,source_type) for downstream audit. Existing databases are upgraded additively at startup.
Configuration
All config via environment variables. See .env.example for the full list. Limited API-key providers are opt-in: set both the API key and ARGUS_<PROVIDER>_ENABLED=true. Missing keys degrade gracefully — providers are skipped, not errors.
When running from the repo, Argus now auto-loads .env and .env.local (without overriding already-exported environment variables). Disable this behavior with ARGUS_AUTOLOAD_DOTENV=false.
Variable | Default | Description |
|
| Production authority is |
| — | HTTP API base URL required by production CLI and MCP adapters |
| — | Scoped caller token for production CLI and MCP adapters |
|
| Explicit development-only local MCP execution |
|
|
|
|
|
|
|
| Set |
|
| SearXNG endpoint |
| — | Remote residential SearXNG endpoint (e.g. over Tailscale) |
|
| Opt in to providers that consume limited credits or quotas |
| — | Brave Search API key |
| — | Serper API key |
| — | Tavily API key |
| — | Exa API key |
| — | Linkup API key |
| — | Parallel AI API key |
| — | You.com API key |
| — | Valyu API key (search, contents, answer) |
| — | Firecrawl API key (content extraction) |
| — | GitHub token (higher rate limit) |
| platformdirs user data dir | Override the Argus runtime corpus root |
| provider-specific | Query-count budget for most providers; USD budget for Valyu |
| false | Enable Crawl4AI extraction step |
| false | Enable You.com Contents API extraction |
| — | Obscura CDP endpoint (e.g. |
| 20 | Timeout for Obscura CLI subprocess calls |
| 168 | Result cache TTL |
|
| Host used by |
|
| Port used by |
|
| Auto-load |
| — | Required for non-local HTTP API and remote MCP callers |
| — | Enables dashboard login and admin API authentication |
|
| Atomic authority selection. |
| — | Exact comma-separated HTTP Host allowlist; required for a remote production listener |
| — | Exact comma-separated browser Origin allowlist. Set explicitly, including an empty value, for remote production |
| — | Stable random secret of at least 32 characters used to bind v2 retrieval sessions to authenticated principals |
|
| Stable organization-policy identity included in accepted execution cohorts |
| — | Public subpath prefix for dashboard links and redirects, e.g. |
| — | Maya's dedicated Argus retrieval-capture endpoint; delivery stays disabled when unset |
| — | Dedicated shared secret for Maya capture delivery; never reuse the generic Maya ingest token |
|
| Maximum durable captures claimed by one delivery pass (bounded to 100) |
|
| Days to retain acknowledged capture bodies before preserving audit metadata only |
/api/v2/* is additive and returns a canonical version-2 envelope. It remains
fail-closed with unready while the evidence authority is disabled. Unsafe
Host, Origin, credential, media-type, and body-size combinations are rejected
before provider, extractor, session, or persistence work. Version-1 routes
retain their established response shapes.
When Not To Use Argus
Argus is best when you need search, capture, provenance, and local artifacts together.
Avoid it when:
you only need one search API and do not need fallback or budget controls
you only need a one-off page scrape with no persistent corpus or report output
you need an end-user search UI rather than backend retrieval infrastructure
you need fully deterministic summarization with no heuristic or LLM-assisted steps
FAQ
How is this different from calling Tavily/Serper directly? Argus calls them for you — plus 13 other providers. You get one ranked, deduplicated result set instead of managing multiple API keys and stitching results together. Free providers are tried first, so you only burn credits when needed.
Can I run only one provider? Yes. Set only the API key for the provider you want. All others are silently skipped. For zero-config, just install and go — DuckDuckGo + Yahoo handle search with no keys.
Do I need Docker?
No. pip install argus-search works immediately on any machine with Python 3.11+. Docker is only needed for SearXNG (set ARGUS_SEARXNG_ENABLED=true in .env) or Crawl4AI (local JS rendering).
Which Python version should contributors use?
Use Python 3.12 for repo development and verification: uv sync --python 3.12 --extra dev --extra mcp then uv run pytest tests/ -v --tb=short. The published package still supports Python 3.11+.
What is the safest way to deploy Argus on a network?
Use Tailscale or another private network, bind explicitly to the trusted interface, set ARGUS_API_KEY, and reserve /api/admin/* for ARGUS_ADMIN_API_KEY. Treat direct internet exposure as an advanced mode behind a reverse proxy.
License
MIT — see CHANGELOG.md for release history.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityDmaintenanceEnables web search for AI agents with pay-per-search in USDC, no API keys needed.Last updatedMIT
- AlicenseAqualityBmaintenanceWeb search for AI agents across 6 engines (Serper, Brave, Exa, Tavily, Firecrawl, Perplexity) through one search tool. Routes each query to the cheapest engine that clears a quality bar and caches repeats. Hosted, streamable-HTTP, BYOK supported.Last updated11MIT
- AlicenseAqualityFmaintenanceFree multi-source web search server for AI agents, with confidence scoring and token optimization.Last updated3825Apache 2.0
- AlicenseAqualityBmaintenanceEnables AI agents to perform unified web searches, GitHub, and GitLab searches with caching, reranking, and fallback across multiple providers.Last updated48919MIT
Related MCP Connectors
Web search for AI agents — one tool across 6 engines, routed to the cheapest + cached.
The best web search for your AI Agent
LLM-ready web search + instant answers + URL-to-clean-text fetch for agents and RAG.
Appeared in Searches
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Khamel83/argus'
If you have feedback or need assistance with the MCP directory API, please join our Discord server