marlow

Unattended by design

Tickets in.
Reviewed pull requests out.

Label a ticket in Linear, Jira, GitHub or Slack. Marlow builds it in a sandbox, reviews and tests its own diff, and opens the pull request. Nobody is at a keyboard.

  • Works from the tracker you already use
  • Self-reviewed, tested and risk-checked before you look
  • You set the merge gate, per project
  • Priced per run — tokens at provider cost
01You do not start it

The same five stages, every time

A ticket starts itself — nothing to open, nobody to prompt. Every stage is durable, and every stage leaves a row behind.

  1. 01

    Webhook

    POST /api/webhooks/linear/org-… · HMAC verified

  2. 02

    Workflow

    label match · or LLM triage

  3. 03

    Dispatch

    task queue: marlow · workflow.start()

  4. 04

    Sandbox

    clone repo · install deps · run agent

  5. 05

    Pull request

    open PR · post status to ticket source

runs.rowid 01HV8ZQ3X9MRT2KP
queued
02You do not babysit it, and you do not take its word for it

Writing the diff is the easy part

Any model can write a diff. The product is everything between the last line it writes and the moment it asks for you.

Every run passes these gates, in this order. The one below is a sample.

  1. review

    It reviews its own diff before you do

    In-pipeline review, then your test command, then a risk verdict on the branch.

    queued
  2. safety

    A migration gets executed, not just read

    Applied to a disposable copy of your schema before anyone trusts the SQL.

    queued
  3. merge

    The last gate is always yours

    Each project picks its policy — open the PR and stop, or wait for CI and merge. A parked run costs nothing.

    queued
Secrets that never sit in plaintext
Encrypted per project, decrypted inside the sandbox at the point of use.
A run's spend is a number, not an invoice line
Every model call is priced at the provider's own rate as it happens and written to the run.

You can prove what it did.

Every decision is one row in an append-only ledger. Six months on, “why did it touch that file” is a query, not an argument.

app/runs/02ea1e86Demo workspace
One run from ticket to pull request: each step, its model calls and its cost
app/runs/9992f4f9Demo workspace
A run parked at the approval gate, waiting for an owner before it merges
You do not teach it twice

Run fifty is not run one

A failed run is tuition — and tuition is not paid twice.

  1. write

    A failed run leaves a lesson

    Every failure distils to one compact lesson on the project.

  2. recall

    The next run reads it first

    It rides a capped block of the next run's prompt.

  3. retire

    What stops helping is dropped

    Recalled by runs that still fail, a lesson loses its place. It forgets on purpose.

  4. graduate

    The durable ones become a pull request

    Repeat lessons distil into a LEARNINGS.md, proposed as a pull request you merge.

  5. its memory is a file in your repo, merged by you.
Use cases

Not everything a team needs is a feature

Most start from a label on the ticket. Review and CI fixes start from the pull request.

coding
Work the small stuff
The export nobody has added, the endpoint that needs pagination.
fix-ci
Fix red CI
Pushes the fix to the same pull request. It never merges.
review-pr
Review a pull request
Judged against your own AGENTS.md. It writes nothing back.
verify-build
Prove the build still boots
Clone, install, build, tear down — on a schedule.
prd
Turn a one-line request into a spec
One line in, a spec out, against the repository's constraints.
intake
Ask the questions a bad ticket is missing
Asks for what a thin ticket is missing, before anything is spent.

Four of the 6 never write a feature.

Where it fits

It is not a faster editor

Editor tools make the hour at the keyboard better. Marlow works the queue when nobody is at one.

attended

a developeran editora diff

An editor assistant, Cursor, Claude Code — Marlow does not replace them.

unattended

a ticketsandboxgatesreview · tests · riska reviewed pull request

Marlow. Hosted, or in your own network on your own provider keys.

The real question: what happens to the forty tickets nobody is going to start?

Primary

Engineering teams with more backlog than reviewers

Label the work nobody has time to start. It comes back as a pull request that has already been reviewed once — and anyone on the team can file the ticket.

Marlow fits a team that has

  • A tracker it actually uses
  • CI
  • A habit of reviewing pull requests

Also

Agencies and studios

Fixed-price delivery makes cost per ticket the margin question. Per-run pricing makes a client’s work cost a number, not a monthly guess.

How agencies use Marlow
Wiring

What you send, what you get back

No SDK, nothing to install in your app. Post a signed webhook, declare what the project runs.

Sources
  • Linear
  • GitHub
  • Jira
  • Slack
  • Webhook
  • GitLabplanned
  • Bitbucketplanned

The ticket's label picks the workflow; anything unlabelled goes to triage.

Outputs
  • GitHub PRs
  • Slack notifications
  • GitLab merge requestsplanned
  • Bitbucket pull requestsplanned

Pull requests open under your own bot account, not ours.

Storage
  • S3-compatible
  • SFTP

Logs and artefacts land on storage you own.

Models

21 models across 7 vendors

OpenAI
7
Anthropic
6
Google
2
Perplexityvia OpenRouter
2
xAI
2
Qwenvia OpenRouter
1
Z.AIvia OpenRouter
1

You bring the keys, so tokens land on your provider bill — Marlow prices the harness, not the models. For the routed rows, the key you bring is OpenRouter's.

keys you can bring

  • Anthropic, OpenAI, Google, xAI, OpenRouter keys
  • Amazon Bedrock
  • OpenAI-compatible endpoints
  • your own Cloudflare AI Gateway

Send tickets from anywhere. The body carries only the ticket; repeat deliveries collapse on (source, externalId).

json
POST /api/webhooks/tickets/{sourceId}
X-Marlow-Signature: sha256=78c3…b201
Content-Type: application/json
{
"externalId": "TASK-2841",
"externalUrl": "https://internal.acme.io/tasks/2841",
"title": "Add CSV export to billing dashboard",
"body": "Customers want a one-click export from the invoices view…",
// The label is what picks the workflow.
"labels": ["coding", "billing"],
"author": {
"email": "morgan@acme.io",
"displayName": "Morgan Vale"
}
}
Control plane

The questions asked by whoever has to approve this

Not everyone who must say yes files tickets.

Where does the code run?

Its own container, on a sandbox image the project sets. The volume dies with the run.

Per project

Whose model keys are used?

Yours. One per organisation and vendor, encrypted, re-probed daily — a revoked key surfaces in settings, not a failed run.

/settings/provider-keys

What is the record?

One append-only row per mutation: organisation, actor, action, target, payload, time.

/settings/audit

What stops it spending?

A spend ceiling and a dispatch pause, refusing even a hand-started run. Cost is recorded per run and model.

/settings/limits · /analytics/costs

What can each person do?

Two roles, owner and member — no finer-grained permissions and no certification yet.

/settings/members

Can it run in our network?

A Helm chart and a compose file. Nothing durable on local disk.

Self-hosted

Measure

What whoever signs off on spend will ask

Your numbers, already in the console.

What shipped?

Pull requests merged per day, against the window before.

/analytics

How long did it take?

Ticket created to merged code, with Marlow's working time split from review, CI and waiting. Unmerged tickets are counted, not dropped.

/analytics

What did it cost?

Model spend per merged pull request, and by model and day.

/analytics · /analytics/costs

No before-Marlow comparison: nothing measured one.

Pricing

Pay for runs, not for seats

A run is one ticket worked to a terminal state. Free fits a team of three; every paid tier has unlimited seats.

Free needs no card. Paid plans are bought from the console’s billing page, monthly or yearly, and can be changed or cancelled there.

  • Free$0forever

    Enough real tickets to know whether it works on your repository.

    Runs included
    50 / month
    Concurrent runs
    1
    Additional runs
    dispatch stops
    Paid yearly
    —
    Token markup
    None
    Start on Free
  • Starter$49per month

    Past Free, not ready for $99.

    Runs included
    100 / month
    Concurrent runs
    2
    Additional runs
    $0.35 each
    Paid yearly
    $490 / year
    Token markup
    None
    Choose Starter
  • Team$99per month

    Routine work through the queue.

    Runs included
    500 / month
    Concurrent runs
    4
    Additional runs
    $0.35 each
    Paid yearly
    $990 / year
    Token markup
    None
    Choose Team
  • Scale$499per month

    Many repositories, one queue.

    Runs included
    3,000 / month
    Concurrent runs
    16
    Additional runs
    $0.25 each
    Paid yearly
    $4,990 / year
    Token markup
    None
    Choose Scale

Nothing that keeps you safe is an upsell.

A platform that meters its own safety features is not one to trust.

  • One sandbox per run, with scoped secrets
  • The append-only audit ledger
  • Workflow selection, triage and custom agents
  • Review, CI verdict and the merge gate
  • Tokens at provider list price — no markup, ever
  • Unlimited projects and repositories

Self-hosting and SSO · talk to us

Prices exclude VAT · Pay yearly for two months free

Start on Free

Start with one boring ticket.

Connect a repository and send it something you have been putting off. Set the gate to “open a pull request and stop” — the worst case is a branch you close.

No card required · nothing to cancel · read the FAQ