DocsGPT earns its size when documents need a product surface
DocsGPT goes beyond a chat box over uploaded PDFs. A team can create agents with their own prompts, knowledge, models, and tools, then connect those agents in a visual workflow. Sources can come from files, websites, Google Drive, SharePoint, Confluence, GitHub, or S3. Answers cite their documents, and guardrails can flag or block secrets, personal data, prompt injection, and ungrounded output.
The same knowledge can appear in the built-in web app, an embeddable widget, an OpenAI-compatible /v1 API, webhooks, or an MCP server. Schedules can run agents without a user waiting in chat. This breadth makes sense for an internal support or research platform. It is excess machinery if your requirement is one folder, one model, and one user.
One command still starts a multi-service system
The README leads with a shell installer that checks for Docker, installs the docsgpt command, and runs docsgpt up. A local installation opens on port 7091. The CLI can show status, follow logs, upgrade, back up data, and stop the stack while keeping its state. Release 0.21.0 also added a one-port standalone Compose arrangement and an air-gapped deployment guide.
Behind that command sit an API, a worker, PostgreSQL, Redis, a vector store, and file storage. You also choose a cloud model provider or provide local inference through Ollama, vLLM, or another OpenAI-compatible server. The abstraction is useful, but it cannot decide retention, backups, network exposure, credential rotation, or model capacity for you. Read the security checklist before giving other people access.
What happened when we ran it
Our sandbox installed commit 3d392b6 in 130 seconds, adding 279 packages and occupying 787 MB on disk. The build succeeded in 12 seconds. The checkout itself contained 2,500 files, about 584,722 lines of source, and used 103.9 MB. We ran it in an unprivileged Debian container with 3 CPUs, 8 GB of RAM, Python 3.12, and no secrets.
The tests stopped after 7 seconds with exit code 4. Pytest was loading tests/conftest.py when Python raised ModuleNotFoundError: No module named 'pytest_postgresql'. No test cases ran, so there is no passed or failed test count to soften that result. The repository declares the plugin in its development group. Our log only establishes that the module was missing from the installed environment that reached collection.
Pip-audit reported 3 known vulnerabilities. The supplied measurement does not name the packages or severity, so claiming a direct exploit path would go beyond the evidence. It is still a release gate: resolve the audit against the exact deployment image, rerun it, and record why any accepted advisory cannot be reached through the service. The repo had 22 CI workflow files and a tests directory, though no root Dockerfile was detected.
Contributors need Node 22 and PostgreSQL binaries
The backend package supports Python 3.12 or newer. The React frontend uses Node.js 22, and contributors are expected to run its lint, test, and build commands separately. Backend tests use pytest-postgresql to start a temporary database cluster. The contribution guide says pg_ctl and initdb must be on the path, even if an ordinary development database already runs in Docker.
That is a credible contributor setup for a 584,722-line platform, but it is not a casual clone-and-test experience. End-to-end checks add PostgreSQL, Redis, a mock language model, the API, worker, and Vite frontend. Some scripts expect explicit database roles and an internal key. The documentation spells this out well. Our 7-second collection failure shows why those details need to be followed exactly.
Team controls distinguish it from a personal RAG app
DocsGPT includes OIDC single sign-on, SCIM provisioning, roles, teams, sharing rules, audit logs, and per-team token or spending quotas. Operators can add OpenTelemetry and use several vector backends, including pgvector, FAISS, Qdrant, Milvus, Elasticsearch, and MongoDB. The MIT license applies to the team features listed in the README.
Those controls make DocsGPT credible for shared use. They also increase the number of policies an owner must settle before launch. A connector can read business data. A REST tool or MCP server can act outside the document store. Sandboxed code and paired-device shell access expand the blast radius further. Start with a narrow agent, minimum permissions, and a model endpoint whose data policy you have reviewed.
October activity is high, with 122 open pull requests
GitHub showed 18,303 stars and a same-day push on October 3, 2026. Release 0.21.0 arrived on September 16 with air-gap work, installer changes, a one-port stack, and a fix for connector OAuth tokens crossing origins. The project was not sitting still when we checked it.
The 169 combined open items split into 47 issues and 122 pull requests. Several new pull requests and connector requests appeared on October 3 alone. That volume indicates active development and a meaningful review burden at the same time. DocsGPT is worth a pilot when its several access paths replace separate internal tools. Make the pilot prove clean test collection, an explained dependency audit, and recovery from a real backup before calling the platform ready.

