RunLedger
Website: https://runledger.io
Deterministic CI regression checks for tool-using agents. Record tool calls once, replay in CI, and fail PRs on mismatches, contract violations, or budget regressions.
- Demo repo: https://github.com/runledger/runledger-demo (main is green; regression branches fail for real reasons)
- If this is useful, please star the repo (it helps a lot).
RunLedger is a CI harness, not an "eval metrics framework":
- DeepEval-style tools help you score behavior.
- RunLedger helps you ship safely by making agent tests deterministic and merge-gated.
Try it now (60 seconds)
pipx install runledger
runledger init
runledger run ./evals/demo --mode replay --baseline baselines/demo.json
Integrations (merged)
- hoangsonww/Agentic-AI-Pipeline - https://github.com/hoangsonww/Agentic-AI-Pipeline/pull/24
- zhongyu09/openchatbi - https://github.com/zhongyu09/openchatbi/pull/8
- joshuaalpuerto/mcp-agent - https://github.com/joshuaalpuerto/mcp-agent/pull/3 Details: docs/integrations.md
Why RunLedger (in one minute)
The problem
Agents regress silently. Standard unit tests can't catch:
- prompt drift that breaks tool schemas
- hallucinated tool arguments
- latency spikes or budget overruns
- flaky external APIs causing false negatives in CI
The solution
RunLedger stops regressions by shifting from "vibes-based" evaluation to deterministic contracts:
- Record & replay: record tool outputs once; replay them in CI for instant, stable tests.
- Strict contracts: enforce tool schemas, calling order, and allowlists.
- Budget gating: fail PRs automatically if wall time, tool-call count, or tool errors exceed defined limits.
RunLedger vs evaluation frameworks
| Feature | DeepEval / Ragas / TruLens | RunLedger |
|---|---|---|
| Primary goal | Scoring quality ("Is this answer helpful?") | Shipping safely ("Did we break the build?") |
| Tool execution | Often live or mocked manually | Record/replay cassettes (automatic mocking) |
| Pass/fail criteria | LLM-graded scores (0.0 - 1.0) | Hard contracts (schema, budgets, order) |
| Best for | Improving prompt quality | Preventing regressions in production |
Note: you can use both. Use DeepEval to calculate scores, and wrap your agent in RunLedger to ensure it runs deterministically in CI.
What it looks like in a PR
PR blocked (checks fail):
Why it failed (RunLedger output):
Artifacts are written to runledger_out/<suite>/<run_id>/:
report.html,summary.json,junit.xml,run.jsonl
FAQ: Why not just use DeepEval?
DeepEval is excellent for evaluation metrics and benchmarking. RunLedger is focused on CI determinism for tool-using agents:
- Record tool calls once -> replay in CI (stable, fast, no flaky external dependencies)
- Merge gates based on hard contracts (schema/tool/budgets), not "LLM-judge vibes"
- Baselines-as-code (diffs + promotions) that fit cleanly into PR workflows
If you already use DeepEval, keep it - RunLedger can be the harness that makes agent tests CI-grade.
When to use RunLedger vs DeepEval
Use RunLedger when you need:
- deterministic CI for tool-using agents (web/APIs/DBs)
- hard pass/fail contracts (schema/tool order/budgets)
- baselines + PR regression gates
Use DeepEval when you need:
- rich evaluation metrics / model-graded scoring / benchmarking workflows
Use both if you want DeepEval scoring inside a deterministic CI harness.
How it works
-
You define a suite (
suite.yaml) and cases (cases/*.yaml). -
The runner launches your agent under test as a subprocess (any language).
-
The agent requests tools via a stdio JSON protocol.
-
The runner either:
- records tool results to a cassette (local/dev), or
- replays tool results from a cassette (CI/deterministic).
-
The agent emits a final JSON output.
-
The runner applies assertions + budgets, compares to a baseline, writes artifacts, and exits non-zero on regressions.
Agent-under-test protocol (language-agnostic)
Transport: newline-delimited JSON messages over stdin/stdout.
Hard rule: agent must write protocol JSON only to stdout. Any human logs must go to stderr (stdout must stay parseable).
Runner -> Agent
task_start
{ "type": "task_start", "task_id": "t1", "input": { "...": "..." } }
tool_result
{ "type": "tool_result", "call_id": "c1", "ok": true, "result": { "...": "..." } }
Agent -> Runner
tool_call
{ "type": "tool_call", "name": "search_docs", "call_id": "c1", "args": { "q": "..." } }
final_output (must be JSON)
{ "type": "final_output", "output": { "category": "billing", "reply": "..." } }
Optional:
log(structured debug)task_error(explicit failure)
Eval suite format
evals/<suite>/suite.yaml (example)
suite_name: support-triage
agent_command: ["python", "agent.py"]
mode: replay # replay | record | live
cases_path: cases
tool_registry:
- search_docs
- create_issue
assertions:
- type: json_schema
schema_path: schema.json
budgets:
max_wall_ms: 20000
max_tool_calls: 10
max_tool_errors: 0
baseline_path: baselines/support-triage.json
evals/<suite>/cases/t1.yaml (example)
id: t1
description: "triage a login ticket"
input:
ticket: "User cannot login"
context:
plan: "pro"
cassette: cassettes/t1.jsonl
assertions:
- type: required_fields
fields: ["category", "reply"]
budgets:
max_wall_ms: 5000
Record/replay tool calls (cassettes)
Why record/replay?
Agents often depend on external tools (search, DB, HTTP). Live calls in CI are:
- slow
- flaky
- non-deterministic
- expensive
Instead:
- record once (live tools) -> write cassette
- replay in CI (deterministic) -> stable and fast
Cassette format (JSONL example)
Each line is one tool invocation:
{"tool":"search_docs","args":{"q":"reset password"},"ok":true,"result":{"hits":[...]}}
{"tool":"create_issue","args":{"title":"Login issue","priority":"p2"},"ok":true,"result":{"id":"ISSUE-123"}}
Replay matching (MVP):
- exact match on
tool+ canonicalizedargs - if not found: the case fails with a clear "cassette mismatch" error
Assertions (deterministic)
MVP assertions:
-
json_schema(validate final output with JSON Schema) -
required_fields(keys exist / basic typing) -
regex/contains(for specific fields) -
tool_contract:- must call tool X
- must not call tool Y
- X before Y (ordering)
Not default-gating (optional later):
- LLM-judge scoring
- semantic similarity scoring
Budgets (merge gates)
MVP budgets:
max_wall_msmax_tool_callsmax_tool_errors
Not yet enforced (accepted in config, reported in artifacts when the agent sends metrics, but they do not fail a run today):
max_tokens_outmax_cost_usd
Baselines + regression checks
On each run, you can compare against a baseline and fail CI if:
- success rate drops below threshold
- average or p95 latency increases beyond allowed delta
Typical workflow:
- record cassettes locally
- establish a baseline from a known-good run
- run replay mode on every PR and gate merges on regressions
runledger baseline promote --from runledger_out/<suite>/<run_id> --to baselines/<suite>.json
runledger run ./evals/<suite> --mode replay --baseline baselines/<suite>.json
Output artifacts
A run produces:
run.jsonl-- append-only event log (steps, tool calls/results, outputs)summary.json-- suite + case metrics, pass/fail, regression summaryjunit.xml-- CI-native pass/fail (each case maps to a test)report.html-- static shareable report (no server required)
These files are intentionally stable so they can be:
- diffed in PRs
- uploaded as CI artifacts
- ingested by a future hosted add-on
GitHub Actions (example)
name: agent-evals
on:
pull_request:
jobs:
evals:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Run deterministic evals (replay)
uses: runledger/Runledger@v0.2
with:
path: ./evals/demo
mode: replay
- name: Upload eval artifacts
uses: actions/upload-artifact@v4
with:
name: agent-eval-artifacts
path: runledger_out/**
Determinism guide (rules of the road)
- Prefer
--mode replayin CI. - Ensure agent writes only JSONL protocol messages to stdout; logs go to stderr.
- Canonicalize tool call args (stable key ordering, avoid volatile fields).
- Avoid timestamps/randomness in final output; if needed, strip/normalize via
normalization.normalization: strip_keys: ["timestamp", "request_id"] strip_paths: ["meta.seed"] replace_text: - pattern: "\\d{4}-\\d{2}-\\d{2}T\\d{2}:\\d{2}:\\d{2}Z" replacement: "<timestamp>"
- Keep cassettes safe to commit: redact secrets by default.
Docs
docs/quickstart.md-- install + first rundocs/assertions.md-- assertions, tool contracts, budgetsdocs/baselines.md-- baselines, diffing, promotiondocs/ci.md-- CI setup with GitHub Actionsdocs/contracts.md-- public contracts (YAML, protocol, artifacts)docs/troubleshooting.md-- common errors and fixes
Roadmap
inittemplates for Python (OpenAI SDK), LangGraph/LangChain, and Node/TS- richer budgets (tokens/cost) via optional
task_metrics - PR comments bot for regression summaries
- plugin system for custom assertions
- HTML report trace viewer improvements
Commercial Support
RunLedger is MIT-licensed and free to self-host. For teams that want done-for-you implementation or ongoing maintenance, we offer:
- Hardening Sprint (fixed-scope implementation to get deterministic CI running fast)
- Assurance (monthly retainer for cassette and case updates, budget tuning, and incident response)
Contact: runledger.io/community.html#contact
Contributing
- Issues and PRs welcome.
- See
CONTRIBUTING.mdfor development setup, style, and testing. - Security issues: see
SECURITY.md.
License
MIT
Metadata
Release files for runledger 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| runledger-0.2.0.tar.gz | 39.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| runledger-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 84.7 kB
Release files / runledger-0.2.0.tar.gz
| Download URL | runledger-0.2.0.tar.gz |
|---|---|
| Size | 39.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
4022ed3b011625a4547a434846e5ce799dadf9e72c65a6ec61f3017d7e56564d
|
|
BLAKE2b-256 checksum How to use checksums |
b8fa9a31c3bffc2f47a3cac4f2b54a05f44f1abd9dea919178008f2fe28d044f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency logRelease files / runledger-0.2.0-py3-none-any.whl
| Download URL | runledger-0.2.0-py3-none-any.whl |
|---|---|
| Size | 45.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
4f0bd495af259e63ea5be545fea7c446b34b1b7368fc110879379b1c52469c6b
|
|
BLAKE2b-256 checksum How to use checksums |
0fa5aa18998a85e8f936e251d79690f2c06d90340b07c3394b251c32d7fdf824
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency log