Intermediate 12 minAgents

Agent Zero with Ollama: Docker installation and limites

Direct response

Yes, Agent Zero (agent0ai project) runs in a Docker container and can call a local Ollama by pointing to http://host.docker.internal:11434, the default address provided by the project for reaching the host from the container. The agent's computer (the container, with its Linux desktop and browser) remains separate from the inference machine: hosting everything locally alone does not guarantee that the built-in browser or extensions stay offline.

Agent Zero is an open-source agent framework published by agent0ai that gives the agent a real Linux desktop in a Docker container, a controllable browser, and coworking tools for documents. This guide covers its installation, connecting it to a local Ollama, choosing the model according to the role (conversation or utility model), and the real limitations of a small local model when faced with this scope of tasks.

By Mohamed Meguedmi·Update 2026-09-28·Tested on Windows, macOS, and Linux

#What Agent Zero is

Agent Zero (repository agent0ai/agent-zero) presents itself as a framework that gives the agent a complete Linux computer: an XFCE desktop in a Docker container, a browser with DOM annotation, live coworking on Markdown files, spreadsheets, and presentations, and a hub of more than 100 community plugins. The project had more than 19,000 stars on GitHub as of September 28, 2026, with the latest version, tagged v2.13, published on September 23, 2026.

This is not a specialized coding agent in the sense of OpenCode or Cline: Agent Zero targets cross-functional tasks (research, desktop application control, web interface review, analysis) at the cost of heavier infrastructure than a simple terminal binary.

The project also highlights “agent profiles” (specialists created on the fly, for example for a cautious financial analysis with spreadsheet deliverables), project management that isolates files, secrets, memories, and repositories by context, and multi-agent collaboration in which a lead agent delegates research, coding, analysis, or review to dedicated subagents. Each of these features consumes context and instruction-following capacity, which directly affects model choice once you move beyond simple chat.

i
In two words
Agent Zero is a Docker container that includes a Linux desktop and a browser for the agent, plus a choice of model provider (including Ollama) completely separate from this runtime infrastructure.

#Install the Docker container

The Local Agents Kit

Agents that act on your machine: agentic Cline, MCP, n8n + Ollama, local automations.

  • Lifetime online access
  • PDF + files
  • Lifetime updates

With Docker already installed, the most direct route is a single command that mounts the instance data in a persistent volume. The project also offers a script installer (A0 Install) for servers and headless mode, as well as a graphical launcher (A0 Launcher) that manages Docker, instances, and ports for you.

Terminal
docker run -p 80:80 -v a0_usr:/a0/usr agent0ai/agent-zero

Once the container is running, the web interface opens on the selected port (80 by default, or the one passed as a parameter) to configure the model provider before the first task. On a server without a graphical interface, the script installer supports a silent mode that creates a specified instance and port without opening a menu, which is useful for automated deployment or a remote machine accessible only through SSH.

#Connect a local Ollama

The official installation documentation explains the process in detail: in the settings for the conversation model, utility model, or embedding model, choose Ollama as the provider, enter the model name expected by Ollama (for example, llama3.2 or qwen2.5:7b), then enter the API URL if it differs from the default value.

→
The default address is not localhost
Agent Zero includes Docker-friendly defaults for Ollama on the host, at http://host.docker.internal:11434. This detail regularly trips up users who try http://localhost:11434 from inside the container, with no result, because localhost there refers to the container itself, not the host machine.

If the container cannot connect to Ollama, the documentation notes that port 11434 must be reachable from the container; the provided Docker Compose file maps host.docker.internal to the host gateway under Docker on Linux, and if both services share the same Docker network, the address can also be http://(nom from the container):11434.

#Which model to choose, and for what role

Agent Zero distinguishes three model slots: chat (main conversation), utility (memory organization, summarization), and embedding (memory search). The model name format depends on the provider: with Ollama, it is the model name alone (gpt-oss:20b), without a provider prefix unlike OpenRouter.

Model role and robustness requirements
RoleDocumented requirement
Chat (conversation)Must follow the agent's communication format (JSON with tool_name/tool_args)
Utility (memory, summary)Very small models (4B) often fail; a 70B model or a high-quality “flash/mini” cloud model works better
EmbeddingLess sensitive to size; used only to index memory for similarity search

The most commonly overlooked point: a decent conversational model can fail in a utility role if it is too small, silently degrading memory quality without the user understanding why the agent “forgets” or confuses facts from one session to the next.

#Tool calling with a small local model

Agent Zero documents a widespread problem with lightweight local models: the model explains the command instead of calling the tool that would execute it. The project proposes a prompt-only fix, without touching the code: the “Tiny Local” profile, which retains the standard tool-call format but removes visible reasoning fields from the communication prompt, asking only for an executable JSON object with tool_name and tool_args.

!
Symptom to watch for
If the agent describes what it "is going to do" instead of acting, or repeats a malformed-message warning without correcting itself, that is the documented sign of a local model that is too weak for the default communication format—not a framework bug.

An alternative that does not change the profile is to add a dedicated prompt file (the .promptinclude.md extension) that repeats the expected discipline: a visible response that is exactly a JSON object with exactly the fields tool_name and tool_args, with no Markdown formatting or text before or after it. The documentation is explicit about this fix’s limitation: it is a prompt and profile adjustment, not a change to the execution code — if a specific model continues to fail despite this discipline, the next step is to change models, not make the prompt even more complex.

#What the Linux desktop really changes

What sets Agent Zero apart from purely terminal-based agents is this complete XFCE desktop inside the container: the agent can open a real graphical application (Blender to model an object, a file manager, a visible terminal), and the user can observe every action while sharing the same virtual mouse and keyboard, with the ability to intervene at any time.

The built-in browser goes beyond simple page control: Annotate mode turns any web page into a surface of clickable instructions—change an element, inspect it, reuse it in another project, or leave a targeted comment that the agent then handles as a task.

!
Self-hosting proves nothing about browser privacy
The fact that the container runs on your own machine does not guarantee that the embedded browser or model inference remain offline: the chosen model provider (Ollama local or a cloud API) and the container's network configuration determine what actually leaves the machine.

#Connect MCP servers

Beyond its built-in tools (browser, terminal, files), Agent Zero can connect to external MCP servers to reach other services: the official documentation describes each MCP connection as a bridge—one can connect Gmail, another a database, and another an automation tool. An MCP server is declared either as a command run locally or as a remote URL, which changes the networking question: a command local to the container faces the same constraints as access to Ollama (host.docker.internal, shared Docker network), while a remote URL follows the container's normal network rules.

The documentation recommends limiting each connection to what is strictly necessary rather than adding connections as a precaution: every connected MCP server expands the surface the model can reach, including with a local model whose tool-calling behavior is less predictable than that of a high-end cloud model.

#Security checklist before connecting the model and tools

Three areas deserve explicit verification before letting Agent Zero operate without constant supervision: container isolation, secrets and API keys, and connected MCP servers.

Security checklist
SurfacePoint to verify
Sandbox / containerStay in Docker rather than running directly on the host; do not mount your entire home directory in the volume without understanding the risk.
Secrets and API keysUse global or project secrets instead of pasting a key in plain text into a prompt, screenshot, or bug ticket
Secret scopeGlobal secrets apply to all conversations and projects unless overridden; a project can define its own isolated secrets that take precedence over global secrets.
Connected MCP serversAdd only connections that are genuinely useful; each additional MCP bridge expands what the model can reach, independently of whether you choose Ollama locally or in the cloud
i
Secrets masked, not absent from risk
Project and global secrets are masked in the interface and may not be included in automatic backups. This protects what is displayed, but does not remove the need to limit MCP connections and the container’s network access to the task’s actual requirements.

#Compared with other local agents

Agent Zero compared with two other agent profiles
FrameworkWhat sets it apart
Agent ZeroA complete Linux desktop (XFCE) and a controllable browser in a Docker container; cross-functional tasks beyond coding
Hermes AgentTerminal and messaging agent (Telegram, Discord…) focused on persistent memory, with no graphical desktop
OpenCode / ClineCode agents in the terminal or editor, without a dedicated container or controllable browser

#Limitations to know before getting started

Misleading search volume
“Agent Zero” also refers to entertainment content in search engines; actual demand for the development framework is narrower than the raw keyword volume suggests.
Disk and RAM footprint
The container includes a full desktop in addition to the agent runtime: plan for more resources than with a minimal CLI agent, even if inference itself runs elsewhere via Ollama.
Undersized utility model
An undersized utility model degrades memory without an explicit error message; it’s the first thing to check if the agent seems to “lose the thread” from one session to the next.
Network internal to the container
host.docker.internal works with Docker Desktop and the provided Linux configuration, but a custom deployment (custom Docker network, remote hosting) requires entering the API URL manually again.
Frequently asked questions
Which Ollama address should you use from Agent Zero in Docker?+
http://host.docker.internal:11434 est l'adresse par défaut prévue par le projet quand Ollama tourne sur la machine hôte et Agent Zero dans son conteneur. localhost:11434 ne fonctionne pas depuis l'intérieur du conteneur, car il pointe vers le conteneur lui-même et non vers l'hôte. Si Ollama et Agent Zero partagent le même réseau Docker, l'adresse peut aussi être http://(nom du conteneur):11434.
Does Agent Zero work without a dedicated GPU?+
The container itself (XFCE desktop, browser, tool orchestration) does not need a GPU to run. A GPU is only needed for model inference, handled separately by Ollama or another provider, local or cloud; an Agent Zero container can therefore run on a small machine as long as inference is offloaded elsewhere on the network.
Why does my local model never call tools in Agent Zero?+
This is documented behavior with small local models, which explain the command instead of actually executing it. The project recommends the “Tiny Local” profile, which removes visible reasoning fields from the communication prompt and asks only for an executable JSON object with tool_name and tool_args, which is easier for a small model to follow.
Does Agent Zero's Linux desktop make the agent safer than a terminal-only agent?+
It isolates actions in a Docker container, limiting their scope on the host machine compared with an agent running directly on the host. But this guarantees neither inference privacy nor the privacy of the integrated browser: both depend on the selected model provider and the container’s network configuration, not on whether a graphical desktop is present.
Do Agent Zero and Hermes Agent do the same thing?+
No. Agent Zero targets a complete computer with a graphical desktop and controllable browser for cross-functional tasks such as research or document manipulation. Hermes Agent is a terminal and messaging agent (Telegram, Discord…) focused on persistent memory and scheduled automations. Both accept a local Ollama endpoint, but target different use cases.
How do you secure secrets and API keys in Agent Zero?+
Never paste an API key in plain text into a prompt, screenshot, or bug report: use the global or project secrets provided by the interface. A project can define its own isolated secrets that override the global secrets; they are masked in the interface, but may not be included in automatic backups, so verify this before relying on them completely.
Should you add all available MCP servers to Agent Zero?+
No. Each MCP connection is a bridge to an external service (messaging, database, automation) that expands what the model can access, including less predictable tool-calling behavior on a local model. The documentation recommends connecting only the servers that are genuinely useful for the current task, rather than enabling the entire catalog as a precaution.

Did this guide help you?

Feedback, an error, or a clarification? Let us know—it improves the guide for everyone.