AIToolScan

OpenDots (Always-On AI Coworkers)

OpenDots — Always-On AI Coworkers, Each With Its Own Container

OpenDots is an MIT-licensed, self-hostable template released October 1, 2026 by CopilotKit as the open-source answer to OpenAI’s closed “dots” product. The unit of work is a Dot: a named specialist with its own role, its own instructions, its own conversation thread, its own permission set, and — optionally — its own isolated computer (a real browser profile, a workspace of files, and a shell). One conversation reaches a Dot three ways: text chat, a live voice call, or a Slack mention. Finished work is not a chat log — it lands as an editable Page inside a Space, with a real block editor, slash commands, autosave and revision checks.

Built on CopilotKit and AG-UI, the open agent-to-UI protocol CopilotKit maintains, with TanStack AI for model streaming, CopilotKit Intelligence for durable Threads, and Channels SDK for Slack. Any OpenAI-compatible model. Web and mobile. Clone it, define your Dots, self-host it.

The isolation claim — what is actually true

Short answer: yes, but narrower than the marketing implies. The isolation is real and it is per-Dot, yet it is optional, a separate service, and it does not cover the autonomous scheduler. Here is the honest breakdown.

LayerWhat it gives youWhere it really livesIsolated?
Dot computerOwn browser profile, own /workspace volume, own shell, persists across stop/startOpenBot’s container supervisor — a separate pinned service you must build and connect yourselfYes — one container per Dot
Per-Dot permissionsBrowser / Files / Shell / Memory granted one Dot at a time, so a writer never inherits a researcher’s accessApplication-level allowlist in the CopilotKit runtimePartly — this is a gate, not a jail
Per-Dot credentialEach Dot derives a distinct computer credential; service keys stay server-side and never reach the browserServer-held, encryptedYes
Scheduled / background workRecurring turns run unattended and resume in their original conversation, with pause and retryServer-side, inside the CopilotKit runtimeNo — the scheduler is not in a sandbox
Public-web researchParallel MCP search (default), or a URL-only reader, or disabledThird-party API at search.parallel.ai/mcp, plus a separate read-only public-page service with capture and navigation limitsNot your Dot’s computer

Three consequences worth internalizing before you deploy it:

  • Isolation is opt-in and it is extra work. OpenDots ships without the computer services. The repo states it plainly: “Computer tools require those services; an unconfigured template does not execute commands on your host.” Out of the box a Dot has no computer at all — which is the safe default, and also means the headline feature is not what you get from npm run dev.
  • The thing that runs on its own is the least isolated thing. A recurring schedule wakes an agent that holds your model key and your Space access, executing in the app process you run — not inside the per-Dot container. Treat unattended schedules as the highest-risk surface, and scope a scheduled Dot’s tool permissions as tightly as its container.
  • gVisor is the hardening step, and it is OpenBot’s, not OpenDots’. OpenBot documents COMPUTER_RUNTIME=runsc to run the per-Bot containers under gVisor where the host supports it. If you are serious about hostile-webpage or untrusted-command exposure, that is the setting to reach for.

What genuinely is stronger here than in most agent products: human takeover. The Computer panel streams browser, files, terminal output and action records, and you can grab control mid-action. Combined with the CEL-style fail-closed gateway in OpenBot — every action is decided and recorded before it happens, and a saved file is logged by path and size but never by contents — that is a meaningfully different security posture from “the agent has a shell and a login.”

How it compares to the other agent tools here

 OpenDotsManusPaperclipAsideOpenBot
ShapeSingle-owner template, clone & customizeHosted SaaS agentSelf-hosted orchestration platform for fleets of agentsBrowser agent / Chrome replacementSelf-hosted agent platform (multi-user, enterprise)
Isolation unitOne container per Dot (optional service)Cloud sandbox VM per taskPer-company data separation, not per-agent computerYour own machine; local-first profileOne container per Bot, + CEL gateway & audit
Concurrency modelSpecialist Dots, separate conversationsPlanning + execution + verification agentsOrg chart, budgets, heartbeats, ticketsOne agent, your browser13+ coworkers, groups, channels
Unattended workServer-side recurring schedulesBackground task executionSchedules and event triggers, atomic checkout, resumeContinuous multi-step autonomousRoutines + lasting responsibilities
GovernancePer-Dot tool perms + Approve & save cardComputer panel, optional interventionBudgets, hard stops, board approvals, immutable auditAgent password manager (Secure Enclave)/admin/boundaries, approvals, SAML, full audit
Output lands inEditable Space pages + per-page chatReports, code, dashboardsIssue tracker—Channel transcript
Beyond chatVoice calls + Slack (Channels SDK)Web & mobileSlack/Teams/SMSBrowser extensionSlack, Teams, SMS, phone
LearningAutomatic Learning → reviewed, published skillsManual SKILL.md—“Dr” modesLearning containers, skill delivery
License / costMIT, self-host, bring your own keySubscription, closedOpen source, embedded PostgresClosed, YC-backedOpen source template, no packages published — clone only

The one-line distinctions: versus Manus, OpenDots trades cloud sandboxes for containers you own, and buys document output and voice with it. Versus Paperclip, it has no org chart, budgets, or event triggers — Paperclip is the fleet manager, OpenDots is the individual worker. Versus Aside, Aside borrows your logged-in browser on your desktop; OpenDots runs a browser with its own separate logins inside a container, so a Dot that gets phished is not you. And versus its own sibling OpenBot: OpenDots is the lighter, single-owner, documents-and-voice template; OpenBot is the heavier platform underneath it, with multi-user auth, org policy, audit review and boundary administration.

Stack

  • AG-UI — streamed messages, tool calls and agent state; the reason computer activity and approval cards render inline mid-task.
  • CopilotKit React SDK + runtime — the chat, tool renderers, and the human-in-the-loop pause, all restyleable or replaceable.
  • Intelligence Threads — durable conversation history, with a separate thread per page and per specialist.
  • TanStack AI — streaming and server-side tool execution against any OpenAI-compatible provider.
  • OpenBot — container supervisor and computer service. Channels SDK — Slack via a managed connection with an explicit workspace/user allowlist.

Quick start

git clone https://github.com/CopilotKit/OpenDots.git
cd OpenDots
npm ci
cp .env.example .env
npm run dev

Node.js 24 and npm. You can create Spaces, write pages and configure Dots before connecting a single service; add conversation and model settings to .env to start chatting. Calls, Slack and Dot computers each have their own setup guide — the computer guide is where you build the pinned container services.

Research path: WEB_SEARCH_PROVIDER=browser restores a URL-only reader, disabled turns the tools off, and the default sends queries and requested URLs to search.parallel.ai/mcp (anonymous, free for light use, PARALLEL_API_KEY for production). Memories and full conversations are not automatically forwarded.

Honest limits

  • Alpha, and the repo says so. Single-owner by design: no shared editing, no invitations, no file uploads, no multi-Dot group conversations, no interactive page embeds. All listed as future work.
  • Verification is uneven. Live Intelligence, model responses and page-context chat were verified September 29, 2026; live OpenBot computer browsing and persistence September 30, 2026. Slack and spoken compute delegation still need connected-service verification — the two flashiest features are the least proven. Cloud schedules and published-skill delivery likewise.
  • Schedules are recurring instructions, not a real goal or event-trigger system. If you want triggers on external events, Paperclip or OpenBot is the better base.
  • Isolation is off by default and add-on. Without the OpenBot services you get a chat agent with no computer — useful, but not the product being sold.
  • Skills need human review and publication in Intelligence before a Dot will use them, and existing conversations are not retroactively enrolled in a Learning container.

Links

GitHub: https://github.com/CopilotKit/OpenDots · Landing page: https://www.copilotkit.ai/opendots · Launch post: https://www.copilotkit.ai/blog/introducing-opendots · The computer layer it depends on: https://github.com/CopilotKit/openbot · AG-UI protocol: https://docs.ag-ui.com · License: MIT