OpenDots is an MIT-licensed, self-hostable template released October 1, 2026 by CopilotKit as the open-source answer to OpenAI’s closed “dots” product. The unit of work is a Dot: a named specialist with its own role, its own instructions, its own conversation thread, its own permission set, and — optionally — its own isolated computer (a real browser profile, a workspace of files, and a shell). One conversation reaches a Dot three ways: text chat, a live voice call, or a Slack mention. Finished work is not a chat log — it lands as an editable Page inside a Space, with a real block editor, slash commands, autosave and revision checks.
Built on CopilotKit and AG-UI, the open agent-to-UI protocol CopilotKit maintains, with TanStack AI for model streaming, CopilotKit Intelligence for durable Threads, and Channels SDK for Slack. Any OpenAI-compatible model. Web and mobile. Clone it, define your Dots, self-host it.
Short answer: yes, but narrower than the marketing implies. The isolation is real and it is per-Dot, yet it is optional, a separate service, and it does not cover the autonomous scheduler. Here is the honest breakdown.
| Layer | What it gives you | Where it really lives | Isolated? |
|---|---|---|---|
| Dot computer | Own browser profile, own /workspace volume, own shell, persists across stop/start | OpenBot’s container supervisor — a separate pinned service you must build and connect yourself | Yes — one container per Dot |
| Per-Dot permissions | Browser / Files / Shell / Memory granted one Dot at a time, so a writer never inherits a researcher’s access | Application-level allowlist in the CopilotKit runtime | Partly — this is a gate, not a jail |
| Per-Dot credential | Each Dot derives a distinct computer credential; service keys stay server-side and never reach the browser | Server-held, encrypted | Yes |
| Scheduled / background work | Recurring turns run unattended and resume in their original conversation, with pause and retry | Server-side, inside the CopilotKit runtime | No — the scheduler is not in a sandbox |
| Public-web research | Parallel MCP search (default), or a URL-only reader, or disabled | Third-party API at search.parallel.ai/mcp, plus a separate read-only public-page service with capture and navigation limits | Not your Dot’s computer |
Three consequences worth internalizing before you deploy it:
npm run dev.COMPUTER_RUNTIME=runsc to run the per-Bot containers under gVisor where the host supports it. If you are serious about hostile-webpage or untrusted-command exposure, that is the setting to reach for.What genuinely is stronger here than in most agent products: human takeover. The Computer panel streams browser, files, terminal output and action records, and you can grab control mid-action. Combined with the CEL-style fail-closed gateway in OpenBot — every action is decided and recorded before it happens, and a saved file is logged by path and size but never by contents — that is a meaningfully different security posture from “the agent has a shell and a login.”
| OpenDots | Manus | Paperclip | Aside | OpenBot | |
|---|---|---|---|---|---|
| Shape | Single-owner template, clone & customize | Hosted SaaS agent | Self-hosted orchestration platform for fleets of agents | Browser agent / Chrome replacement | Self-hosted agent platform (multi-user, enterprise) |
| Isolation unit | One container per Dot (optional service) | Cloud sandbox VM per task | Per-company data separation, not per-agent computer | Your own machine; local-first profile | One container per Bot, + CEL gateway & audit |
| Concurrency model | Specialist Dots, separate conversations | Planning + execution + verification agents | Org chart, budgets, heartbeats, tickets | One agent, your browser | 13+ coworkers, groups, channels |
| Unattended work | Server-side recurring schedules | Background task execution | Schedules and event triggers, atomic checkout, resume | Continuous multi-step autonomous | Routines + lasting responsibilities |
| Governance | Per-Dot tool perms + Approve & save card | Computer panel, optional intervention | Budgets, hard stops, board approvals, immutable audit | Agent password manager (Secure Enclave) | /admin/boundaries, approvals, SAML, full audit |
| Output lands in | Editable Space pages + per-page chat | Reports, code, dashboards | Issue tracker | — | Channel transcript |
| Beyond chat | Voice calls + Slack (Channels SDK) | Web & mobile | Slack/Teams/SMS | Browser extension | Slack, Teams, SMS, phone |
| Learning | Automatic Learning → reviewed, published skills | Manual SKILL.md | — | “Dr” modes | Learning containers, skill delivery |
| License / cost | MIT, self-host, bring your own key | Subscription, closed | Open source, embedded Postgres | Closed, YC-backed | Open source template, no packages published — clone only |
The one-line distinctions: versus Manus, OpenDots trades cloud sandboxes for containers you own, and buys document output and voice with it. Versus Paperclip, it has no org chart, budgets, or event triggers — Paperclip is the fleet manager, OpenDots is the individual worker. Versus Aside, Aside borrows your logged-in browser on your desktop; OpenDots runs a browser with its own separate logins inside a container, so a Dot that gets phished is not you. And versus its own sibling OpenBot: OpenDots is the lighter, single-owner, documents-and-voice template; OpenBot is the heavier platform underneath it, with multi-user auth, org policy, audit review and boundary administration.
git clone https://github.com/CopilotKit/OpenDots.git
cd OpenDots
npm ci
cp .env.example .env
npm run dev Node.js 24 and npm. You can create Spaces, write pages and configure Dots before connecting a single service; add conversation and model settings to .env to start chatting. Calls, Slack and Dot computers each have their own setup guide — the computer guide is where you build the pinned container services.
Research path: WEB_SEARCH_PROVIDER=browser restores a URL-only reader, disabled turns the tools off, and the default sends queries and requested URLs to search.parallel.ai/mcp (anonymous, free for light use, PARALLEL_API_KEY for production). Memories and full conversations are not automatically forwarded.
GitHub: https://github.com/CopilotKit/OpenDots · Landing page: https://www.copilotkit.ai/opendots · Launch post: https://www.copilotkit.ai/blog/introducing-opendots · The computer layer it depends on: https://github.com/CopilotKit/openbot · AG-UI protocol: https://docs.ag-ui.com · License: MIT