OpenInstinct

A self-hosted iMessage assistant that operates websites while keeping passwords and payment approvals under user control.

Stars
★ 394
Last updated
today
License
MIT
Primary language
TypeScript

At a glance

How it runs
Self-hosted serviceWeb appChat bot
Works with
Universal · cross-platform
Cost
Needs a paid subscription or licence
Setup effort
High · needs real infrastructure
You'll need
Vercel Pro plan for the documented deploymentKernel cloud browserNeon PostgresLinq iMessage connectorVercel AI GatewayPrivate Vercel Blob storageNode.js 24 and pnpm 11.24.0 for local developmentDocker Desktop or another Docker Compose installation for local developmentShell / CLINetwork accessLocal filesystem
Typical use
An individual who wants to request a movie booking over iMessage and have a browser reach checkout with the theater, showtime, seat, and total.
Not a fit if
  • Teams requiring production-ready software
  • Deployers unwilling to pay for Vercel Pro
  • Users who require fully offline operation
Source review
65/100 · Some gaps

What does this agent do, and when should you use it?

OpenInstinct is a personal assistant accessed through iMessage and a signed-in web workspace, with Kernel cloud browsers handling tasks such as ticket booking and shopping. Its encrypted vault and browser autofill let the browser use saved credentials without placing those passwords in the model context. Neon Postgres stores application data and workstreams, while private Vercel Blob storage holds generated keys, persistent memory, and browser images; model traffic goes through Vercel AI Gateway. The primary deployment runs in the user's own Vercel Pro account and connects Linq, Kernel, Neon, and Blob, with optional Google Workspace and Link wallet integrations. The project says it can use any model and documents requirements for non-Vercel hosting, although the guided architecture remains closely tied to Vercel services. The README explicitly says the software is not intended for production use, making it a better fit for technical adopters evaluating an experimental personal automation stack.

A request arrives from iMessage or the authenticated web workspace, after which OpenInstinct uses Eve to coordinate the agent and a Kernel cloud browser to navigate sites, fill forms, and advance transactions. Linq supplies the iMessage line, outbound messaging, and the /eve/v1/linq inbound webhook. Vault values are encrypted before database storage, and browser autofill keeps saved passwords out of the model's context. Before each production agent turn, per-user memory is recalled from private Vercel Blob storage; database workstreams preserve goals, decisions, observations, and unfinished steps across conversations. An optional user-scoped Google OAuth grant supports Gmail, Calendar, and read-only Contacts, with Vercel Connect storing and refreshing tokens. The optional @stripe/link-integrations-eve path can initiate Link wallet approvals, but every spend request still requires user approval in Link and wallet access is unavailable to scheduled workers.

  1. An individual who wants to request a movie booking over iMessage and have a browser reach checkout with the theater, showtime, seat, and total.
  2. A self-hoster who wants an assistant to sign into websites without exposing stored passwords to the model context.
  3. A user who needs goals, decisions, and unfinished personal tasks recalled across separate conversations.
  4. A Google Workspace user willing to grant OAuth access for Gmail, Calendar, and contact lookup from one assistant.
  5. A US or Canadian consumer who wants an agent to prepare purchases while retaining per-transaction approval through Link.
  6. A developer studying how iMessage, cloud browsers, persistent memory, and an encrypted vault can form a personal agent.

How do you install or deploy this agent?

The recommended route is the repository's Deploy with Vercel button using a Vercel Pro team. The guided deployment connects Kernel, Neon, private Vercel Blob storage, Linq, and Vercel AI Gateway. After deployment, complete the one-time Phone Numbers verification in the Linq connector's Vercel Connect settings, open the deployed application, and sign in with a phone number. Link wallet and Google Workspace require separate setup.

Local development requires Node.js 24, pnpm 11.24.0, a running Docker Compose installation, Kernel credentials, and either an AI Gateway API key or an OIDC token from a linked Vercel project:

git clone https://github.com/Merit-Systems/OpenInstinct.git
cd OpenInstinct
pnpm install --frozen-lockfile

For fully manual configuration, copy the environment template and set KERNEL_API_KEY and AI_GATEWAY_API_KEY in .env.local:

cp .env.example .env.local

# Set KERNEL_API_KEY and AI_GATEWAY_API_KEY in .env.local.

Start the local stack with:

pnpm dev

This starts PostgreSQL from compose.yaml, applies committed migrations, and launches the application. Use pnpm dev:app when intentionally using an externally managed database. A non-Vercel production host must also explicitly provide BETTER_AUTH_SECRET, BETTER_AUTH_URL, SECRET_ENCRYPTION_KEY, DATABASE_URL, DATABASE_URL_UNPOOLED for migrations, and BLOB_READ_WRITE_TOKEN for private Blob storage.

How do you use this agent?

After deployment, complete Linq phone verification, open the web application, and sign in with the verified phone number. Tasks can then be sent to the Linq iMessage number; the optional LINQ_PHONE_NUMBER setting adds a click-to-message shortcut in the workspace. Browser work runs through the background workflow and can draw on persistent memory and workstreams to continue goals and unfinished steps.

To enable Google Workspace, configure a Google Cloud consent screen, enable the Gmail API, Google Calendar API, and People API, create OAuth web credentials, and register https://connect.vercel.com/callback as a redirect URI. Create the connector using top-level clientId and clientSecret fields, set GOOGLE_CONNECTOR_UID, and redeploy. Purchasing additionally requires a registered Stripe Link Agent Wallet application and the LINK_CLIENT_ID, LINK_CLIENT_SECRET, STRIPE_PUBLISHABLE_KEY, and BETTER_AUTH_URL settings. Connect the wallet from the application's Link wallet page; the connection alone does not approve spending, and each purchase must be approved in Link.

What are this agent's strengths and limitations?

Pros
  • Browser autofill uses saved credentials without putting them in model context, while vault values are encrypted before reaching the database.
  • It combines iMessage, a web workspace, cloud-browser execution, persistent memory, and scheduled work in one self-hosted assistant.
  • The project can use any model and documents the secrets, database connections, and Blob token needed outside Vercel.
  • Vercel Connect stores and refreshes Google tokens, while OpenInstinct retains only the stable user identity needed to request them.
  • Link requires approval for each spend request; connecting a wallet does not itself authorize a purchase.
Limitations
  • The project explicitly states that it is not intended for production use.
  • The recommended deployment requires Vercel Pro because the minute-by-minute scheduled check exceeds Hobby cron limits.
  • The base architecture depends on Kernel, Neon, Linq, Vercel AI Gateway, and private Blob storage, creating a multi-service setup and failure surface.
  • Google Workspace requires a separately configured Google Cloud OAuth application; testing grants expire after seven days, and wider distribution may require verification and a security assessment.
  • Deleting the private Blob store loses the automatically generated encryption key, while key rotation requires re-encrypting existing vault values.
  • Active Eve sessions are deployment-version sensitive: an Eve 0.69 session cannot be moved onto this repository's Eve 0.66.3 deployment.

How does this agent compare with similar options?

Key facts side by side with the most closely related agents.

Agent Source review Form / cost Stars Updated Language Full support on
OpenInstinct This agent 65 · Some gaps Self-hosted servicePaid ★ 394 today TypeScript —
Iva Personal Assistant 85 · Good Chat botFree + model costs ★ 228 2d ago TypeScript ChatGPT · Codex
MindsHub Cowork 55 · Major gaps Web appFreemium ★ 40k 25d ago Makefile —
Octop Self-Hosted Assistant 67 · Some gaps CLIFree + model costs ★ 7k today Python Codex · Claude Code · OpenAI API

How does FollowAgents rate this agent?

FollowAgents source review · FARS-2.1
Some gaps
65/ 100 5-point scale 3.3 / 5
Trust 16/29
Reliability 9/14
Adaptability 12/18
Convention 14/18
Effectiveness 9/13
Verifiability 5/8
Why each dimension lost points
Trust16 / 29 · 2.8/5

The evidence shows user-scoped Google grants, avoidance of the permanent-delete mail scope, encryption of vault values before database storage, browser autofill intended to keep passwords outside model context, per-purchase Link approval, and a fairly explicit map of Blob, database, browser, messaging, Google, and wallet data flows. Deductions apply because email, label, and calendar writes explicitly have no additional tool approval, while the browser agent has a broad real-world action surface; payment credentials may persist in tool results; no vulnerability scan, SBOM, or sustained dependency-security process is shown; and there is no general undo mechanism for external actions. Components and the claimed company are attributed, but registry verification and concrete maintenance ownership are absent.

Reliability9 / 14 · 3.2/5

The README, dependency declarations, and focused tests are broadly consistent on OAuth behavior, user scoping, retry-safe mail/calendar operations, and error propagation. CI installs from a frozen lockfile and runs checks plus a runtime smoke command. Deductions apply because none of this was executed for the assessment, operation depends on numerous external services, and active Eve sessions have explicit version-compatibility constraints. The supplied tests cover selected failures rather than comprehensive user-facing retry, degradation, and recovery behavior.

Adaptability12 / 18 · 3.3/5

Documentation covers self-hosted users, guided Vercel deployment, local development, non-Vercel hosting, Google Workspace, iMessage, and an optional wallet. It also distinguishes interactive from scheduled capabilities, identity mapping, and environment-specific requirements. Deductions apply because the product remains closely coupled to a particular vendor stack, the non-Vercel route is only partially developed, and the evidence does not fully specify ambiguity handling, conflicting natural-language triggers, or tool-selection rules for every consequential action.

Convention14 / 18 · 3.9/5

The README is well organized and gives unusually thorough deployment, local-development, key, migration, cost, limitation, and troubleshooting notes. The full MIT license agrees with package metadata, and the non-production warning is prominent. Deductions apply because there is no formal FAQ, release history, or changelog; the package name “local-vault-assistant” differs from OpenInstinct and its version is still 0.0.0; and beyond the copyright holder there is no clear maintainer, support path, response commitment, or update policy.

Effectiveness9 / 13 · 3.5/5

The material presents a coherent iMessage workflow combining browser tasks, mail, calendar, contacts, and user-approved purchasing. The illustrated result includes actionable booking details, and costs and the required Pro tier are disclosed. Deductions apply because central utility claims rely mainly on documentation and a demo image rather than supplied operational results or broad task evidence. Multiple paid or quota-limited services, substantial setup, and the explicit non-production warning make the general cost-benefit case less certain.

Verifiability5 / 8 · 3.1/5

Several claims can be traced and cross-checked across the README, package manifest, CI, and tests, including Eve/Link versions, constrained Google scopes, user isolation, absence of extra write approvals, and stable idempotency identifiers. Deductions apply because important security claims such as vault encryption, model-context isolation, and Blob key lifecycle lack corresponding implementation files in the supplied evidence, while broad task claims lack independent corroboration. The documentation separates some limitations from behavioral statements, but does not systematically label assumptions, guarantee boundaries, or unverified claims.

Risks and how to mitigate them
  • The agent can send mail, change mailbox state, create calendar events that notify attendees, and act on real websites. These operations lack a uniform additional confirmation step, so tool permissions should be reviewed and constrained before connecting live accounts.
  • Payment credentials may be retained in Eve tool results. Instructions not to repeat them in chat do not replace verification of encryption, retention, access control, and deletion behavior for stored results.
  • The automatically generated vault key resides in private Blob storage. Deleting that store can make existing vault data unrecoverable, and key rotation requires a separate re-encryption process.
  • The repository explicitly says it is not intended for production use and depends on several external services, Vercel Pro, quotas, and version compatibility. This static review did not execute or independently validate its security or reliability claims.
Evidence confidence: Low Reviewed Oct 05, 2026 Reviewed revision 08ef7e012ecc
See the full review method →

FAQ

What does it cost to operate?
The code is MIT-licensed, but the recommended deployment requires Vercel Pro. Kernel, Neon, and some AI Gateway usage have free plans or credits; Linq, private Blob usage, excess model consumption, and other resources can incur charges. Purchases approved through Link are paid from the user's wallet.
Are passwords or encryption keys exposed to the model?
Saved vault values are encrypted before database storage, and browser autofill is designed to keep passwords out of model context. Automatically created Better Auth and vault-encryption keys live in private Blob storage; deleting that store loses the generated key.
What permissions does the Google integration receive?
It uses a user-scoped OAuth grant for Gmail, Calendar, and read-only Contacts. Gmail requests gmail.modify rather than the permanent-delete mail.google.com scope. User-requested email and calendar operations run without an additional Eve tool approval.
Can the agent spend money without approval?
Connecting a wallet does not approve purchases. Every spend request requires approval in Link, and wallet access is limited to interactive conversations rather than scheduled workers or scheduled result delivery.
Can it run outside Vercel?
The documentation specifies secrets, database connections, and Blob credentials for a non-Vercel host, so an alternative deployment is possible. However, the guided path and several integrations are built around Vercel Connect, AI Gateway, and Blob, leaving the adopter responsible for configuring and maintaining the alternative path.
View on GitHub ↗ Install ↓

Related agents