by Anil-matcha
Open-source alternative to OpenAI Dots: self-hosted AI chat, tools, approvals, connectors, and computer tasks.
# Add to your Claude Code skills
git clone https://github.com/Anil-matcha/open-dotsLast scanned: 9/30/2026
{
"issues": [
{
"file": "README.md",
"line": 71,
"type": "secret-exfiltration",
"message": "Instruction appears to send credentials/secrets to an external endpoint",
"severity": "medium"
}
],
"status": "PASSED",
"scannedAt": "2026-09-30T10:18:36.877Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how open-dots compares with popular alternatives.
open-dots is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by Anil-matcha. Open-source alternative to OpenAI Dots: self-hosted AI chat, tools, approvals, connectors, and computer tasks. It has 4,646 GitHub stars.
Yes. open-dots passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/Anil-matcha/open-dots" and add it to your Claude Code skills directory (see the Installation section above).
open-dots is primarily written in Python. It is open-source under Anil-matcha on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh open-dots against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Open Dots is an open-source alternative to OpenAI Dots: a self-hosted AI workspace for chat, tool use, approvals, connectors, and computer tasks. It brings model conversations, a governed action gateway, approval prompts, and an optional isolated browser runtime into one local-first app.
Open Dots is independently built and is not affiliated with or endorsed by OpenAI, xAI, or any model provider. It offers a self-hostable, inspectable alternative for people looking for an open-source OpenAI Dots alternative, with local data and explicit approval for higher-risk actions.
Status: Prototype / active development. Intended for local experimentation; multi-user hosting and hostile-web isolation are not production ready.
/search <query>. It runs through the governed action gateway like the other tools, works with the keyless You.com free profile, and produces audit events.Open Dots gives developers and individuals a self-hosted AI workspace they can inspect and adapt. Use it as an open-source alternative to OpenAI Dots when you want local-first conversation storage, configurable model access, visible approval steps, and an optional computer runtime under your control. It is a separate project with its own implementation and current limitations; see the provider and runtime notes below before deploying it.
Clone and start the API:
git clone https://github.com/Anil-matcha/open-dots.git
cd open-dots/server
python -m venv .venv
source .venv/bin/activate
python -m pip install -r requirements.txt
export MODEL_API_KEY="your_api_key"
export MODEL_API_BASE_URL="https://your-inference-host.example/api/v1"
python run.py
The API is available at http://127.0.0.1:8000; interactive docs are at /docs.
In a second terminal, start the web client:
cd open-dots/client
npm install
npm run dev
Open http://127.0.0.1:3000 and sign in with the Open Dots owner token. On first start, the server creates .auth-token under DATA_DIR (default ~/.open-dots). Read that file locally and paste its value into the sign-in form, or use the value of APP_AUTH_TOKEN if you configured one. This is a separate credential from your model provider API key, which you enter in App Settings after signing in. Never commit, share, or put the owner token in a public frontend environment variable.
Browser sessions use distinct HttpOnly cookies with server-enforced expiry. Sign out revokes the current session, and restarting the API invalidates all browser sessions. Direct API clients can continue to send the owner token as a Bearer credential. Loopback requests, including container gateway and reverse-proxy traffic, must authenticate too.
The default inference adapter sends a prediction request to {MODEL_API_BASE_URL}/{model_id} and uploads images to {MODEL_API_BASE_URL}/upload_file. Configure it with a service that implements this request and response contract and supports the model IDs you select.
Open Settings → Model provider and expand the collapsed panel to enter the API base URL, choose Responses or Prediction, save an API key, and configure model IDs and the default model. Use the API root (usually ending in /v1), without appending /responses. Model IDs accept one per line or comma-separated values. Saving refreshes the model menus and sets the default for newly created assistants; existing assistants keep their selected model.
For an OpenAI Responses-compatible service, choose Responses API. Requests stream from /responses with Bearer authentication, preserve conversation roles, and send attached images as data URLs. The Chat Completions protocol is not implemented. Under Custom headers, keep stored headers, replace the complete set, or explicitly remove them. Keys and header values are encrypted locally and are not displayed after saving; a blank API key preserves its stored value.
The same settings are available through the authenticated settings API (POST /api/v1/settings): model_api_wire_api, model_api_base_url, model_api_key, and model_api_headers. Use clear_model_api_headers: true to remove stored headers explicitly.
Set model_ids to the service's supported chat model IDs and default_model to one of those exact IDs. Both model menus use the configured catalog; the application does not rewrite model IDs. Omitted settings retain their previous values, and empty credential/header values retain stored secrets.
| Variable | Default | Purpose |
|---|---|---|
MODEL_API_KEY |
empty | Provider key fallback when no key is saved in settings |
MODEL_API_BASE_URL |
empty | Required base URL for the configured inference API |
DEFAULT_MODEL |
gpt-5-mini |
Initial model for new assistants |
COMPOSIO_API_KEY |
empty | Optional connector credential |
YDC_API_KEY |
empty | Optional You.com API key for /search; the keyless free profile is used when unset |
DATA_DIR |
~/.open-dots |
SQLite state and local keys |
APP_ENCRYPTION_KEY |
generated in DATA_DIR |
Optional Fernet key for encrypted credentials |
APP_AUTH_TOKEN |
generated in DATA_DIR |
Server-side owner credential for sign-in and direct API access |
WORKSPACE_ROOT |
project root | Directory boundary for approved workspace actions |
COMPUTER_PROVIDER |
fake |
Computer provider: fake, docker, or remote |
HOST / PORT |
127.0.0.1 / 8000 |
API bind address |
For non-loopback access, set APP_AUTH_TOKEN only on the server, use HTTPS with AUTH_COOKIE_SECURE=1, and set a narrow CORS_ORIGINS list. Configure the public API address with NEXT_PUBLIC_API_URL, and sign in through the form; do not embed credentials in NEXT_PUBLIC_* variables. Keep the UI and API on the same site so the browser can send the session cookie. The built-in session store targets one API process; sessions are not shared between workers or instances.
If you previously built with NEXT_PUBLIC_API_TOKEN, rotate the owner credential, remove that variable, and rebuild/redeploy the client. Existing public assets may contain the old credential. Old cookies containing the master token are no longer accepted; users must sign in again.
/search <query> in chat runs a governed, read-only web lookup through the You.com MCP server and hands the results to the assistant as action context, so it can answer with current information.
YDC_API_KEY the keyless free profile is used, which serves a reduced read-only tool set.YDC_API_KEY to use the authenticated endpoint with higher limits.search.web (risk external). Like connector.github_list_issues, it is an explicit, read-only command typed by the user, so it does not pause for approval; every run still produces the standard gateway audit events.The default fake adapter is for local development and deterministic behavior. To enable the Docker/Playwright computer provider:
docker build -t open-dots-computer:1.62.1 ./runtime
export COMPUTER_PROVIDER=docker
export COMPUTER_DOCKER_IMAGE=open-dots-computer:1.62.1
The daemon must be running. Containers use a separate workspace per assistant, a read-only root filesystem, dropped capabilities, and resource limits. Computer navigation and other higher-risk operations go through the action gateway and approval flow. This is not a hardened sandbox for hostile websites; review network egress, image provenance, and credential exposure before using it with untrusted content.
For a remote computer service, configure COMPUTER_PROVIDER=remote and the COMPUTER_REMOTE_* variables in server/app/config.py.
Next.js client ── HTTP + SSE ── FastAPI API
├── SQLite + encrypted settings
├── configurable inference adapter
├── Composio connector adapter
└── action gateway + approvals + audit
├── confined workspace tools
└── fake / Docker / remote computer
The main code areas are client/ (Next.js UI), server/app/routers/ (HTTP API), server/app/services/ (providers, persistence, approvals, and tools), and runtime/ (Docker computer driver).