FuturPulse analysis · 5 October 2026
Open Dot is an open-source Mac desktop agent that keeps working until the user quits it, stores its data locally, and asks before sending, posting, paying or changing anything. It is not an OpenAI product, despite claims circulating since 29 September 2026.
At a glance
- Open Dot’s repository says passwords are encrypted with a key in macOS Keychain and typed into pages without being shown to the model.
- Open Dot can use an E2B cloud computer, a local Docker container, or a folder on the Mac for code work.
- CopilotKit OpenDots is a separate, self-hosted template with per-agent browser, file and shell permissions.
- Parallel Search MCP offers web search and page extraction to MCP-aware agents, with anonymous search available without an API key.
- For a first run, the safest choice is read-only research with no connected email, banking, calendar or payment account.
What is Open Dot, exactly?
Open Dot is a personal autonomous-agent application designed to run on a user’s Mac. Each “dot” has a browser profile that can remain logged in, a chat thread, optional schedules, and optional triggers from connected services. The project says the app runs a local server inside its desktop window, while closing the window does not stop work; quitting with ⌘Q does. The project’s installation and architecture notes make that local-first distinction clear.
An autonomous agent is software that can take several steps toward a goal without waiting after every click. That creates a practical safety problem: reading an inbox is one kind of permission, while sending an email or buying an item is another. Open Dot’s stated approach is to let the agent read connected services, but require approval before it sends, posts, pays for, or changes something.
That approval boundary is more useful than a generic “agent safety” claim. A first-time user can inspect the browser, take control for logins or captchas, and hand control back afterwards. The project also describes a smaller review model that checks a proposed risky action against the user’s rules before an approval card appears.
What shipped versus what was promised?
The key distinction is between public code that can be inspected today and product claims that do not yet have a matching vendor announcement. The timeline below separates the named open projects from reported “Dots” claims. Dates are given once where the public project material provides them.
Claimed launch: Open Dot’s README says OpenAI launched “Dots” on this date and says access requires ChatGPT Pro or Business Premium. What can be verified: Open Dot itself shipped as a public repository that runs on a Mac with an OpenAI or OpenRouter key. The repository is the available primary evidence for Open Dot, not an OpenAI product announcement. Open Dot’s README
Shipped in another project: CopilotKit says live Intelligence, model-response and page-context chat flows for OpenDots were verified on this date. Limit: OpenDots calls itself an early-development template rather than a hosted product, so users must run and configure its infrastructure themselves. The OpenDots project page
Shipped locally: OpenDots says it verified local computer browsing, file creation, shell checks, persistent files, realtime speech and call receipts. Not yet verified: its Slack connection and spoken compute delegation still needed connected-service testing. That is a useful example of a project drawing a line between a demo and an integrated deployment.
Practical status: Open Dot offers a Mac-first personal-agent route, while CopilotKit OpenDots offers a build-your-own multi-surface workspace. Neither public repository proves the broader claims made in social posts about a fully released proprietary OpenAI “Dots” service.
Which desktop-agent design is safer?
For a personal computer, the safer design is the one that keeps credentials narrow, makes actions visible, and puts a person at the last irreversible step. Open Dot’s strongest first-run features are its approval prompts, its visible browser takeover, and its password design. Its README says saved passwords are encrypted with a macOS Keychain-derived key and entered directly into the page, rather than shown to the model.
OpenDots takes a more deployment-oriented approach. Each agent can receive its own computer, browser profile and workspace, with browser, file and shell permissions set per Dot. Its server keeps service credentials and derives a different computer credential for each agent. That separation is a better fit for a team building specialists, but it demands more operational care than a single Mac app.
| Decision a first-time user faces | Open Dot | CopilotKit OpenDots | Safer starting choice |
|---|---|---|---|
| Where the agent runs | Mac desktop application with a local server. | Self-hosted web and mobile template. | Use the Mac app only on a private computer. |
| Risky actions | Rules and approval cards for sends, posts, payments and changes. | Human review cards can pause a tool call before a save. | Require approval for every write action. |
| Computer access | Cloud, Docker or local-folder workspace choices. | Per-Dot browser, file, shell and takeover controls. | Start with browser reading only. |
| Persistent work | Routines and triggers run only while the application stays open. | Scheduled server-side turns can pause and retry. | Do not enable schedules until manual work is trustworthy. |
There is no published security score that fairly ranks these projects. The meaningful comparison is therefore architectural: Open Dot focuses on an individual Mac and consent cards, while OpenDots exposes more granular deployment controls for builders. The table reflects the projects’ own feature descriptions, including OpenDots’ stated browser-isolation and permission model. AG-UI’s protocol overview explains why agents need explicit interrupts, cancellation and human approval: they are long-running, stateful systems rather than ordinary one-request software.
How should you set up Open Dot safely?
The safest first run should prove that the agent can research without proving that it can act. Do not begin by connecting Gmail, Slack, GitHub, a calendar, a bank, a password manager, or any service that can spend money. Start with a disposable research task on public web pages.
- Build or run it on a private Mac. Open Dot is designed for the user’s Mac and has no login screen. Do not expose its local service to the public internet.
- Add one model key. Use either an OpenAI key or an OpenRouter key at first. Adding both expands options, but makes it harder to identify which service handled a task.
- Turn computer use off for the first test. The project documents a setting that limits the agent to opening pages and reading them when computer control is disabled.
- Use a public, reversible job. Ask for a summary of a public website and require source links in the response.
- Watch the live browser. If a login prompt, captcha, purchase page, file download or account-setting page appears, take over rather than approving it.
- Only then connect one low-risk account. A read-only or test account is preferable to a primary work inbox.
Open Dot requires Node 22 or newer, pnpm and Chrome when run from source; Playwright Chromium can substitute when Chrome is absent. Its desktop build is not notarized, so the project instructs Mac users to right-click and choose Open on first launch. That bypass should be treated as a prompt to inspect the repository and build provenance, not as routine advice for unknown downloads. Pi Pod’s self-hosting guidance offers the broader principle: isolation and self-hosting can improve control, but they also transfer operations and patching responsibility to the user.

When should you connect email and Slack?
Connect an account only after you can name the exact task, the exact account, and the exact allowed action. “Manage my inbox” is too broad. “Read messages from one newsletter and prepare an unsent weekly summary” is a bounded instruction that a person can inspect.
Open Dot uses Composio for Gmail, Calendar, Slack, Notion, GitHub and other app connections. A connection is not merely a convenience feature: it gives a tool authority to act as the user in that service. Composio’s token-custody documentation says provider credentials are kept out of prompts and tool arguments, but the project API key remains a secret with permission to act on connected accounts.
Use these rules before adding a connected service:
- Connect a separate test account before a primary personal or company account.
- Permit reading and draft creation before sending, editing, deleting or sharing.
- Set approval rules for every external write action, including calendar invitations.
- Never leave a payment method available during an early experiment.
- Remove the connection after the trial, then confirm access is revoked at the provider.
For a team deployment, identity mapping matters as much as model quality. CopilotKit’s Channels design says the application maps Slack or Teams users to app users, so the relevant person’s tool permissions follow them. Its Channels documentation also says platform credentials stay outside the agent process, while the agent itself remains where the operator runs it.
Should you enable schedules and triggers?
No, not on the first day. Schedules turn a task into a recurring process, while triggers wake an agent when an outside event occurs. Both increase the chance that an old instruction runs in a new and unexpected context.
Open Dot says routines and triggers work only while the application is open. A routine due while the Mac sleeps is skipped, as are trigger events arriving then. That behavior reduces surprise work during downtime, but it also means a user should not rely on it for a deadline-sensitive or security-critical workflow.
Start with manual runs for several days. Review the browser history, files, drafts, approvals and unexpected tool calls. Then enable one daily routine that produces a private summary, not an outward-facing action. Keep the schedule narrow: a single source, a single output location, and no authority to send anything.
Triggers deserve a stricter rule. An email from a bank, a support ticket, or a GitHub issue can contain untrusted text that tries to redirect the agent. Treat trigger content as data to summarize, not instructions to obey. If a trigger leads to a write action, require a fresh approval at the final step.
How do search and memory change the risk?
Web search makes an agent more useful because it can gather current information, but it also exposes the agent to misleading pages and hostile instructions. A sensible design limits search to research tasks, records the sources used, and prevents web-page text from silently changing the agent’s permissions.
Parallel’s Search MCP documentation describes a search-and-extract service for MCP-aware agents. MCP, or Model Context Protocol, is a standard way to connect an agent to tools and data. The service distinguishes web search from fetching a specific page, a useful pattern because a system can narrow sources first and inspect selected pages second.
Memory needs the same discipline. Open Dot says individual dots can remember things and save skills for recurring work. Keep personal preferences separate from credentials, legal documents, medical data and sensitive work instructions. A memory that is convenient for one agent can become risky if another agent receives the same context without a clear need.
CopilotKit’s Intelligence product separates capabilities such as durable conversation streams, user memories, automatic learning, analytics and channels. Its overview says cloud-hosted and self-hosted routes use the same application APIs. That flexibility is valuable, but users should decide where conversation history and learned skills live before enabling either.
What we could not verify?
No primary OpenAI announcement was available here to confirm the reported proprietary “Dots” product name, plan requirements, model name, market availability, cloud-computer terms, or claims that agents can spend without approval. OpenAI could settle those points through a product page, release notes, safety documentation and pricing terms.
Open Dot’s repository describes its intended controls, but it does not publish an independent security audit, a notarized Mac build, or a complete test report for every connected service. Composio, Open Dot maintainers and independent security researchers could settle those questions through signed releases, scope-by-scope permission documentation and reproducible security assessments.

