# Open Dots

> Updated 2026-09-30 · type: tool · category: mcp-agents · status: active · rev 1

Open Dots self-hosts an AI agent workspace with a deny-by-default gateway that pauses higher-risk actions for explicit human approval before they run.

- Open source: yes (MIT)
- Self-hostable: yes
- Pricing model: free
- Best for: A team that wants an owned, self-hosted agent workspace — chat plus tool integrations and optional computer automation — with a human-in-the-loop approval gate on risky actions, as an open alternative to a hosted 'Dots'-style product.
- Not for: A team that wants a fully-managed hosted agent with no infrastructure to run, or one that needs the agent to act fully autonomously with no approval friction on higher-risk actions.
- Last verified: 2026-09-30

- **Canonical:** https://gtmstacker.com/registry/tool/open-dots/
- **Source:** [anil-matcha · GitHub](https://github.com/anil-matcha/open-dots)
- **Tags:** mcp-agents, ai-infrastructure, agent-workspace, governance, approvals, self-hostable
- **Repository:** https://github.com/anil-matcha/open-dots

## Is Open Dots open source?

Yes, Open Dots is open source under the MIT license.

## How much does Open Dots cost?

Open Dots is free to use.

## Can I self-host Open Dots?

Yes, Open Dots can be self-hosted (the source is available under the MIT license).

## Alternatives & related

- [OpenAPPA](https://gtmstacker.com/registry/tool/openappa/)
- [agent-custody](https://gtmstacker.com/registry/tool/agent-custody/)
- [OpenShell](https://gtmstacker.com/registry/tool/openshell/)


---

Open Dots is a self-hosted AI agent workspace — chat, tool integration, and optional computer automation — with a deny-by-default gateway that pauses higher-risk actions for explicit human approval before they run. Open source: yes (MIT); self-hostable; free OSS. It has ~4.8k stars and is active (104 commits), positioned as an open alternative to hosted "Dots"-style agent workspaces.

## What it does

Open Dots gives you an agent workspace you run yourself: a chat surface, integrations to the tools the agent can call, and optional computer automation for actions beyond API calls. The distinguishing piece is governance built into the runtime — a deny-by-default gateway that does not let higher-risk actions execute silently. When the agent reaches for something sensitive, the gateway pauses and waits for an explicit human approval, so the default posture is "ask first" rather than "act and log." You self-host the whole thing, which keeps the workspace, its tool credentials, and its automation on infrastructure you control. Open source: yes (MIT); self-hostable; free OSS.

## Provenance

- MIT per repo (license read from GitHub metadata, not guessed); ~4,800 stars; 104 commits on main; self-hostable (github.com/anil-matcha/open-dots, verified 2026-09-30).
- Deny-by-default gateway: pauses higher-risk actions for explicit user approval before execution; chat + tool integration + optional computer automation.
- Surfaced in the GTM Stacker X/Twitter signal report (2026-09-30 pass); license/facts independently verified 2026-09-30.
- The gateway's risk classification and coverage are the project's own design (vendor-claim); not independently audited here.

## Why it matters for a GTM stack

An agent wired into your CRM, inbox, and browser is useful exactly because it can act — which is also the risk. Open Dots is the self-hosted version of that agent with the safety valve in the runtime: higher-risk actions stop for a human before they happen, and the whole workspace runs on your own infrastructure rather than a vendor's. For a GTM team that wants agent leverage on real systems without handing an autonomous process unattended write access, the deny-by-default posture is the right default. The honest read: "deny-by-default" is the project's design claim, so the real question is which actions it classes as higher-risk and whether that matches your threat model — check the gateway's coverage before trusting it, and keep the approval gate on while the agent's computer-automation reach is wide.
