Skip to main content

dot-mcp

Personal MCP agent for ChatGPT, Claude, and Gemini: shell, files, memory, goals, tasks, inbox, scheduler, and self-hosted OAuth — running on your own machine.

⚠️ The server gives full shell access to whoever holds a credential. Expose it only while you use it, then stop it (dot-mcp stop).

Install

pip install dot-mcp

Requires Python 3.10+ and OpenSSH (ssh, ssh-keygen) for the tunnel.

Use

dot-mcp start    # server + public URL (runs in background)
dot-mcp status   # check if it is running
dot-mcp stop     # stop server + tunnel

dot-mcp start prints everything the connector needs:

Public URL            https://xxxx.tunnl.gg/mcp/
Owner secret          <stored on your machine>
OAuth Client ID       dots-xxxxxxxx
OAuth Client secret   <stored on your machine>

Add the Public URL as a custom MCP connector (auth = OAuth). Approve once with the owner secret when asked. The tunnel URL stays the same on restart; the free tunnel expires after 24h or 2h idle.

Options: --port (default 33041), --data-dir (default ~/.dot-mcp), --json (script-friendly output).

What it can do (22 tools)

  • Shell: run_command (background sessions + timeout) + read_output
  • Files: list_dir, read_file (paged + sha256), write_file (atomic + guards), append_file, edit_file
  • Memory: remember, recall, forget — persists across chats
  • Goals/Tasks: set_goal, add_update, get_state, add_task, complete_task
  • Inbox: notify_user, poll_inbox, ack_inbox — messages across chats
  • Scheduler: add_schedule, list_schedules, remove_schedule — background jobs that run between chats
  • UI: open_workspace — embedded dashboard (tasks, memory, sessions)

Security model

  • /mcp/ requires Authorization: Bearer (OAuth JWT or owner secret) — anything else gets 401, even from localhost
  • OAuth 2.1 is self-hosted: dynamic registration, PKCE, 1h JWT + rotating 30d refresh tokens, manual Client ID/secret for Claude-style connectors
  • Per-IP rate limits (300/min API, 30/min auth), append-only audit.jsonl, cross-process file locks, atomic writes
  • Known limits: the tunnel provider sees traffic (TLS ends at their edge); back up ~/.dot-mcp yourself

Local-only mode (no tunnel)

export OPENAI_API_KEY=sk-...
python -m dot_mcp.local_agent          # chat loop
python -m dot_mcp.local_agent --list   # list tools only

Develop

./setup.sh                      # venv + editable install
.venv/bin/python -m pytest tests/ -q   # test suite
python -m build                 # wheel in dist/

See CHANGELOG.md for release notes.

License

MIT

Metadata

Release files for dot-mcp 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dot-mcp 0.1.1
File Size Uploaded
dot_mcp-0.1.1.tar.gz 34.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for dot-mcp 0.1.1
File Interpreter ABI Platform
dot_mcp-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 68.7 kB

Release files / dot_mcp-0.1.1.tar.gz

Download URL dot_mcp-0.1.1.tar.gz
Size 34.4 kB
Tags Source
SHA-256 checksum
How to use checksums
404da6b75a9805bc2e4d16503882474df5df8ccef92460a6391f830b986cba68
BLAKE2b-256 checksum
How to use checksums
697e34dcd2296b9b4830553d46bbe482475be6222408f21e8af978a02ce6c03f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 11, 2026.

Transparency log

Release files / dot_mcp-0.1.1-py3-none-any.whl

Download URL dot_mcp-0.1.1-py3-none-any.whl
Size 34.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7df49ddbc69372b185a294cfe8b44e1b7bac5cc8445a14ef0b17ec323e086f5b
BLAKE2b-256 checksum
How to use checksums
80fc2e07cb8c69b43bf69bd391bda21566671cc48195b266c67cbda7d90d4dd3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 11, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page