dot-mcp
Personal MCP agent for ChatGPT, Claude, and Gemini: shell, files, memory, goals, tasks, inbox, scheduler, and self-hosted OAuth — running on your own machine.
⚠️ The server gives full shell access to whoever holds a credential. Expose it only while you use it, then stop it (
dot-mcp stop).
Install
pip install dot-mcp
Requires Python 3.10+ and OpenSSH (ssh, ssh-keygen) for the tunnel.
Use
dot-mcp start # server + public URL (runs in background)
dot-mcp status # check if it is running
dot-mcp stop # stop server + tunnel
dot-mcp start prints everything the connector needs:
Public URL https://xxxx.tunnl.gg/mcp/
Owner secret <stored on your machine>
OAuth Client ID dots-xxxxxxxx
OAuth Client secret <stored on your machine>
Add the Public URL as a custom MCP connector (auth = OAuth). Approve once with the owner secret when asked. The tunnel URL stays the same on restart; the free tunnel expires after 24h or 2h idle.
Options: --port (default 33041), --data-dir (default ~/.dot-mcp),
--json (script-friendly output).
What it can do (22 tools)
- Shell:
run_command(background sessions + timeout) +read_output - Files:
list_dir,read_file(paged + sha256),write_file(atomic + guards),append_file,edit_file - Memory:
remember,recall,forget— persists across chats - Goals/Tasks:
set_goal,add_update,get_state,add_task,complete_task - Inbox:
notify_user,poll_inbox,ack_inbox— messages across chats - Scheduler:
add_schedule,list_schedules,remove_schedule— background jobs that run between chats - UI:
open_workspace— embedded dashboard (tasks, memory, sessions)
Security model
/mcp/requiresAuthorization: Bearer(OAuth JWT or owner secret) — anything else gets 401, even from localhost- OAuth 2.1 is self-hosted: dynamic registration, PKCE, 1h JWT + rotating 30d refresh tokens, manual Client ID/secret for Claude-style connectors
- Per-IP rate limits (300/min API, 30/min auth), append-only
audit.jsonl, cross-process file locks, atomic writes - Known limits: the tunnel provider sees traffic (TLS ends at their edge);
back up
~/.dot-mcpyourself
Local-only mode (no tunnel)
export OPENAI_API_KEY=sk-...
python -m dot_mcp.local_agent # chat loop
python -m dot_mcp.local_agent --list # list tools only
Develop
./setup.sh # venv + editable install
.venv/bin/python -m pytest tests/ -q # test suite
python -m build # wheel in dist/
See CHANGELOG.md for release notes.
License
MIT
Metadata
Release files for dot-mcp 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| dot_mcp-0.1.1.tar.gz | 34.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| dot_mcp-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 68.7 kB
Release files / dot_mcp-0.1.1.tar.gz
| Download URL | dot_mcp-0.1.1.tar.gz |
|---|---|
| Size | 34.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
404da6b75a9805bc2e4d16503882474df5df8ccef92460a6391f830b986cba68
|
|
BLAKE2b-256 checksum How to use checksums |
697e34dcd2296b9b4830553d46bbe482475be6222408f21e8af978a02ce6c03f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 11, 2026.
Transparency logRelease files / dot_mcp-0.1.1-py3-none-any.whl
| Download URL | dot_mcp-0.1.1-py3-none-any.whl |
|---|---|
| Size | 34.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7df49ddbc69372b185a294cfe8b44e1b7bac5cc8445a14ef0b17ec323e086f5b
|
|
BLAKE2b-256 checksum How to use checksums |
80fc2e07cb8c69b43bf69bd391bda21566671cc48195b266c67cbda7d90d4dd3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 11, 2026.
Transparency log