Moxie — the open-source money agent that acts on your money, only with your approval. Local-first, consent-first.
Project description
🦡 Moxie
The open-source money agent that acts — and never without your say-so.
Moxie doesn't care about a company's excuses. It just gets your money back — and asks you first, every time.
Named for the honey badger — small, fearless, famously relentless. It badgers companies until your money comes back.
The whole loop in 30 seconds: scan finds ~$591/yr of waste in the sample data, review shows you each fix and asks first (that n is the point — you're in control), verify proves the audit log hasn't been touched. Runs on bundled sample data — no bank, no API key.
Why Moxie exists
AI agents today split into two camps: ones that reach everywhere (OpenClaw) and ones that get smarter over time (Hermes). Neither answers the question that actually matters with your money: what will you let it do when the downside is real?
Look at who already touches your money:
- Receipt & finance organizers (Expensify, Firefly III, Receiptor AI) — they file and track. They don't act.
- Money-action services (DoNotPay, Rocket Money, Pine AI) — they act, but as closed black boxes that have burned users' trust (DoNotPay was FTC-fined for overstating its AI; Rocket Money has acted as users without asking).
- ChatGPT + Plaid — read-only by design: it can spot a subscription to cancel, but it won't cancel it.
Moxie bridges the gap, trust-first. It files your receipts (email + photo), reads your accounts, finds waste and wrong charges, and acts on them — cancelling, disputing, chasing refunds — but every action is previewed, approved by you, logged in a tamper-evident audit trail, and backed by the receipt as evidence. It's open-source and local, so you can read every line and your data never has to leave your machine.
Moxie never moves money. It cancels, disputes, and negotiates on your behalf. Paying, transferring, and trading are deliberately out of scope (that's a licensing and liability minefield). See the build spec.
What it does
- 🧾 Receipt vault —
moxie receipt photo.jpg(local Tesseract OCR — images never leave your machine) ormoxie receipt --email(read-only IMAP scan). Parsed, filed, matched to transactions, and attached to disputes as evidence automatically. - 🔎 Finds problems — zombie subscriptions, duplicate/wrong charges, missing refunds, gouge renewals.
- ✅ Acts — with your consent — drafts the cancellation/dispute, shows it to you (editable), and sends it only when you approve and
MOXIE_LIVE=true. Default is drafts-only. Receipt attached as proof. - 📮 Three action tiers — email from your own mailbox (SMTP), guided deep-links (Moxie shows the exact cancel page + clicks; you click), and per-merchant browser automation (optional, double-gated, sandboxed).
- 📊 A money dashboard that grows on request — accounts, trends, and upcoming bills out of the box, and you can ask Moxie in chat to add cards ("track my Netflix spend", "keep eating out under £150/mo"). The model only ever proposes validated specs — never code — and you confirm every card.
- 📁 A document vault —
~/.moxie/vault/files your receipts, statements, bills, and confirmations; browse and upload from the dashboard, imported CSVs archive themselves, everything encrypted at rest withmoxie encrypt on. - 🛡️ Trust Vault — deny-by-default policy engine, preview/simulate, approval gates, and a hash-chained, tamper-evident audit log.
- 🧩 Community skill library — reusable "how to cancel with X / dispute with Y" skills, each carrying its own success rate.
- 🔒 Local-first & BYO key — runs on your machine with your own LLM API key, or fully offline with a local model.
Quickstart
Two commands. Everything else happens in your browser.
pip install moxie-agent # or from source: git clone https://github.com/JacobBrooke1/moxie.git && cd moxie && pip install -e .
moxie dashboard # ← your browser opens; do everything from there
The dashboard walks you through setup in three steps, all on your machine:
- Connect your Claude API key — pasted locally, tested live, stored in
~/.moxie(or skip it: Moxie also runs a local Ollama model, or rules-only). - Get your transactions in — drop in any bank CSV (parsed in the browser, read-only) or click "Try with sample data" to see the whole consent-first loop with no bank and no key.
- Pair Telegram (optional) — text Moxie like a PA and approve findings from your phone.
Works the same locally or on a VPS (see docs/HOSTING.md). If moxie isn't recognized on Windows, use python -m moxie dashboard — pip's Scripts dir isn't on PATH; both work everywhere.
Prefer the terminal? The full CLI (power users & automation)
moxie init # set up ~/.moxie
moxie scan # find issues (add --csv statement.csv or --pdf statement.pdf)
moxie review # approve or skip each fix — nothing sends without your yes
moxie budget # this month: in / out / left
moxie connect truelayer # link a bank read-only (or gocardless / plaid)
moxie sync # pull fresh transactions + balances
moxie log # the tamper-evident audit trail
moxie verify # confirm the log hasn't been altered
moxie doctor # check your whole setup
Bank linking honesty note: every aggregator is a cloud third party. You hold the provider account (Moxie the project runs no servers), access is read-only AIS — Moxie cannot move money by construction — and CSV/PDF stays the fully no-cloud path. UK consents lapse ~90 days; the dashboard and moxie doctor tell you when to re-consent.
Going live (optional — everything works drafts-only without this): approving an action really sends it only when you flip the flag and configure your own mailbox:
# .env — your own email account (use an app password, never your real one)
MOXIE_SMTP_HOST=smtp.gmail.com
MOXIE_SMTP_USER=you@gmail.com
MOXIE_SMTP_PASSWORD=your-app-password
MOXIE_LIVE=true # default: false = drafts only
moxie review # 🔴 live: an approved cancel actually emails
moxie kill # panic button: force drafts-only until --release
Cancellations that work better on the merchant's website use guided deep-links: Moxie shows the exact URL and clicks (from the merchant's skill) and you do the final click — no passwords, no CAPTCHA fights.
⚠️ Status: feature-complete, pre-review. The Trust Vault, live action layer, bank providers, receipts, and the security hardening checklist (encryption at rest, OS keychain, dashboard token/CSRF, rate limiting) are all implemented and tested. What's missing is an independent security review — until then, use your own judgment with real financial data, keep
MOXIE_LIVEoff unless you've read the code, and see SECURITY.md for exactly where the edges are.
How it works
CAPTURE receipts (email + photo/OCR) + CONNECT accounts (Plaid / CSV, read-only)
→ ORGANIZE file receipts, match to transactions
→ DETECT zombie subs, duplicate charges, missing refunds
→ PROPOSE an action card: "Dispute this $40 double charge? I have the receipt."
→ APPROVE you confirm (because it can't be undone)
→ EXECUTE cancellation / dispute / refund email
→ LOG append-only, hash-chained audit trail with the receipt attached
Nothing in the right-hand column happens without passing the Trust Vault. For the full security model — the deny-by-default policy engine, the fail-safe consent design, the hash-chain math, and the threat model — see docs/HOW_IT_WORKS.md.
Why preview-and-approve, not "undo"
Most money actions are one-way — you can't cleanly un-cancel a subscription or un-send a dispute. So Moxie's safety is before the action (simulate → approve), not a promise to reverse it after. That's the whole reason consent is mandatory.
Run it 24/7
moxie serve # dashboard + Telegram bot + daily loop, one process
The daily loop re-scans every morning and pings you only when there's something new to decide. A Mac mini at home is the ideal host — always-on, and your bank data never leaves a machine you own. systemd/launchd units and a Dockerfile ship in deploy/; the full guide is docs/HOSTING.md.
Moxie Dash — the control plane
moxie dashboard # → http://127.0.0.1:8484
A local status page in the OpenClaw / Hermes tradition, but money-shaped: heartbeat, brain, Telegram, data, and audit-chain status at a glance, findings with approve/skip (same Trust Vault pipeline), and — most importantly — the setup home: paste your API key and BotFather token here, click detect my chat id, and it walks you through Telegram pairing. Keys are written to ~/.moxie/.env on the machine Moxie runs on; the audit log records that setup changed, never the secrets themselves.
It binds to 127.0.0.1 only. Running Moxie on a Mac mini or a VPS? Reach the dash through an SSH tunnel (ssh -L 8484:127.0.0.1:8484 you@host) — never expose it to the open internet.
The brain & the Telegram channel
Moxie has three layers, and you can stop at any of them:
- Rules (no key needed) — deterministic, explainable detectors. Everything above runs on these. Eight of them: duplicate charges, zombie subscriptions, trials-that-stuck, price-hike renewals, duplicate services, bank fees, FX fees, and short refunds.
- The brain (bring your own Anthropic key) — set
MOXIE_API_KEYin a.envfile and ask it things:moxie ask "can I afford £120 trainers this month?". Answers are grounded in the money picture — real income, committed subscriptions, and what's genuinely left this month (moxie budgetshows the same figures; balance appears once a bank is linked). It states figures and trade-offs and lets you decide — it's not a financial adviser and won't pretend to be. Its standing orders live in~/.moxie/instructions.md— a plain-English list of what it should do each day. Edit it; that file is the agent. - The offline brain (no key, no cloud) — run a local model instead: install Ollama,
ollama pull llama3.1, and setMOXIE_MODEL=ollama:llama3.1. Same instructions, same guardrails, zero cloud calls. - The Telegram channel (optional) —
moxie telegramruns a bot you can text like a PA, plus a daily loop that re-scans and messages you only when there's something new to decide. Decisions are remembered — skip something once and Moxie won't nag you about it for 60 days.
# .env: TELEGRAM_BOT_TOKEN from @BotFather, then pair:
moxie telegram # message your bot; it replies with your chat id
# put MOXIE_TELEGRAM_CHAT_ID=<that id> in .env, restart, done
Channel security (borrowed from OpenClaw's design): the bot is paired to exactly one chat and ignores everyone else; approvals are two-step (/approve 2, then YES); the brain never executes anything — every action still passes the Trust Vault; and sensitive setup (keys, bank links) only ever happens on your computer, never over chat.
Privacy & security
- Local-first. Your receipts, transactions, and audit log live on your machine — encrypted at rest once you run
moxie encrypt on. - Bring your own key. Moxie uses your LLM API key, or a local/offline model (Ollama) + local OCR (Tesseract) so receipt images never touch a cloud service.
moxie secret setkeeps keys in the OS keychain instead of a file. - Least privilege. Bank access is read-only AIS via a provider you choose and own; Moxie never moves money — it's hard-denied in policy.
- Tamper-evident. The audit log is hash-chained — any edit to past entries fails
moxie verify.
Security is the precondition for everything else here — see SECURITY.md.
Built on the OpenClaw / Hermes ecosystem
Moxie deliberately fits the world it came from, so the plumbing is familiar and only the moat is new:
- Language & install — Python (Hermes is ~82% Python), installed via a one-line
curl … | bashthat prefersuv, exactly like Hermes. - Skills — the same
SKILL.mdconvention used by OpenClaw and the agentskills.io standard (they live inmoxie/seed_skills/and ship in the package), so skills stay portable and shareable (think ClawHub, but for money-actions). - Familiar CLI —
moxie doctorand friends echohermes doctor/openclawso anyone from that world feels at home. - Sandboxing — action execution is designed to run sandboxed (Docker by default, as OpenClaw does for untrusted sessions).
What's not borrowed is the whole point: the Trust Vault (consent-first, tamper-evident) and the money-action layer are ours.
Contributing
The most valuable contribution is skills — encoded know-how for cancelling/disputing with a specific merchant, bank, or service; they genuinely drive how Moxie acts. See moxie/seed_skills/README.md for the format, CONTRIBUTING.md for good first issues, and integrations/moxie-bridge/ if you want your OpenClaw/Hermes agent to talk to Moxie (look, never touch).
Design
The security model and architecture rationale live in docs/HOW_IT_WORKS.md — including why Moxie is standalone rather than a skill inside a general-purpose agent, and exactly what the Trust Vault does and doesn't defend against.
License
MIT — free and open. Use it, fork it, learn from it.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file moxie_agent-0.4.0.tar.gz.
File metadata
- Download URL: moxie_agent-0.4.0.tar.gz
- Upload date:
- Size: 140.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
c8255a8129710cfd685f1db24009a724962e174e0654e4f5544445ef2df9b9d1
|
|
| MD5 |
8d601e700ab43db61d72ad5e85b8c6a0
|
|
| BLAKE2b-256 |
295d6e9b0fc8b76908691cdadf0b6cc2a98f06b73b6fa74848b8ab930984de2d
|
Provenance
The following attestation bundles were made for moxie_agent-0.4.0.tar.gz:
Publisher:
release.yml on JacobBrooke1/moxie
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
moxie_agent-0.4.0.tar.gz -
Subject digest:
c8255a8129710cfd685f1db24009a724962e174e0654e4f5544445ef2df9b9d1 - Sigstore transparency entry: 2092443332
- Sigstore integration time:
-
Permalink:
JacobBrooke1/moxie@05cbd31dbf24c5568ab827941d02101f9848f631 -
Branch / Tag:
refs/tags/v0.4.0 - Owner: https://github.com/JacobBrooke1
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@05cbd31dbf24c5568ab827941d02101f9848f631 -
Trigger Event:
push
-
Statement type:
File details
Details for the file moxie_agent-0.4.0-py3-none-any.whl.
File metadata
- Download URL: moxie_agent-0.4.0-py3-none-any.whl
- Upload date:
- Size: 113.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a53ba25286252b8b563732465a1b104650479181e33aab5baeb4624782cbfd0f
|
|
| MD5 |
f68e73f33b2f08affe42a85827ebf584
|
|
| BLAKE2b-256 |
f87cb79e2c5a1fa1da82ff7dd7f6564a8572f6a915c1837862403a17ea053c6c
|
Provenance
The following attestation bundles were made for moxie_agent-0.4.0-py3-none-any.whl:
Publisher:
release.yml on JacobBrooke1/moxie
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
moxie_agent-0.4.0-py3-none-any.whl -
Subject digest:
a53ba25286252b8b563732465a1b104650479181e33aab5baeb4624782cbfd0f - Sigstore transparency entry: 2092443629
- Sigstore integration time:
-
Permalink:
JacobBrooke1/moxie@05cbd31dbf24c5568ab827941d02101f9848f631 -
Branch / Tag:
refs/tags/v0.4.0 - Owner: https://github.com/JacobBrooke1
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@05cbd31dbf24c5568ab827941d02101f9848f631 -
Trigger Event:
push
-
Statement type: