Skip to main content

An interactive terminal AI agent you can fully undo — any model, acts on your real files, every action reversible.

Project description

opendot
An interactive terminal AI agent you can fully undo.

CI PyPI Python versions License: MIT


opendot works directly on your real files and shell — but unlike other terminal agents, every action it takes is snapshotted first, so you can see exactly what it did and cleanly walk it back. Files and shell commands, not just in-repo edits. Commands whose effects escape your workspace (network, sudo, git push, deleting outside the working dir) are flagged and confirmed before they run, with an honest note about what can't be undone.

That's the point of opendot: an agent you can let loose because nothing it does is a surprise, and (almost) nothing is irreversible.

Install

# try it instantly, no install
uvx opendot

# recommended (isolated global CLI)
uv tool install opendot        # or: pipx install opendot

# also works
pip install opendot

Use

opendot                              # open an interactive chat
opendot -p "summarize this project"  # one-shot, for scripts / CI
opendot --model claude-opus-4-5      # launch with a specific model (see below)

opendot log                          # audit: what has the agent done here?
opendot undo                         # revert the last action
opendot undo 000004                  # restore the workspace to before action #4

Inside the chat, slash-commands: /model (searchable model picker), /provider (connect a provider + paste an API key), /log, /undo, /clear, /compact, /help.

Any model

Any model works — cloud, local, or Hugging Face. You need an API key for the provider you want to use (opendot is BYO-key; it doesn't host models). Pick a model and paste a key right inside the chat with /model and /provider, or set the key in your environment and pass --model:

Provider Env var Example --model Get a key
OpenAI OPENAI_API_KEY gpt-5.1 platform.openai.com/api-keys
Anthropic ANTHROPIC_API_KEY claude-opus-4-5 console.anthropic.com
Google GEMINI_API_KEY gemini/gemini-3-pro aistudio.google.com/apikey
DeepSeek DEEPSEEK_API_KEY deepseek/deepseek-chat platform.deepseek.com
Groq GROQ_API_KEY groq/llama-3.3-70b-versatile console.groq.com/keys
Hugging Face HF_TOKEN huggingface/together/deepseek-ai/DeepSeek-R1 huggingface.co/settings/tokens
Ollama (local, no key) ollama/qwen3 run ollama.com locally

Reasoning models stream their thinking live.

Which model runs. The default is gpt-5.1. If its key (OPENAI_API_KEY) isn't set but another provider's key is, opendot automatically switches to that provider on launch — e.g. with only DEEPSEEK_API_KEY set, a bare opendot uses deepseek/deepseek-chat. If no provider key is found, opendot starts fine but the first message shows a hint to set a key or run /provider (rather than a raw provider error). ollama/* models need no key — just a local Ollama.

Connect MCP servers

opendot is an MCP client: connect any MCP server and its tools become available to the agent alongside the built-in ones. Manage them from inside the chat with /mcp (a dropdown of your servers and their status, with "➕ Add a server"), or from the command line:

# a stdio server — put its launch command after `--`
opendot mcp add <name> --env KEY=VALUE -- <command> [args...]

# a remote server (http/sse)
opendot mcp add <name> --url <https url>

# a remote server that needs auth — pass an HTTP header
opendot mcp add supabase \
  --url "https://mcp.supabase.com/mcp?project_ref=<id>&read_only=true" \
  --header "Authorization=Bearer <your-supabase-access-token>"

opendot mcp list           # show configured servers
opendot mcp remove <name>  # remove one

Servers are stored in ~/.opendot/mcp.json and connect automatically on the next launch; connected servers appear in the sidebar. For authenticated remote servers, opendot supports the header/token method (e.g. Supabase's access token) — the interactive browser-OAuth flow is not implemented yet.

Because opendot can't know what an external tool does, every MCP tool call is treated as irreversible — it's confirmed before running and marked ✗ in the ledger. Your built-in file/shell actions stay snapshotted and undoable as usual.

Connect apps with Composio

Beyond MCP, opendot can connect to Composio's 3000+ app tools (Gmail, Slack, GitHub, Notion, Linear, …) using your own Composio API key. Install the extra and use /composio in the chat:

pip install 'opendot[composio]'
  • The first /composio asks for your Composio API key (stored in ~/.opendot/composio.json, owner-readable only).
  • After that, /composio lists the available apps. Pick one — if it needs OAuth, opendot opens your browser to authorize and waits for you to finish; direct/API-key connectors activate immediately.
  • Enabled apps appear in the sidebar; their tools load on the next launch.

Composio tools reach external services, so — like MCP — every call is treated as irreversible: confirmed first, marked ✗ in the ledger.

Project rules — OPENDOT.md

Drop an OPENDOT.md in your project. Its prose is given to the agent as context. You can also control what gets snapshotted with an opendot block:

```opendot
# snapshot these even though they'd normally be skipped:
snapshot: dist
# never snapshot these:
skip: data, *.log
```

By default opendot skips .git, node_modules, virtualenvs, and build caches when snapshotting — your rules override those in either direction.

How the reversibility works

  • Before every file write or shell command, opendot snapshots the working directory into a content-addressed store in ~/.opendot (each unique file stored once, so snapshots are cheap).
  • Every action is recorded in an append-only ledger you can inspect with opendot log.
  • opendot undo restores the workspace to a chosen point, exactly.
  • A conservative classifier decides which shell commands are workspace- contained (auto-run, undoable) vs. escaping (confirmed first, marked irreversible). When unsure, it asks.

Honest boundary: opendot cannot undo effects that leave your machine (a sent email, a dropped remote database, a git push). It tells you before running those, rather than pretending otherwise.

Contributing

Issues and PRs welcome — see CONTRIBUTING.md for setup and the one hard rule (don't break reversibility). Security reports go through SECURITY.md.

git clone https://github.com/vedaant00/opendot
cd opendot
uv pip install -e ".[dev]"   # or: pip install -e ".[dev]"
pytest

Status

Early (alpha). The interactive agent, local tools, and the full reversibility engine work and are tested. Streaming, slash-commands, and OPENDOT.md rules are in. A richer TUI and more tools are coming.

MIT licensed.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

opendot-0.0.4.tar.gz (247.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

opendot-0.0.4-py3-none-any.whl (60.1 kB view details)

Uploaded Python 3

File details

Details for the file opendot-0.0.4.tar.gz.

File metadata

  • Download URL: opendot-0.0.4.tar.gz
  • Upload date:
  • Size: 247.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for opendot-0.0.4.tar.gz
Algorithm Hash digest
SHA256 5f4dfbc0a7a3ef7bc6638834a433c242e154d9a0f597930895b3a5e3166b5967
MD5 71f0a6f30e766279d4823109d3b1337a
BLAKE2b-256 7571bb84265b766ba41f2f9e25b09865a10d26f104b5e33751e27e8b437a7353

See more details on using hashes here.

Provenance

The following attestation bundles were made for opendot-0.0.4.tar.gz:

Publisher: release.yml on vedaant00/opendot

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file opendot-0.0.4-py3-none-any.whl.

File metadata

  • Download URL: opendot-0.0.4-py3-none-any.whl
  • Upload date:
  • Size: 60.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for opendot-0.0.4-py3-none-any.whl
Algorithm Hash digest
SHA256 46eed8b93e8111cb2a60accfb6a9e06cd26d342496c65655f0780bdddf33983a
MD5 7fba5bca4d60fca59c26280f4a16ae03
BLAKE2b-256 05d1e8789afe04250a32edcd331fb32b901fe4719c4fa42ae8b6e67424c25ce1

See more details on using hashes here.

Provenance

The following attestation bundles were made for opendot-0.0.4-py3-none-any.whl:

Publisher: release.yml on vedaant00/opendot

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page