{"slug": "openinstinct-eve-agent", "title": "OpenInstinct Eve Agent", "summary": "OpenInstinct released Eve, an open-source, self-hostable personal iMessage assistant that can operate a browser to book movie tickets, handle groceries and complete other chores while keeping passwords, credit cards and context under the user's control. The agent runs in the user's own Vercel account, where secrets are encrypted before reaching the database and models never see them, and it can use any model. The one-click Vercel deploy provisions Kernel for cloud browsers, Neon for Postgres, a private Vercel Blob store for browser images, per-user memory and installation secrets, and a Linq connector for iMessage, with inference handled by Vercel AI Gateway and usage billed to the user's Vercel account.", "body_md": "A personal iMessage assistant that can use a browser like you.\n\nIt can do your chores, book you movie tickets, or handle your groceries. You stay in control of your passwords, credit cards and context.\n\nIt's Open Source, self-hostable, and can use any model.\n\n### Why self-host?\n\nPersonal agents are much more useful when they can sign in, book, buy and act on your behalf. But your accounts, your passwords, are the keys to your digital kingdom. OpenInstinct runs in your own Vercel account. Secrets are encrypted before they touch your database and models never see them. Verify yourself by reading the code!\n\n### Deployment\n\nThe Vercel one-click deploy flow provisions [Kernel](https://kernel.sh/) for cloud browsers,\n[Neon](https://neon.tech/) for Postgres, and a private Vercel Blob store for\nbrowser images, per-user memory, and installation secrets. It also creates and\nattaches a [Linq](https://linq.app/) connector for iMessage. Vercel AI Gateway\nhandles inference. Usage is billed to your Vercel account.\n\nOn first use, OpenInstinct creates independent Better Auth and vault-encryption keys in the private Blob store. Vercel supplies the application URL, database, Kernel, Blob, and Linq configuration, so the deploy flow requires no environment-variable values. For a non-Vercel host or an existing installation that manages its own keys, set both secret overrides and the public application URL explicitly:\n\n```\n1BETTER_AUTH_SECRET=\"$(openssl rand -base64 32)\"2BETTER_AUTH_URL=https://your-host3SECRET_ENCRYPTION_KEY=\"$(openssl rand -base64 32)\"\n```\n\nThe application database schema and versioned migrations live in `db/`. The\nDrizzle application store uses `DATABASE_URL` for runtime queries; its migration\ncommands require the direct `DATABASE_URL_UNPOOLED` connection. Run\n`pnpm db:migrate` before starting against a new or upgraded local database.\nVercel uses Turbo to run the uncached migration task before its application\nbuild.\n\nTreat the private Blob store as production key material: deleting it loses the automatically generated encryption key, and rotating that key requires re-encrypting existing vault values.\n\n#### Blob storage\n\nThe one-click deploy creates and connects a private Blob store automatically.\nVercel supplies `BLOB_STORE_ID` and a short-lived `VERCEL_OIDC_TOKEN` to each\ndeployment, so there is no long-lived Blob credential to copy.\n\nOpenInstinct uses this store for persistent per-user memory and browser images. Production conversations require it because memory is recalled before each agent turn. Local Eve development uses process-local memory instead.\n\nOngoing undertakings use a separate `workstreams` memory slot backed by the\napplication database. Run the application migrations before using this feature;\nit needs no additional service or credentials. The root agent can save goals,\nconstraints, decisions, source-linked observations, and unresolved steps across\nconversations. It recalls an index of the eight most recently updated active or\nwaiting workstreams, then reads the selected record before continuing. Older and\ncompleted workstreams remain searchable.\n\nWorkstreams are scoped by authenticated workspace and Eve's deployment-aware memory key. Updates require the current revision. Each scope retains content for up to 100 bounded records; the agent asks which obsolete record to forget at capacity. Forgetting erases the content and source references, retaining only a tombstone to prevent an interrupted save from restoring them. Existing chat history is unchanged. This slot is available only in interactive root turns; remembering work does not start a job, create a schedule, or authorize an action.\n\nFor an existing Vercel project, link it first with\n`eve link --project <your-vercel-project> --non-interactive`, then create and\nconnect the store with one command:\n\n```\n1pnpm exec vercel blob create-store open-instinct-images --access private --yes --environment production --environment preview --environment development\n```\n\nOutside Vercel, set `BLOB_READ_WRITE_TOKEN` from a private Blob store instead.\nThe memory provider uses that token explicitly, and browser image capture uses the\nsame store.\n\n#### Linq iMessage setup\n\nThe deploy button creates a managed line, writes `LINQ_CONNECTOR`, and\nattaches the inbound webhook trigger automatically. For an existing Vercel\nproject, link the checkout, create a Linq line, and attach its connector for both\napp tokens and inbound webhook triggers:\n\n```\n1vercel link2vercel connect create linq --connection-method line --name open-instinct --json3vercel connect attach <returned-connector-uid> --project <your-vercel-project> --environment production --triggers --trigger-path /eve/v1/linq --yes4vercel env add LINQ_CONNECTOR production --value <returned-connector-uid> --yes5eve deploy --non-interactive --yes\n```\n\nThe create command returns the connector UID. Repeat the attachment and\nenvironment-variable steps for preview or development if those environments\nshould use Linq too. `LINQ_PHONE_NUMBER` is an optional E.164 override that adds\na click-to-message shortcut in the workspace; Linq delivery itself uses the\nline assigned to the connector.\n\nBefore the first sign-in, open the connector's Vercel Connect settings and\nfollow the one-time Phone Numbers verification instruction. Additional users\nverify themselves by messaging the connector's Linq number once. The\n`--triggers --trigger-path /eve/v1/linq` options are also required: attaching a\nconnector without them permits outbound token access but does not forward\nincoming messages to OpenInstinct.\n\n### Google Workspace connection\n\nOpenInstinct can use a user's Gmail, Calendar, and read-only Contacts through a\nuser-scoped Google OAuth grant. Vercel Connect stores and refreshes the tokens;\nOpenInstinct stores only the stable user identity used to request them. Gmail\naccess deliberately uses `gmail.modify`, not the permanent-delete\n`mail.google.com` scope.\n\n1. \nIn one Google Cloud project, configure the OAuth consent screen and enable the Gmail API, Google Calendar API, and People API.\n2. \nCreate OAuth web credentials. Add `https://connect.vercel.com/callback` as an authorized redirect URI, then\ndownload the client-secret JSON.\n3. \nVercel expects top-level `clientId` and`clientSecret` keys, not Google's\nnested`web.client_id` and`web.client_secret` download. Convert the download\ninto a temporary file outside the repository, then create and attach the\nconnector:\n\n```\n1vercel link2google_credentials_file=\"$(mktemp)\"3jq '{clientId: .web.client_id, clientSecret: .web.client_secret}' /absolute/path/to/downloaded-client-secret.json > \"$google_credentials_file\"4vercel connect create google --connection-method oauth --name open-instinct --data @\"$google_credentials_file\"5rm -f \"$google_credentials_file\"6vercel connect attach <returned-connector-uid> --project <your-vercel-project> --environment production --yes7vercel env pull\n```\n\n Never commit either credential file.\n4. \nSet `GOOGLE_CONNECTOR_UID` to the returned UID and redeploy. The default is`google/open-instinct` .\n\nGotchas:\n\n- Attach the connector separately to every Vercel environment that should use it. A production attachment does not make preview or local development work.\n- The Gmail read/modify scope is restricted. A Google OAuth app in Testing mode only works for listed test users, and those grants expire after seven days. Broader distribution requires Google's OAuth verification and may require a security assessment.\n- The scopes requested here must also be declared on the Google consent screen. After changing scopes or enabled APIs, disconnect and reconnect the account so Google issues a grant with the new access.\n- The grant is keyed to the authenticated OpenInstinct user. iMessage reaches the same grant only when its verified phone number maps to that Better Auth account.\n- Google Contacts search uses a provider-side lazy cache, so a contact created moments ago may not appear immediately.\n- User-requested email and calendar operations run without an extra Eve tool approval. Calendar events with attendees send Google invitations.\n\n### Link wallet\n\nThe root agent mounts `@stripe/link-integrations-eve` in\n`agent/extensions/link.ts`. It uses Stripe's bundled wallet tools and skills,\nwith per-user authorization through the existing Better Auth\naccount. It does not use a shared wallet token.\n\nTo enable it, register a Link OAuth client and configure `LINK_CLIENT_ID`,\n`LINK_CLIENT_SECRET`, and `STRIPE_PUBLISHABLE_KEY` on the server. Register the\nexact redirect URI `https://<your-app-host>/api/auth/callback/link` with Stripe,\nincluding a separate localhost URI when developing locally. Set\n`BETTER_AUTH_URL` to the canonical application origin. These values are optional\nfor installations that do not use Link.\n\nApply the database migration with `pnpm db:migrate` before enabling Link. It\nenforces one Link wallet per OpenInstinct account. Disconnect the current wallet\nbefore connecting a different one; reconnecting the same wallet refreshes its\ngrant.\n\nUsers connect or disconnect their wallet from Link wallet in the sidebar. An agent request that needs a wallet sends a native connection link. Opening it redirects to Link's consent screen after any required OpenInstinct sign-in, then resumes through Eve's authorization callback. Purchase approval links use Link's original URLs directly. Connection attempts expire after ten minutes and belong to the signed-in user. Better Auth stores encrypted grants and refreshes tokens; disconnection revokes the Link grant before removing it. Phone sign-in continues to work after disconnecting a wallet.\n\nWallet access is available in interactive conversations, not scheduled workers\nor scheduled result delivery. Spend requests run without an extra Eve tool\napproval and always request purchase approval in Link. Its tools can\nreturn payment credentials into stored Eve tool results; the bundled skills\ninstruct the agent not to repeat them in chat. Financial-data tools also require\nthe corresponding Link grant scopes; the default grant requests\n`payment_methods.agentic` and `userinfo:read`.", "url": "https://wpnews.pro/news/openinstinct-eve-agent", "canonical_source": "https://vercel.com/templates/eve/openinstinct-eve-agent", "published_at": "2026-10-05 07:39:08+00:00", "updated_at": "2026-10-05 07:48:48.032729+00:00", "lang": "en", "topics": ["ai-agents", "ai-products", "ai-tools", "developer-tools", "artificial-intelligence"], "entities": ["OpenInstinct", "Eve", "Vercel", "Kernel", "Neon", "Linq", "Vercel AI Gateway", "Better Auth"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/openinstinct-eve-agent", "markdown": "https://wpnews.pro/news/openinstinct-eve-agent.md", "text": "https://wpnews.pro/news/openinstinct-eve-agent.txt", "jsonld": "https://wpnews.pro/news/openinstinct-eve-agent.jsonld"}}