---
title: "OpenInstinct eve Agent"
description: "Personal iMessage assistant that can do your chores, book movie tickets, and handle groceries."
url: "https://vercel.com/templates/eve/openinstinct-eve-agent"
links:
  repository: "https://github.com/Merit-Systems/OpenInstinct"
  demo: "https://openinstinct.sh/"
  deploy: "https://vercel.com/new/clone?demo-title=OpenInstinct+eve+Agent&demo-description=Personal+iMessage+assistant+that+can+do+your+chores%2C+book+movie+tickets%2C+and+handle+groceries.&demo-url=https%3A%2F%2Fopeninstinct.sh%2F&project-name=open-instinct&repository-name=open-instinct&repository-url=https%3A%2F%2Fgithub.com%2FMerit-Systems%2FOpenInstinct&connect=%5B%7B%22type%22%3A%22linq%22%2C%22env%22%3A%22LINQ_CONNECTOR%22%2C%22triggers%22%3Atrue%2C%22triggerPath%22%3A%22%2Feve%2Fv1%2Flinq%22%7D%5D&stores=%5B%7B%22type%22%3A%22integration%22%2C%22protocol%22%3A%22other%22%2C%22productSlug%22%3A%22kernel%22%2C%22integrationSlug%22%3A%22kernel%22%7D%2C%7B%22type%22%3A%22integration%22%2C%22protocol%22%3A%22storage%22%2C%22productSlug%22%3A%22neon%22%2C%22integrationSlug%22%3A%22neon%22%7D%2C%7B%22type%22%3A%22blob%22%2C%22access%22%3A%22private%22%7D%5D&demo-image=%2F%2Fimages.ctfassets.net%2Fe5382hct74si%2F67tZZIyFLJ0mnljhGpubER%2F541b9c555d397be559eb8168d5a49fa1%2FUntitled_Design__49___1_.png"
---

# OpenInstinct eve Agent

Personal iMessage assistant that can do your chores, book movie tickets, and handle groceries.

**A personal iMessage assistant that can use a browser like you.**

It can do your chores, book you movie tickets, or handle your groceries.
You stay in control of your passwords, credit cards and context.

It's Open Source, self-hostable, and can use any model.

## Why self-host?

Personal agents are much more useful when they can sign in, book, buy and act
on your behalf. But your accounts, your passwords, are the keys to your digital
kingdom. OpenInstinct runs in your own Vercel account. Secrets are encrypted
before they touch your database and models never see them. Verify yourself by
reading the code!

## Deployment

The Vercel one-click deploy flow provisions [Kernel](https://kernel.sh) for cloud browsers,
[Neon](https://neon.tech) for Postgres, and a private Vercel Blob store for
browser images, per-user memory, and installation secrets. It also creates and
attaches a [Linq](https://linq.app) connector for iMessage. Vercel AI Gateway
handles inference. Usage is billed to your Vercel account.

On first use, OpenInstinct creates independent Better Auth and vault-encryption
keys in the private Blob store. Vercel supplies the application URL, database,
Kernel, Blob, and Linq configuration, so the deploy flow requires no
environment-variable values. For a non-Vercel host or an existing installation
that manages its own keys, set both secret overrides and the public application
URL explicitly:

```bash
BETTER_AUTH_SECRET="$(openssl rand -base64 32)"
BETTER_AUTH_URL=https://your-host
SECRET_ENCRYPTION_KEY="$(openssl rand -base64 32)"
```

The application database schema and versioned migrations live in `db/`. The
Drizzle application store uses `DATABASE_URL` for runtime queries; its migration
commands require the direct `DATABASE_URL_UNPOOLED` connection. Run
`pnpm db:migrate` before starting against a new or upgraded local database.
Vercel uses Turbo to run the uncached migration task before its application
build.

Treat the private Blob store as production key material: deleting it loses the
automatically generated encryption key, and rotating that key requires
re-encrypting existing vault values.

### Blob storage

The one-click deploy creates and connects a private Blob store automatically.
Vercel supplies `BLOB_STORE_ID` and a short-lived `VERCEL_OIDC_TOKEN` to each
deployment, so there is no long-lived Blob credential to copy.

OpenInstinct uses this store for persistent per-user memory and browser images.
Production conversations require it because memory is recalled before each agent
turn. Local Eve development uses process-local memory instead.

Ongoing undertakings use a separate `workstreams` memory slot backed by the
application database. Run the application migrations before using this feature;
it needs no additional service or credentials. The root agent can save goals,
constraints, decisions, source-linked observations, and unresolved steps across
conversations. It recalls an index of the eight most recently updated active or
waiting workstreams, then reads the selected record before continuing. Older and
completed workstreams remain searchable.

Workstreams are scoped by authenticated workspace and Eve's deployment-aware
memory key. Updates require the current revision. Each scope retains content for up to 100
bounded records; the agent asks which obsolete record to forget at capacity.
Forgetting erases the content and source references, retaining only a tombstone
to prevent an interrupted save from restoring them. Existing chat history is
unchanged. This slot is available only in interactive root turns; remembering
work does not start a job, create a schedule, or authorize an action.

For an existing Vercel project, link it first with
`eve link --project <your-vercel-project> --non-interactive`, then create and
connect the store with one command:

```bash
pnpm exec vercel blob create-store open-instinct-images --access private --yes --environment production --environment preview --environment development
```

Outside Vercel, set `BLOB_READ_WRITE_TOKEN` from a private Blob store instead.
The memory provider uses that token explicitly, and browser image capture uses the
same store.

### Linq iMessage setup

The deploy button creates a managed line, writes `LINQ_CONNECTOR`, and
attaches the inbound webhook trigger automatically. For an existing Vercel
project, link the checkout, create a Linq line, and attach its connector for both
app tokens and inbound webhook triggers:

```bash
vercel link
vercel connect create linq --connection-method line --name open-instinct --json
vercel connect attach <returned-connector-uid> --project <your-vercel-project> --environment production --triggers --trigger-path /eve/v1/linq --yes
vercel env add LINQ_CONNECTOR production --value <returned-connector-uid> --yes
eve deploy --non-interactive --yes
```

The create command returns the connector UID. Repeat the attachment and
environment-variable steps for preview or development if those environments
should use Linq too. `LINQ_PHONE_NUMBER` is an optional E.164 override that adds
a click-to-message shortcut in the workspace; Linq delivery itself uses the
line assigned to the connector.

Before the first sign-in, open the connector's Vercel Connect settings and
follow the one-time **Phone Numbers** verification instruction. Additional users
verify themselves by messaging the connector's Linq number once. The
`--triggers --trigger-path /eve/v1/linq` options are also required: attaching a
connector without them permits outbound token access but does not forward
incoming messages to OpenInstinct.

## Google Workspace connection

OpenInstinct can use a user's Gmail, Calendar, and read-only Contacts through a
user-scoped Google OAuth grant. Vercel Connect stores and refreshes the tokens;
OpenInstinct stores only the stable user identity used to request them. Gmail
access deliberately uses `gmail.modify`, not the permanent-delete
`mail.google.com` scope.

1. In one Google Cloud project, configure the OAuth consent screen and enable
   the Gmail API, Google Calendar API, and People API.
2. Create OAuth web credentials. Add
   `https://connect.vercel.com/callback` as an authorized redirect URI, then
   download the client-secret JSON.
3. Vercel expects top-level `clientId` and `clientSecret` keys, not Google's
   nested `web.client_id` and `web.client_secret` download. Convert the download
   into a temporary file outside the repository, then create and attach the
   connector:

   ```bash
   vercel link
   google_credentials_file="$(mktemp)"
   jq '{clientId: .web.client_id, clientSecret: .web.client_secret}' /absolute/path/to/downloaded-client-secret.json > "$google_credentials_file"
   vercel connect create google --connection-method oauth --name open-instinct --data @"$google_credentials_file"
   rm -f "$google_credentials_file"
   vercel connect attach <returned-connector-uid> --project <your-vercel-project> --environment production --yes
   vercel env pull
   ```

   Never commit either credential file.

4. Set `GOOGLE_CONNECTOR_UID` to the returned UID and redeploy. The default is
   `google/open-instinct`.

Gotchas:

- Attach the connector separately to every Vercel environment that should use
  it. A production attachment does not make preview or local development work.
- The Gmail read/modify scope is restricted. A Google OAuth app in Testing mode
  only works for listed test users, and those grants expire after seven days.
  Broader distribution requires Google's OAuth verification and may require a
  security assessment.
- The scopes requested here must also be declared on the Google consent screen.
  After changing scopes or enabled APIs, disconnect and reconnect the account so
  Google issues a grant with the new access.
- The grant is keyed to the authenticated OpenInstinct user. iMessage reaches
  the same grant only when its verified phone number maps to that Better Auth
  account.
- Google Contacts search uses a provider-side lazy cache, so a contact created
  moments ago may not appear immediately.
- User-requested email and calendar operations run without an extra Eve tool
  approval. Calendar events with attendees send Google invitations.

## Link wallet

The root agent mounts `@stripe/link-integrations-eve` in
`agent/extensions/link.ts`. It uses Stripe's bundled wallet tools and skills,
with per-user authorization through the existing Better Auth
account. It does not use a shared wallet token.

To enable it, register a Link OAuth client and configure `LINK_CLIENT_ID`,
`LINK_CLIENT_SECRET`, and `STRIPE_PUBLISHABLE_KEY` on the server. Register the
exact redirect URI `https://<your-app-host>/api/auth/callback/link` with Stripe,
including a separate localhost URI when developing locally. Set
`BETTER_AUTH_URL` to the canonical application origin. These values are optional
for installations that do not use Link.

Apply the database migration with `pnpm db:migrate` before enabling Link. It
enforces one Link wallet per OpenInstinct account. Disconnect the current wallet
before connecting a different one; reconnecting the same wallet refreshes its
grant.

Users connect or disconnect their wallet from **Link wallet** in the sidebar.
An agent request that needs a wallet sends a native connection link. Opening it
redirects to Link's consent screen after any required OpenInstinct sign-in, then
resumes through Eve's authorization callback. Purchase approval links use Link's
original URLs directly. Connection attempts expire after ten
minutes and belong to the signed-in user. Better Auth stores encrypted grants
and refreshes tokens; disconnection revokes the Link grant before removing it.
Phone sign-in continues to work after disconnecting a wallet.

Wallet access is available in interactive conversations, not scheduled workers
or scheduled result delivery. Spend requests run without an extra Eve tool
approval and always request purchase approval in Link. Its tools can
return payment credentials into stored Eve tool results; the bundled skills
instruct the agent not to repeat them in chat. Financial-data tools also require
the corresponding Link grant scopes; the default grant requests
`payment_methods.agentic` and `userinfo:read`.

## Related Templates

### [eve Software Factory](https://vercel.com/templates/eve/eve-software-factory)

Software factory built on eve: AI agents work each stage of the development loop, and people make the judgment calls.

### [eve Incident Response Agent](https://vercel.com/templates/eve/eve-incident-response-agent)

sre investigates production issues using a hypothesis-driven approach and outputs verifiable evidence from connected sources.

### [eve Personal Agent](https://vercel.com/templates/nuxt/eve-personal-agent)

Fork your own personal agent. One identity across web, Slack, and iMessage, with memory you can import, edit, and approve.

## Related Integrations

### [KERNEL](https://vercel.com/marketplace/kernel)

crazy fast, open source infra for AI agents to access the internet

### [Neon](https://vercel.com/marketplace/neon)

Postgres serverless platform designed to build reliable and scalable apps

---

## Additional documentation

The [Vercel Knowledge Base](https://vercel.com/kb) contains guides and answers to common questions about Vercel, including deployment, framework configuration, domains, caching, and troubleshooting.
