Open Instinct: an open-source personal AI agent you text
Open Instinct is an MIT-licensed, open-source alternative to Instinct: a personal AI agent you text on iMessage, running in one Maritime microVM per person.
Open Instinct is an open-source, MIT-licensed personal AI agent you text on iMessage, and an alternative to Instinct that you deploy yourself. You send it an iMessage, and it books the dinner, checks you into the flight, or asks your partner's agent when you are both free. It has its own phone number, its own email address, and its own computer. The code is at github.com/mariagorskikh/open-instinct.
We built it as a from-scratch, documented take on Instinct, the closed, invite-only assistant you text. Every person who uses Open Instinct gets their own agent in their own microVM on Maritime, with a Linux desktop the agent can click on. This post is about that part: why one machine per person, and what the machine does.
Five services, each behind one package
The agent is a stack of services, each wrapped in one small package you can swap for something else:
Why one machine per person
A personal agent is the clearest case we know for one agent per user. Its memory is your life: who your partner is, which seat you like, the dinner you moved twice. It holds access to your email and calendar. It keeps a browser logged into your airline account. None of that should share a process, a disk, or a browser profile with anyone else.
So Open Instinct never multiplexes. Each person's agent runs in its own Firecracker microVM, and everything it knows lives under /data in that VM: config, conversation sessions, contacts and trust tiers, the audit log, secrets. Removing a person means deleting one agent. A bad tool run in one person's agent cannot read another person's mail, because there is no other person on the machine.
Isolation also keeps the trust model simple. Open Instinct sorts everyone who messages you into six tiers, from owner and partner down to friend, contact, and stranger, and enforces them in code before any tool runs. Your partner's agent can read your calendar. A friend's can only ask when you are free. A stranger gets a polite no, and you get a one-line text saying who asked for what. That policy only means something if the data it guards is not sitting next to someone else's.
The tiers matter most when agents talk to each other. Ask for dinner with Sam, and your agent asks Sam's agent through Inkbox, within the key you gave Sam. The two agents do the back-and-forth on their own machines, and each of you gets one question.
The agent has a computer, not a browser API
Most of what a personal assistant does has no API. Checking in for a flight, holding a table, cancelling a subscription: these happen on websites built for people. Open Instinct creates its Maritime agent with desktop: true, which gives the VM a real Linux desktop with Chromium and a local control service, desktopd, on loopback port 5911. The agent takes screenshots, clicks, and types through it, and reads and writes files on the same machine. Ask for a brief "as a PDF" and it writes one there and texts it to you.
The desktop also handles the moment every agent dreads: the login page. When a site wants a password, a 2FA code, or card details, the agent calls request_takeover and texts you a link. You open the same live desktop from your phone, type the password yourself, hand control back, and the agent carries on. The model never sees the credential. Agents deployed with --no-desktop can fall back to a hosted Maritime Computer over MCP instead.
Payments use the same desktop. The agent fills the cart in its own browser, stops at the final total, and asks Stripe Link for a one-time card for exactly that amount. You approve on your phone, it pays, and the card is dead afterwards. Limits live in a spend policy file: ask above an amount, a daily cap, and things that always need a yes. Without a wallet connected, it hands you the checkout screen instead.
How a text reaches a sleeping agent
An agent that waits for texts spends nearly all of its life waiting. On Maritime it does not have to be running for that. After 900 idle seconds (the default, and configurable with --idle) the VM is snapshotted and freed, and its disk and desktop state are kept. The next message wakes it.
The path for one text:
- You send an iMessage. Inkbox receives it and posts a signed webhook to the Open Instinct gateway.
- The gateway verifies the signature, drops duplicates and delivery receipts, and forwards the event to your agent through Maritime's chat API.
- Maritime wakes your VM and posts the event to the agent's
/chat. - The agent does the work, replies to you through Inkbox, and sleeps again once it has been idle long enough.
The gateway is one small always-on service for a whole deployment. It holds no conversation state and never sees the model; it maps each person to their agent and relays. The agent VM has no public port of its own, so the only way in is Maritime's authenticated API. Long tasks do not hold the line open either: the agent acknowledges within a reply budget (20 seconds by default) and sends the final answer through Inkbox when it is done.
How to deploy Open Instinct on Maritime
The agent ships as a container image that follows Maritime's bring-your-own contract: bind 0.0.0.0:$PORT, answer GET /health and POST /chat, keep state under /data. For one person:
export INKBOX_ADMIN_API_KEY=...
export ANTHROPIC_API_KEY=sk-ant-...
export MARITIME_API_KEY=mk_...
pnpm instinct init --name "Maria" --phone +14155550100 --email maria@example.com --handle maria-instinct
pnpm instinct deploy --image ghcr.io/mariagorskikh/open-instinct-agent:latestdeploy creates a custom agent with desktop: true, a health check on /health, and an externalId derived from your handle, and passes your keys in as encrypted secrets. Add --dry-run to print the exact request with the secrets redacted.
For many people, the gateway adds a signup page. Each signup creates an Inkbox identity, mints a key scoped to it, subscribes its webhooks, and provisions a Maritime agent whose externalId is the user's id. Each step is saved as it completes, and the externalId means a retried signup finds the existing agent instead of creating a second billed one. The full walkthrough is in DEPLOY-MARITIME.md, and the provisioning API underneath is documented here.
What you give up
Open Instinct is not affiliated with Instinct, or with OpenInstinct, an unrelated project from Merit Systems.
The takeaway
A personal agent needs three things a chatbot does not: an identity people can text, a computer to do the work on, and a place to keep one person's life that belongs to that person alone. Open Instinct gets the first from Inkbox and the other two from one Maritime microVM per person. Fork it, swap any piece, and run your own.
A personal agent is a person-shaped workload: one identity, one computer, one disk.











