All articles
Architecture

Open Instinct: an open-source personal AI agent you text

Open Instinct is an MIT-licensed, open-source alternative to Instinct: a personal AI agent you text on iMessage, running in one Maritime microVM per person.

Maritime Team·October 5, 2026·8 min read

Open Instinct is an open-source, MIT-licensed personal AI agent you text on iMessage, and an alternative to Instinct that you deploy yourself. You send it an iMessage, and it books the dinner, checks you into the flight, or asks your partner's agent when you are both free. It has its own phone number, its own email address, and its own computer. The code is at github.com/mariagorskikh/open-instinct.

Open Instinct, the open-source personal agent you text
Open Instinct, the open-source personal agent you text

We built it as a from-scratch, documented take on Instinct, the closed, invite-only assistant you text. Every person who uses Open Instinct gets their own agent in their own microVM on Maritime, with a Linux desktop the agent can click on. This post is about that part: why one machine per person, and what the machine does.

Illustrative threads from the project README: coordinating a dinner with another person's agent, handing over the screen for a login, and declining a stranger
Illustrative threads from the project README: coordinating a dinner with another person's agent, handing over the screen for a login, and declining a stranger

Five services, each behind one package

The agent is a stack of services, each wrapped in one small package you can swap for something else:

  • Inkbox is the phone company. It gives the agent a phone number, an iMessage line, an email address, and an agent-to-agent endpoint, and it signs every inbound webhook.
  • Pi runs the loop. Model calls, tool calls, sessions. A policy guard sits in front of every tool. The default model is Claude Fable 5.1, and any provider in Pi's catalog works.
  • Composio connects apps. Text "connect my Notion" and the agent sends back an authorization link.
  • Stripe Link pays. For each purchase the agent asks your wallet for a single-use card for the exact amount, and you approve it on your phone. The agent never holds a card.
  • Maritime is where the agent lives. One microVM per person, a desktop inside it, and a disk that survives.
Who does what. Inkbox carries the messages; the loop, the model, the apps, and the wallet all run inside one Maritime microVM per person
Who does what. Inkbox carries the messages; the loop, the model, the apps, and the wallet all run inside one Maritime microVM per person

Why one machine per person

A personal agent is the clearest case we know for one agent per user. Its memory is your life: who your partner is, which seat you like, the dinner you moved twice. It holds access to your email and calendar. It keeps a browser logged into your airline account. None of that should share a process, a disk, or a browser profile with anyone else.

So Open Instinct never multiplexes. Each person's agent runs in its own Firecracker microVM, and everything it knows lives under /data in that VM: config, conversation sessions, contacts and trust tiers, the audit log, secrets. Removing a person means deleting one agent. A bad tool run in one person's agent cannot read another person's mail, because there is no other person on the machine.

Isolation also keeps the trust model simple. Open Instinct sorts everyone who messages you into six tiers, from owner and partner down to friend, contact, and stranger, and enforces them in code before any tool runs. Your partner's agent can read your calendar. A friend's can only ask when you are free. A stranger gets a polite no, and you get a one-line text saying who asked for what. That policy only means something if the data it guards is not sitting next to someone else's.

Six tiers, six keys. The closer someone is to the owner, the more their agent may ask
Six tiers, six keys. The closer someone is to the owner, the more their agent may ask

The tiers matter most when agents talk to each other. Ask for dinner with Sam, and your agent asks Sam's agent through Inkbox, within the key you gave Sam. The two agents do the back-and-forth on their own machines, and each of you gets one question.

Two people, two agents, two machines. The line between them is Inkbox
Two people, two agents, two machines. The line between them is Inkbox
Your agent talks to Sam's agent. Sam holds a friend key: free/busy yes, calendar titles no, no booking without asking
Your agent talks to Sam's agent. Sam holds a friend key: free/busy yes, calendar titles no, no booking without asking

The agent has a computer, not a browser API

Every agent gets a desk: a screen, a keyboard, and files that stay put
Every agent gets a desk: a screen, a keyboard, and files that stay put

Most of what a personal assistant does has no API. Checking in for a flight, holding a table, cancelling a subscription: these happen on websites built for people. Open Instinct creates its Maritime agent with desktop: true, which gives the VM a real Linux desktop with Chromium and a local control service, desktopd, on loopback port 5911. The agent takes screenshots, clicks, and types through it, and reads and writes files on the same machine. Ask for a brief "as a PDF" and it writes one there and texts it to you.

The desktop also handles the moment every agent dreads: the login page. When a site wants a password, a 2FA code, or card details, the agent calls request_takeover and texts you a link. You open the same live desktop from your phone, type the password yourself, hand control back, and the agent carries on. The model never sees the credential. Agents deployed with --no-desktop can fall back to a hosted Maritime Computer over MCP instead.

Payments use the same desktop. The agent fills the cart in its own browser, stops at the final total, and asks Stripe Link for a one-time card for exactly that amount. You approve on your phone, it pays, and the card is dead afterwards. Limits live in a spend policy file: ask above an amount, a daily cap, and things that always need a yes. Without a wallet connected, it hands you the checkout screen instead.

How the agent pays: checkout on its own desktop, a single-use card for the exact total, and your approval first
How the agent pays: checkout on its own desktop, a single-use card for the exact total, and your approval first

How a text reaches a sleeping agent

An agent that waits for texts spends nearly all of its life waiting. On Maritime it does not have to be running for that. After 900 idle seconds (the default, and configurable with --idle) the VM is snapshotted and freed, and its disk and desktop state are kept. The next message wakes it.

The path for one text:

  1. You send an iMessage. Inkbox receives it and posts a signed webhook to the Open Instinct gateway.
  2. The gateway verifies the signature, drops duplicates and delivery receipts, and forwards the event to your agent through Maritime's chat API.
  3. Maritime wakes your VM and posts the event to the agent's /chat.
  4. The agent does the work, replies to you through Inkbox, and sleeps again once it has been idle long enough.

The gateway is one small always-on service for a whole deployment. It holds no conversation state and never sees the model; it maps each person to their agent and relays. The agent VM has no public port of its own, so the only way in is Maritime's authenticated API. Long tasks do not hold the line open either: the agent acknowledges within a reply budget (20 seconds by default) and sends the final answer through Inkbox when it is done.

How to deploy Open Instinct on Maritime

The agent ships as a container image that follows Maritime's bring-your-own contract: bind 0.0.0.0:$PORT, answer GET /health and POST /chat, keep state under /data. For one person:

export INKBOX_ADMIN_API_KEY=...
export ANTHROPIC_API_KEY=sk-ant-...
export MARITIME_API_KEY=mk_...
pnpm instinct init --name "Maria" --phone +14155550100 --email maria@example.com --handle maria-instinct
pnpm instinct deploy --image ghcr.io/mariagorskikh/open-instinct-agent:latest
The instinct command: set up, run, deploy, payments, people and trust, persona, schedules
The instinct command: set up, run, deploy, payments, people and trust, persona, schedules

deploy creates a custom agent with desktop: true, a health check on /health, and an externalId derived from your handle, and passes your keys in as encrypted secrets. Add --dry-run to print the exact request with the secrets redacted.

For many people, the gateway adds a signup page. Each signup creates an Inkbox identity, mints a key scoped to it, subscribes its webhooks, and provisions a Maritime agent whose externalId is the user's id. Each step is saved as it completes, and the externalId means a retried signup finds the existing agent instead of creating a second billed one. The full walkthrough is in DEPLOY-MARITIME.md, and the provisioning API underneath is documented here.

The gateway's signup page. Every signup provisions an identity and a Maritime agent
The gateway's signup page. Every signup provisions an identity and a Maritime agent
The connect page: text one line once, and after that you just talk to your agent
The connect page: text one line once, and after that you just talk to your agent

What you give up

  • A desktop costs more than a chat agent. desktop: true sizes the VM at 4 GiB of memory and 2 vCPU by default. Sleep keeps the idle cost low, but every person still has a floor. The 15-minute idle default is also generous for wakes the agent starts on its own; the math on that is here, and --idle lowers it.
  • There is still a relay. Maritime's signed webhooks verify one signature scheme today, and it is not Inkbox's. Until it is, inbound texts need the gateway, or instinct dev --tunnel on your own machine. The agent already verifies Inkbox signatures itself, so the gateway becomes optional for a single person once the platform supports the scheme.
  • Beta where it touches the real world. The repository runs 909 tests across nine packages, and they pass. The live iMessage path and the Maritime deploy were exercised by hand against real identities, not in CI.
  • No ride or delivery APIs. Rides, food, and reservations go through the agent's own browser, with a takeover for logins and payment.

Open Instinct is not affiliated with Instinct, or with OpenInstinct, an unrelated project from Merit Systems.

The takeaway

A personal agent needs three things a chatbot does not: an identity people can text, a computer to do the work on, and a place to keep one person's life that belongs to that person alone. Open Instinct gets the first from Inkbox and the other two from one Maritime microVM per person. Fork it, swap any piece, and run your own.

Your phone, your agent, its computer
Your phone, your agent, its computer

A personal agent is a person-shaped workload: one identity, one computer, one disk.