com.openworker.desktop). This shell also supervises the Python server process.127.0.0.1:8765 on the local machine. It has a default cap of 12 model-tool iterations per task.coworker/, 149 TypeScript/TSX files under surfaces/gui/, and 78 backend test modules OpenWorker does not lock users into a single provider. It supports 30 curated models across multiple categories, all of which require the user to bring their own API key (BYOK) . The supported models include:
One of OpenWorker's key features is its approach to safety. Every tool call an agent makes is classified into one of four risk tiers :
To protect against prompt injection attacks, OpenWorker includes a built-in "ops persona" that instructs the model to treat content from tools, logs, files, and incoming messages as untrusted data rather than instructions. This defense is written directly into the shipped persona configuration .
OpenWorker currently runs on Mac, with Windows support listed as "coming soon" . The project is in open beta and is described as fully usable, with self-updating capabilities
.
OpenWorker is explicitly positioned as a shift from the chatbot model. Instead of prompting a conversation, a user specifies a desired outcome (e.g., "triaged inbox," "polished document," "Slack reply with Q3 numbers," "updated calendar entry"). The agent then breaks that goal into steps, works across local files and connected applications, and pauses for human approval before taking consequential actions . It supports over 25 integrations plus MCP, covering tools like Telegram, GitHub, Slack, Jira, Notion, Linear, HubSpot, Outlook, Gmail, and Google Calendar
.