What ChatGPT agent does
OpenAI started rolling out ChatGPT agent on July 17, 2025, for Pro, Plus and Team users. It combines Operator's ability to click around websites with deep research, and it can use a terminal. (TechCrunch)
How it uses a computer:
- It works in its own isolated environment with a visual browser, a text browser and a terminal. (TechTarget)
- When a site needs a password, the user switches to takeover mode and types it in themselves. (TechTarget)
- It asks permission before consequential actions, such as purchases or sending emails. Users can also turn on watch mode to supervise it. (TechTarget)
On September 29, 2026, OpenAI added Dots: always-on agents in ChatGPT for Pro and Business Premium users. (TechCrunch) Each dot has its own cloud computer, and the user can view it while it works. Users set rules for what a dot does on its own and what needs their approval. (9to5Google)
The pattern
The agent has a computer of its own. The model never handles the password: a person signs in by taking over the screen. Risky steps wait for an explicit yes. To build this into your product, you need a machine per user, a way for the user to watch it and take control, and an approval step in your agent loop.
Build it with the Responses API and Burrowbox
Burrowbox isn't involved with OpenAI. Each Burrowbox machine has an MCP endpoint, and the OpenAI Responses API can call remote MCP servers directly, so the model can drive the machine with no MCP client on your side.
1. Create the machine
curl -X POST https://burrowbox.dev/api/machines \
-H "Authorization: Bearer $BURROWBOX_KEY" -H "Content-Type: application/json" \
-d '{"name": "sam", "size": "tiny", "externalId": "user_42", "ttlMinutes": 60}'
# → { "id": "2f6aeedcd3", "mcpUrl": "https://burrowbox.dev/api/machines/2f6aeedcd3/mcp", "mcpToken": "tmm_…", … }
2. Point the model at the machine's MCP endpoint
Reading tools run without asking. Everything else (clicks, form fills, shell commands) comes back as an approval request.
import OpenAI from "openai";
const openai = new OpenAI();
const machineTool = {
type: "mcp",
server_label: "burrowbox",
server_url: process.env.MCP_URL, // the machine's mcpUrl
authorization: process.env.MCP_TOKEN, // the machine's mcpToken
require_approval: { never: { tool_names: ["browser_navigate", "browser_snapshot", "browser_screenshot", "screenshot"] } },
};
let resp = await openai.responses.create({
model: "gpt-6-astra",
tools: [machineTool],
input: "Find a table for two on Friday at 7pm on example-bookings.com and get it ready to confirm.",
});
3. Ask the user before acting
for (const item of resp.output.filter((o) => o.type === "mcp_approval_request")) {
const ok = await askUser(`Allow ${item.name}(${item.arguments})?`); // your UI
resp = await openai.responses.create({
model: "gpt-6-astra",
tools: [machineTool],
previous_response_id: resp.id,
input: [{ type: "mcp_approval_response", approve: ok, approval_request_id: item.id }],
});
}
console.log(resp.output_text);
This handles one round of approvals. A real loop repeats it until no requests are left.
4. Takeover for logins
When the agent reaches a login page, create an interactive live-view link and show it to the user. They type their password into the machine's browser, and it never goes through the model. Cookies are kept when the machine stops, so they usually only sign in once.
curl -X POST https://burrowbox.dev/api/machines/$MACHINE_ID/live-view \
-H "Authorization: Bearer $BURROWBOX_KEY" -H "Content-Type: application/json" \
-d '{"mode": "browser", "interactive": true, "ttlSeconds": 600, "allowedOrigins": ["https://app.example.com"]}'
# → { "url": "https://burrowbox.dev/embed/2f6aeedcd3?t=…", "iframe": "<iframe …>" }
For a watch mode, create the link with "interactive": false. Input is then blocked on the machine itself, not only in the page. To skip takeover entirely, store the login in the machine's vault, and the agent can use browser_login without seeing it.
5. Always on, like Dots
Set "ttlMinutes": null (PATCH /api/machines/{id}) to keep a machine running, or use a scheduled job with wakeIfStopped and stopAfter so it only runs (and bills) while it has work. A tiny machine costs $0.07 an hour while running. See Billing.
Create an account to try it.
Sources
- TechCrunch, OpenAI launches a general-purpose agent in ChatGPT: https://techcrunch.com/2025/07/17/openai-launches-a-general-purpose-agent-in-chatgpt/
- TechTarget, ChatGPT agent explained: https://www.techtarget.com/whatis/feature/ChatGPT-agents-explained
- TechCrunch, OpenAI launches Dots: https://techcrunch.com/2026/09/29/openai-launches-dots-its-bubbly-agentic-avatar/
- 9to5Google, OpenAI launches Dots: https://9to5google.com/2026/09/29/openai-dots-agent/
- OpenAI docs, MCP and connectors (Responses API): https://developers.openai.com/api/docs/guides/tools-connectors-mcp
- Burrowbox docs: https://burrowbox.dev/docs
Originally published on the Burrowbox blog.
Top comments (0)