Find LinkedIn prospects, draft outreach, and run human-paced campaigns from your AI agent.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Omentir is an open-source alternative to LinkedIn outreach and automation tools like HeyReach and Gojiberry.
It's an AI sales workspace for finding qualified LinkedIn prospects, drafting contextual outreach, running human-paced campaigns, and handling replies β but you own the code and run it on your own infrastructure.
Use the managed product at omentir.com, or self-host the same application code with your own Firebase, Gemini, and Unipile accounts.
One codebase: hosted cloud and self-host share this repo. RUN_LOCALLY=TRUE switches auth, billing, marketing, and hosted-only mail off. Public brand contacts for omentir.com stay in source on purpose (see src/lib/hosted-identity.ts); they are not used for self-hosted operation.
People use Omentir from chat and coding agents without sharing LinkedIn passwords:
https://omentir.com/api/agent/v1/mcp β sign in and approve Connect workspace β enable tools in the chat.Authorization: Bearer <token> to the MCP endpoint or REST /api/agent/v1/*.mode: steal_customers + competitor company URLs). If you have more than one company, ask it to list workspaces and switch.Docs: MCP integration, Agent API, agents.md (machine guide), OpenAPI.
Omentir is self-hostable with external managed services. It is not offline or dependency-free. You provide Firebase/Firestore, Unipile, and either a Gemini API key or a Google Cloud Vertex AI project.
Self-hosting removes the Omentir subscription, but Firebase/Google AI and Unipile can still cost money.
Install Git and either Docker with Docker Compose, or Bun 1.3. Then clone and configure the project:
Open .env and fill in every uncommented blank value. Complete the provider setup below before starting the server.
Generate independent secrets with:
Use that (or a password manager) for at least:
LOCAL_SESSION_SECRET (required)LOCAL_APP_PASSWORD (required unless you explicitly allow open access β see Access control)CRON_SECRET (required unless automation is fully disabled)UNIPILE_WEBHOOK_SECRET (required for reply and relation webhooks)For an initial setup with all automation disabled, leave CRON_SECRET blank and set AUTOMATION_DISABLED=true instead. Keep ENABLE_LIVE_AUTOMATION=false until dry-run output has been reviewed.
Docker is the supported self-hosting path. Omentir runs on amd64 and arm64.
Open http://localhost:3000. Press Ctrl+C to exit the log view without stopping Omentir. Stop the server later with docker compose down.
Port binding: Compose publishes the app as 127.0.0.1:3000:3000 only. That means the container is reachable from the same machine (http://localhost:3000), not from other devices on your LAN or the public internet. This is intentional: a misconfigured or passwordless instance must not become reachable just because Docker started.
To expose the app on a real host (LAN/VPS):
127.0.0.1:3000 (or change the Compose bind only if you understand the risk).APP_BASE_URL to the exact public HTTPS origin (no trailing slash).LOCAL_APP_PASSWORD (do not enable open access on a public URL).For local development:
For a production-style local server:
Open http://localhost:3000. Sign in with LOCAL_APP_PASSWORD unless you opted into open access (see below).
Bun is the package manager and script runner, but bun run dev deliberately starts Next on Node rather than under bun --bun. In dev, Turbopack loads every package in serverExternalPackages (firebase-admin among them) through a hashed specifier such as firebase-admin-<hash>/firestore, which only resolves via a loader hook Next installs in Node. Bun's resolver does not run that hook, so bun --bun next dev fails on the first Firestore import with ResolveMessage: Cannot find module. Production is unaffected: built output emits plain requires, so build and start still run under Bun.
Self-host mode uses a single workspace and a signed, HTTP-only session cookie (omentir_local_session), not Clerk.
| Setting | Behavior |
|---|---|
LOCAL_APP_PASSWORD set (12+ characters, high entropy) | Login form requires that password. This is the default expectation. |
LOCAL_APP_PASSWORD blank and LOCAL_ALLOW_OPEN_ACCESS unset/false | Startup fails. Blank password is no longer enough to run an unprotected instance. |
LOCAL_ALLOW_OPEN_ACCESS=true and blank password | Explicit opt-in: welcome screen with a βContinue to overviewβ button (no password). Use only on a trusted machine / private network. |
LOCAL_ALLOW_OPEN_ACCESS=true and password set | Password is still required (open-access flag does not weaken a configured password). |
LOCAL_SESSION_SECRET | Required always. Minimum 32 characters, high entropy. Used to HMAC-sign session tokens. Changing it invalidates all existing sessions. |
Additional login hardening that matters for operators:
POST /api/local-auth/login only accepts requests whose Origin matches APP_BASE_URL.?next= return path is sanitized so values like //evil.com cannot open-redirect the browser after sign-in. Only same-origin relative paths (starting with a single /) are allowed.HttpOnly, SameSite=Lax, and Secure when APP_BASE_URL is HTTPS.firebase deploy --only firestore:indexes, or create the indexes from Firestore error links. The source is firestore.indexes.json.
firebase deploy --only firestore:rules. Omentir reaches Firestore only through the server-side Admin SDK, so the shipped firestore.rules denies all direct browser/client access. Keep it deployed β it stops anyone from reading or writing your data with a leaked project ID or web API key.GOOGLE_CLOUD_PROJECT, GOOGLE_CLOUD_LOCATION, and GOOGLE_APPLICATION_CREDENTIALS_JSON, enable Vertex AI, and grant the service account Vertex AI User.Copy .env.example to .env. Required local settings are validated at server startup:
| Variable | Scope | Secret | Runtime behavior |
|---|---|---|---|
RUN_LOCALLY=TRUE | local | no | Selects built-in single-workspace authentication |
APP_BASE_URL | shared | no | Canonical server URL; HTTPS required off localhost |
LOCAL_APP_PASSWORD | local | yes* | Required access password unless open access is explicitly allowed; minimum 12 characters when set |
LOCAL_ALLOW_OPEN_ACCESS | local | no | Must be exactly true to allow a passwordless welcome screen |
LOCAL_SESSION_SECRET | local | yes | Independent random value, minimum 32 characters |
LOCAL_USER_NAME / LOCAL_USER_EMAIL | local | no | Display identity for the single local workspace |
FIREBASE_PROJECT_ID | shared | no | Dedicated Firebase project |
FIREBASE_SERVICE_ACCOUNT_KEY | shared | yes | Service-account JSON; malformed JSON fails startup |
UNIPILE_DSN / UNIPILE_API_KEY | shared | mixed | Unipile endpoint and credential |
UNIPILE_WEBHOOK_SECRET | shared | yes | Authenticates reply and relation webhooks |
GEMINI_API_KEY | local/simple | yes | Gemini Developer API path |
| Vertex variables | shared/advanced | yes | Alternative to GEMINI_API_KEY |
CRON_SECRET | shared | yes | Required unless automation is disabled; used by the built-in scheduler and job routes |
ENABLE_LIVE_AUTOMATION | local | no | Live sends remain off unless exactly true |
AUTOMATION_DISABLED | shared | no | Emergency stop; skips scheduler and job execution |
RESEND_API_KEY / RESEND_FROM_EMAIL | optional | yes/mixed | Transactional notifications only in local mode |
ALLOWED_DEV_ORIGINS | dev only | no | Extra hostnames for Next.js HMR when using tunnels/proxies |
* Treat LOCAL_APP_PASSWORD as a secret even though it is typed by a human.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/omentir)<a href="https://allmcps.com/mcp/omentir"><img src="https://allmcps.com/api/badge/omentir?style=directory" alt="Omentir on AllMCPs" /></a>