ChatGPT Work plugins vs open-source Kortix connectors and automation
ChatGPT Work installs plugins from OpenAI's directory; Kortix is the open-source AI Operating System, where a connector is a declaration in your own repo. Credentials stay server-side, every call is Allow, Ask, or Block, and automation runs on cron and webhook triggers.
The declaration is the deployment
A connector and a trigger, as they appear in kortix.yaml.
connectors: - slug: gmail-read name: Gmail read only provider: pipedream app: gmail authorization_strategy: user policies: - match: search_email action: always_runtriggers: - slug: daily-digest type: cron cron: '0 0 9 * * 1-5' prompt: Summarize yesterday's commits.What a connector is in Kortix
A connector links a Kortix project to an external tool or service, and the agent calls it as a tool inside a session. You declare most connectors in kortix.yaml, or in another YAML file the manifest lists under imports:, and connecting a chat platform or a machine creates its connector for you. The declaration is the deployment: kortix ship commits the manifest and pushes it, so the connector and its policy reach the project with the rest of the configuration. The definition lives in git, while credentials live in the platform and never in the manifest.
ChatGPT Work plugins install into OpenAI's product
In ChatGPT Work, an app connects ChatGPT to a service such as Google Drive or Slack, and a plugin packages one or more apps and skills into an installable workflow (OpenAI's connected apps page). You add a plugin from OpenAI's directory, and the plugin definition belongs to that product. A Kortix connector is a block of YAML in a repo you own, so you can read it, diff it, and move it. The migration guide covers what moves with a project and what an export leaves behind.
Connector credentials are brokered server-side
Connector credentials are brokered server-side and never enter the machine. When an agent calls a connector, Kortix attaches the credential outside the sandbox, checks the agent grant and the connector policy, calls the external API, and returns the result. Secret values never appear in the repo. In ChatGPT Work, an app reaches the information the connected account can already see, and that access stays inside ChatGPT.
Every call is Allow, Ask, or Block
A connector carries policies, a list of match and action pairs that glob tool names. Actions are always_run, require_approval, block, shown as Allow, Ask, Block. Approval holds the call; the agent's turn pauses and resumes. The rule reaches down to the arguments of each call, and approval gates are off until you set them. The governance and permissions page covers the agent grants and the change-request gate behind these settings.
Automation runs on cron and webhook triggers
A trigger starts a session with no person present, and Kortix supports exactly two trigger types: cron and webhook. A cron trigger runs on a schedule you set, and a webhook trigger runs when an external service sends a signed request to the project's webhook URL. You declare triggers in kortix.yaml or an imported file, and the schedule goes live once the change lands on the default branch. Each trigger holds a prompt that renders as the fired session's first message.
Questions about connectors and triggers.
Are Kortix connectors the same as ChatGPT Work plugins?
In ChatGPT Work, an app connects ChatGPT to a service such as Google Drive or Slack, and a plugin packages apps and skills into an installable workflow in OpenAI's directory. In Kortix, a connector is a declaration in kortix.yaml, or in a file the manifest lists under imports:, so the definition lives in a repo you own.
Where do connector credentials live?
Connector credentials are brokered server-side and never enter the machine. Kortix attaches the credential outside the sandbox, checks the agent grant and the connector policy, calls the external API, and returns the result. Secret values never appear in the repo.
Can an agent run on a schedule without a person?
Yes. A trigger starts a session with no person present, and Kortix supports exactly two trigger types: cron and webhook. A cron trigger runs on a schedule you set, and a webhook trigger runs when an external service sends a signed request to the project’s webhook URL.
What happens when an agent calls a tool I have not approved?
It depends on the connector's policy. Actions are always_run, require_approval, block, shown as Allow, Ask, Block. Approval holds the call; the agent's turn pauses and resumes. Approval gates are off until you set them.
Own your connectors and your automation.
Declare them in your repo and run them under policy you set.
Open source · Any model, your keys · Self-host, VPC, or on-prem