chipotlai-max: a meme fork of OpenCode pointed at Chipotle's support bot
The AI coding agent that runs on stolen Chipotle compute 🌯 Fork of OpenCode with Pepper AI as default model. Community project to add providers from Home Depot, Lowes, Target, Starbucks & more.
At a glance
- What is it?
- A TypeScript fork of OpenCode that ships Pepper, Chipotle's IPsoft Amelia support agent, as the default model through a local OpenAI-compatible proxy, with the legal and reliability risks documented in plain language.
- Who is it for?
- chipotlai-max is worth reading as a demonstration of how an agent harness and a model endpoint are separated, not as a tool to adopt. The proxy exposes a plain OpenAI-compatible surface at localhost:3000/v1 with no API key, which means the interesting part is the seam between the two halves: any OpenCode user can point a provider at a local endpoint and get the same behaviour, and the retailer bot table shows how many other endpoints could be wired the same way.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository last received commits 125 days ago.
- What is it written in?
- Mainly TypeScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 20, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What a meme fork of OpenCode actually changed
The starting point is OpenCode, which the README credits as MIT licensed with more than 120,000 stars. On top of that, this fork sets a default provider and model, applies Chipotle brand colours, and repackages the result. That is genuinely the short version of the diff, and it is worth saying so plainly, because the interesting engineering is not in the fork at all.
What OpenCode brings is the agent itself: a terminal interface, a TypeScript monorepo under `packages/`, and the surrounding tooling. The repository tree shows what that costs in surface area: `packages/`, `sdks/`, `specs/`, `patches/`, `infra/`, `nix/`, a `docs/` directory, `AGENTS.md` and `CLAUDE.md` at the root, `sst.config.ts`, `turbo.json`, a `flake.nix`, and a dedicated `chipotle-llm-provider` directory. There is also a `STATS.md`, which is unusual enough to notice.
The root `package.json` makes the toolchain concrete. It is a private ESM package managed by `[email protected]`, with workspaces covering `packages/*`, `packages/console/*`, `packages/sdk/js` and `packages/slack`. Scripts include `dev`, `dev:desktop` for a Tauri build, `dev:web`, `dev:storybook`, `typecheck` through turbo, and a `verify:retail` target that runs `script/verify-retail-providers.cjs` before the provider package's own check. The root `test` script is a deliberate refusal: it prints a message telling you not to run tests from the root and exits non-zero.
So the fork is a configuration and distribution exercise on top of a substantial upstream codebase. Calling it a rewrite would be wrong; calling it a rebrand with a real provider adapter attached would be accurate.
The Pepper proxy is the actual product
The model behind the default configuration is Pepper, the customer support assistant at Chipotle. The README sets out the story: on 12 and 13 March 2026 the bot went viral after users found it could solve LeetCode problems, write Python and reverse a linked list. It runs on IPsoft Amelia, not on a Claude or GPT model, and the README notes it was still live at the time of writing.
The mechanism was built by a different person. The README credits @Gonzih with reverse engineering the Amelia WebSocket, SockJS and STOMP backend and releasing a production ready OpenAI-compatible proxy. That proxy runs locally, exposes `http://localhost:3000/v1`, and needs no API keys. This fork's contribution is to point OpenCode at it.
The shipped configuration is a small table and it is worth reading as a unit:
| Setting | Value | | Provider | `chipotle-pepper` | | Model | `pepper-1` | | Base URL | `http://localhost:3000/v1` | | API Key | `burrito-2026` |
The API key value is the joke and also the point. Anything is accepted because the proxy is a local process that never authenticates upstream. Cost is listed as zero for the same reason, which is also why the risk list exists. The upstream architecture described in `chipotle-llm-provider/src/` is an Express server, a WebSocket client and an OpenAI-compatible `/v1/chat/completions` endpoint, which is a clean separation: the agent side never learns it is talking to a restaurant chatbot.
Running it takes bun, a submodule and a shell script
Setup is short and the recursive clone flag is not optional, because the provider lives in a submodule or submodule-style directory with its own package lifecycle:
git clone --recursive https://github.com/cyberpapiii/chipotlai-max.git
cd chipotlai-max
bun install
./start-chipotlai.shThe manual path exists for people who want the two halves in separate terminals:
cd chipotle-llm-provider && npm install && npm run dev
bun run devNote the split toolchains. The agent side runs on bun, and the root `package.json` pins `packageManager` to `[email protected]` with a `bun.lock` and a `bunfig.toml` alongside it. The provider package uses npm. That is a small friction point: two install paths, two lockfiles, and no single command that guarantees both are in sync.
A few other details suggest a real working setup rather than a static page. There is a `.husky/` directory wired to the `prepare` script, `.editorconfig` and `.prettierignore` for formatting, `.zed/` and `.vscode/` for editor configuration, `.signpath/` which points at code signing, and `install` as an executable at the root. The `dev:desktop` script runs Tauri, so a desktop shell exists alongside the terminal interface. Whether any of that is documented well enough to use is another matter, since the README covers installation and configuration and then stops.
Why every retailer chatbot is on the wanted list
The contribution section is the most sustained part of the README, and its framing is blunt: Chipotle patched Pepper, so the project wants help with other retailers. The status table tracks seven brands and, unusually, records what is actually finished. Only Chipotle is listed as built in. Home Depot's Magic Apron beta is wired as `magic-apron-1` with public widget assets found but still needing an authorized adapter endpoint. Sephora's AI Beauty Chat is `beauty-chat-1`, with the page described as access controlled from the authoring environment. Nordstrom's Rosie is `rosie-1` on Sierra, Lowe's Mylow is `mylow-1`, IKEA's Billie is `billie-1`, and Expedia's Virtual Agent is `virtual-agent-1`. All four of those need the same missing piece: an authorized adapter endpoint.
The contribution rules are specific in a way that suggests the project has already made one set of mistakes and does not want repeats. Step three asks for an authorized OpenAI-compatible proxy for the bot adapter and says explicitly not to hardcode browser cookies or one-time guest tokens. A pull request needs adapter notes and verification. The `verify:retail` script in the root `package.json` exists to check this, which is the kind of small piece of tooling that separates a project collecting contributions from a project collecting screenshots.
That gap between wired and working is the honest headline of the table. Six of the seven entries are stubs pointing at an endpoint nobody has authorization for, and the README does not pretend otherwise.
The reliability and legal caveats stated without hedging
The README has a short section on risks and legal position, and it is worth reproducing rather than paraphrasing. The project reverse engineers Chipotle's production support bot, and a terms of service violation is called likely. The proxy can break at any time, with the note that a Chipotle patch ends it. Sessions are rate limited through an anonymous pool with `MAX_POOL_SIZE=5`. The stated purpose is educational and for jokes, with an explicit instruction not to use it on production codebases.
The refusal to hedge is the most useful thing here. A reader is told, before anything else, that this is not a supported inference endpoint and that its lifetime is bounded by someone else's patch schedule. There is also a `SECURITY.md` at the root, which is a reasonable signal in the opposite direction: a project that expects to be reported on takes reporting seriously even when the underlying premise is a joke.
What the repository does not offer is any release history at all. There are no published releases, no version tags, and no changelog, so the only reliable record of change is commit history on the default branch, which is `master`. The last push recorded for the project is 2026-06-03. For a fork whose upstream is moving quickly, that gap between an actively referenced upstream and a pinned mirror is worth checking before you rely on anything.
Editorial conclusion
chipotlai-max is worth reading as a demonstration of how an agent harness and a model endpoint are separated, not as a tool to adopt. The proxy exposes a plain OpenAI-compatible surface at localhost:3000/v1 with no API key, which means the interesting part is the seam between the two halves: any OpenCode user can point a provider at a local endpoint and get the same behaviour, and the retailer bot table shows how many other endpoints could be wired the same way. The README is unusually direct about the downside, including a likely terms of service violation and a proxy that can stop working when the upstream vendor patches, and it says plainly not to use it on production codebases. Start with `bun install` and `./start-chipotlai.sh` if you want to see the wiring, and read the adapter notes in `chipotle-llm-provider/src/` before judging whether the pattern transfers.
Frequently asked questions
What AI does Chipotle use?
Chipotle's Pepper assistant runs on IPsoft Amelia. This project's README states explicitly that it is not Claude and not GPT, and that the bot went viral in March 2026 after users found it could write Python and solve LeetCode problems.
Is Chipotle's bot written in Python?
Not according to this project. Pepper is built on IPsoft Amelia and communicates over WebSocket, SockJS and STOMP, which the proxy reverse engineered. The bot can write Python, which is a different thing from being written in it.
How do I install chipotlai-max?
Clone the repository recursively, run `bun install`, then start the proxy and CLI with `./start-chipotlai.sh`. The recursive flag matters because the `chipotle-llm-provider` package is managed separately with npm.
Which retail chatbots already have providers in chipotlai-max?
Seven brands are tracked: Chipotle Pepper, Home Depot Magic Apron, Sephora AI Beauty Chat, Nordstrom Rosie, Lowe's Mylow, IKEA Billie and Expedia's Virtual Agent. Only Pepper is built in; the rest are wired as model IDs and still need an authorized adapter endpoint.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/cyberpapiii-chipotlai-max)