Open Source
Open Source

Open-source Dots: 2,400 stars in three days

A teardown of feder-cr/dots (GitHub API snapshot 2026-10-02): 2,416 stars, 421 forks, MIT-licensed Python, created 2026-09-29 - an open-source isotope that hit escape velocity the day after OpenAI's closed Dots debut. Its core thesis: the model is swappable with one flag, the browser is what the website actually sees. A real Firefox engine patched in C++ decides the fingerprint inside the engine rather than as a page-inspectable JavaScript coat; one seed equals one consistent identity (screen, fonts, GPU, timezone and language agree, reproducibly); nothing for a page to find (no WebDriver flag, no DevTools protocol, no automation globals); the pointer travels before it clicks and keys are pressed one at a time so events arrive trusted; --profile-dir keeps logins across runs; with --proxy the timezone and language follow the exit. Models come from OpenRouter with a one-flag swap, and the companion repo invisible_playwright_mcp exposes the same browser as an MCP server for Claude Code, Codex and Gemini CLI. The README states plainly it is not affiliated with OpenAI. Includes a compliance boundary note: respect target-site terms and local law; no fraud, ticket-scalping or bulk sign-ups.

Published October 2, 20269 min read
<!-- open-dots-browser-agent-resource | open-source | Open-source Dots: 2,400 stars in three days -->

When OpenAI shipped its always-on agent Dots at DevDay 2026 on September 29, the first reaction from much of the community was predictable: another managed service gated behind a subscription tier. The official framing calls Dots a "highly capable, always-on agent," available on Pro and Business Premium in eligible markets, with Enterprise and Edu workspaces needing an admin to switch on a beta. Meanwhile, a repository called feder-cr/dots was quietly created that very same day. GitHub API records show it was created at 2026-09-29T23:06 UTC, just hours after DevDay wrapped. By the 2026-10-02 GitHub API snapshot this article uses, it had pulled 2,416 stars and 421 forks, under an MIT license, written mostly in Python. An open-source version reaching 2,400 stars in three days, the day after the closed-source original launched, is the hardest fact in this story.

One thing to settle first: the two Dots share nothing but a name. The README ends with an explicit declaration: "Not affiliated with OpenAI. MIT licensed." The name collision looks like a well-timed ride on the news cycle, but for users it turns out to be convenient. If you want to understand what an always-on agent of this kind actually looks like, the official version requires a subscription tier; the open-source one starts with a handful of commands and lets you pick the model yourself.

The core thesis: swap the model, but the browser is what the website sees

The README opens with a single line that deserves to be quoted in full: every AI agent is a model and a browser. You can swap the model with one flag. The browser is what the website sees. That sentence is the foundation of the entire project, and the point where it parts ways with the sea of "Playwright with extras" tools.

Unpack the argument. When a web agent fails, the model is rarely why. The page never loaded, a challenge appeared, the login expired, the click did not land. All of that happens in the browser, before the model gets to think. In other words, the ceiling of a web agent is set less by how smart its model is and more by how much its underlying browser resembles the browser a real person uses. The model decides what the agent thinks; the browser decides whether the website treats the agent like a person. Open-source dots bets everything on the second half: it ships with its own browser, and that browser is built to be "the one that does not get blocked."

An engine-level fingerprint is not a JavaScript coat of paint

This is the most interesting technical claim in the project, and worth a careful explanation. The README states it plainly: a real Firefox engine, patched in C++. The fingerprint is decided inside the engine, not painted over with JavaScript that a page can inspect.

Most anti-detection schemes for automated browsers work at the page layer. A Playwright- or Selenium-driven browser launches with a pile of automation flags, and the community's answer is to inject JavaScript that papers over them: rewrite the navigator object, fake the WebGL renderer string, patch the canvas fingerprint. These approaches share a structural weakness. The coat of paint lives in the same page execution environment the page itself runs in, so a detection script can go looking for the seams of the paint. Detection and evasion fight inside one shared sandbox, where each side can reach the other. It is an arms race with no finish line.

Engine-level modification takes a different road. Dots patches the C++ source of Firefox directly, so fingerprint-relevant values, including screen, fonts, GPU, timezone and language, are already a coherent configuration inside the engine. By the time a page's JavaScript reads them, they are facts reported by the engine itself, not a sticker that can be peeled off. The metaphor writes itself: a JavaScript coat of paint is a mask on a face, and an engine-level change is the face itself. A mask can be lifted and checked. This is the precise meaning of "a page cannot detect the paint with JS": it is not that the paint got more convincing, it is that there is no paint at all.

The supporting details read like a checklist of everything detection scripts normally probe. Nothing for a page to find: no WebDriver flag, no DevTools protocol, no automation globals. The input layer is humanized too. The pointer travels to what it clicks, and keys are pressed one at a time, so every event the page receives is a trusted one. "Trusted event" is a formal term in the browser security model: events produced by the operating system's input stack are trusted, while script-synthesized events carry an isTrusted value of false. Dots makes sure the page only ever sees the former.

One identity per seed, one memory per profile

A consistent fingerprint is the passing grade. The harder problem is continuity of identity. Dots handles it with one identity per seed: pass a --seed flag, and screen resolution, font list, GPU model, timezone and language all agree with each other, and the same seed produces the same "person" on every run. This matters more than it sounds. A real user's device fingerprint is stable; the visit today and the visit tomorrow come from the same machine. An agent that shows up with a brand-new random fingerprint every run looks, to a risk engine, like a machine that changes its shell daily. Too clean is itself an anomaly.

Memory comes from --profile-dir, which keeps logins and cookies from one run to the next. The browser has a history: sites you logged into on the first run do not need a second login. Pair it with a proxy and the README's phrase applies: where it connects from is who it is. With --proxy, the timezone and the language follow the exit. An IP in Berlin gets a Berlin timezone and matching language preferences, with none of the telltale mismatches like a European IP paired with a browser clock set to East Asia.

Any model on OpenRouter, one flag away

The model layer is deliberately thin. One line from the README: the model is any model on OpenRouter, and --model changes it. Start it with --openrouter-key, pick whichever provider you like, and token costs flow through your own OpenRouter account. The design is consistent with the project's core thesis. If the model can be swapped with one flag, there is no reason to lock users into any single API. It is also practical: the browser layer runs locally, the model is just the brain, and the brain can change vendors without the body moving. The OpenRouter abstraction has a quiet bonus, too. Harder multi-step planning can run on a flagship model, while simple information extraction can use a cheaper one, with the same browser doing the work either way. For automation that opens pages by the dozen, that flexibility is real money saved.

The companion repo: lending the browser to your CLI agents

Dots on its own is a complete agent with an interface. Start it, open http://127.0.0.1:8765, and you get the conversation on the left and the live browser on the right. But there is a second way to use it. A sibling repository in the same organization, invisible_playwright_mcp, exposes this browser as an MCP server, and the README names Claude Code, Codex, Gemini CLI or any MCP client as consumers. The relationship between the two repos is stated bluntly: dots is its interface. The division of labor is appealing. You may already run a strong CLI coding agent whose weakest link is the browser step. Now that step can be swapped wholesale for the dots engine: the coding agent stays the brain, and the browser belongs to this open-source engine.

License, boundaries, and a dose of cold water

The license holds no surprises. The GitHub API license field reads MIT (2026-10-02 snapshot), the README confirms MIT licensed at the end, and it states clearly that the project is not affiliated with OpenAI. MIT means no extra constraints on commercial use, modification or redistribution, so companies can adapt it into internal tooling without license friction.

One paragraph has to be said plainly. The technical principles of anti-detection browsers like dots are fair game for public discussion. Engine-level fingerprinting and seed-based identity consistency are written in the README itself, and understanding them is valuable for anyone doing web automation, risk engineering or compliance work. But "does not get blocked" is a description of the technology, not a permission slip. Automated access to any third-party website must respect that site's terms of service and local law. This is not a tool for fraud, ticket scalping or mass account registration; automate only accounts you are authorized to use and business that is your own. The technical layer says the detector has a harder time finding you. The legal and contractual layer runs on different rules entirely. Do not blur the two. Treating "never blocked" as an unconditional promise is a mistake whose cost lands on the user, and this note exists so readers do not make it.

Three days and 2,400 stars tells you the demand is real: the bottleneck of web agents genuinely sits at the browser layer, and people voted with their clicks. What the repository still has to prove is engineering staying power beyond the hype, because engine-level patching means tracking Firefox upstream releases for the long haul. For the full command-level walkthrough, watch for the upcoming SOP article on this site. For the broader arc of the computer-use agent wave, see the era overview and the computer-use agents comparison; for how browser automation fits into sandboxing and isolation, read the sandbox isolation comparison. For another take on the self-hosted route, OpenClaw and its gateway-plus-many-entrances design are the opposite pole of dots' single-browser approach.

Back to the question in the headline. An open-source Dots with 2,400 stars in three days: which website task would you run first? Fare comparison is a good starting point, the kind of grinding work where an agent checks every date. The README's own example sends the agent to look up a one-way economy fare from Milan to Lisbon, read the cheapest fare for each day from the 12th to the 16th of next month, say so when a date has no availability, and never guess a number. That example shows exactly where browser-layer capability earns its keep. The hard part is not whether the model can do arithmetic. It is whether the browser can open every page, steadily, and read it correctly.

FAQ

Q1: What is the relationship between open-source dots and OpenAI's official Dots? A1: None. The README ends with "Not affiliated with OpenAI. MIT licensed." The official Dots is the always-on agent announced at DevDay 2026, tied to Pro and Business Premium subscriptions in eligible markets per the official framing. Open-source dots is an independent third-party project that runs self-hosted. The names collide; the code and ownership do not connect.

Q2: How does its anti-detection design differ from Playwright plus an anti-detection plugin? A2: The difference is the layer. Plugin schemes are a JavaScript coat of paint: scripts injected into the page environment cover up automation flags, and a detection script can probe the seams. Dots patches the C++ engine of Firefox directly, so the fingerprint is decided inside the engine and pages receive engine-reported facts with nothing to peel off.

Q3: Which models does it use, and what does it cost? A3: Any model on OpenRouter, switched with --model, started with --openrouter-key. Token costs run through your own OpenRouter account. The repository itself is MIT licensed and free; the cost structure is free software plus self-paid model tokens.

Q4: Can I plug it into Claude Code or Codex? A4: Yes. The sibling repository invisible_playwright_mcp exposes this browser as an MCP server. The README names Claude Code, Codex, Gemini CLI or any MCP client, and describes dots as the interface to that server. Run dots --help for the full list of options.

Q5: What boundaries should I respect when automating with it? A5: Follow the target site's terms of service and local law. Do not use it for fraud, ticket scalping or mass account registration. Automate only accounts you are authorized to access and business that is your own. "Does not get blocked" describes the technology, not a license, and it is not an unconditional promise. The tool is neutral; the responsibility sits with the user.

This article is AI-assisted and human-edited. Last updated: 2026-10-02

FAQ

What is the relationship between open-source dots and OpenAI's official Dots?
None. The README ends with "Not affiliated with OpenAI. MIT licensed." The official Dots is the always-on agent announced at DevDay 2026, tied to Pro and Business Premium subscriptions in eligible markets per the official framing. Open-source dots is an independent third-party project that runs self-hosted. The names collide; the code and ownership do not connect.
How does its anti-detection design differ from Playwright plus an anti-detection plugin?
The difference is the layer. Plugin schemes are a JavaScript coat of paint: scripts injected into the page environment cover up automation flags, and a detection script can probe the seams. Dots patches the C++ engine of Firefox directly, so the fingerprint is decided inside the engine and pages receive engine-reported facts with nothing to peel off.
Which models does it use, and what does it cost?
Any model on OpenRouter, switched with --model, started with --openrouter-key. Token costs run through your own OpenRouter account. The repository itself is MIT licensed and free; the cost structure is free software plus self-paid model tokens.
Can I plug it into Claude Code or Codex?
Yes. The sibling repository invisible_playwright_mcp exposes this browser as an MCP server. The README names Claude Code, Codex, Gemini CLI or any MCP client, and describes dots as the interface to that server. Run dots --help for the full list of options.
What boundaries should I respect when automating with it?
Follow the target site's terms of service and local law. Do not use it for fraud, ticket scalping or mass account registration. Automate only accounts you are authorized to access and business that is your own. "Does not get blocked" describes the technology, not a license, and it is not an unconditional promise. The tool is neutral; the responsibility sits with the user.

Related

Open Source

DeepSeek Harness: A Plugin-Everything Agent Framework

DeepSeek open-sourced its agent orchestration framework DeepSeek Harness (CLI: dsh) on GitHub under MIT, written in TypeScript and built on the Cordis runtime with an "everything-is-a-plugin" architecture that modularly assembles AI pipelines. The repo was created 2026-08-13 and passed 200k stars within ~3 weeks; it is currently 0.1.3-alpha, a developer preview with breaking changes expected (read SAFETY.md first). Launch the Web UI with `npx @deepseek-ai/dsh web` at http://127.0.0.1:3080.

Sep 5, 202610 min read
Open Source

410 TFlops, 95 Percent of Peak: DeepSeek Opens Its Ascend Stack

A repo-by-repo teardown of DeepSeek's Ascend kernel stack (2026-10-01 GitHub API snapshot): TileKernels, 1883 stars, MIT (dozens of TileLang-DSL operators - MoE routing, FP8/FP4 quantization, Engram gating, manifold hyper-connections - with an Ascend backend added 09-30 that auto-selects at runtime, acknowledging Huawei's engineering support); DeepGEMM-Ascend, 418 stars, MIT (fully API-compatible with the main repo, Ascend 950 first release, CANN 9.20 + torch_npu + Python 3.10+, Ascend scaling-factor packing differs from NVIDIA); DeepEP-Ascend, 190 stars (EPBuffer V2.5-compatible, validated on 950DT + CANN 9.2.0 + torch_npu 2.13.0rc1, and - as of the snapshot - no LICENSE file in the repo root, so commercial use awaits clarification); FlashMLA, 13015 stars, MIT (Ascend sparse attention at 410 TFlops / 95% peak prefill and 360 TFlops / 83% decoding, versus 1460/950 TFlops on B200; fused kernel is CUDA-only). Cross-referenced against the NVIDIA-side repos (DeepGEMM 7,907 stars, DeepEP 10,231); treat each repo's LICENSE file as the final license authority.

Oct 1, 20269 min read
Open Source

Step-Code Open Source: StepFun's Terminal Agent at 438 Stars

A fact-check of stepfun-ai/Step-Code (2026-09-27 GitHub API snapshot: 438 stars, 41 forks, TypeScript, license field MIT, created 2026-06-01, pushed 2026-09-26, 44 open issues). A terminal coding agent covering the full task loop of reading code, editing code and running tests; it binds to the Step provider (auto-discovers Step models at login, the opposite of MiniMax Code's BYOK multi-provider route); it supports MCP servers, Agent Skills and multi-agent orchestration out of the box; the /goal command delegates long-horizon tasks; StepPage publishes a local page as a live static site in one command. Vendor-reported figures: Terminal Bench 2.1 pass rate 80.9% tied for first, self-built Multi-Frame benchmark 73.3% on top, lowest average 5.09M tokens — all tagged vendor self-reported and not independently retested.

Sep 27, 20269 min read