TL;DR

dots (feder-cr/dots) is an MIT-licensed, self-hosted web agent that pairs any OpenRouter model with a Firefox build patched at the C++ level so that anti-bot systems see a normal person, not automation. It was pushed to GitHub at 23:06 UTC on September 29, 2026, the same day OpenAI announced its own “dots” at DevDay, and the README’s last line reads “Not affiliated with OpenAI.” Three days later it has 2,415 stars and 421 forks.

The thing to understand before you star it: dots is not a new project. The entire repository is a 20-line cli.py and a pyproject.toml that pins one dependency, invisible-playwright-mcp==0.70.2. The pyproject says so in capital letters: “THE WHOLE PRODUCT IS THIS LINE.” dots is invisible-playwright-mcp ui under a shorter name. The browser, the agent loop, the web UI and the MCP server all live in the sibling repo feder-cr/invisible_playwright_mcp, which is itself the renamed and gutted Auto_Jobs_Applier_AIHawk repository (the viral 2024 LinkedIn job-application bot) and still carries its 31,749 stars.

Verdict: the underlying stealth browser is one of the more serious open-source answers to “my agent keeps getting captchas,” and the MCP server is a genuinely useful drop-in for Playwright MCP prompts. The dots repo itself is a name grab timed to OpenAI’s launch. Install the upstream package by its real name, skip the wrapper, and do not expect it to run on a Mac.

Quick reference

Repogithub.com/feder-cr/dots (wrapper), invisible_playwright_mcp (the actual code)
Stars2,415 (2026-10-02), created 2026-09-29
LicenceMIT (AGPL-3.0 for releases before 2026-09-02)
LanguagePython 3.11+; engine is a patched Firefox (C++), 240-262 MB download, ~550 MB unpacked
PlatformsWindows x86_64, Linux x86_64/arm64; macOS unsupported since late August 2026
Installuvx --from git+https://github.com/feder-cr/dots dots --openrouter-key sk-or-...
Default modelz-ai/glm-5.3-flash on OpenRouter; any OpenRouter id via --model
Web UIhttp://127.0.0.1:8765, no authentication
MCP tools16, names mirror Microsoft’s Playwright MCP, no tab tools
Upstream versioninvisible-playwright-mcp 0.70.2 (PyPI, 2026-09-25)

What dots actually is

The repo’s file tree is README.md, pyproject.toml, LICENSE, a CI workflow, one test file and src/dots/cli.py. The CLI, in full:

"""`dots` is `invisible-playwright-mcp ui`, and nothing else."""
import sys

SUBCOMMAND = "ui"

def main(argv: list[str] | None = None) -> None:
    from invisible_playwright_mcp.cli import main as group
    args = list(sys.argv[1:] if argv is None else argv)
    group(args=[SUBCOMMAND, *args], prog_name="dots")

It routes through the upstream command group rather than the ui command directly so that a .env in the working directory is still read. That is the only design decision in the repo. The dependency is an exact pin (==0.70.2) because the command group is not a public API.

So the honest way to review dots is to review the thing it wraps. The family has three layers:

  1. invisible_core: turns a seed into a coherent fingerprint, Firefox preferences, proxy settings and geolocation.
  2. invisible_playwright: the engine as a Python library. Playwright’s exact API (sync and async) on a Firefox patched at the source, with Bezier-curve mouse motion and trusted input events. Created May 13, 2026; 2,990 stars.
  3. invisible_playwright_mcp: an MCP server over that engine, plus the web UI and agent loop that dots exposes.

The pitch for the browser layer is the same as CloakBrowser’s, just on Firefox instead of Chromium: the fingerprint is decided inside the engine, not painted over with JavaScript a page can inspect. Screen, fonts, GPU, timezone and language agree with each other; --seed returns the same identity every run; there is no WebDriver flag, no DevTools protocol and no automation globals. The pointer travels to what it clicks, keys are pressed one at a time, and with --proxy the timezone and locale follow the exit IP.

The AIHawk inheritance

This matters for anyone judging the project by its star count. github.com/feder-cr/Auto_Jobs_Applier_AIHawk 301-redirects to invisible_playwright_mcp today. The repo was created on August 4, 2024, and its 31,749 stars were earned by a LinkedIn auto-apply bot that hit 81 points on Hacker News in October 2024. Issue #1390 documents the switch: the aihawk PyPI name was deleted on September 23, 2026 to free invisible-playwright-mcp, and 0.70.0 is “the first release under the new name.” The job-applier code is gone.

Nothing about that is hidden, but a 31K-star badge implies a browser-agent community of 31K that does not exist yet. The engine’s 2,990 stars and dots’ 2,415 are the honest numbers.

Setup: Linux in five minutes

You need Python 3.11+, uv, and an OpenRouter key. The wrapper is not on PyPI (that dots name belongs to an unrelated project), so it installs from git:

curl -LsSf https://astral.sh/uv/install.sh | sh
source $HOME/.local/bin/env
uvx --from git+https://github.com/feder-cr/dots dots --openrouter-key sk-or-...

Or skip the wrapper and run the real thing, which is identical:

uvx invisible-playwright-mcp ui --openrouter-key sk-or-...

First start downloads the sealed Firefox build from a GitHub release (262 MB on Linux x64) and verifies its sha256. Then open http://127.0.0.1:8765.

Passing the key as a flag puts it in your shell history and process list; a .env with OPENROUTER_API_KEY in the directory you run from avoids both. Precedence is --flag > environment > .env > default, and only the current directory is read, never parents.

Options that matter

FlagWhat it does
--modelAny OpenRouter model id. Default z-ai/glm-5.3-flash. Also INVISIBLE_MCP_MODEL
--proxyhttp://user:pass@host:8080 or socks5://host:1080. Timezone, locale and egress follow the proxy
--seedInteger. Same seed, same browser identity, every run
--profile-dirPersist logins and cookies across restarts
--headedShow the Firefox window (the UI streams the page anyway)
--binaryUse an engine you already have; must match the pinned build or startup refuses
--host, --portDefault 127.0.0.1:8765. Changing the host exposes an interface with no authentication

The README’s example prompt is a good illustration of what the agent is for:

Go to <URL>. One way, Milan to Lisbon, economy, one adult. Check every date from the 12th to the 16th of next month and read the cheapest fare for each day. If a date has no availability, say so. Do not guess a number.

Airline sites are exactly where a Playwright-with-stealth-plugin agent gets a Cloudflare interstitial on the second request. Whether this one gets through on your target is something you have to test; the project publishes detection-suite results (5/5 suites passed for the engine), not per-site guarantees.

Using the same browser from Claude Code, Codex or Gemini CLI

The web UI is just one client of the MCP server. Any other MCP client can use the browser directly:

# Claude Code
claude plugin marketplace add feder-cr/invisible_playwright_mcp
claude plugin install invisible-playwright-mcp@feder-cr

# Codex
codex plugin marketplace add feder-cr/invisible_playwright_mcp
codex plugin add invisible-playwright-mcp@feder-cr

# Gemini CLI
gemini extensions install https://github.com/feder-cr/invisible_playwright_mcp

Clients that take a config file (Claude Desktop, Cursor, Windsurf, Cline, Zed, VS Code) register uvx invisible-playwright-mcp as a stdio server, with STEALTHFOX_PROXY, STEALTHFOX_SEED and STEALTHFOX_PROFILE_DIR under env.

The server exposes 16 tools (browser_open, browser_navigate, browser_snapshot, browser_read_text, browser_read_html, browser_take_screenshot, browser_watch, browser_click, browser_click_at, browser_type, browser_select_option, browser_press_key, browser_evaluate, plus open/close/list/status). Names mirror Microsoft’s Playwright MCP so existing prompts work, with one departure: there are no tab tools.

Instead of tabs, a session has exactly two browsers. main is the identity: its cookies, fingerprint and logins, persisted so that browser_open with no arguments “brings back the person this session already was.” support is a disposable helper with its own fingerprint for anything that must not touch that identity (a throwaway mailbox for a verification code). It dies with the process. Each browser drives one page; a second tab inside main is the one thing the design exists to prevent.

The wiki’s own warning is worth repeating: “Added is not connected.” Every install command above writes a config entry without running anything, so check claude plugin list or codex mcp list before trusting it.

Community reaction

The reaction so far is star velocity more than discussion. dots went from zero to 2,415 stars between September 29 and October 2, 2026, and was a top GitHub story on The Daily Commit on September 30. There is no Hacker News thread for dots itself; the engine repo got a 20-point, one-comment HN post in May 2026 (“Stealth Firefox that passes every bot detection test”). Reddit search turned up nothing substantial.

The activity that does exist is in the upstream issue tracker, and it is almost entirely the author talking to himself. Of the twenty most recently updated issues on invisible_playwright_mcp, nineteen are opened by feder-cr: an intensely maintained one-person project, not a community. Those issues are informative about where the server is weak today: browser_download (#1404) and browser_upload_files (#1403) do not exist yet, browser_type can report “typed into” before a field has kept the text (#1401, #1405), browser_snapshot does not reach controls inside open shadow roots (#1399), and password-box values leak into snapshots (#1397).

Honest limitations

  • No macOS. The big one for the audience most likely to try an “open-source OpenAI dots.” macOS support was tested in May 2026 (engine issues #5, #7), then removed in late August: issue #89 records “macOS esce” (macOS exits) “consistent with the end of support on the core side,” and #187 dropped the macOS note from the README. A Mac user needs a Linux VM or a remote box.
  • The wrapper adds nothing. dots is a shorter name for invisible-playwright-mcp ui, pinned to one version. If upstream ships a fix, you wait for the pin to move.
  • OpenRouter only for the standalone UI. No direct Anthropic, OpenAI or Ollama path for the standalone agent; over MCP you use whatever model your client runs, which is the cleaner route anyway. A closed issue (#1383) added OrcaRouter as a second provider, so this is loosening.
  • One page per browser, no tabs, max two browsers. Multi-tab comparison workflows become sequential navigation.
  • No file upload or download yet. Both are open feature issues as of October 1, 2026.
  • An unauthenticated local UI. --host 0.0.0.0 exposes a browser that holds your logins to the network with no password.
  • Launch telemetry. Every browser launch fetches a one-line counter file from a GitHub release so the author can count launches. No identifier is sent, but GitHub sees your IP. Nothing goes to the author’s own servers, because there are none.
  • Stealth is a moving target. A detection suite passed in September is not Cloudflare in December, and pinned Firefox builds inherit Firefox’s patch lag.
  • Terms of service. The README’s “Using it responsibly” section is two sentences. Evading bot detection on a site that forbids automation is your problem, not the tool’s.

dots vs the alternatives

dots / invisible_playwright_mcpCloakBrowserOpenAI dotsMicrosoft Playwright MCP
What it isStealth Firefox + MCP server + local agent UIStealth Chromium, Playwright/Puppeteer drop-inHosted always-on agents with cloud computersPlain Chromium over MCP
Runs whereYour Windows/Linux machineYour machine (Win/Linux/macOS)OpenAI’s cloudYour machine
Anti-detectionEngine-level Firefox patches, humanized input87 engine-level Chromium patches, humanize=TrueNot the goal; sites can and do block itNone
ModelAny OpenRouter model (UI) or your MCP client’s modelBring your own agentGPT-6 Astra onlyYour MCP client’s model
PriceFree, MITWrapper MIT; current binary needs a free key for 1 session, paid Pro aboveIncluded with ChatGPT Pro ($100/$200/$500 per month) and Business PremiumFree, Apache-2.0
macOSNoYesN/A (cloud)Yes
TabsNo (main + support browsers)YesYesYes

For a stealth browser in code, CloakBrowser and invisible_playwright are direct competitors; the choice is Chromium vs Firefox and which one currently passes the detector you care about. For a stealth browser in an assistant you already use, invisible_playwright_mcp has the more complete MCP story, with Claude Code and Codex plugin installs CloakBrowser lacks. For an always-on agent that works while you sleep across 4,000 apps, neither open-source project is that; OpenAI’s dots and Meta’s Muse are, and OpenMuse is the closer open-source analogue.

Should you use it?

Use invisible_playwright_mcp (by its real name) if you run Linux or Windows, your agent’s failures are “the page blocked me” rather than “the model got confused,” and you want that browser inside Claude Code, Codex or Cursor with a two-line install. The engine-level approach is the right one and the pace of fixes is high.

Skip dots the repo. It is a redirect with a README, and its name will age badly once OpenAI’s product is what people mean by the word. Do not bother if you are on a Mac, need file uploads, or need multi-tab workflows today.

FAQ

No. OpenAI announced “dots,” always-on GPT-6 Astra agents with their own cloud computers, at DevDay on September 29, 2026. feder-cr pushed the dots repository at 23:06 UTC the same day, describing it as “Open-source dots for the web,” with “Not affiliated with OpenAI” in the README. They share a name and the idea of an agent with its own browser, nothing else: OpenAI’s runs in OpenAI’s cloud on one model; feder-cr’s runs on your machine with any OpenRouter model.

What is the difference between dots, invisible_playwright_mcp and invisible_playwright?

invisible_playwright is the engine: a Firefox patched at the C++ level, exposed through Playwright’s Python API. invisible_playwright_mcp is the MCP server and local web UI built on that engine; it is the renamed Auto_Jobs_Applier_AIHawk repository, which is why it shows 31,749 stars. dots is a 20-line wrapper that runs invisible-playwright-mcp ui under a different name, pinned to version 0.70.2.

Does dots run on macOS?

No. Supported platforms are Windows x86_64 and Linux x86_64 and arm64. macOS was supported in May 2026 and dropped in late August 2026 when the Playwright fork moved into the engine repo (issue #89). Mac users need a Linux VM, a container host or a remote server; the web UI can then be reached over an SSH tunnel.

Which models does dots support?

The standalone web UI accepts any OpenRouter model id through --model or INVISIBLE_MCP_MODEL; the default is z-ai/glm-5.3-flash. Over MCP, the model is whichever one your client (Claude Code, Codex, Gemini CLI, Cursor) is running; the server only provides the browser tools.

Running a browser with a consistent fingerprint is legal in most jurisdictions; what you do with it is governed by the target site’s terms, computer-misuse laws and data-protection rules. The project’s guidance is to read the terms of the sites you point it at, respect rate limits, and never submit anything a human has not read. Automating a site that prohibits automation can get accounts banned regardless of how good the stealth is.

Sources