Back
Open-source AI coworker logs in with 2FA while the model never sees passwords
SiTech AI Team2 წთ. საკითხავი

Open-source AI coworker logs in with 2FA while the model never sees passwords

Developer Daniel Ehrhardt released Godmode Bot, an open-source AI coworker with a real browser and the user's logins and 2FA codes, designed so that the model itself never receives those secrets.

Every AI agent Daniel Ehrhardt tried worked well until it reached a login screen, and then it needed a password, a one-time code or a human. So he built Godmode Bot, an MIT-licensed AI coworker with a real browser plus the user's logins and 2FA codes, while the model itself never sees those secrets. He published it on dev.to on 27 September.

What Godmode Bot is

Godmode Bot is a Tauri 2 desktop app for macOS, Windows and Linux that also runs headless on a server, NAS or Raspberry Pi with a web dashboard. Claude Code is the brain and browser-use drives a managed Chromium. A user can start with one chat request or build a team of persistent agents with their own instructions, memory and schedules.

Godmode Bot logging into a portal with a vault password and a 2FA code

Fill, don't reveal

Logins and TOTP secrets live in a local vault: scrypt, a key-encryption key, a random 256-bit data key and AES-256-GCM per secret.

When an agent reaches a login form it calls a tool such as vault_fill_login or vault_fill_totp, and Godmode types the value into the page over CDP, so the password never enters the model's context. Fills are site-bound, so a phishing or prompt-injected lookalike page gets nothing, and every secret access is written to an audit log.

Passwords can be imported from Chrome, 1Password, Bitwarden, Apple Passwords or Firefox, and 2FA codes from a screenshot of a Google Authenticator export QR code.

Agents are git repositories

Every agent gets its own git repository with CLAUDE.md, MEMORY.md, transcripts, redacted run logs and a workspace folder. Every run is committed, so what an agent learned and did can be inspected and rolled back. Agents can also run on cron routines, delegate tasks to subagents or import a Chrome session.

Limits and availability

Each turn runs claude -p --output-format stream-json in the agent's repository and streams every thought, tool call and screenshot to the UI. The browser can be watched live and taken over, for example to solve a CAPTCHA.

The author is explicit about the trade-off: agents run Claude Code with bypass permissions, so there are no permission prompts. For sensitive setups he advises a VM or a container; SECURITY.md describes the threat model. Desktop builds are in the project's releases, the headless version starts with docker compose up -d on port 7777, and the code is on GitHub at codextde/godmode-bot.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.