Software Development

I built an open-source AI coworker that logs in with 2FA without the model ever seeing your passwords

The landscape of artificial intelligence automation has long faced a persistent, frustrating barrier: the login screen. While modern AI agents have grown remarkably proficient at executing complex workflows, writing code, and navigating unstructured data, they inevitably grind to a halt the moment they encounter basic security gates. Requiring usernames, passwords, and multi-factor authentication (2FA) tokens has traditionally meant that human users had to intervene manually, breaking the promise of fully autonomous digital labor.

Addressing this critical vulnerability in agentic workflows, software developer Daniel Ehrhardt has introduced Godmode Bot, an open-source MIT-licensed AI coworker designed to interact with real browsers, handle authentication protocols, and execute tasks without ever exposing sensitive credentials to the underlying large language model.

I built an open-source AI coworker that logs in with 2FA without the model ever seeing your passwords

Bridging the Autonomy Gap in AI Agents

For years, developers experimenting with browser automation and AI agents have had to choose between security and autonomy. If an agent is given direct access to plaintext passwords or API keys to navigate a portal, those credentials risk being leaked, logged, or inadvertently exposed in model context windows and telemetry data. Conversely, withholding credentials renders the agent incapable of performing end-to-end tasks that require authentication, such as downloading monthly invoices, checking enterprise dashboards, or managing cloud infrastructure.

Godmode Bot attempts to solve this architectural paradox through a "fill, don’t reveal" mechanism. Built as a cross-platform desktop application using Tauri 2 for macOS, Windows, and Linux—with headless server support for Raspberry Pi, NAS units, and cloud environments—the software utilizes Claude Code as its core reasoning engine and browser-use to drive a managed instance of Chromium.

Rather than feeding credentials directly to the language model, Godmode Bot manages secrets through a secure local vault. When an automated task requires signing into a platform, the application’s local middleware injects the credentials directly into the browser DOM without the AI model ever perceiving the underlying password or 2FA seed.

See also  Cooley Launches GO Public With OpenAI to Bring AI Into IPO Preparation
I built an open-source AI coworker that logs in with 2FA without the model ever seeing your passwords

Architecture and Secret Management

The underlying philosophy of Godmode Bot centers on strict separation between the AI’s cognitive loop and the execution of sensitive operations. The project supports seamless importing of existing credential stores, allowing users to migrate passwords from mainstream password managers including Chrome, 1Password, Bitwarden, Apple Passwords, and Firefox. Furthermore, multi-factor authentication codes can be imported securely via screenshots of Google Authenticator export QR codes, accommodating multi-account setups without manual entry.

A standout architectural choice in Godmode Bot is its integration with Git repositories. Every autonomous agent instantiated within the application operates out of its own dedicated local repository, typically structured under the user’s home directory (~/.godmode/agents/).

Within this repository structure, an agent maintains several key components:

I built an open-source AI coworker that logs in with 2FA without the model ever seeing your passwords
  • CLAUDE.md: Defines the agent’s specific identity, system prompt, and operating instructions.
  • MEMORY.md: Stores long-term memory acquired across sessions, allowing the agent to refine its execution strategies over time.
  • conversations/<id>.md: Maintains exhaustive transcripts of interactions.
  • runs/<date>/<id>.jsonl: Contains raw, scrubbed event logs where all sensitive data and secrets are thoroughly redacted.
  • workspace/: Acts as a staging directory for files, documents, and data generated during the agent’s execution.

Because every operational run is committed to the local Git repository, users retain complete auditability. Operators can review exactly what an agent learned, examine historical actions, track performance drift, and instantly roll back changes if an agent deviates from expected behavior.

Execution Flow and Human-in-the-Loop Oversight

The operational loop of Godmode Bot is designed for transparency. Each turn of execution runs a command (claude -p --output-format stream-json) directly within the agent’s Git repository. This streams every thought process, tool invocation, and visual screenshot to the user interface in real time.

A local Model Context Protocol (MCP) gateway supplies the agent with specialized tools, including vault interaction capabilities, inter-agent delegation utilities, and a dedicated report_missing_login function. Crucially, users are not forced into a fully hands-off paradigm. Operators can observe the browser automation live alongside the chat interface and seamlessly intervene at any moment—such as taking manual control to solve complex CAPTCHAs or approving ambiguous UI prompts before returning control to the agent.

See also  Confluent Revolutionizes Kafka Schema Management by Decoupling Schema IDs from Message Payloads
I built an open-source AI coworker that logs in with 2FA without the model ever seeing your passwords

Security Model and Industry Implications

As autonomous software agents transition from experimental toys to practical productivity tools, security models have come under intense scrutiny. Ehrhardt has published a detailed threat model via the project’s security documentation, noting an important caveat for prospective users: Godmode Bot executes Claude Code with bypass permissions enabled, meaning traditional confirmation prompts for tool executions are disabled.

Consequently, the developer advises treating Godmode Bot with the same level of trust one would afford a human coworker with direct access to a workstation. For enterprise deployments or highly sensitive environments, best practices dictate running the application inside an isolated virtual machine or containerized infrastructure.

The release of Godmode Bot arrives at a pivotal time for autonomous systems. As organizations increasingly adopt agentic workflows to automate repetitive administrative labor, the ability to securely handle authentication without compromising enterprise credentials remains a primary engineering hurdle. By decoupling credential handling from the large language model’s cognitive context, Godmode Bot offers a compelling blueprint for secure, verifiable browser automation.

I built an open-source AI coworker that logs in with 2FA without the model ever seeing your passwords

Looking ahead, the project roadmap includes the development of a full computer-use virtual machine mode, which would extend the agent’s capabilities beyond the browser into native desktop operating system environments. Source code, documentation, and installation guides are publicly available under the MIT license via the project’s official GitHub repository, with ongoing community feedback steering the development of future vault designs and multi-agent coordination protocols.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Tech Newst
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.