{"slug": "i-built-an-open-source-ai-coworker-that-logs-in-with-2fa-without-the-model-ever", "title": "I built an open-source AI coworker that logs in with 2FA without the model ever seeing your passwords", "summary": "A developer has released Godmode Bot, an open-source (MIT) AI coworker that pairs a real browser with stored logins and 2FA codes while keeping those secrets hidden from the underlying model. Built with Tauri 2 and using Claude Code as its reasoning engine plus browser-use to drive a managed Chromium, it supports macOS, Windows, Linux and headless server deployments, with per-agent git repositories that log every run and can be rolled back. Credentials are injected into pages over CDP via vault_fill_login and vault_fill_totp tools, and the project ships a SECURITY.md threat model and Docker Compose setup.", "body_md": "Every AI agent I tried had the same weak spot: it was great until it reached a login screen. Then it needed a password, a 2FA code, or me.\n\nSo I built **[Godmode Bot](https://github.com/codextde/godmode-bot)**, an open-source (MIT) AI coworker that has a real browser plus your logins and 2FA codes. The model never sees any of those secrets.\n\nGodmode Bot is a desktop app for macOS, Windows and Linux built with Tauri 2. It can also run headless on a server, NAS or Raspberry Pi with a web dashboard. It uses [Claude Code](https://code.claude.com) as the brain and [browser-use](https://github.com/browser-use/browser-use) to drive a managed Chromium.\n\nYou can start with a single chat (\"log into our billing portal and download September's invoice\"), or build a team of persistent agents that each have their own instructions, memory, schedules and history.\n\nThis is the part I spent the most time on.\n\n`vault_fill_login` or `vault_fill_totp`. Godmode types the value into the page over CDP. Getting secrets in is easy too. You can import passwords from Chrome, 1Password, Bitwarden, Apple Passwords or Firefox, and 2FA from a screenshot of a Google Authenticator *export* QR code (multi-account codes work).\n\nEvery agent gets its own repository:\n\n```\n~/.godmode/agents/invoice-collector/\n├── CLAUDE.md                 # identity & instructions\n├── MEMORY.md                 # long-term memory the agent maintains\n├── conversations/<id>.md     # transcripts\n├── runs/2026-09-27/<id>.jsonl# raw event logs (secrets redacted)\n└── workspace/                # files the agent produced\n```\n\nEvery run is committed, so you can see exactly what an agent learned and did, and roll it back.\n\nEach turn runs `claude -p --output-format stream-json` inside the agent's git repo and streams every thought, tool call and screenshot to the UI. A local MCP gateway gives the agent vault tools, delegation tools and `report_missing_login`. You can watch the browser live next to the chat and take control at any point, for example to solve a CAPTCHA.\n\nAgents run Claude Code with bypass permissions, so there are no permission prompts. Treat it like a trusted coworker with access to your machine. For sensitive setups, run it in a VM or container. [SECURITY.md](https://github.com/codextde/godmode-bot/blob/main/SECURITY.md) covers the threat model.\n\n`docker compose up -d` and open I'd love feedback, especially on the vault design and what you'd want agents to do next. A full computer-use VM mode is on the roadmap.", "url": "https://wpnews.pro/news/i-built-an-open-source-ai-coworker-that-logs-in-with-2fa-without-the-model-ever", "canonical_source": "https://dev.to/danielehrhardt/i-built-an-open-source-ai-coworker-that-logs-in-with-2fa-without-the-model-ever-seeing-your-48ep", "published_at": "2026-09-27 22:24:34+00:00", "updated_at": "2026-09-27 22:30:48.084929+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools", "agent-protocols", "ai-products"], "entities": ["Godmode Bot", "Claude Code", "browser-use", "Tauri 2", "Chromium", "1Password", "Bitwarden", "Google Authenticator"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/i-built-an-open-source-ai-coworker-that-logs-in-with-2fa-without-the-model-ever", "markdown": "https://wpnews.pro/news/i-built-an-open-source-ai-coworker-that-logs-in-with-2fa-without-the-model-ever.md", "text": "https://wpnews.pro/news/i-built-an-open-source-ai-coworker-that-logs-in-with-2fa-without-the-model-ever.txt", "jsonld": "https://wpnews.pro/news/i-built-an-open-source-ai-coworker-that-logs-in-with-2fa-without-the-model-ever.jsonld"}}