onionwright
A real browser
that moves like a real person.
Stealth browsers hide the browser. Your agent still moves like a machine. onionwright fixes both halves, so it can run a session unattended and look like someone at a laptop.
co skills add onionwright co browser do "sign in and export last month's invoices"$0.10 per browser-hourSee what it clears
What it clears
The tells that flag an agent, and what each one reads as instead.
| Check | Stock Chrome | onionwright |
|---|---|---|
| navigator.webdrivermeasured | exposed | removed in the engine |
| BotD verdictmeasured | bot | not a bot |
| Sec-CH-UA brand | HeadlessChrome | Google Chrome |
| rebrowser-bot-detectormeasured | 2 checks flagged | 0 flagged |
| bot.sannysoft.commeasured | WebDriver flagged | 0 flagged |
| Mouse and keyboard | instant jumps, even keystrokes | human motor timing |
| Synthetic events | isTrusted = false | trusted over CDP |
Marked rows are measured on the same detector, same flags, one run each. Nothing clears every check, including the products that say they do — the full results, including what it misses.
What a stealth browser leaves out
A stealth browser
Patches the fingerprint so the browser looks ordinary. Everything about how it is used still comes from whoever is driving — which is fine when that is a person with hands.
A browser built to be driven by software
Same engine-level patches, plus the part a person supplies without thinking: curved mouse paths that overshoot and correct, dwell before a click, keystroke intervals that vary by which fingers type them. Your agent gets the behaviour it cannot generate on its own.
navigator.webdriver, the Sec-CH-UA header and the WebGL renderer are decided before any script runs — a driver-side library can only paper over them afterwards. How sites detect automation.
Pricing
Pay for the hours you use. No subscription, no seat count, no minimum.
Pay as you go
$0.10 / browser-hour
8 hours a day is about $18 a month. One concurrent session. Full pricing.
StartEnterprise
More than one at a time
Several browsers in parallel, separate identities, deployment on your own infrastructure. That needs a conversation rather than a checkout, because the answer depends on where you are running it.
See what changesStart now
No dashboard to sign up for. Paste this into whatever AI you already drive — it installs onionwright and hands back a top-up link with your key in it.
Set me up to run OpenOnion's browser, and tell me where I stand. 1. If connectonion isn't installed here, install it (it's a pip package; "co init" creates my account and my key). 2. Run the topup skill: read my balance, tell me roughly how many browser-hours that is at $0.10/hour, and give me a recharge link with my key already in it. 3. If my balance is low or zero, lead with the link. If it's healthy, just tell me and keep the link for later. Don't show me my private key. Don't make me copy my public key by hand — read it for me and put it in the link.
Questions
What is onionwright?
A patched Chromium build plus a humanized input layer. It removes engine-level automation signals no driver-side library can reach, and drives the mouse and keyboard with human motor timing.
How is it different from Playwright or Puppeteer?
It runs underneath them, not instead of them. Playwright drives the browser; onionwright changes what the browser reports and how the input looks. Your existing code works unchanged.
How is it different from patchright or puppeteer-stealth?
Those patch the driver — the only layer they can reach. navigator.webdriver and the Sec-CH-UA header are decided before any script runs, so they are fixed in the engine here.
What does it cost?
$0.10 per browser-hour from your ConnectOnion balance — about $18 a month at eight hours a day. One concurrent session; more is an enterprise conversation.
Does it pass every bot detection test?
No, and neither does anything else. rebrowser-bot-detector, BotD and bot.sannysoft.com all report zero flags on it, where stock Chrome under the same driver is caught by each. What it does not clear is one protocol-level leak from enabling the CDP Runtime domain — no public detector tests for it, and ours is the only harness that sees it. Documented, with the list of what it misses.
Where does it run?
On your machine — a real host has a coherent fingerprint for free, which is the part no software synthesises convincingly. Linux x86-64 today; macOS is next and not built yet, so a Mac cannot install it.