Skip to content
Agents tracked: 378 Downloads (7d): 242M down 5.8% GitHub stars: 8.3M VS Code installs: 151M Releases (7d): 389 Agent status: 1 with issues Updated Oct 10, 2026

Obscura by h4ckf0r0day

The headless browser for AI agents and web scraping

Browser and computer-use agents Open source · Apache-2.0Free to start

Recently added on Oct 10, 2026. The description, category and pricing were filled in from public metadata and have not been checked by an editor yet.

Price
Free (OSS)
free and open source
Popularity
#6 in Browser
Gid Score 41 / 100 · #113 of 378 overall
Trend
Gaining stars fast
about +71 GitHub stars a day
Development
Actively updated
latest 0.2.4, 6d ago
Community
28.7K GitHub stars
public signals

What Obscura does

Key facts

Makerh4ckf0r0day
First releasedApril 2026
LicenseApache-2.0
Main languageRust
Open issues and PRs197

Pricing

Open source under the Apache-2.0 licence; check the website for any paid hosted plans.

, checked Oct 10, 2026. Prices change often; confirm before you buy.

Compare prices of all agents

Quick answers

Compare Obscura with another agent

vs
# Agent Gid Score Downloads 7d 7d 30d VS Code installs Stars Latest release Price
25
Browser UseBrowser Use
60 2.2M down 3.2% — — 117K+92/day 0.13.113d ago Free
31
StagehandBrowserbase
59 2.1M down 10.8% up 29.0% — 25.6K+13/day 3.7.343d ago Free + $20/mo
33
Agent BrowserVercel Labs
58 1.7M down 19.9% up 59.8% — 43.7K+44/day 0.39.0yesterday Free (OSS)
72
ARTEMIS NewGoogle
48 — — — — 11.2K+52/day — Free (OSS)
79 46 — — — — 8,521+68/day 0.3.210d ago Free (OSS)
125 39 — — — — 26.4K+6/day — Free (OSS)

Ratings from people who use Obscura

No ratings yet. Used Obscura? Rate it and say what it is good and bad at.

Obscura news

All AI agent news

  1. New on AgentGid AgentGid

    74 agents added to AgentGid

    Symphony, OpenShell, Codex Security, NemoClaw, Agent Browser, Opensre, Caveman, Brag, Open Code Review, Understand-Anything, Codegraph, BrowserSkill and 62 more

  2. Release GitHub Releases

    Obscura 0.2.4 released

    This release focuses on automation reliability, browser compatibility, and reducing unnecessary engine work. It fixes frame teardown crashes, adds recovery for failed CDP workers, improves input…; • Frame teardown no longer crashes under garbage collection…

What changed: recent Obscura releases

6 stable releases in the last 90 days · Full changelog

0.2.4
  • This release focuses on automation reliability, browser compatibility, and reducing unnecessary engine work. It fixes frame teardown crashes, adds recovery for failed CDP workers, improves input…
  • • Frame teardown no longer crashes under garbage collection. Borrowed iframe contexts are cleaned up safely when their isolate is destroyed, fixing process aborts during page closure (\#1197). •…
  • • Teredo addresses containing a forbidden IPv4 destination are rejected by the SSRF gate (\#1098). • The standalone renderer HTTP loader applies the same private-network restrictions as page…
  • • Network events reach observer sessions, including intercepted requests, without losing their target routing (\#1128, \#1194). • Worker navigation responses expose the final HTTP status. Blocked…
  • • Fetch resolves when response headers are available rather than waiting for the complete buffered body (\#1146). • Fetch and XHR cancellation stop native request work and release…
  • • Unchanged pages reuse retained rendering work, and transform measurement avoids repeated layout churn (\#1111, \#1110). • Native controls inherit font shorthand correctly and retain their…
0.2.3
  • Security, concurrency, and browser compatibility are the focus of this release. The JavaScript engine has been updated, exposed CDP and MCP servers now have built-in authentication, concurrent…
  • • CDP and MCP now protect exposed control ports. Non-loopback binds require a bearer token of at least 32 bytes. Browser-origin requests and invalid Host headers are rejected, request sizes and…
  • • CDP supports OBSCURACDPTOKEN; MCP HTTP supports OBSCURAMCPTOKEN. Non-loopback binds are refused without a sufficiently long token. • CDP rejects browser-origin requests and DNS-rebinding-style…
  • • Concurrent pages on one connection retain independent JavaScript heaps and object handles (#872). • Browser attachment sessions are unique and detach independently (#978). • Client state is…
  • • Render resources use the owning page transport, preserving proxy, stealth, headers, cookies, interception, SSRF checks, and request accounting (#890). • CORS validates preflight permissions and…
  • • Font databases are cached across documents, reducing repeated startup and discovery work (#879). • Repeated text runs reuse bounded shaping templates, and table column measurement avoids…
0.2.2
  • A wide compatibility and robustness pass: generated CDP clients (chromiumoxide, spider) now work end to end, Playwright form filling and context setup complete, one page script can no longer…
  • • Generated CDP clients work. Page.enable emits the initial load sequence once per page with a schema-complete frame, so chromiumoxide's newpage no longer hangs before the first navigation and its…
  • • Runtime.evaluate and callFunctionOn report thrown or rejected values through exceptionDetails, the field clients rebuild page errors from (#746). • Execution contexts are owned by their session,…
  • • The SSRF deny-set covers IPv6 embedded-IPv4 (6to4/NAT64), CGNAT, and IANA special-purpose ranges, and the stealth client applies the same DNS guard and honors --allow-private-network (#810,…
  • • Text inputs paint their value, and textarea lays out as a real control box (#685). • The screenshot warmup fetches only the font sources the renderer will use, not every entry in a src list…
  • • postMessage honors targetOrigin, stopping cross-origin leaks between frames (#704). • HTMLInputElement.indeterminate is implemented, and label activation clicks the associated control (#732). •…
0.2.1
  • Child frames now run their own scripts and talk to the parent page, MCP keeps driving the page between tool calls, and rendering, CDP, and stealth all gained fidelity and consistency fixes. 122…
  • • iframes run their own scripts. Child frames get their own V8 realm, a page can reach into its same-origin frames, postMessage flows between a page and its frames, and CDP reports the real child…
  • • Runtime.bindingCalled is delivered to the session that subscribed. • Input.insertText embeds text as a JSON literal, so text with newlines or quotes is inserted instead of dropped. •…
  • • DOMParser produces a <parsererror> document for malformed XML mime types, matching Chrome's signal. • Document.createEvent rejects unknown interface names (#610), and DOMStringMap is exposed…
  • • Runtime.removeBinding validates binding names, closing a JS injection path into the page (#578). • DOM.setFileInputFiles is gated behind --allow-file-access, matching the file:// navigation…
  • • New tools/live-view.mjs watches agent sessions live with target-following and adaptive pacing, with a guide under docs/. • Cross-compilation builds generate the V8 snapshot with the…
0.2.0
  • Native rendering: block and inline layout, Flexbox, Grid, tables, floats, positioning, scrolling, transforms, text shaping, images, SVG, Canvas, forms, gradients, shadows, and animations.
  • Modern websites: external stylesheets, JavaScript modules, dynamic imports, hydration, responsive images, web fonts, observers, Shadow DOM, and custom elements.
  • Screenshots: viewport, clipped, scrolled, and full-page capture with PNG, JPEG, and WebP output through CDP.
  • Screencasting: activity-driven PNG or JPEG frames with sizing, quality controls, acknowledgement backpressure, and isolated CDP sessions.
  • PDF export: print styles, pagination, paper sizes, margins, scale, landscape mode, backgrounds, page ranges, and streamed output.
  • React-controlled form filling through MCP
0.1.11
  • CDP sessions are now isolated and safe to run concurrently, DOM traversal and template handling are substantially more browser-compatible, sequential embedded Browser sessions no longer share…
  • • Concurrent CDP sessions no longer share V8 state. Each connection owns its runtime and browser context, preventing cross-isolate aborts and stopping cookies, headers, targets, and User-Agent…
  • • CDP WebSocket responses can use frames up to 64 MiB (#405). • DOM.getDocument depth is bounded so deeply nested pages cannot crash a worker (#396). • Client-controlled log previews are truncated…
  • • structuredClone now preserves CryptoKey objects, ArrayBuffers and typed-array views, cyclic graphs, Error.cause, and own proto properties (#390, #421, #425). • HTMLFormElement.submit() bypasses…
  • • Dynamically inserted external scripts receive a bounded settle window so direct and nested script chains can finish and dispatch load (#477). • Template serialization reads template metadata by…
  • • SSE keep-alive streams run independently and no longer block every later MCP request (#493). • MCP request lines, headers, and bodies share a bounded read deadline, preventing stalled or…

Obscura popularity and usage data

The GitHub repository has 28.7K stars, 2,184 of them added in the last 30 days. The latest stable release is 0.2.4, published Oct 4, 2026; there were 2 stable releases in the past 30 days.

GitHub starsrunning total 28.7K

Download the raw daily series: obscura.csv

Gid Score breakdown

Adoption—
Community61
Attention—
Momentum54

Each component is scored 0 to 100 from public signals; a dash means no data for it. Methodology.

Obscura FAQ

How much does Obscura cost?

Open source under the Apache-2.0 licence; check the website for any paid hosted plans.

Is Obscura open source?

Yes. Obscura is open source, released under the Apache-2.0 license.

How popular is Obscura?

The GitHub repository has 28.7K stars, 2,184 of them added in the last 30 days. The latest stable release is 0.2.4, published Oct 4, 2026; there were 2 stable releases in the past 30 days.

What is the latest version of Obscura?

The latest stable release we track is 0.2.4, published on Oct 4, 2026.

What are the alternatives to Obscura?

The closest alternatives in the same category by Gid Score are Browser Use, Stagehand, Agent Browser, ARTEMIS.

For the makers of Obscura badges, corrections

Add a live badge to your README or site:

AgentGid: #6 in Browser Gid Score: 41/100

[![AgentGid: #6 in Browser](https://agentgid.com/badges/obscura-rank.svg)](https://agentgid.com/agents/obscura/)
[![Gid Score: 41/100](https://agentgid.com/badges/obscura-score.svg)](https://agentgid.com/agents/obscura/)

Something wrong or outdated on this page? Send a correction with a link to the official source. More for makers.

Where these numbers come from

GitHub: h4ckf0r0day/obscura. Site rank: obscura.sh on the Tranco list. See data sources for how each one is collected.

Product facts and pricing were checked against: obscura.sh, github.com.