OpenReplay

openreplay.comcontributed by Samuele Ongaro

YES

Replaceable in one session with an AI coding agent.

Open-source session replay with developer tooling attached: network requests, console output and state changes alongside the recording.

Promptfree, for everyone, and the only version there is
Build me session replay that replaces a hosted OpenReplay: what the user actually saw, with the network and console beside it — and read the privacy section before you record anybody.

Read this first. Session replay records a person using your product: what they typed, where they moved, what was on their screen. It is the most invasive thing in this catalogue, and it is routinely deployed without anybody thinking about that. Build it with masking on by default, a stated retention, and a way for a person to be excluded — or do not build it. A replay tool that captures a password field once has done something you cannot undo.

STACK
- Node 20+ with Fastify for ingestion and the interface
- SQLite through better-sqlite3 for metadata, plain files or an S3-compatible store for the event streams
- rrweb for recording and playback. Do not write a DOM recorder — it is years of edge cases
- Caddy in front

THE DATA MODEL
- sessions: id, project_id, visitor_hash, user_external_id, started_at, ended_at, duration_ms, page_count, event_count, country, device, browser, os, screen_bucket, bytes, has_error, has_rage_click, has_dead_click, is_bot
- pages: id, session_id, path, title, entered_at, left_at, load_ms, largest_contentful_paint_ms
- events_blob: one compressed file per session holding the rrweb stream
- issues: id, session_id, kind, at_ms, detail_json — an error, a rage click, a dead click, a slow response
- network: id, session_id, at_ms, method, url_path, status, duration_ms, request_bytes, response_bytes
- console: id, session_id, at_ms, level, message
- consents: visitor_hash, decision, at — if you are asking, and in many places you must

MASKING, WHICH COMES BEFORE EVERYTHING ELSE
- Mask by default, reveal by exception. The opposite ordering guarantees that something sensitive is captured on the first day
- Every input's value masked unless explicitly allow-listed. Password fields never captured under any configuration — remove the code path entirely rather than making it a setting
- Payment fields, and anything inside an element marked sensitive, replaced with blocks before the event leaves the browser. Masking on the server is too late: the data has already travelled
- Text nodes maskable per selector, so a page showing personal data is recorded as layout without content
- Files, canvases and iframes not captured unless deliberately enabled
- A test page containing a password, a card number and a personal address, run through the recorder, with the stored stream inspected by hand before this goes anywhere near production. Do that every release

RECORDING
- The script is small and lazy: it must not delay the page, and it must stop recording rather than degrade the experience if the browser is struggling
- Sampling: record a percentage of sessions, plus every session that hits an error, which is where the value actually is
- Buffered and sent in batches, compressed, with a cap on bytes per session — an infinite scroll page can produce enormous streams
- Stop after a maximum duration
- Never record a session where the visitor has opted out, and honour do-not-track as an opt-out even though it is unfashionable

WHAT MAKES A REPLAY USEFUL
- The network panel beside the timeline: requests with status and duration, so a stall in the recording lines up with a slow response
- Console output, including errors with stack traces
- Automatic issue detection: rage clicks, dead clicks, a form abandoned after an error, a request that failed. Those markers on the timeline are what turn hours of video into a list worth watching
- Jump to the first issue, and skip inactivity by default
- Speed control, and a keyboard for the whole thing

FINDING SESSIONS
- Filter by everything: page, error, issue kind, duration, country, device, user identifier, custom traits from your application
- Save a filter as a list you return to
- Sessions listed with their issues visible, so the choice of what to watch is informed

RETENTION AND RIGHTS
- A stated retention — days, not months — enforced by a sweeper that actually deletes both metadata and blobs
- Deletion by user identifier, so a request to be erased can be honoured in one command, including from backups' next cycle
- An exclusion list by identifier and by address hash
- Access to replays restricted and audited: every viewing recorded with who watched what. That log is what keeps this tool honest inside your own company
- Every one of these written in your privacy notice in plain words

OPERATIONS
- .env: DATABASE_PATH, BLOB_PATH, BASE_URL, HASH_SALT, SESSION_SECRET, RETENTION_DAYS, SAMPLE_RATE
- Migrations on boot, each once
- Storage is the expensive half: measure bytes per session early and set the sampling rate from that, not from optimism
- Disk watchdog that sheds recording rather than filling the volume
- Health endpoint reporting ingest lag and free space

WHAT MATTERS MOST
Masking and retention. Build mask-by-default, then inspect a real recorded stream by hand for anything you would not want to read aloud. Everything else here is a video player — this is the part where getting it wrong is a breach rather than a bug.

Give me the repository, the recorder configuration, the player, migrations, .env.example, the masking test page, and a README that opens with the privacy position.

What you lose

  • Storage and playback infrastructure for thousands of sessions, which is the expensive half
  • Automatic issue detection for rage clicks and dead clicks
  • A hosted instance kept patched

If you would rather not build

  • Microsoft Clarity, which is free but processes elsewhere

What it costs

read from their page 15 Aug 2026

PlanBilled monthlyBilled yearlyLast read
—$199/mo—15 Aug 2026

Their pricing page is where these came from. Seeing a different price? Tell us.

The escape hatch

open source · no votes, no paid placement

OpenReplay

$0

The product itself, self-hostable with the privacy controls built in.

openreplay/openreplayfree · open source

rrweb

$0

The recording library, if you want only the capture half.

rrweb-io/rrwebfree · open source

Why this verdict

our own opinion · changed only by a person

79/100

Verdict yes at 79 because the software is free. What you take on is storage cost and the obligations that come with holding recordings.

History

tracked since 10 Aug 2026 · nothing is ever overwritten

Interest · last 30 dayspeak 2/day
views01230 Aug4 Sept9 Sept14 Sept19 Sept24 Sept28 Sept
— views— prompt copies none yet— votes none yet

Questions about OpenReplay

answered from the record above

Is OpenReplay free?

No — the plan we track is $199 a month. Dedicated from $199/month, billed hourly, for a managed instance; the software is free to self-host.

Can you replace OpenReplay by building your own?

YES. Replaceable in one session with an AI coding agent. Replacement score 79 out of 100, build time one session. Read what you lose before you decide.

How much does OpenReplay cost?

$199 a month on Cloud — $2,388 a year. Recorded 14 Aug 2026.

What do you lose by replacing OpenReplay?

Storage and playback infrastructure for thousands of sessions, which is the expensive half; Automatic issue detection for rage clicks and dead clicks; A hosted instance kept patched. If any of those carry weight for you, keep paying.

Is there an open-source alternative to OpenReplay?

Yes: OpenReplay, rrweb. The prompt on this page is for when you want it your way instead.

Related entries

same category first, most replaced first

All 36 in Analytics

Not sending yet

Every week, something stops being worth paying for.

New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.

free forever · no tracking pixel · stored here, never passed to anyone

Esc