Open-source session replay with developer tooling attached: network requests, console output and state changes alongside the recording.
Build me session replay that replaces a hosted OpenReplay: what the user actually saw, with the network and console beside it — and read the privacy section before you record anybody. Read this first. Session replay records a person using your product: what they typed, where they moved, what was on their screen. It is the most invasive thing in this catalogue, and it is routinely deployed without anybody thinking about that. Build it with masking on by default, a stated retention, and a way for a person to be excluded — or do not build it. A replay tool that captures a password field once has done something you cannot undo. STACK - Node 20+ with Fastify for ingestion and the interface - SQLite through better-sqlite3 for metadata, plain files or an S3-compatible store for the event streams - rrweb for recording and playback. Do not write a DOM recorder — it is years of edge cases - Caddy in front THE DATA MODEL - sessions: id, project_id, visitor_hash, user_external_id, started_at, ended_at, duration_ms, page_count, event_count, country, device, browser, os, screen_bucket, bytes, has_error, has_rage_click, has_dead_click, is_bot - pages: id, session_id, path, title, entered_at, left_at, load_ms, largest_contentful_paint_ms - events_blob: one compressed file per session holding the rrweb stream - issues: id, session_id, kind, at_ms, detail_json — an error, a rage click, a dead click, a slow response - network: id, session_id, at_ms, method, url_path, status, duration_ms, request_bytes, response_bytes - console: id, session_id, at_ms, level, message - consents: visitor_hash, decision, at — if you are asking, and in many places you must MASKING, WHICH COMES BEFORE EVERYTHING ELSE - Mask by default, reveal by exception. The opposite ordering guarantees that something sensitive is captured on the first day - Every input's value masked unless explicitly allow-listed. Password fields never captured under any configuration — remove the code path entirely rather than making it a setting - Payment fields, and anything inside an element marked sensitive, replaced with blocks before the event leaves the browser. Masking on the server is too late: the data has already travelled - Text nodes maskable per selector, so a page showing personal data is recorded as layout without content - Files, canvases and iframes not captured unless deliberately enabled - A test page containing a password, a card number and a personal address, run through the recorder, with the stored stream inspected by hand before this goes anywhere near production. Do that every release RECORDING - The script is small and lazy: it must not delay the page, and it must stop recording rather than degrade the experience if the browser is struggling - Sampling: record a percentage of sessions, plus every session that hits an error, which is where the value actually is - Buffered and sent in batches, compressed, with a cap on bytes per session — an infinite scroll page can produce enormous streams - Stop after a maximum duration - Never record a session where the visitor has opted out, and honour do-not-track as an opt-out even though it is unfashionable WHAT MAKES A REPLAY USEFUL - The network panel beside the timeline: requests with status and duration, so a stall in the recording lines up with a slow response - Console output, including errors with stack traces - Automatic issue detection: rage clicks, dead clicks, a form abandoned after an error, a request that failed. Those markers on the timeline are what turn hours of video into a list worth watching - Jump to the first issue, and skip inactivity by default - Speed control, and a keyboard for the whole thing FINDING SESSIONS - Filter by everything: page, error, issue kind, duration, country, device, user identifier, custom traits from your application - Save a filter as a list you return to - Sessions listed with their issues visible, so the choice of what to watch is informed RETENTION AND RIGHTS - A stated retention — days, not months — enforced by a sweeper that actually deletes both metadata and blobs - Deletion by user identifier, so a request to be erased can be honoured in one command, including from backups' next cycle - An exclusion list by identifier and by address hash - Access to replays restricted and audited: every viewing recorded with who watched what. That log is what keeps this tool honest inside your own company - Every one of these written in your privacy notice in plain words OPERATIONS - .env: DATABASE_PATH, BLOB_PATH, BASE_URL, HASH_SALT, SESSION_SECRET, RETENTION_DAYS, SAMPLE_RATE - Migrations on boot, each once - Storage is the expensive half: measure bytes per session early and set the sampling rate from that, not from optimism - Disk watchdog that sheds recording rather than filling the volume - Health endpoint reporting ingest lag and free space WHAT MATTERS MOST Masking and retention. Build mask-by-default, then inspect a real recorded stream by hand for anything you would not want to read aloud. Everything else here is a video player — this is the part where getting it wrong is a breach rather than a bug. Give me the repository, the recorder configuration, the player, migrations, .env.example, the masking test page, and a README that opens with the privacy position.
What you lose
- Storage and playback infrastructure for thousands of sessions, which is the expensive half
- Automatic issue detection for rage clicks and dead clicks
- A hosted instance kept patched
If you would rather not build
- Microsoft Clarity, which is free but processes elsewhere
What it costs
read from their page 15 Aug 2026
| Plan | Billed monthly | Billed yearly | Last read |
|---|---|---|---|
| — | $199/mo | — | 15 Aug 2026 |
Their pricing page is where these came from. Seeing a different price? Tell us.
The escape hatch
open source · no votes, no paid placement
OpenReplay
$0The product itself, self-hostable with the privacy controls built in.
openreplay/openreplayfree · open source
Why this verdict
our own opinion · changed only by a person
79/100
Verdict yes at 79 because the software is free. What you take on is storage cost and the obligations that come with holding recordings.
History
tracked since 10 Aug 2026 · nothing is ever overwritten
Questions about OpenReplay
answered from the record above
Is OpenReplay free?
No — the plan we track is $199 a month. Dedicated from $199/month, billed hourly, for a managed instance; the software is free to self-host.
Can you replace OpenReplay by building your own?
YES. Replaceable in one session with an AI coding agent. Replacement score 79 out of 100, build time one session. Read what you lose before you decide.
How much does OpenReplay cost?
$199 a month on Cloud — $2,388 a year. Recorded 14 Aug 2026.
What do you lose by replacing OpenReplay?
Storage and playback infrastructure for thousands of sessions, which is the expensive half; Automatic issue detection for rage clicks and dead clicks; A hosted instance kept patched. If any of those carry weight for you, keep paying.
Is there an open-source alternative to OpenReplay?
Yes: OpenReplay, rrweb. The prompt on this page is for when you want it your way instead.
Related entries
same category first, most replaced first
Every week, something stops being worth paying for.
New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.
free forever · no tracking pixel · stored here, never passed to anyone

