AGPL-3.0

Self-host: the free engine

Free

Free for one gateway, forever. The commands below install the same engine running across this site. No demo build, no SaaS, nothing calls home.

Download the latest release v8.2.5 published 2026-07-23
All assets & checksums →

Direct one-click downloads. GitHub redirects each link to the latest matching asset. Verify with SHA256SUMS.txt.

Native binary · or embed (auto-detected; click to switch)
Full getting-started guide →
  1. 1.
    Install (Homebrew)
    brew install scottgal/stylobot/stylobot
  2. 2.
    Run (foreground; shows the live CLI detection table)
    stylobot 5080 http://localhost:3000

    Add -d to background as a daemon (no CLI UI). The web dashboard ships in stylobot-all (Docker), stylobot-ui (remote viewer), and the UI SDKs (TypeScript, ASP.NET); see the getting-started guide.

  1. 1.
    Install (Chocolatey or winget)
    choco install stylobot
    winget install Mostlylucid.StyloBot
  2. 2.
    Run (foreground; shows the live CLI detection table)
    stylobot 5080 http://localhost:3000

    Add -d to background as a daemon (no CLI UI). The web dashboard ships in stylobot-all (Docker), stylobot-ui (remote viewer), and the UI SDKs (TypeScript, ASP.NET); see the getting-started guide.

  1. 1.
    Install (apt, Cloudsmith-signed)
    curl -1sLf 'https://dl.cloudsmith.io/public/mostlylucid/stylobot/setup.deb.sh' | sudo bash
    sudo apt update && sudo apt install stylobot
  2. 2.
    Run (foreground; shows the live CLI detection table)
    stylobot 5080 http://localhost:3000

    Add -d to background as a daemon (no CLI UI). The web dashboard ships in stylobot-all (Docker), stylobot-ui (remote viewer), and the UI SDKs (TypeScript, ASP.NET); see the getting-started guide.

  1. 1.
    Add the NuGet package to your ASP.NET Core app
    dotnet add package mostlylucid.botdetection
  2. 2.
    Wire it up in Program.cs
    builder.Services.AddStyloBot();
    app.UseStyloBot();

    Detection runs in-process with no proxy hop. The ASP.NET UI SDK package ships the dashboard view components your app can mount at any route. TypeScript SDK is available for non-.NET frontends; see the getting-started guide.

  1. 1.
    Download from GitHub Releases

    Pick the asset for your platform: stylobot-linux-x64.tar.gz, stylobot-linux-arm64.tar.gz, stylobot-osx-arm64.tar.gz, stylobot-osx-x64.tar.gz, or stylobot-win-x64.zip from the releases page.

  2. 2.
    Verify provenance + extract
    gh attestation verify stylobot-linux-x64.tar.gz --owner scottgal
    tar xzf stylobot-linux-x64.tar.gz && chmod +x ./stylobot
  3. 3.
    Run (foreground; shows the live CLI detection table)
    ./stylobot 5080 http://localhost:3000

    Add -d to background as a daemon (no CLI UI). The web dashboard ships in stylobot-all (Docker), stylobot-ui (remote viewer), and the UI SDKs (TypeScript, ASP.NET); see the getting-started guide.

Docker on any OS
Bundled gateway + dashboard (the free engine in one container)
  1. 1.
    Run
    docker run -p 8080:8080 scottgal/stylobot-all:latest
  2. 2.
    Open the dashboard
    http://localhost:8080/_stylobot

    This is the FOSS engine, no license required. stylobot-gateway ships the proxy-only image; stylobot-sidecar is a 36 MB AOT detector your app calls directly.

What's in the free engine

  • ✓ 49 detectors voting on every request
  • ✓ Local dashboard with read-only config editor
  • ✓ SQLite persistence out of the box
  • ✓ Optional Ollama / LlamaSharp local LLM escalation
  • ✓ TypeScript + ASP.NET dashboard UI SDKs
  • ✓ Zero PII: HMAC-SHA256 hashed signatures
  • ✓ Nothing calls home. AGPL-3.0 licensed.
All install paths →

Paid tiers

Both tiers are self-hosted. No per-request charges. No data leaves your host.

30-day trial Try any version free for 30 days. Tune your policies, export your config, keep what you tuned. Renew, or switch to the FOSS binary against your exported JSON.

Single Site

from £25 / month

Name your price. Cancel any time.

  • ✓ One gateway host
  • ✓ SQLite persistence
  • ✓ Hot-reload config editing
  • ✓ Commercial dashboard surface
  • ✓ ASP.NET, log, and OTel packs
  • ✓ Self-hosted, no per-request charges
Start free trial Why Single Site, and buy →
Good for

One gateway, one site. Single operator or small team who wants the editing surface without Postgres overhead.

Most popular

Startup

£50 / month + £10 / managed domain

Detection is unlimited across every domain. £10/month buys per-domain management; first managed domain included. Cancel any time.

  • ✓ Everything in Single Site
  • ✓ Postgres + pgvector persistence
  • ✓ Detection runs unmetered across every domain, shared reputation pool
  • ✓ Per-domain management: dedicated policy, live editing, dashboard
  • ✓ Control plane + multi-gateway fleet
  • ✓ Self-hosted, no per-request charges
Start free trial Why Startup, and buy →
Good for

Early-stage SaaS or small team. Postgres-backed fleet state, the full config editor, and pack support from day one.

Need Enterprise (SSO, custom packs, multi-region)? Talk to us.

Monitoring packs

Stack-specific bundles, included in the paid tiers.

Included in paid tiers

ASP.NET pack

A commercial pack, included in every paid tier: hot-reload endpoint and policy config plus the live management UI for ASP.NET Core apps. Includes the OTel pack; Traffic Shape pack to follow.

How to add it to an ASP.NET Core app →

See plans
Coming Q3 2026

WordPress pack

Plugin signatures, REST/XML-RPC abuse patterns, login-page rate gates. Built for WordPress installs that face credential stuffing and content scraping.

Coming Q4 2026

Magento pack

Cart-fraud rules, checkout-flow protection, and storefront abuse detection. Built for e-commerce stores dealing with ATO and gift-card fraud.

What's in each tier

Capability Self-host (FOSS) Single Host ($5/mo) Startup ($50/mo)
Detection engine (49 detectors)
Local dashboard (read)
SQLite persistence
Postgres + pgvector persistence--
Hot-reload config editing-
Commercial dashboard surface-
OTel pack--
Traffic Shape pack (coming soon)--
ASP.NET monitoring (read)
ASP.NET monitoring (live management)-packpack
WordPress pack (Q3 2026)-packpack
Magento pack (Q4 2026)-packpack
Supportcommunityemailemail

FAQ

What's in FOSS vs paid?
The engine and the dashboard read are in FOSS. Hot-reload writes, fleet management, compliance, and packs are paid. See /open-source for the full FOSS feature list and the comparison table above.
Does the £10/domain limit which sites are protected?
No. Detection has no domain limit on any tier: run Stylo.Bot across as many domains as you like and every one is protected, sharing one reputation pool. The £10/month buys per-domain management, a dedicated dashboard and policy for that domain. Domains you haven't added stay protected by the shared pool; they just don't get their own dashboard.
How do packs work?
Packs are stack-specific bundles of detectors, policies, and live-management UI. The ASP.NET pack read side ships in FOSS; the paid tier unlocks live management. New stacks ship as full packs: WordPress (Q3 2026), Magento (Q4 2026), Umbraco to follow.
What if my license expires?
When the JWT expires, the licensed binary flips itself into FOSS mode: it exports your current config to JSON, switches to SQLite local writes, disables the hot-reload management endpoints, and keeps serving traffic via the FOSS detection engine. Renew to bring the paid stores back on the next restart, or drop the plain FOSS stylobot binary in against the exported JSON. Nothing is blocked because of an expired license.
Can I trial it, tune it, and then run FOSS?
Yes, that's a deliberate path. Take the 30-day trial. Use the hot-reload config editor to tune your policies and detector thresholds against your real traffic. Export the result. When the trial JWT runs out, the binary flips into FOSS mode against the same config and keeps running. For a small operator who needs the paid tools to dial things in but doesn't need ongoing fleet management or compliance reporting, that's the right fit.
How is the paid version delivered?
Every license + pack buys a specific AOT-compiled binary built with the features you bought. No dynamic plugin loading, no FOSS binary that "unlocks" from a key file. The sidecar is 36 MB. Paid features never live in the FOSS code path, which is how the FOSS engine stays free and the paid features stay licensed.
Detected on this site, right now
R LIVE
Total: Bots: Humans:
Dashboard