Open source error tracking: MIT, Apache 2.0, FSL, Shield
open source error tracking
License first. What counsel signs for a self-hosted error tracker that still takes a Sentry DSN.
On this pageShowHide
"Open source error tracking" is a license question before it is a feature list. Counsel asks what they can ship, modify, and redistribute. Operators ask how many containers they run. Do not mix those answers into one mushy "free and open" line.
What the phrase means here
Open source error tracking on this page means software you can run yourself for exception ingest, with a published license text, that accepts events from an official Sentry SDK after a DSN change, or ships its own SDK. Hosted free quotas are a different column on Best free error tracking. Install shortlists live on Best self-hosted error tracking.
OSI permissive row
MIT and Apache 2.0 are the licenses most SaaS and B2B teams can take without a special exception. GlitchTip is MIT. Epure is Apache 2.0. Both keep a DSN swap path for exceptions. GlitchTip usually runs about four services including Redis or Valkey. Epure runs two Compose services: epure and postgres:16-alpine, with no Redis in the OSS compose. Pick GlitchTip when MIT and Django maturity win. Pick Epure when Apache 2.0 and Postgres-as-default win, and the product you want is grouped exceptions without a suite.
PostHog is also MIT, but the self-host compose is a full analytics stack. It is open source and it is not the same job as a two-container error tracker. Put it on an analytics shortlist, not this one, unless you already live in that product.
Source-available row
Bugsink uses Polyform Shield. You can read the code and self-host. Shield is not an OSI license. It carries a noncompete-style restriction that blocks some commercial uses. That is a counsel call, not a footnote. Telebugs is a paid binary appliance ($299 once per domain on the public page cited elsewhere on this site), not an OSI grant. If the RFP says "OSI-approved," Shield and paid appliances fail the clause even when the ops story is excellent.
FSL and the full suite
Sentry's self-hosted software is under the Functional Source License (FSL), not Apache or MIT. The product is the suite: errors plus tracing, replay, profiling, and the rest of the fleet. Official docs ask for about 16 GB RAM on the full install and document COMPOSE_PROFILES=errors-only for a lighter profile that is still a large compose. FSL is a deliberate license choice. Treat it as such. Read Sentry self-hosted RAM before you size a box, and disclose the errors-only profile when you argue footprint.
Lived counsel conversation
The last time I put Epure in front of counsel, the question was not "does it group stack traces." The question was "can a customer fork this and sell a competing hosted service tomorrow." Apache 2.0 answers that with a clear patent grant and permissive redistribution. MIT answers it for GlitchTip. Shield answers it with a no for some competing uses. FSL answers it with Sentry's own terms. That conversation finished in one meeting when the license table was on the wall. The feature matrix never made it into the room.
Two gotchas show up when teams shop "open source" by GitHub stars alone. First, stars do not encode license class. A popular Shield or FSL repo can look identical to MIT in a roundup table until legal reads the file. Second, "Sentry compatible" on a README often means DSN accept for errors, not OSI status and not full protocol parity. Epure is explicit: partial compatibility for exception events. Replay, tracing, and profiling stay out of the product.
How you try the Apache row
Clone https://github.com/epure-sh/epure, run docker compose up -d, curl http://localhost:8080/health until you see {"status":"ok"}, create a project, copy the DSN, point your official Sentry SDK at it, set sample rates for traces, replay, and profiles to 0, and send one exception. Expect HTTP 202 and an Issues row. Prod overlay: deploy/docker-compose.prod.yml with real passwords and EPURE_PUBLIC_URL. You own backups (pg_dump) and upgrades. That ops work is real. It is the cost of a $0 license.
Limits
Open source is not zero ops. Disk fills. Images need pins. Epure Cloud list prices (Pro $24, Plus $79) are published and Cloud is not live as of 2026-10-05. Self-host is what ships. If you need session replay or distributed tracing as a product, buy or self-host a suite that includes them. If you need OSI and exceptions only, GlitchTip and Epure are the row. Pairwise: vs GlitchTip, vs Bugsink, vs Sentry.
Compare the license table to the ops table
License class does not tell you how many processes wake up at boot. MIT GlitchTip still wants a worker and usually a Redis or Valkey role beside Postgres. Apache Epure wakes two containers. Shield Bugsink can wake one. FSL Sentry wakes a flotilla even when you set COMPOSE_PROFILES=errors-only. Put both tables on the same whiteboard: counsel signs the left column, on-call lives in the right column.
I have seen teams pick MIT because the word felt safer, then spend a weekend learning Celery queues they did not need for exception triage. I have also seen teams reject Apache because they had already standardized on MIT elsewhere, which is a fine policy if it is written down. Write the policy. Then pick the row.
Activation without a second product
If the license row is Apache 2.0 and the ops row is two containers, the try path is Compose, health, DSN, sample rates at 0, one exception, Issues. If the license row is MIT and you already run Django, GlitchTip's docs are the try path. If Shield is signed, Bugsink's one-container path is the try path. Do not start with a feature bake-off that ignores the license file. The bake-off is how shortlists become twins of each other.