Browser for AI agents
A real browser your AI agent drives.
WebPilot.si gives every user their own persistent browser. Agents drive it over MCP, programs over REST. Logins come from a vault the agent never sees, and when a step needs a person, the agent hands it over and waits.
Running it yourself? Install guide
> browser_open {"url": "en.wikipedia.org/wiki/Web_browser"} opened t1 (read) title: Web browser - Wikipedia - link "History" [ref=e14] - searchbox "Search Wikipedia" [ref=e3] > browser_login {"site": "shop.example"} logged_in · password and code from the vault > browser_handoff {"reason": "captcha"} Your turn: https://api.webpilot.si/handoff/… · waiting for the person to press Done
What you get
Everything an agent needs to use the web like a person
01A real browser that stays
Each person gets their own headed Chromium with a persistent profile. Logins, cookies and history survive between runs and restarts (tabs live while the browser runs), and are never shared with another user.
02Logins the agent never sees
Passwords, card details and authenticator keys live in an encrypted vault. The agent asks for browser_login or fill_secret by name; the values are typed into the page and never returned or logged.
03Hand-offs to a person
When a step needs a human (a CAPTCHA, a code from a phone, an approval) the agent sends a "Your turn" link: the message, the browser live, and a Done button it waits for.
04Live viewer
Watch the browser as the agent works, from any device. Links are short-lived and show one user's browser only; taking over is allowed per user and enforced by the server.
05Run reports and replay
Record a tab and get one self-contained HTML report (every step, its screenshot, network and console errors) plus JUnit XML. Replay the flow later from stored locators, without an LLM.
06Guarded writes
Tabs open read-only unless asked for act. Per-site rules make a bank read-only while a shop stays writable. Every action is in the audit log, and page text is fenced as untrusted data.
How it works
From token to finished run
- Get a tokenAn admin creates your user; the token is shown once. Logins go in the vault (admin console or
cbu vault set). - ConnectPoint your agent at
/mcp, or your code at/v1or the Python or TypeScript SDK. Your browser starts on first use. - Look, act, checkSnapshot the page, act by element ref, confirm with text or a screenshot. Read tabs cannot change anything.
- People step in, runs leave evidenceHand-offs bring a person in for one step. Recordings give a report, JUnit XML and a replayable script.
Three ways in
MCP for agents, REST and SDKs for programs
One service behind all three: the same tabs, vault, policy and limits, whichever door you use.
MCP, for agents
Claude Code, Cursor, Codex, Claude Desktop or any MCP client gets the browser_* tools over Streamable HTTP, with your token.
claude mcp add --transport http webpilot \
https://api.webpilot.si/mcp \
--header "Authorization: Bearer $WEBPILOT_TOKEN"
# Cursor, Codex, Claude Desktop: see /examplesREST API v1
Resources with stable ids, typed errors, idempotent retries and an OpenAPI 3.1 contract. Any language with HTTP.
TAB=$(curl -s -X POST https://api.webpilot.si/v1/tabs \
-H "Authorization: Bearer $WEBPILOT_TOKEN" \
-H "content-type: application/json" \
-d '{"url": "example.com"}' | jq -r .id)
curl -s https://api.webpilot.si/v1/tabs/$TAB/text \
-H "Authorization: Bearer $WEBPILOT_TOKEN"Python and TypeScript SDKs
Typed clients and errors, retries with backoff and logs. pip install webpilot-si · npm install webpilot-si (Node, Deno, Bun, edge).
from webpilot import WebPilot # the token comes from WEBPILOT_TOKEN with WebPilot("https://api.webpilot.si") as wp: tab = wp.open("en.wikipedia.org/wiki/Web_browser") print(tab.snapshot().title) print(tab.read_text()[:300]) tab.close() // TypeScript: the same calls, awaited const tab = await new WebPilot({ baseUrl: "https://api.webpilot.si" }).open("example.com"); console.log((await tab.snapshot()).title);
Examples
Runnable examples
Each runs against your gateway and a small local fixture site (or Wikipedia and example.com). See them all.
- python/read_page.pyOpen a page in a read tab, print its text, headings and links (Wikipedia by default).
- python/vault_login.pyLog in with a vault entry: the password and TOTP never reach your code. Save the session.
- python/handoff.pyHand one step (a 2FA code) to a person with a "Your turn" link and wait until they are done.
- python/record_and_replay.pyRecord a checkout, save the run report and JUnit XML, then replay it without an LLM.
- python/download.pyClick a download link, wait for the file, read its rows and save it locally.
- mcp/claude-desktop.jsonClaude Desktop: claude_desktop_config.json through the mcp-remote bridge.