Admin
Users, tokens, vault entries, site policies and browser settings on this gateway. The admin key manages users; it cannot drive a browser.
Sign in
The admin token is CBU_ADMIN_TOKEN, or the one generated at /data/admin.token in the container (docker exec cbu cat /data/admin.token). It is kept only in this tab's session.
Users
Agents send it as Authorization: Bearer <token> to . Setup snippets: /docs.
| User | Created | Browser | Tabs | Connections |
|---|
Sign-up and email
Access requests
| Received | Who | What they want to build | Status |
|---|
Vault
Select a user above to manage the logins their agent may use. Values are encrypted on the server; nobody can read them back.
| Site | Username | Fields |
|---|
Site policy
Select a user above (Policy) to set what their agent may do per site: read only (no network writes; sensitive actions refused), ask (sensitive actions and writes need a person's approval; with approvals off they run and are audited as would ask) or allowed. Rules are checked in order and the first match wins; a read tab still blocks every write.
| # | Host | Mode |
|---|
Browser
Select a user above (Browser) to set their browser's locale, time zone, location, window size, colour scheme and user agent (for every site, and per site: the first matching row wins and its filled-in fields replace the defaults), and to import cookies from another browser as a saved session.
Empty = not set here (a site row inherits it from the defaults); - = the browser's own value. Location: latitude,longitude[,accuracy m]. Size: 1280x800.
Persistent profile: off by default. Empty hardware and screen fields use the generated identity; a site row inherits defaults. Use - for a native value. Client hints accept UserAgentMetadata JSON and require a user agent. WebGL vendor and renderer must be set together. Paced input defaults to on with the profile. Reload pages after saving.
| Sites | Locale | Time zone | Location | Size | Colours | User agent | Block ads | Profile | CPU threads | Memory GiB | Screen | Platform | Client hints JSON | WebGL vendor | WebGL renderer | Paced input |
|---|
Import cookies
A Cookie-Editor or EditThisCookie export (JSON), a Netscape cookies.txt or a Playwright storageState. It becomes a saved session the user's agent can load; values are encrypted on the server and never shown, here or to the agent.