Give your agent a real Chromium browser to open sites, sign in, fill forms, and download files. Watch it live, replay every step, and hand it the keyboard when it needs you.
The agent browser is a real Chromium browser that runs inside your agent’s cloud sandbox. With it, an agent can open any website, click and type like a person, sign in with saved logins, fill forms, and download files, including on sites that need JavaScript, a signed-in session, or a real browser to load.You can watch the browser live from the chat, take over when the agent needs a human, and replay every browser step after the task finishes.
An agent paused on a sign-in page. The handoff card is on the left, the live browser on the right.
Open pages, click, type, scroll, switch tabs, and read what is on screen, including JavaScript-heavy pages.
Sign in without seeing passwords
Type saved logins and 2FA codes into a site. The agent never sees the password. See Browser Logins and Profiles.
Stay signed in across tasks
Sign-ins are saved to a browser profile at the end of each turn and restored on the next task.
Ask you for help
When it hits a login, 2FA code, CAPTCHA, or purchase confirmation, the agent pauses and hands the browser to you.
Show its work
Watch the browser live in the side panel, and replay a recording of every browser step afterwards.
Browse from another country
Route traffic through a residential proxy so sites see a visitor from the country you pick.
Use the browser for sites and tasks no connector covers. When a connector covers the app (Gmail, Salesforce, Notion, and so on), it is faster and more reliable than clicking through the site.
Your organization hasn’t given your role access to the browser yet. Reach out to your organization admin and ask them to add the Agent browser feature to your role. Until they do, agents you run work without the browser.
As soon as the browser starts, a Browser panel opens on the right side of the chat. It has two modes, switched from the pill at the bottom of the panel.
Live
Replay
Live streams the agent’s browser as it works, with its real tab strip, Back, Forward, Reload, and an address bar.
While the agent is driving, the page has a blue glow.
You can click and type directly in the page. Your clicks and typing go to the real browser.
Type a URL or search terms in the address bar. Anything that is not a web address becomes a Google search.
Open a new tab with + and switch tabs from the tab strip.
If someone else in the chat is using the browser, you see a label with their name, such as Max is using the browser.
The blue glow means the agent is driving.
Replay · N steps plays back a recording of every browser step in the chat, as one timeline.
Step back and forward between browser steps, play or pause, scrub, and change the playback speed.
The tab strip and address bar replay with the clip, so you can see which page each step was on.
Screenshots the agent took are marked on the timeline.
Open the replay later from Browser replay under the agent’s message.
Only one driver at a time. While a person is controlling the browser, the agent cannot run browser steps on the same page. During a handoff, only the person the browser was handed to can control it.
Every browser step is recorded. Recordings are attached when the turn finishes, so a running or paused turn never shows a half-finished clip. A very long step is cut off at the frame limit and marked Truncated at the frame limit.Recordings from a subagent stay in that subagent’s own chat; they are not copied into the parent chat.
The agent hands the browser to you when it reaches something only you can do: a sign-in it has no login for, a 2FA or one-time code, a CAPTCHA it could not pass, an SSO button, approving on your phone, or confirming a purchase. This is a browser handoff. The agent pauses until you answer.
Fill in the fields and click Continue. The agent receives sensitive values only as references, never as text. It types them into the page with a secure fill that checks the site first. The password field is masked in the live view, recordings, and screenshots.
A resolved handoff that saved the login.
Use the live panel to sign in, enter the code, or pass the check, then click Continue. The agent looks at the page and picks up from there. Use this for SSO buttons, CAPTCHAs, phone approvals, and purchase confirmations, where there is nothing to type.
When the chat runs in Slack, the handoff posts to the thread with buttons:
Handoff
Buttons
With fields
Enter the details (opens a form), I did it in the browser, I couldn’t do it
Without fields
Open in Gumloop, I did it in the browser, I couldn’t do it
Sensitive fields in the Slack form show the host they can be typed on. You can also open the browser in Gumloop, complete the step there, then hand it back from the thread.
The card resolves to one of: Completed in the browser, Could not be completed in the browser, or Saved the login for <site> as <NAME> and sent it to the agent.
Only the person whose message the agent is working on can answer its handoff. Everyone else in the chat sees the card as waiting for that person.
Set Proxy in the Browser section to a country (Browse from). The browser then exits through a residential proxy in that country, so sites see a visitor from there. Off is the default.
Each sandbox keeps one exit IP for its lifetime.
The agent is told which country it browses from.
Changing the proxy restarts the browser. Open tabs close, but sign-ins are kept.
The browser remembers which websites it is signed in to with a browser profile. At the end of each turn, Gumloop saves any new sign-ins to the profile, and the next task starts already signed in, even in a brand-new chat.
After the handoff, the agent is signed in and reports the saved login. Later chats on this agent start signed in.
When a saved session has expired, the agent signs back in with a saved login and the end-of-turn save keeps the new session. For profile ownership, importing your own browser’s sign-ins, and 1Password, see Browser Logins and Profiles.
The browser has no separate charge. Browser steps aren’t billed as tool calls, and the proxy, recordings, and live view are free. A browser task is billed like any other agent chat:
Compute: 5 credits per minute the agent spends working in the browser.
Chat & Reasoning: the model reading pages and screenshots.
Time spent waiting on you during a handoff isn’t billed.
No. Login passwords, 2FA setup keys, and sensitive handoff answers are never shown to the agent and are not stored in the sandbox environment. The agent refers to them by name, and Gumloop types them in for it. 2FA codes are generated by Gumloop at the moment of typing, so the setup key never enters the sandbox. The username is not secret: the agent can read it.
Can a page trick the agent into typing my password somewhere else?
Every secure fill is checked against the login’s site before anything is typed: the scheme, port, and host of the frame the field lives in must match. A mismatch types nothing and tells the agent to ask you instead. Handoff answers are locked to the exact host they were asked on, and the card shows you that host before you type.
Can someone see the password in the live view or recording?
No. Password and code fields are masked before and after typing, including if the site has a show-password toggle, and a screenshot is skipped if a typed field cannot be masked. Values are also kept out of chat transcripts and logs.
What should admins assume about bound logins?
These protections defend against a web page steering the agent. They are not a hard boundary against an agent that sets out to extract a value from its own sandbox. Treat every login an agent can type as usable by that agent, and bind only the logins it needs. For tighter control, restrict Agent browser with Custom Roles.
Check three things: the Browser section is turned on and saved, your role allows Agent browser, and the task actually needs a browser. If a connector can do the job, the agent may use it instead. To force the browser, ask explicitly, for example “Use your browser to open …”.
I turned the browser on, but the agent still can't use it. Why?
If your organization uses Custom Roles, Agent browser is denied by default and is checked for whoever runs the agent, not whoever configured it. A teammate whose role lacks it gets an agent without the browser. See Why does it say “Turned off for your role”? for what to ask your admin and how they turn it on.
Can I take over the browser while the agent is working?
Yes. Click into the Live view and use the page. While you hold control, the agent cannot run browser steps on that page, so it is best to take over when the agent asks with a handoff.
Why did my open tabs disappear?
The browser restarts when the proxy setting changes or when it switches to a different browser profile. Tabs close; sign-ins in the profile are kept. A tab that stops responding for about a minute is also closed, and the agent is told so it does not retry the same page.
The agent signed in, but the next chat is signed out. Why?
The usual causes:
The chat was incognito. Incognito chats never save or restore sign-ins.
Someone else ran it. With the default User-owned profile, each person has their own sign-ins, so a teammate’s run starts from their profile, not yours.
The site signed the browser out. Sessions expire. Give the agent a login so it can sign back in on its own.
No. Mobile viewports, mobile user agents, and touch emulation are not supported. The agent reports mobile checks as not testable rather than as site failures.
Can the agent get past CAPTCHAs?
Most of the time. When it cannot, it hands the browser to you with a handoff so you can solve it in the live view.