> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gumloop.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Agent Browser

> Give your agent a real Chromium browser to open sites, sign in, fill forms, and download files. Watch it live, replay every step, and hand it the keyboard when it needs you.

The agent browser is a real Chromium browser that runs inside your agent's cloud sandbox. With it, an agent can open any website, click and type like a person, sign in with saved logins, fill forms, and download files, including on sites that need JavaScript, a signed-in session, or a real browser to load.

You can watch the browser live from the chat, take over when the agent needs a human, and replay every browser step after the task finishes.

<Frame caption="An agent paused on a sign-in page. The handoff card is on the left, the live browser on the right.">
  <img src="https://mintcdn.com/agenthub/Ub5FqmL64LsOO4Hg/images/agent-browser/chat-handoff-full.png?fit=max&auto=format&n=Ub5FqmL64LsOO4Hg&q=85&s=8c96f3ff698c11abab2e6a25fd6e580e" alt="Chat with a browser handoff card asking for a username and password, next to the live browser panel showing a login page" width="2560" height="1626" data-path="images/agent-browser/chat-handoff-full.png" />
</Frame>

***

## What can the agent browser do?

<Columns cols={2}>
  <Card title="Browse like a person" icon="arrow-pointer">
    Open pages, click, type, scroll, switch tabs, and read what is on screen, including JavaScript-heavy pages.
  </Card>

  <Card title="Sign in without seeing passwords" icon="key">
    Type saved logins and 2FA codes into a site. The agent never sees the password. See [Browser Logins and Profiles](/core-concepts/browser_logins_and_profiles).
  </Card>

  <Card title="Stay signed in across tasks" icon="cookie">
    Sign-ins are saved to a browser profile at the end of each turn and restored on the next task.
  </Card>

  <Card title="Ask you for help" icon="hand">
    When it hits a login, 2FA code, CAPTCHA, or purchase confirmation, the agent pauses and hands the browser to you.
  </Card>

  <Card title="Show its work" icon="video">
    Watch the browser live in the side panel, and replay a recording of every browser step afterwards.
  </Card>

  <Card title="Browse from another country" icon="globe">
    Route traffic through a residential proxy so sites see a visitor from the country you pick.
  </Card>
</Columns>

<Tip>
  Use the browser for sites and tasks no [connector](/core-concepts/credentials) covers. When a connector covers the app (Gmail, Salesforce, Notion, and so on), it is faster and more reliable than clicking through the site.
</Tip>

***

## How do I turn on the browser for an agent?

The browser is an ability you turn on per custom agent, from the **Browser** section of the agent's configuration.

<Steps>
  <Step title="Open the agent's configuration">
    Open the agent and find the **Browser** section in the configuration panel. When the browser is off, it reads **Give your agent a browser**.

    <Frame>
      <img src="https://mintcdn.com/agenthub/Ub5FqmL64LsOO4Hg/images/agent-browser/agent-browser-off.png?fit=max&auto=format&n=Ub5FqmL64LsOO4Hg&q=85&s=8c0e029693c5092ad938de6435ce9153" width="380" alt="Browser section with the empty state Give your agent a browser and a Turn on button" data-path="images/agent-browser/agent-browser-off.png" />
    </Frame>
  </Step>

  <Step title="Click Turn on">
    The section expands to show the **Browser** toggle and its settings.

    <Frame>
      <img src="https://mintcdn.com/agenthub/Ub5FqmL64LsOO4Hg/images/agent-browser/agent-browser-on.png?fit=max&auto=format&n=Ub5FqmL64LsOO4Hg&q=85&s=9d7cb92b55787d54d0ad13a3eb8b3387" width="380" alt="Browser section turned on, with rows for Browser, Proxy, Browser profile, and 1Password, and a Login button" data-path="images/agent-browser/agent-browser-on.png" />
    </Frame>
  </Step>

  <Step title="Configure it (optional)">
    | Setting | What it does |
    | - | - |
    | **Proxy** | **Off** by default. Pick a country to browse as a visitor from that country. See [Proxy](#how-do-i-browse-from-another-country). |
    | **Browser profile** | Whose saved sign-ins the browser starts with. See [Browser profiles](/core-concepts/browser_logins_and_profiles#browser-profiles). |
    | **1Password** | Let the agent type logins from a 1Password vault. See [1Password](/core-concepts/browser_logins_and_profiles#1password). |
    | **+ Login** | Bind a saved website login to the agent. See [Logins](/core-concepts/browser_logins_and_profiles#logins). |
  </Step>

  <Step title="Save the agent">
    Click **Save**. The browser is available from the next message.
  </Step>
</Steps>

<Note>
  Turning the browser off also turns off its proxy, browser profile, and 1Password settings. Logins you bound stay listed so you can still remove them.
</Note>

### Which agents get the browser?

| Agent | Browser access |
| - | - |
| **New custom agents** | Turned on by default when the person who creates the agent is allowed to use the browser. |
| **Existing custom agents** | Off until someone turns it on in the **Browser** section. |
| **[Gumball](/core-concepts/gumball)** | Available whenever your role allows the browser. There is nothing to configure. |

If you do not see a **Browser** section at all, the browser is not available on your account yet.

### Why does it say "Turned off for your role"?

Your organization hasn't given your role access to the browser yet. **Reach out to your [organization admin](https://www.gumloop.com/settings/organization/members?role=admin)** and ask them to add the **Agent browser** feature to your role. Until they do, agents you run work without the browser.

#### For admins: turn on the browser for a role

On Enterprise organizations, the browser is controlled by the **Agent browser** feature in [Custom Roles](/enterprise-features/user_groups). It is off by default.

<Steps>
  <Step title="Open Custom Roles">
    Go to [Settings > Organization > Custom Roles](https://www.gumloop.com/settings/organization/groups).
  </Step>

  <Step title="Open the role">
    Click the role the person belongs to. To turn it on for everyone, open your default role (the one every new member joins, such as **Default Group**).
  </Step>

  <Step title="Add the Agent browser feature">
    Open the **Features** tab, click **Add Features**, select **Agent browser**, and click **Add Features**.
  </Step>
</Steps>

<Frame caption="Agent browser added to a role's Features tab.">
  <img src="https://mintcdn.com/agenthub/Ub5FqmL64LsOO4Hg/images/agent-browser/custom-role-agent-browser.png?fit=max&auto=format&n=Ub5FqmL64LsOO4Hg&q=85&s=aa0f6c104fa9e301cc487f7170110c6f" alt="Custom role Features tab listing Agent browser under Agents" width="1880" height="690" data-path="images/agent-browser/custom-role-agent-browser.png" />
</Frame>

The change applies from the person's next message. No one needs to reconfigure their agents.

***

## How do I watch the agent use the browser?

As soon as the browser starts, a **Browser** panel opens on the right side of the chat. It has two modes, switched from the pill at the bottom of the panel.

<Tabs>
  <Tab title="Live">
    **Live** streams the agent's browser as it works, with its real tab strip, **Back**, **Forward**, **Reload**, and an address bar.

    <Frame>
      <img src="https://mintcdn.com/agenthub/Ub5FqmL64LsOO4Hg/images/agent-browser/live-view-panel.png?fit=max&auto=format&n=Ub5FqmL64LsOO4Hg&q=85&s=62063955a6525757cae4384593a7f75d" width="360" alt="Live browser panel with a tab, back, forward, reload, the address bar, and a signed-in page" data-path="images/agent-browser/live-view-panel.png" />
    </Frame>

    * While the agent is driving, the page has a blue glow.
    * You can click and type directly in the page. Your clicks and typing go to the real browser.
    * Type a URL or search terms in the address bar. Anything that is not a web address becomes a Google search.
    * Open a new tab with **+** and switch tabs from the tab strip.
    * If someone else in the chat is using the browser, you see a label with their name, such as *Max is using the browser*.

    <Frame caption="The blue glow means the agent is driving.">
      <img src="https://mintcdn.com/agenthub/Ub5FqmL64LsOO4Hg/images/agent-browser/live-view-agent-driving.png?fit=max&auto=format&n=Ub5FqmL64LsOO4Hg&q=85&s=f51e311a317d10e31f0d6d5db0fe9216" width="340" alt="Live browser panel with a blue glow around the page while the agent types into a login form" data-path="images/agent-browser/live-view-agent-driving.png" />
    </Frame>
  </Tab>

  <Tab title="Replay">
    **Replay · N steps** plays back a recording of every browser step in the chat, as one timeline.

    <Frame>
      <img src="https://mintcdn.com/agenthub/Ub5FqmL64LsOO4Hg/images/agent-browser/replay-view.png?fit=max&auto=format&n=Ub5FqmL64LsOO4Hg&q=85&s=22b4852f3cf90ed4e2390d24738831c5" width="360" alt="Browser replay of a login page with the Live and Replay pill and playback controls for step back, step forward, play, scrubber, time, and speed" data-path="images/agent-browser/replay-view.png" />
    </Frame>

    * Step back and forward between browser steps, play or pause, scrub, and change the playback speed.
    * The tab strip and address bar replay with the clip, so you can see which page each step was on.
    * Screenshots the agent took are marked on the timeline.
    * Open the replay later from **Browser replay** under the agent's message.
  </Tab>
</Tabs>

<Info>
  Only one driver at a time. While a person is controlling the browser, the agent cannot run browser steps on the same page. During a handoff, only the person the browser was handed to can control it.
</Info>

### When do recordings appear?

Every browser step is recorded. Recordings are attached when the turn finishes, so a running or paused turn never shows a half-finished clip. A very long step is cut off at the frame limit and marked **Truncated at the frame limit**.

Recordings from a [subagent](/core-concepts/agents) stay in that subagent's own chat; they are not copied into the parent chat.

***

## When does the agent ask me for help?

The agent hands the browser to you when it reaches something only you can do: a sign-in it has no login for, a 2FA or one-time code, a CAPTCHA it could not pass, an SSO button, approving on your phone, or confirming a purchase. This is a **browser handoff**. The agent pauses until you answer.

```mermaid theme={"dark"}
flowchart LR
  A[Agent reaches a login or check] --> B{Can it finish alone?}
  B -- Yes --> C[Agent continues]
  B -- No --> D[Handoff card in chat]
  D --> E[You type values in the card]
  D --> F[You do it in the live browser]
  D --> G[Skip]
  E --> H[Agent types them in and continues]
  F --> C
  G --> I[Agent continues without it]
```

### What does the handoff card look like?

<Frame>
  <img src="https://mintcdn.com/agenthub/Ub5FqmL64LsOO4Hg/images/agent-browser/chat-handoff-card.png?fit=max&auto=format&n=Ub5FqmL64LsOO4Hg&q=85&s=8fdb0403e28f3be77742dc6c9c9d9c37" width="428" alt="Handoff card with Username and Password fields, a note that sensitive values can only be typed on the-internet.herokuapp.com, a Save login checkbox, and Skip and Continue buttons" data-path="images/agent-browser/chat-handoff-card.png" />
</Frame>

| Part | What it means |
| - | - |
| **Status banner** | *Use the browser in the side panel, then continue. The agent is paused until you do.* |
| **Instructions** | What the agent needs, written by the agent. |
| **Fields** | Up to six inputs, such as a username, password, or one-time code. Password and code fields are sensitive. |
| **Sensitive values can only be typed on `<host>`** | Sensitive values are locked to the exact host the browser was on when it asked. They cannot be typed anywhere else. |
| **Save login for `<site>`** | Saves the username and password to your Vault so the agent can sign in next time without asking. Pick **Only me** or **My team** when both are offered. |
| **Skip** | Decline. The agent continues without your help. |
| **Open browser** / **Continue** | Open the live panel if it is closed, then continue once you have entered values or finished in the browser. |

### How do I answer a handoff?

<Tabs>
  <Tab title="Type the values in the card">
    Fill in the fields and click **Continue**. The agent receives sensitive values only as references, never as text. It types them into the page with a secure fill that checks the site first. The password field is masked in the live view, recordings, and screenshots.

    <Frame caption="A resolved handoff that saved the login.">
      <img src="https://mintcdn.com/agenthub/Ub5FqmL64LsOO4Hg/images/agent-browser/chat-steps-resolved-handoff.png?fit=max&auto=format&n=Ub5FqmL64LsOO4Hg&q=85&s=79e489cd48600047e76f0785374696da" width="380" alt="Agent steps showing the handoff resolved with Saved the login for the-internet.herokuapp.com as THE_INTERNET_HEROKUAPP_COM and sent it to the agent" data-path="images/agent-browser/chat-steps-resolved-handoff.png" />
    </Frame>
  </Tab>

  <Tab title="Do it in the browser yourself">
    Use the live panel to sign in, enter the code, or pass the check, then click **Continue**. The agent looks at the page and picks up from there. Use this for SSO buttons, CAPTCHAs, phone approvals, and purchase confirmations, where there is nothing to type.
  </Tab>

  <Tab title="From Slack">
    When the chat runs in Slack, the handoff posts to the thread with buttons:

    | Handoff | Buttons |
    | - | - |
    | With fields | **Enter the details** (opens a form), **I did it in the browser**, **I couldn't do it** |
    | Without fields | **Open in Gumloop**, **I did it in the browser**, **I couldn't do it** |

    Sensitive fields in the Slack form show the host they can be typed on. You can also open the browser in Gumloop, complete the step there, then hand it back from the thread.
  </Tab>
</Tabs>

The card resolves to one of: **Completed in the browser**, **Could not be completed in the browser**, or *Saved the login for `<site>` as `<NAME>` and sent it to the agent*.

<Note>
  Only the person whose message the agent is working on can answer its handoff. Everyone else in the chat sees the card as *waiting for* that person.
</Note>

***

## How do I browse from another country?

Set **Proxy** in the **Browser** section to a country (**Browse from**). The browser then exits through a residential proxy in that country, so sites see a visitor from there. **Off** is the default.

* Each sandbox keeps one exit IP for its lifetime.
* The agent is told which country it browses from.
* Changing the proxy restarts the browser. Open tabs close, but sign-ins are kept.
* Proxy bandwidth is not billed separately.

***

## How does the agent stay signed in?

The browser remembers which websites it is signed in to with a **browser profile**. At the end of each turn, Gumloop saves any new sign-ins to the profile, and the next task starts already signed in, even in a brand-new chat.

<Frame caption="After the handoff, the agent is signed in and reports the saved login. Later chats on this agent start signed in.">
  <img src="https://mintcdn.com/agenthub/Ub5FqmL64LsOO4Hg/images/agent-browser/chat-signed-in-full.png?fit=max&auto=format&n=Ub5FqmL64LsOO4Hg&q=85&s=514d18779f4ffcd30de75e0cd2351a30" alt="Chat where the agent reports it is signed in, with the browser panel showing a Secure Area page" width="2560" height="1626" data-path="images/agent-browser/chat-signed-in-full.png" />
</Frame>

When a saved session has expired, the agent signs back in with a [saved login](/core-concepts/browser_logins_and_profiles#logins) and the end-of-turn save keeps the new session. For profile ownership, importing your own browser's sign-ins, and 1Password, see [Browser Logins and Profiles](/core-concepts/browser_logins_and_profiles).

***

## Limits

| Limit | Value |
| - | - |
| **Window** | Desktop Chromium. Mobile and device emulation are not supported, so mobile-only checks cannot be tested. |
| **Handoff fields** | 6 per handoff |
| **Recording** | One clip per browser step, cut off at the frame limit |
| **Sign-in saving** | At the end of each turn, not mid-turn |
| **Incognito chats** | No browser profile is restored or saved |

The browser shares the agent's [Code Sandbox](/core-concepts/agent_sandbox_and_secrets), so the sandbox's limits apply too.

***

## How is the browser billed?

The browser has no separate charge. Browser steps aren't billed as tool calls, and the proxy, recordings, and live view are free. A browser task is billed like any other [agent chat](/core-concepts/credits):

* **Compute:** 5 credits per minute the agent spends working in the browser.
* **Chat & Reasoning:** the model reading pages and screenshots.

Time spent waiting on you during a handoff isn't billed.

***

## How are passwords kept safe?

<AccordionGroup>
  <Accordion title="Does the agent ever see my password?" icon="eye-slash">
    No. Login passwords, 2FA setup keys, and sensitive handoff answers are never shown to the agent and are not stored in the sandbox environment. The agent refers to them by name, and Gumloop types them in for it. 2FA codes are generated by Gumloop at the moment of typing, so the setup key never enters the sandbox. The **username** is not secret: the agent can read it.
  </Accordion>

  <Accordion title="Can a page trick the agent into typing my password somewhere else?" icon="shield">
    Every secure fill is checked against the login's site before anything is typed: the scheme, port, and host of the frame the field lives in must match. A mismatch types nothing and tells the agent to ask you instead. Handoff answers are locked to the exact host they were asked on, and the card shows you that host before you type.
  </Accordion>

  <Accordion title="Can someone see the password in the live view or recording?" icon="video">
    No. Password and code fields are masked before and after typing, including if the site has a show-password toggle, and a screenshot is skipped if a typed field cannot be masked. Values are also kept out of chat transcripts and logs.
  </Accordion>

  <Accordion title="What should admins assume about bound logins?" icon="triangle-exclamation">
    These protections defend against a web page steering the agent. They are not a hard boundary against an agent that sets out to extract a value from its own sandbox. Treat every login an agent can type as usable by that agent, and bind only the logins it needs. For tighter control, restrict **Agent browser** with [Custom Roles](/enterprise-features/user_groups).
  </Accordion>
</AccordionGroup>

***

## FAQ

<AccordionGroup>
  <Accordion title="Why isn't my agent using the browser?">
    Check three things: the **Browser** section is turned on and saved, your role allows **Agent browser**, and the task actually needs a browser. If a [connector](/core-concepts/credentials) can do the job, the agent may use it instead. To force the browser, ask explicitly, for example *"Use your browser to open ..."*.
  </Accordion>

  <Accordion title="I turned the browser on, but the agent still can't use it. Why?">
    If your organization uses Custom Roles, **Agent browser** is denied by default and is checked for whoever runs the agent, not whoever configured it. A teammate whose role lacks it gets an agent without the browser. See [Why does it say "Turned off for your role"?](#why-does-it-say-%E2%80%9Cturned-off-for-your-role%E2%80%9D) for what to ask your admin and how they turn it on.
  </Accordion>

  <Accordion title="Can I take over the browser while the agent is working?">
    Yes. Click into the **Live** view and use the page. While you hold control, the agent cannot run browser steps on that page, so it is best to take over when the agent asks with a handoff.
  </Accordion>

  <Accordion title="Why did my open tabs disappear?">
    The browser restarts when the proxy setting changes or when it switches to a different browser profile. Tabs close; sign-ins in the profile are kept. A tab that stops responding for about a minute is also closed, and the agent is told so it does not retry the same page.
  </Accordion>

  <Accordion title="The agent signed in, but the next chat is signed out. Why?">
    The usual causes:

    * **The chat was incognito.** Incognito chats never save or restore sign-ins.
    * **Someone else ran it.** With the default **User-owned** profile, each person has their own sign-ins, so a teammate's run starts from their profile, not yours.
    * **The site signed the browser out.** Sessions expire. [Give the agent a login](/core-concepts/browser_logins_and_profiles#how-do-i-give-an-agent-a-login) so it can sign back in on its own.

    See [Browser profiles](/core-concepts/browser_logins_and_profiles#browser-profiles) for how sign-ins are saved.
  </Accordion>

  <Accordion title="Can the agent test my site on mobile?">
    No. Mobile viewports, mobile user agents, and touch emulation are not supported. The agent reports mobile checks as not testable rather than as site failures.
  </Accordion>

  <Accordion title="Can the agent get past CAPTCHAs?">
    Most of the time. When it cannot, it hands the browser to you with a handoff so you can solve it in the live view.
  </Accordion>
</AccordionGroup>

***

## Related

<Columns cols={2}>
  <Card title="Browser Logins and Profiles" icon="key" href="/core-concepts/browser_logins_and_profiles">
    Saved logins, 2FA, browser profiles, importing sign-ins, and 1Password.
  </Card>

  <Card title="Code Sandbox & Secrets" icon="code" href="/core-concepts/agent_sandbox_and_secrets">
    The sandbox the browser runs in, and the Vault.
  </Card>

  <Card title="Human in the Loop" icon="user-check" href="/core-concepts/human_in_the_loop">
    Approvals and questions that pause an agent.
  </Card>

  <Card title="Custom Roles" icon="users-gear" href="/enterprise-features/user_groups">
    Grant or restrict Agent browser per role.
  </Card>
</Columns>
