Browser
Your agent's own browser.
A real Chromium for each account, on its own virtual screen. It keeps its tabs and logins, it answers to MCP and REST alike, and the server, not the prompt, decides what it may change.
Persistence
Nothing starts from zero.
The browser belongs to one person, so it behaves like theirs: it remembers. Every client with the same token reaches the same browser.
Tabs
Tabs keep their ids across connections and restarts. Close the laptop, reconnect tomorrow from another client, and t3 is still the tab you left.
Profile
One Chromium profile per account: cookies, local storage, history and site permissions. The browser stops after 20 idle minutes; the profile stays on disk.
Saved sessions
Save a site's cookies and storage under a name, encrypted like passwords, and load it into any tab later. Or import a cookie export from your own browser.
Snapshots and refs
Agents read the page as a list, not a picture.
- browser_snapshot lists interactive elements with role, name and a ref (e1, e2 …); new ones are marked
- Act by ref: click (real mouse or DOM), type, fill, fill a whole form, press keys, hover, scroll
- read_text for the rendered text; screenshots when the agent needs to see
- browser_find_text, browser_extract (tables, links, meta, form fields), the tab's network log
Uploads and downloads
Files in and out, of any type.
- Upload up to 20 files into a file input or picker button
- Downloads are kept per user: read as text (PDF, XLSX, DOCX, CSV, HTML), as rows, or as the file
- A short-lived link hands a download to a person
- browser_read: a URL's main content as Markdown without opening a tab
Recordings
Evidence for every run.
- browser_record writes one self-contained HTML report with a screenshot per step, and JUnit XML
- Background tabs are recorded too
- Turn a recording into a script and replay it without an LLM
- Signed webhooks when a recording stops, a replay finishes or a download completes
Guarded writes
Rules the server enforces.
An instruction in a prompt is a request. These are checks in the gateway, for MCP and REST alike.
- Read and act tabs
- A read tab blocks every write at the network level. Writes need an act tab.
- Site rules
- Per site: read-only, ask or allowed. Read-only refuses writes, logins, secrets and JavaScript.
- Untrusted page text
- Everything a page says reaches the agent fenced and labelled as data.
- Audit log
- Every write, login, secret use and hand-off, with the user on every line.
One URL, one token
Every client, the same browser.
MCP for agents, REST and the SDKs for programs. The token decides whose browser it is; nothing the client sends can change that.
export WEBPILOT_TOKEN=cbu_... # console → Settings → Tokens
claude mcp add --transport http webpilot https://api.webpilot.si/mcp \
--header "Authorization: Bearer $WEBPILOT_TOKEN"Give your agent a browser that remembers.
Start with the free trial. Connect Claude Code, Cursor, Codex or your own code in a minute.