Browser
Operates like a human
A web product with no MCP server, operated the way a person would: a browser, on the sites you allow.
What a member can do
Some products have no MCP server: an old CRM, a supplier's portal, an internal admin page. A member can still use
one, by driving a browser through it. You bind a browser to a prefix you choose, such as crm, with the sites it
may open, and a task names the actions it may take there:
| Action | What it does |
|---|---|
crm.navigate |
Opens a URL, or the start URL again when given none. |
crm.click |
Clicks an element, found by a selector. |
crm.type |
Fills a field, found by a selector, with text. |
crm.extract |
Reads the text of an element: body for the whole page. |
crm.screenshot |
Captures the page as it is. |
A task has to name each action it may take. The bare prefix, crm, gives it no browser at all. What each action
takes is in the Computer-Use tools reference.
Each run gets its own browser, a headless Chromium, opened at the start URL on its first action and closed when the run ends. It starts signed out, with nothing kept from an earlier run. A browser is only ever driven by a run of a task: a member's chat never offers one.
Only the sites you allow
Every page the browser opens has to be on one of the binding's sites: the host itself, or any subdomain of it. A
navigation anywhere else is refused before the browser moves, and the run is told which site was blocked
(computer_use_site_blocked). Where the browser actually lands is checked again after every action, so a link or
a redirect cannot take it off the list either: it is taken back to the last allowed page, or closed if it cannot
be, and the action is refused.
What the model reads
Anything typed into a field that looks like it holds a secret (a password, a token, a key, a PIN), and every cookie
the browser holds, is taken out of everything the member reads back: results, addresses, and error messages alike.
A screenshot is stored with the run and never put in front of the model: the member reads a page with extract.
Which models can drive it
A run whose task names a browser action starts only on a model trusted to operate a browser. Today those are
Anthropic's Claude Opus, Sonnet and Haiku models from version 4 on, and Claude 3.5 Sonnet, whether through an
Anthropic key or OpenRouter. On any other model the run stops before the model is called, with
computer_use_model_unsupported, and shows on Blockers: change the member's model, then retry it. See
Spend and models.
Who connects it
A browser binding holds no credential. It is three things: a prefix, the sites, and a start URL on one of those sites. What the sites see is a signed-out visitor.
A binding can sit on the enterprise, a team, a member, a role or a task, and the one further down replaces the one
above: task, then role, then member, then team, then enterprise. A binding lower down may leave out sites that a
wider one it inherits from allows. Adding a site that the wider one does not allow is refused
(widens_<layer>_grant), unless you are the person who bound the wider one, or the CEO.
Planned
Signing in
When the browser reaches a sign-in page, the run will pause and tell you. You take over that browser, sign in as the member, and hand it back, and the member carries on inside the product. What the sign-in left behind (the site's cookies, never a password) will be kept for that member on that site, so its later runs start signed in. Each binding will list the sign-ins it keeps, by member and site, with Revoke sign-in beside each: the next run meets the sign-in page again.
What waits for you
Nothing a browser does waits for you unless the task declares a gate on it. Gate one action, such as crm.click,
and every click waits; gate the prefix, crm, and every action does, reading included. A gated action waits with
exactly what it was about to do (the selector, the text, the address), and nothing happens on the site until you
approve it on Gates. See Gates and tool scopes.
On a task where a click can save, send or delete something, gate click, or keep the binding's sites to pages
where it cannot.
Planned
Saving waits for you by itself
A browser action that saves or submits something will wait for your approval whatever the task declares: a form submission, a navigation that sends data to the site, or a request the page sends. Reading, typing, following links and clicks that submit nothing will go ahead. A task will also be able to mark a browser step as the same decision as a tool it gates, so the browser is never a way round that gate. Each approval will show the screen the action was about to be taken on, and a run's page will show a screenshot of every step it took.
Setup
- In the portal, on Tools (or a member's or team's page → Tools), choose Add tool.
- Kind: Computer-Use. Tool type: the prefix your tasks will use, such as
crm. - Allowed sites: one host per line, with no
https://and no path:crm.example.com. A host covers its subdomains. List only what the work needs. - Start URL: where the browser opens, on one of those sites:
https://crm.example.com/. - Choose Bind browser.
- On the task, name each action it needs (
crm.navigate,crm.extract,crm.click, …), and declare a gate on each one that should wait for you. - Check it. Run the task. The run page shows every action, and the address the browser was on after it.
Troubleshooting
| What you see | Why | What to do |
|---|---|---|
computer_use_not_on_task |
The task lists the bare prefix, crm, not its actions |
Name each action: crm.navigate, crm.click, … |
computer_use_site_blocked: <host> |
The page is on a host the binding does not allow | Add the host to the binding's sites, if the work needs it |
computer_use_model_unsupported |
The run's model cannot operate a browser | Change the member's model to one that can, then retry the run |
computer_use_browser_unavailable |
No browser could be started for the run | Nothing about your task is wrong. Retry the run from Blockers |
| Calls fail as though nothing were bound | The start URL is not on one of the binding's sites, so it gives no browser | Put the start URL's host in the sites |
Saving a binding is refused when it adds a site (widens_<layer>_grant over the API) |
A wider binding it inherits from does not allow that site | Ask whoever bound the wider one to add it there, or leave the site out |
| A click or a field is not found | The selector does not match the page as it is | Have the task extract the page (body) to see what is there, and adjust its skill |