Computer-Use tools
The verbs a run can call on a Computer-Use binding: a browser for a product with no MCP server, limited to the sites the binding allows.
Generated from the built-in tools registry. Do not edit by hand.
Some products have no MCP server. A Computer-Use binding gives a run a browser instead: a prefix the enterprise chooses, the hosts it may open, and a start URL. A task names each verb it may use under that prefix, <prefix>.<verb>, and gets no browser for a bare prefix.
The browser only opens the hosts the binding allows. Credentials the run uses are taken out of everything the model reads back.
| Tool | What it does | Effect |
|---|---|---|
<prefix>.navigate |
Open url in the run's browser. |
read |
<prefix>.click |
Click the element selector names. |
write |
<prefix>.type |
Type text into the element selector names. |
write |
<prefix>.screenshot |
Take a screenshot of the page. | read |
<prefix>.extract |
Read the text of the element selector names. |
read |
<prefix>.download |
Download the file the site offers at url, or behind the control selector names, and keep it as a run file a person can take from the run. |
read |
<prefix>.upload |
Attach a run file, named by the handle (file) a download or the task gave it, to the file input selector names. Waits for a person to approve it first. |
write |
<prefix>.navigate
Open url in the run's browser.
What the model reads:
Open a page in this run's browser. Pass url, the full address, on one of the sites the <prefix> binding allows: any other host is refused. Returns the address the browser reached, after any redirect.
| Field | Type | Required | Description |
|---|---|---|---|
url |
string | yes | The full address to open. Its host must be one of the sites the binding allows. |
- Effect: read.
- Retry: Safe: repeating the call changes nothing.
- Called by: a run.
- Needs:
- A Computer-Use binding on this prefix (host-only allowed sites and a start URL), a model that can drive a browser, and a task that lists
<prefix>.<verb>by name: a bare prefix grants no browser.
- A Computer-Use binding on this prefix (host-only allowed sites and a start URL), a model that can drive a browser, and a task that lists
- Returns: The page reached.
| Error | When | What happens |
|---|---|---|
computer_use_model_unsupported |
The run's model is not one trusted to drive a browser. The run is blocked before any model call. | Run fails |
computer_use_browser_unavailable |
No browser could be started for the run. | Run fails |
computer_use_site_blocked |
The page is on a host outside the binding's allowed sites. | Tool error |
computer_use_failed |
The browser action itself failed. | Tool error |
<prefix>.click
Click the element selector names.
What the model reads:
Click one element on the page open in this run's browser. Pass selector, a CSS selector for it. Returns the address the browser is on afterwards.
| Field | Type | Required | Description |
|---|---|---|---|
selector |
string | yes | A CSS selector for the element to click. |
- Effect: write.
- Retry: Not retry-safe: a repeat acts again.
- Called by: a run.
- Needs:
- A Computer-Use binding on this prefix (host-only allowed sites and a start URL), a model that can drive a browser, and a task that lists
<prefix>.<verb>by name: a bare prefix grants no browser.
- A Computer-Use binding on this prefix (host-only allowed sites and a start URL), a model that can drive a browser, and a task that lists
| Error | When | What happens |
|---|---|---|
computer_use_model_unsupported |
The run's model is not one trusted to drive a browser. The run is blocked before any model call. | Run fails |
computer_use_browser_unavailable |
No browser could be started for the run. | Run fails |
computer_use_site_blocked |
The page is on a host outside the binding's allowed sites. | Tool error |
computer_use_failed |
The browser action itself failed. | Tool error |
<prefix>.type
Type text into the element selector names.
What the model reads:
Type into one field on the page open in this run's browser. Pass selector, a CSS selector for the field, and text, which replaces what the field holds. Returns the address the browser is on afterwards.
| Field | Type | Required | Description |
|---|---|---|---|
selector |
string | yes | A CSS selector for the element to type into. |
text |
string | yes | What to put in the element. It replaces what the element holds. |
- Effect: write.
- Retry: Not retry-safe: a repeat acts again.
- Called by: a run.
- Needs:
- A Computer-Use binding on this prefix (host-only allowed sites and a start URL), a model that can drive a browser, and a task that lists
<prefix>.<verb>by name: a bare prefix grants no browser.
- A Computer-Use binding on this prefix (host-only allowed sites and a start URL), a model that can drive a browser, and a task that lists
| Error | When | What happens |
|---|---|---|
computer_use_model_unsupported |
The run's model is not one trusted to drive a browser. The run is blocked before any model call. | Run fails |
computer_use_browser_unavailable |
No browser could be started for the run. | Run fails |
computer_use_site_blocked |
The page is on a host outside the binding's allowed sites. | Tool error |
computer_use_failed |
The browser action itself failed. | Tool error |
<prefix>.screenshot
Take a screenshot of the page.
What the model reads:
Take a screenshot of the page open in this run's browser. Takes no arguments. The screenshot is reported by its size, not pasted into the conversation.
Takes no arguments.
- Effect: read.
- Retry: Safe: repeating the call changes nothing.
- Called by: a run.
- Needs:
- A Computer-Use binding on this prefix (host-only allowed sites and a start URL), a model that can drive a browser, and a task that lists
<prefix>.<verb>by name: a bare prefix grants no browser.
- A Computer-Use binding on this prefix (host-only allowed sites and a start URL), a model that can drive a browser, and a task that lists
- Returns: The screenshot, reported by size rather than pasted into the conversation.
| Error | When | What happens |
|---|---|---|
computer_use_model_unsupported |
The run's model is not one trusted to drive a browser. The run is blocked before any model call. | Run fails |
computer_use_browser_unavailable |
No browser could be started for the run. | Run fails |
computer_use_site_blocked |
The page is on a host outside the binding's allowed sites. | Tool error |
computer_use_failed |
The browser action itself failed. | Tool error |
<prefix>.extract
Read the text of the element selector names.
What the model reads:
Read the text of one element on the page open in this run's browser. Pass selector, a CSS selector for it. Every credential the run used is taken out of the text before you read it.
| Field | Type | Required | Description |
|---|---|---|---|
selector |
string | no | A CSS selector for the element whose text to read. |
- Effect: read.
- Retry: Safe: repeating the call changes nothing.
- Called by: a run.
- Needs:
- A Computer-Use binding on this prefix (host-only allowed sites and a start URL), a model that can drive a browser, and a task that lists
<prefix>.<verb>by name: a bare prefix grants no browser.
- A Computer-Use binding on this prefix (host-only allowed sites and a start URL), a model that can drive a browser, and a task that lists
- Returns: The text, with every credential the run used taken out.
| Error | When | What happens |
|---|---|---|
computer_use_model_unsupported |
The run's model is not one trusted to drive a browser. The run is blocked before any model call. | Run fails |
computer_use_browser_unavailable |
No browser could be started for the run. | Run fails |
computer_use_site_blocked |
The page is on a host outside the binding's allowed sites. | Tool error |
computer_use_failed |
The browser action itself failed. | Tool error |
<prefix>.download
Download the file the site offers at url, or behind the control selector names, and keep it as a run file a person can take from the run.
What the model reads:
Download a file from the site open in this run's browser and keep it as a run file. Pass url, the file's address on one of the sites the <prefix> binding allows, or selector, a CSS selector for the control whose click starts the download. url is used when both are given, and every redirect is checked against the allowed sites. Returns the run file's handle (id), name, size and content type, and the URL it came from, never its bytes.
| Field | Type | Required | Description |
|---|---|---|---|
url |
string | no | The file's address. Its host, and every redirect's, must be one of the sites the binding allows. Used instead of selector when both are given. |
selector |
string | no | A CSS selector for the element whose click starts the download. |
- Effect: read.
- Retry: Safe: repeating the call changes nothing.
- Called by: a run.
- Needs:
- A Computer-Use binding on this prefix (host-only allowed sites and a start URL), a model that can drive a browser, and a task that lists
<prefix>.<verb>by name: a bare prefix grants no browser.
- A Computer-Use binding on this prefix (host-only allowed sites and a start URL), a model that can drive a browser, and a task that lists
- Returns: The run file's handle (
id), name, size and content type, and the URL it came from. Never its bytes.
| Error | When | What happens |
|---|---|---|
computer_use_model_unsupported |
The run's model is not one trusted to drive a browser. The run is blocked before any model call. | Run fails |
computer_use_browser_unavailable |
No browser could be started for the run. | Run fails |
computer_use_site_blocked |
The page is on a host outside the binding's allowed sites. | Tool error |
computer_use_failed |
The browser action itself failed. | Tool error |
computer_use_file_not_saved |
The downloaded file could not be kept, for example because the artifact store refused its size. | Tool error |
<prefix>.upload
Attach a run file, named by the handle (file) a download or the task gave it, to the file input selector names. Waits for a person to approve it first.
What the model reads:
Attach a file this run holds to a file input on the page open in this run's browser. Pass selector, a CSS selector for the file input, and file, the handle of a run file: the id a download returned, or the handle of a file the task was given. A path or a URL is refused. A person approves every upload before the file is attached. Returns the address the browser is on afterwards.
| Field | Type | Required | Description |
|---|---|---|---|
selector |
string | yes | A CSS selector for the element to attach the file to. |
file |
string | yes | The handle of a file this run holds: the id a download returned, or the handle of a file the task was given. A path or a URL is refused. |
- Effect: write.
- Retry: Not retry-safe: a repeat acts again.
- Called by: a run.
- Needs:
- A Computer-Use binding on this prefix (host-only allowed sites and a start URL), a model that can drive a browser, and a task that lists
<prefix>.<verb>by name: a bare prefix grants no browser.
- A Computer-Use binding on this prefix (host-only allowed sites and a start URL), a model that can drive a browser, and a task that lists
- Returns: The page the file was attached on.
| Error | When | What happens |
|---|---|---|
computer_use_model_unsupported |
The run's model is not one trusted to drive a browser. The run is blocked before any model call. | Run fails |
computer_use_browser_unavailable |
No browser could be started for the run. | Run fails |
computer_use_site_blocked |
The page is on a host outside the binding's allowed sites. | Tool error |
computer_use_failed |
The browser action itself failed. | Tool error |
computer_use_upload_refused |
The upload named something that is not a file this run holds: a path, a URL, or a handle no file has. | Tool error |
computer_use_upload_rejected |
A person rejected the upload. Nothing was attached. | Tool error |
computer_use_upload_timed_out |
Nobody answered the upload's gate before the enterprise timeout. Nothing was attached. | Tool error |