Skip to content
Everruns Cloud is open in early access. Run agents without operating the platform.
IDbrowser_use
CategoryBrowser
FeaturesLeased resources
Dependenciessession_storage
RiskHigh (the model reads and acts on whatever the page shows)
AvailabilityExperimental

Browser use lets an agent work in a web browser through what the page is made of, not only what it looks like. The agent reads the page as an accessibility tree, where every element it can act on carries a ref such as ref_3. It then clicks, hovers, scrolls to, or fills that element by ref. It can still take screenshots and act on viewport coordinates when the structure is not enough, and it can open, switch, and close tabs.

The browser tool is a regular function tool, so it works with any model. Screenshots and zoom need a model that accepts images; the other actions return text. It follows the action vocabulary of Claude’s browser_toolset_20260801. On Claude models that take that toolset, the agent uses Claude’s own browser tool instead, which those models are trained on, and reads the open tabs from the toolset’s browser state. The actions, the safety rules, and the limits are the same either way.

The browser is the session’s persistent Browserless browser. Connect Browserless from Settings → My agent experience first. The agent shares that browser with the Browserless tools and with Computer Use, so a page one opens is a page the others see.

Performs one action. Every successful result carries a browser_state object: every open tab with its tab_id, title and URL, which tab is active, and in state_changes the tabs opened since the previous result.

A target is either {"type": "ref", "ref": "ref_3"} or {"type": "coordinate", "x": 412, "y": 230}, in pixels of the viewport.

actionParametersWhat it does
read_pageoptional filter (interactive or all), depth, refRead the page as an accessibility tree with refs. By default it lists what is in the viewport; interactive lists only the controls; all includes the rest of the page; ref reads one element’s subtree
findqueryUp to 20 elements that best match a description such as search box or sign up button
get_page_textnoneThe page’s text, main content first
form_inputtarget (a ref), value (text, a choice, or true/false for a checkbox)Set a field’s value and fire its input and change events
left_click, right_click, middle_click, double_click, triple_clicktarget, optional modifiers such as shiftClick the element’s center or the point
hover, mouse_movetarget (mouse_move takes a coordinate)Move the pointer
left_click_dragfrom, targetPress, drag, and release
left_mouse_down, left_mouse_uptargetPress or release the left button there
scrolltarget, scroll_direction, optional scroll_amount (1 to 10, default 3)Scroll at that point
scroll_totarget (a ref)Scroll the element into view
typetextType at the keyboard focus
keytext (space-separated keys or combos, such as Tab Tab Enter or ctrl+a), optional repeatPress keys
hold_keytext, duration (seconds, up to 30)Hold keys down, then release them
waitduration (seconds, up to 30)Pause
screenshotnoneCapture the viewport
zoomregion ([x0, y0, x1, y1])That part of the viewport, enlarged to the viewport size
navigateurl, or back, forward, reloadLoad a page or step through history
new_tab, list_tabsnoneOpen a blank tab and make it current, or list the tabs
switch_tab, close_tabtab_idMake a tab current, or close it

Any action also takes an optional tab_id to act on that tab; it becomes the current tab.

Example calls:

{ "action": "find", "query": "email field" }
{ "action": "form_input", "target": { "type": "ref", "ref": "ref_4" }, "value": "[email protected]" }
{ "action": "left_click", "target": { "type": "ref", "ref": "ref_7" } }

Refs belong to the page they were read from. After a navigation, or when the page removes the element, using one returns an error that tells the agent to read the page again; a ref is never applied to a different element.

javascript_exec, file_upload, read_console, and read_network are not offered. A call that asks for one is refused.

FieldDefaultDescription
viewport_width1280Viewport width in pixels (320 to 1920)
viewport_height800Viewport height in pixels (320 to 1200)
max_actions_per_session500Hard cap on actions in one session
native_toolstrueUse Claude’s native browser toolset on models that have one. When off, every model uses the browser function tool.

When Claude sends several browser actions in one turn and one fails, the later ones are not run; each answers that an earlier action failed.

  • The model reads everything on the page. Text, tab titles, and URLs can try to steer the agent. The capability tells the model to treat them as untrusted data and to stop and ask before typing credentials, making purchases, sending messages, or confirming irreversible actions. Add tool_approval when a person must approve every browser call before it runs.
  • Refs stay out of the page. Everruns keeps the table that maps refs to elements; the page cannot read or move it, so a ref read as “Cancel” cannot be pointed at “Buy”.
  • Page scripts cannot tamper with reads and fills. get_page_text and form_input run in a separate script world, so a page that overrides built-in functions does not change what they read or write.
  • Keep credentials out of reach. Do not give a browser-use agent a browser that is signed in to accounts it should not use.
  • Egress. navigate takes only http and https addresses; an address without a scheme is read as https. It refuses private and internal addresses and follows the session’s network access list. Everruns makes every request the page makes, in every tab, and applies the same rules to each one. If a page navigates somewhere blocked on its own, it is reset to a blank page and the action reports an error.
  • Budget. max_actions_per_session stops runaway loops.

Browser use is experimental and ships behind the browserless_browser_use feature flag (FEATURE_BROWSERLESS_BROWSER_USE sets its rollout grade).