Skip to content

Connecting

Pairing, and two checks on every connection

Any web page can open a WebSocket to 127.0.0.1, so Browsentic Bridge checks who is calling before anything else.

  • The Origin header decides first

    Browsers set it and page scripts cannot forge it, so a web page is refused before any credential is read. A Host that is not loopback is refused too, which stops DNS rebinding.

  • Then a secret that never crosses the wire

    Pairing takes a single-use code that expires in ten minutes. Both sides prove they hold it over fresh nonces, so a program squatting on the port cannot pose as Browsentic Bridge.

  • A session key you can revoke

    Pairing leaves a key bound to that browser. It survives restarts and updates until you run browsentic revoke.

Acting

Approvals: what the agent must ask you first

Reading and clicking need no approval. Anything that commits something or sends data somewhere stops and says what it is about to do.

Asks you first

  • Submitting a form, Enter in a field included
  • Uploading or downloading a file
  • Leaving the sites the run is about
  • Moving to a tab it was not pointed at
  • Solving a captcha
  • Running code the agent wrote, shown in full
  • Typing a saved password into a page
  • Calling a site’s WebMCP tool

Refused, whatever you say

  • javascript:, data: and file: links
  • Reading a page’s raw HTML
  • Reading network response bodies
  • A saved password in a URL
  • Running page code for an MCP client

Deny is final: the agent is told to stop, not to look for another way. A card the agent stops waiting for comes down, so a late yes never runs anything. An MCP client has nobody to ask, so anything that would ask is refused for it by default.

Reading

What the agent sees of a page

A hostile page can try to talk the agent into something, so page text is changed before the model reads it, and the run is held to its sites.

  • Fenced

    Page text arrives inside a marker that is random every time Browsentic Bridge starts, so a page cannot fake the end of it and pass as your instructions.

  • Sealed

    Passwords, API keys, tokens and card numbers become placeholders. The value stays in your browser and goes back only into a field you approve.

  • Scoped

    A run stays on the sites it started on or that you named. Going anywhere else asks you, and nothing read from a page can widen the list.

On your computer

What the agent can reach on your computer, and what Browsentic stores

The side panel starts a third-party agent CLI as you. Browsentic narrows what that process can touch, as far as each CLI allows.

claude Claude Code, the strictest
  • This browser, through Browsentic
  • Your shell
  • Your files
  • Your other MCP servers
  • Cloud keys in your environment

Each CLI offers different levers: Claude Code’s allowlist is the strictest, Codex can still read files through its read-only sandbox, and Antigravity follows your own settings.

  • Environment sealed

    Cloud keys, registry tokens and database URLs from your shell are removed before the agent starts. It keeps only what it needs to sign in.

  • Recordings keep placeholders

    A recording stores which field you filled, not what you typed. Keeping real values is a per-recording choice, off by default.

  • Nothing in your repository

    Keys, logs and config live in ~/.browsentic, readable only by you. Skills, recordings and screenshots live in ~/browsentic.

  • Speech is the browser’s own

    No speech model is downloaded. In Chrome, audio goes to Google to become text, and Browsentic only receives the text.

Limits

Two risks no layer removes

Neither is a bug with a fix on the way. Read both before you rely on Browsentic.

Pairing controls which browser, not which program

Anything running as your user can read Browsentic Bridge’s lockfile and drive a browser you already paired. Your user account is the trust boundary.

Prompt injection is still possible

Fencing, scope and approvals make it harder, not impossible. A persuasive page can still mislead the agent, so keep approvals on and be deliberate on sites you do not trust.

Questions

Security questions people ask

Is it safe to let an AI agent use my logged-in browser?

As safe as the limits you keep on it. Browsentic connects to nothing until you pair it, asks before anything that submits, uploads or leaves the site, keeps passwords away from the model and fences page text as data. No layer makes a model immune to a persuasive page, so keep approvals on for anything that matters.

Can a website connect to Browsentic?

No. Browsentic Bridge refuses any connection whose Origin is a web page, and browsers set that header themselves. An extension still needs a pairing code or session key, and neither ever crosses the wire.

Does Browsentic see my passwords?

The agent does not. A password, API key, token or card number on a page is replaced by a placeholder before the result leaves the browser, and the value is typed back only into a field you approve. Browsentic Bridge never holds it.

Can the agent run commands on my computer?

It is started with the browser’s tools and, as far as its CLI allows, without a shell or file access. Claude Code’s allowlist is the strictest; Codex can still read files through its read-only sandbox, and Antigravity follows your own settings.

Does anything go to a Browsentic server?

There is no Browsentic server. The extension talks only to Browsentic Bridge on 127.0.0.1, and the Bridge starts your agent CLI, which talks to its own model provider as it always does. In Chrome, voice input goes to Google to become text.

Report a vulnerability

Open a private GitHub security advisory rather than a public issue, so it is looked at before anything is published.

Give your browser a superpower.

Free and open source under Apache 2.0, with no API key, subscription or account. One line installs Browsentic Bridge and opens the extension’s store page. Nothing connects until you pair the two.