$ npm install --global [email protected] $ cockroach-browser bootstrap $ cockroach-browser doctor
Release candidate 0.5.0-rc.1
Governed browser execution for AI agents
Full browsers when fidelity matters. A measured 28.25 MiB non-visual lane when it does not.
Route AI automation to Chromium, Firefox, WebKit, or an explicitly preflighted experimental Obscura lane. Keep every bounded session behind declared origins, effects, approvals, resource budgets, and verifiable evidence.
Open source under AGPL-3.0-or-later. Price: $0. No hosted browser, proxy network, or CAPTCHA bypass is claimed.
01 / RUN IT
Install, diagnose, then verify the claim.
Use the release candidate for the runtime. Use the repository verifier to bind the checked-in benchmark artifacts to their source, binary digest, narrative, and exact pass and fail verdicts.
$ git clone https://github.com/AjnasNB/cockroach-browser.git $ cd cockroach-browser $ npm ci $ npm run verify:lightweight-proof
02 / ROUTE
Two execution lanes. One explicit capability contract.
Choose from machine-readable support data before launch. Cockroach Browser does not silently trade fidelity for memory inside a governed session.
Chromium, Firefox, and WebKit
Use the full engines when the job requires rendered behavior, screenshots, PDFs, traces, HAR, video, frames, uploads, downloads, profiles, extensions, or upstream operator APIs.
- Headless or headed sessions
- Complete pinned Playwright and Puppeteer Core re-exports
- Semantic snapshots, actions, evidence, and receipts
Experimental Obscura for compatible non-visual work
Use the separately installed, digest-pinned provider only after exact capability preflight. Compatible work includes bounded navigation, JavaScript, DOM inspection, forms, and structured extraction.
- Explicit experimental opt-in
- Visual actions denied by Cockroach policy
- Lightpanda remains manifest and preflight only
Routing rule: use the lightweight lane only when every required capability is admitted. Use a full engine for visual output, browser fidelity, persistent state, or unsupported work.
03 / PREFLIGHT
Unsupported work fails before launch.
Inspect exact engine capabilities without creating a session. Supported requirements pass. Experimental requirements need explicit acceptance. Unsupported requirements always reject.
import { preflightEngineActions } from "cockroach-browser";
const check = preflightEngineActions({
engine: "obscura",
actions: ["navigate", "extract.structured"]
});
if (!check.ok) {
console.error(check.unmet);
}
- supportedAdmitted
The exact engine requirement is implemented for that lane.
- experimentalDenied by default
Set
allowExperimental: trueonly after the host accepts the boundary. - unsupportedAlways rejected
Choose another engine. Preflight never silently changes lanes.
GET /v1/enginesBrowserClient.engines()browser_enginesbrowser_engine_preflight04 / GOVERN
Authority, action, evidence, and memory stay distinct.
The runtime keeps browser execution bounded and reviewable. Optional integrations add approval or cited project memory without inheriting browser authority.
Owner, purpose, origins, actions, effects, credentials, and finite budgets.
One typed action against one admitted engine and session.
Structured outcome, artifact IDs, input and output digests, and receipt hash.
Qarinah receives versioned metadata through a host-supplied sink. It cannot dispatch actions.
Approval when consequence demands it
A separately configured Maqam adapter can own exact approval, replay protection, dispatch, and governance receipts for selected browser operations.
Review the approval boundaryCited history without ambient authority
The optional adapter emits metadata-only outcomes with evidence IDs and receipt hashes. Retrieved history is untrusted observation, not instruction or authorization.
Review the memory boundary05 / CONNECT
Keep the browser surface your tools already expect.
Use governed sessions for agent work or import the complete pinned upstream operator APIs when unrestricted library compatibility is the job.
Chromium, Firefox, WebKit
Headless or headed sessions through the bounded runtime.
Playwright and Puppeteer Core
Complete re-exports from the exact pinned declaration sets, kept separate from bounded policy claims.
Browse the generated API inventoryMCP, TypeScript, HTTP, CLI
Plus authenticated Python, Java, .NET, Ruby, and Go daemon clients.
CDP, WebDriver BiDi, mobile WebDriver
Explicit CDP attachment, raw BiDi transport, and Appium-compatible mobile transport.
06 / DEPLOY
Start local. Move only into infrastructure you control.
The package ships runtime and operator surfaces, not a Cockroach-operated browser cloud. Choose the deployment shape that matches your host, evidence, and capacity boundary.
Embedded runtime
Construct BrowserRuntime inside a TypeScript process and keep orchestration in the host.
Loopback daemon
Run the authenticated local API, dashboard, metrics, jobs, and activity stream on the operator machine.
Owned container
Package a Docker worker with explicit storage, memory, shared-memory, and network boundaries.
Reviewed worker pool
Route to healthy authenticated workers by declared capacity, weight, and tags. Keep profiles local to their owner.
07 / APPLY
Built around the jobs browser operators repeat.
The same runtime can serve agent interaction, release evidence, stateful local workflows, and owned browser infrastructure without pretending those jobs have one universal engine.
Observe, target, act, and return a cited result
Give a planner bounded semantic snapshots, snapshot-scoped references, typed actions, challenge state, and receipt-linked outcomes.
Connect an agentKeep visual and diagnostic evidence together
Capture screenshots, PDFs, paired captures, traces, HAR, video, console, network, audits, and visual diffs on full engines.
Inspect evidence featuresAutomate stateful applications without a hosted dependency
Use named isolated profiles, storage checkpoints, files, downloads, forms, tabs, and explicit secrets in your own process or worker.
Explore workflow patternsExpose one governed contract across several engines
Preflight capabilities, enforce per-session budgets, monitor workers, and retain machine-readable evidence for each admitted operation.
Operate the runtime08 / VERIFY
Exact proof, including the failed target.
The 30 MiB fixture passed. The 25 MiB fixture did not. Together they preserve 958 raw process-tree observations, every measured launch, conformance checks, source identity, and artifact digests.
| Target | Verdict | Min | Median | p95 | Max | Observations |
|---|---|---|---|---|---|---|
| 30 MiB | PASS | 28,893,184 | 29,347,840 | 29,569,024 | 29,622,272 28.25 MiB | 478 |
| 25 MiB | FAIL | 28,831,744 | 29,323,264 | 29,634,560 | 29,679,616 28.30 MiB | 480 |
Every public number binds to exact artifacts and source.
478 observations at 30 MiB plus 480 at 25 MiB equals 958 retained observations.
- 30 MiB artifact
- obscura-0.2.1-constrained-non-visual-30mib-2026-09-03-rc1.json
f90b31d6f5d5096300ac2722ed835db0483a76dc4d51ee85e86604a6634c0aa7 - 25 MiB artifact
- obscura-0.2.1-constrained-non-visual-25mib-2026-09-03-rc1.json
581eb93577d6b52c71e02d7e0b71914f88acd0920a6e0e06925aae0a4575d2df - Source tree SHA-256
fb0c4597e39f319dd9b6f3bab02777c395e9d8d84906981bf939a39b470e7279- Runtime build SHA-256
6738efa4000ba482db83c9dc95ba2f21caed31de96f30dcd342e5dc722d86025- Benchmark harness SHA-256
08a5294f2d446765f712b93c9bfaaca010b1d043ded638d1f4f57b5038c97e86
Challenges are a handoff, not a bypass target.
The runtime detects login, consent, CAPTCHA, and denied-access states, records the state, pauses automation, and waits for a human or an explicitly authorized resolver. It does not defeat site controls or promise access after denial.
Read the security model