Thanks to visit codestin.com
Credit goes to cockroachbrowser.com

Cockroach Browser AI browser automation logo Release candidate 0.5.0-rc.1

Governed browser execution for AI agents

Full browsers when fidelity matters. A measured 28.25 MiB non-visual lane when it does not.

Route AI automation to Chromium, Firefox, WebKit, or an explicitly preflighted experimental Obscura lane. Keep every bounded session behind declared origins, effects, approvals, resource budgets, and verifiable evidence.

Chromium + Firefox + WebKitExperimental Obscura lane66 typed actionsMCP + SDK + API

Open source under AGPL-3.0-or-later. Price: $0. No hosted browser, proxy network, or CAPTCHA bypass is claimed.

01 / RUN IT

Install, diagnose, then verify the claim.

Use the release candidate for the runtime. Use the repository verifier to bind the checked-in benchmark artifacts to their source, binary digest, narrative, and exact pass and fail verdicts.

TerminalInstall and diagnose
$ npm install --global [email protected]
$ cockroach-browser bootstrap
$ cockroach-browser doctor
Local firstLoopback defaultToken authenticated
RepositoryVerify checked-in proof
$ git clone https://github.com/AjnasNB/cockroach-browser.git
$ cd cockroach-browser
$ npm ci
$ npm run verify:lightweight-proof

02 / ROUTE

Two execution lanes. One explicit capability contract.

Choose from machine-readable support data before launch. Cockroach Browser does not silently trade fidelity for memory inside a governed session.

Lane AFull fidelity

Chromium, Firefox, and WebKit

Use the full engines when the job requires rendered behavior, screenshots, PDFs, traces, HAR, video, frames, uploads, downloads, profiles, extensions, or upstream operator APIs.

  • Headless or headed sessions
  • Complete pinned Playwright and Puppeteer Core re-exports
  • Semantic snapshots, actions, evidence, and receipts
Configure a full-engine session
Lane BMeasured lightweight

Experimental Obscura for compatible non-visual work

Use the separately installed, digest-pinned provider only after exact capability preflight. Compatible work includes bounded navigation, JavaScript, DOM inspection, forms, and structured extraction.

  • Explicit experimental opt-in
  • Visual actions denied by Cockroach policy
  • Lightpanda remains manifest and preflight only
Inspect engine negotiation

Routing rule: use the lightweight lane only when every required capability is admitted. Use a full engine for visual output, browser fidelity, persistent state, or unsupported work.

03 / PREFLIGHT

Unsupported work fails before launch.

Inspect exact engine capabilities without creating a session. Supported requirements pass. Experimental requirements need explicit acceptance. Unsupported requirements always reject.

TypeScriptExact action preflight
import { preflightEngineActions } from "cockroach-browser";

const check = preflightEngineActions({
  engine: "obscura",
  actions: ["navigate", "extract.structured"]
});

if (!check.ok) {
  console.error(check.unmet);
}
  1. supported
    Admitted

    The exact engine requirement is implemented for that lane.

  2. experimental
    Denied by default

    Set allowExperimental: true only after the host accepts the boundary.

  3. unsupported
    Always rejected

    Choose another engine. Preflight never silently changes lanes.

GET /v1/enginesBrowserClient.engines()browser_enginesbrowser_engine_preflight

04 / GOVERN

Authority, action, evidence, and memory stay distinct.

The runtime keeps browser execution bounded and reviewable. Optional integrations add approval or cited project memory without inheriting browser authority.

01Session contract

Owner, purpose, origins, actions, effects, credentials, and finite budgets.

02Browser dispatch

One typed action against one admitted engine and session.

03Evidence record

Structured outcome, artifact IDs, input and output digests, and receipt hash.

04Optional cited memory

Qarinah receives versioned metadata through a host-supplied sink. It cannot dispatch actions.

Maqam

Approval when consequence demands it

A separately configured Maqam adapter can own exact approval, replay protection, dispatch, and governance receipts for selected browser operations.

Review the approval boundary
Qarinah

Cited history without ambient authority

The optional adapter emits metadata-only outcomes with evidence IDs and receipt hashes. Retrieved history is untrusted observation, not instruction or authorization.

Review the memory boundary

05 / CONNECT

Keep the browser surface your tools already expect.

Use governed sessions for agent work or import the complete pinned upstream operator APIs when unrestricted library compatibility is the job.

Full engines

Chromium, Firefox, WebKit

Headless or headed sessions through the bounded runtime.

Operator APIs

Playwright and Puppeteer Core

Complete re-exports from the exact pinned declaration sets, kept separate from bounded policy claims.

Browse the generated API inventory
Agent and app clients

MCP, TypeScript, HTTP, CLI

Plus authenticated Python, Java, .NET, Ruby, and Go daemon clients.

Protocols

CDP, WebDriver BiDi, mobile WebDriver

Explicit CDP attachment, raw BiDi transport, and Appium-compatible mobile transport.

205 generated class and interface owners1625 grouped members1998 signaturesMachine-readable inventory

06 / DEPLOY

Start local. Move only into infrastructure you control.

The package ships runtime and operator surfaces, not a Cockroach-operated browser cloud. Choose the deployment shape that matches your host, evidence, and capacity boundary.

01

Embedded runtime

Construct BrowserRuntime inside a TypeScript process and keep orchestration in the host.

02

Loopback daemon

Run the authenticated local API, dashboard, metrics, jobs, and activity stream on the operator machine.

03

Owned container

Package a Docker worker with explicit storage, memory, shared-memory, and network boundaries.

04

Reviewed worker pool

Route to healthy authenticated workers by declared capacity, weight, and tags. Keep profiles local to their owner.

07 / APPLY

Built around the jobs browser operators repeat.

The same runtime can serve agent interaction, release evidence, stateful local workflows, and owned browser infrastructure without pretending those jobs have one universal engine.

AI agent builders

Observe, target, act, and return a cited result

Give a planner bounded semantic snapshots, snapshot-scoped references, typed actions, challenge state, and receipt-linked outcomes.

Connect an agent
QA and release engineering

Keep visual and diagnostic evidence together

Capture screenshots, PDFs, paired captures, traces, HAR, video, console, network, audits, and visual diffs on full engines.

Inspect evidence features
Local and controlled environments

Automate stateful applications without a hosted dependency

Use named isolated profiles, storage checkpoints, files, downloads, forms, tabs, and explicit secrets in your own process or worker.

Explore workflow patterns
Browser platform maintainers

Expose one governed contract across several engines

Preflight capabilities, enforce per-session budgets, monitor workers, and retain machine-readable evidence for each admitted operation.

Operate the runtime

08 / VERIFY

Exact proof, including the failed target.

The 30 MiB fixture passed. The 25 MiB fixture did not. Together they preserve 958 raw process-tree observations, every measured launch, conformance checks, source identity, and artifact digests.

Obscura 0.2.1 constrained non-visual fixture recorded 2026-09-03
TargetVerdictMinMedianp95MaxObservations
30 MiBPASS28,893,18429,347,84029,569,02429,622,272
28.25 MiB
478
25 MiBFAIL28,831,74429,323,26429,634,56029,679,616
28.30 MiB
480
Frozen RC1 evidence

Every public number binds to exact artifacts and source.

478 observations at 30 MiB plus 480 at 25 MiB equals 958 retained observations.

30 MiB artifact
obscura-0.2.1-constrained-non-visual-30mib-2026-09-03-rc1.jsonf90b31d6f5d5096300ac2722ed835db0483a76dc4d51ee85e86604a6634c0aa7
25 MiB artifact
obscura-0.2.1-constrained-non-visual-25mib-2026-09-03-rc1.json581eb93577d6b52c71e02d7e0b71914f88acd0920a6e0e06925aae0a4575d2df
Source tree SHA-256
fb0c4597e39f319dd9b6f3bab02777c395e9d8d84906981bf939a39b470e7279
Runtime build SHA-256
6738efa4000ba482db83c9dc95ba2f21caed31de96f30dcd342e5dc722d86025
Benchmark harness SHA-256
08a5294f2d446765f712b93c9bfaaca010b1d043ded638d1f4f57b5038c97e86
130mapped capabilities on current main
119available surfaces on current main
66typed browser actions from source
2immutable benchmark artifacts
Access boundary

Challenges are a handoff, not a bypass target.

The runtime detects login, consent, CAPTCHA, and denied-access states, records the state, pauses automation, and waits for a human or an explicitly authorized resolver. It does not defeat site controls or promise access after denial.

Read the security model