Anchor Browser for AI agents
Anchor Browser gives AI agents a way to control a real web browser through an API, turning clicks, typing, and page reading into callable actions. Developers use it to automate web tasks. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Anchor Browser.
Run a browser automation task
Create and deploy a task that clicks through a web flow such as filling a form.
Read content from a live session
Get the webpage content or clipboard content from an active browser session.
Confirm before ending all sessions
Ending every active browser session at once is disruptive and should be confirmed before it runs.
64 Anchor Browser actions, graded by risk.
Every Anchor Browser action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
21Look things up. Allowed by default.
- anchor_browser.list_tasksList Tasks
- anchor_browser.get_profile2Get Profile (v2)
- anchor_browser.list_profilesList Profiles
- anchor_browser.list_sessionsList Sessions
- anchor_browser.get_task_draftGet Task Draft
- anchor_browser.list_extensionsList Extensions
- anchor_browser.get_task_versionGet Task Version
- anchor_browser.get_session_pagesGet Session Pages
- anchor_browser.get_task_metadataGet Task Metadata
- anchor_browser.list_integrationsList Integrations
- anchor_browser.list_task_versionsList Task Versions
- anchor_browser.get_browser_sessionGet Browser Session
- anchor_browser.get_webpage_contentGet Webpage Content
- anchor_browser.list_agent_resourcesList Agent Resources
- anchor_browser.list_task_executionsList Task Executions
- anchor_browser.get_clipboard_contentGet Clipboard Content
write
37Create and change things. Allow, or ask the user first.
- anchor_browser.create_taskCreate Task
- anchor_browser.create_profileCreate Profile
- anchor_browser.update_profileUpdate Profile
- anchor_browser.create_integrationCreate Integration
- anchor_browser.update_task_metadataUpdate Task Metadata
- anchor_browser.create_or_update_task_draftCreate or Update Task Draft
- anchor_browser.run_taskRun Task
- anchor_browser.type_textType Text
- anchor_browser.move_mouseMouse Move
- anchor_browser.paste_textPaste Text
- anchor_browser.click_mouseClick Mouse
- anchor_browser.deploy_taskDeploy Task
- anchor_browser.pause_agentPause Agent
- anchor_browser.upload_fileUpload File
- anchor_browser.resume_agentResume Agent
- anchor_browser.signal_eventSignal Event
destructive
6Delete, cancel or archive. Ask first, or deny outright.
- anchor_browser.delete_taskDelete Task
- anchor_browser.delete_profileDelete Profile
- anchor_browser.delete_extensionDelete Extension
- anchor_browser.delete_integrationDelete Integration
- anchor_browser.delete_task_versionDelete Task Version
- anchor_browser.drag_and_dropDrag and Drop
Anchor Browser in three steps.
- 01Your users connect Anchor BrowserThey add their Anchor Browser api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create Task” can wait for the user, and “delete Task” can be denied outright.
- 03Any agent can actYour agent calls Anchor Browser through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('anchor_browser', { read: 'allow', write: 'ask', // create_task destructive: 'deny', // delete_task }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Anchor Browser connects.
Users add their Anchor Browser api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same Anchor Browser connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Anchor Browser from any agent.
Anchor Browser and Arc0, answered.
Can I use Anchor Browser with Claude, ChatGPT or Cursor?
Yes. Connect Anchor Browser to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Anchor Browser actions you allow.
How do users connect Anchor Browser?
Users add their Anchor Browser api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which Anchor Browser actions can my agent take?
64 in total: 21 read, 37 write and 6 destructive, such as “create Task”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Anchor Browser?
Yes. Actions like “delete Task” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Anchor Browser too?
Yes. The same Anchor Browser connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Anchor Browser into your agent.
Your users connect Anchor Browser once, under your brand. Your agent gets 64 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan