Kernel for AI agents
Kernel gives agents access to cloud-hosted browsers and browser automation infrastructure for running scripted web tasks. Engineering teams pull it into internal tools and scripts rather than building the same capability themselves. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Kernel.
Run a browser automation task
Execute a scripted browser action against a target site to complete a repetitive web task.
Check a browser session's status
Check the status of a running cloud browser session before sending it a new command.
Manage credentials with approval
Store or update a stored credential in the vault only after the user explicitly confirms it.
25 Kernel actions, graded by risk.
Every Kernel action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
3Look things up. Allowed by default.
- kernel.search_docsSearch docs
- kernel.get_more_toolsGet more tools
- kernel.get_connection_contextGet connection context
write
22Create and change things. Allow, or ask the user first.
- kernel.webmcpWebmcp
- kernel.manage_appsManage apps
- kernel.browser_curlBrowser curl
- kernel.exec_commandExec command
- kernel.manage_vaultsManage vaults
- kernel.manage_proxiesManage proxies
- kernel.manage_replaysManage replays
- kernel.computer_actionComputer action
- kernel.manage_api_keysManage api keys
- kernel.manage_browsersManage browsers
- kernel.manage_profilesManage profiles
- kernel.manage_projectsManage projects
- kernel.submit_feedbackSubmit feedback
- kernel.manage_extensionsManage extensions
- kernel.manage_credentialsManage credentials
- kernel.manage_vault_cardsManage vault cards
destructive
0Delete, cancel or archive. Ask first, or deny outright.
- No destructive actions.
Kernel in three steps.
- 01Your users connect KernelThey sign in to Kernel on Arc0 Connect, under your brand, and approve the access you ask for.
- 02You set the rulesReads run, and writes like “webmcp” can wait for the user to approve.
- 03Any agent can actYour agent calls Kernel through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('kernel', { read: 'allow', write: 'ask', // webmcp destructive: 'deny', }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Kernel connects.
Kernel runs its own MCP server behind OAuth. Arc0 registers the client, users approve access on Arc0 Connect, and your agent reaches Kernel through the same endpoint, policies and audit log as every other app.
The same Kernel connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- OAuth 2.0 (MCP)
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Kernel from any agent.
Kernel and Arc0, answered.
Can I use Kernel with Claude, ChatGPT or Cursor?
Yes. Connect Kernel to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Kernel actions you allow.
How do users connect Kernel?
Kernel runs its own MCP server behind OAuth. Arc0 registers the client, users approve access on Arc0 Connect, and your agent reaches Kernel through the same endpoint, policies and audit log as every other app.
Which Kernel actions can my agent take?
25 in total: 3 read, 22 write and 0 destructive, such as “webmcp”. Your policies decide which of them each agent may call.
Can I make my agent read-only in Kernel?
Yes. Allow read actions and deny writes in the Kernel policy. Your agent can still look things up, and any write it attempts is blocked and logged.
Can my own backend call Kernel too?
Yes. The same Kernel connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Kernel into your agent.
Your users connect Kernel once, under your brand. Your agent gets 25 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan