Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

WebRun Browser Automation

REMOTE · API.WEBRUN.AI · SCANNED AUG 14

Run multi-step tasks in a real Chrome browser: persistent environments, live view, human takeover.

Available components

76 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security97
  • The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
  • Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
  • HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
  • The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
  • DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
  • The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
Schema Quality & AI Usability59
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 7822 tokens (~372/item across 21 items; 21 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management17
  • Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities60
  • Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · api.webrun.ai

# add to Claude Code
claude mcp add --transport http ai-webrun-webrun https://api.webrun.ai/mcp
# ~/.codex/config.toml
[mcp_servers.ai-webrun-webrun]
url = "https://api.webrun.ai/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "ai-webrun-webrun": {
      "type": "remote",
      "url": "https://api.webrun.ai/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add ai-webrun-webrun --url https://api.webrun.ai/mcp --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  ai-webrun-webrun:
    url: "https://api.webrun.ai/mcp"
// mcp.json
{
  "mcpServers": {
    "ai-webrun-webrun": {
      "type": "http",
      "url": "https://api.webrun.ai/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 14 Aug 26 0
    • The server rewrote its instructions, which are the text every model session reads security
    • Tool “list_environments” rewrote its description, which is the text the model reads security
    • Tool “create_agent” rewrote its description, which is the text the model reads security
    • Tool “create_workflow” rewrote its description, which is the text the model reads security
    • Schema quality: 273 → 372 functional
    • “create_workflow” reworded the description of “workListEnabled” cosmetic
    • “create_workflow” reworded the description of “environmentId” cosmetic
    • “create_workflow” reworded the description of “variableValues” cosmetic
    • “create_workflow” reworded the description of “templateVariables” cosmetic
    • “create_agent” reworded the description of “environmentId” cosmetic
    • “create_agent” reworded the description of “memory” cosmetic
    • “create_agent” reworded the description of “prompt” cosmetic
    • “create_agent” reworded the description of “variables” cosmetic
    • “create_workflow” reworded the description of “promptTemplate” cosmetic
    • “create_workflow” reworded the description of “memoryContract” cosmetic
    • “create_workflow” reworded the description of “memory” cosmetic
    • “update_workflow” reworded the description of “workListEnabled” cosmetic
    • “update_workflow” reworded the description of “variableValues” cosmetic
    • “update_workflow” reworded the description of “templateVariables” cosmetic
    • “update_workflow” reworded the description of “promptTemplate” cosmetic
    • “update_workflow” reworded the description of “memoryContract” cosmetic
    • “update_workflow” reworded the description of “memory” cosmetic
  • 13 Aug 26 −1
    • New tool “trigger_workflow”, which the server declares destructive security
    • New tool “pause_agent”, which the server declares destructive security
    • New tool “resume_agent”, which the server declares destructive security
    • New tool “update_workflow”, which the server declares destructive security
    • Schema quality: 137 → 273 functional
    • Schema quality: good → excellent functional
    • New tool “create_agent” functional
    • New tool “create_workflow” functional
    • New tool “get_workflow” functional
    • New tool “list_agents” functional
    • New tool “list_workflows” functional
  • 11 Aug 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 10 Aug 26 0
    • The server rewrote its instructions, which are the text every model session reads security
    • Stability: unverified → 0.03 functional
  • 9 Aug 26 +40
    • Transport: unverified → pass security
    • Authorization: fail → pass security
    • First check of Authorization: partial security
    • MCP protocol: unverified → fail functional
    • Tool coverage: unverified → 100 functional
    • First check of Tool coverage: 100 functional
    • First check of Schema quality: fail functional
    • First check of Schema quality: excellent functional
    • First check of Schema quality: fail functional
    • First check of Tool coverage: 100 functional
  • 8 Aug 26 36

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 14 Aug 2026 · Probed https://api.webrun.ai/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=webrun.ai CN=WE1,O=Google Trust Services,C=US 12 Aug 2026 10 Nov 2026 ECDSA 256 ECDSA-SHA256 5a96d9210ce9d9881318ddab2ee8612d
SANs: webrun.ai, *.webrun.ai
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b
DNSSEC secure

Validation of api.webrun.ai. Secure

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
ai. present 3799 8 Verified
webrun.ai. present 2371 13 Verified
api.webrun.ai. Verified address RRset verified with the apex keys
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer resource_metadata="https://api.webrun.ai/.well-known/oauth-protected-resource/mcp", scope="task:create task:read task:terminate"

Bearer resource_metadata="https://api.webrun.ai/.well-known/oauth-protected-resource/mcp", scope="task:create task:read task:terminate"
Header Value
strict-transport-security max-age=31536000; includeSubDomains
content-security-policy default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
x-content-type-options nosniff
x-frame-options SAMEORIGIN
referrer-policy no-referrer

Protected resource metadata

Document https://api.webrun.ai/.well-known/oauth-protected-resource/mcp
Retrieved Yes
Resource https://api.webrun.ai/mcp
Authorisation server https://app.webrun.ai
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://api.webrun.ai/mcp Verified 200
http (plaintext) http://api.webrun.ai/mcp HTTPS enforced 301 https://api.webrun.ai/mcp
MCP tools · 21 exposed · ~6,881 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
browser_task ~533

Execute a browser automation task in a real Chrome browser running in a WebRun cloud environment (docs.webrun.ai). Creates a session, runs the task, and auto-terminates. Best for simple one-off tasks. May navigate, fill forms, and submit data on third-party websites as the task requires.

NameTypeReqDescription
debugCbooleanEnable debug mode on the instance (default: false)
environmentIdstringEnvironment ID for persistent profile session. Use list_environments to find available IDs. Without this, a disposable instance is used.
filesarrayOptional file IDs to attach (from /files/upload). Max 5 files.
maxDurationnumberMax duration in minutes (default: 5)
modelstringOptional model name or profile key (from global config). Falls back to the configured default.
outputSchemaobjectJSON Schema for structured output (required if outputType is structured_json)
outputTypestringResponse format (default: text)
policyIdstringPolicy ID to apply automation guardrails (domain restrictions, capability controls, LLM role). Optional.
promptstringyesTask description in natural language
proxyobjectProxy configuration. WebRun-managed: { source: "WebRun", country: "GB" }. Custom: { source: "custom", type: "http"|"socks", host, port, username?, password? }. Omit for no proxy.
reach_out_modestringControls proactive chat-platform messages (Telegram/WhatsApp/Slack/Discord/Teams) to bot users on the same environment. Default: "off" — no messages are sent unless this is set explicitly. "guardrail…
secretsarrayDomain-matched secrets [{match, fields}] passed to instance (not stored)
startingUrlstringOptional starting URL
timezonestringIANA timezone name for the session, e.g. "America/New_York", "Europe/London", "Asia/Tokyo". Date/time-sensitive instructions (e.g. "tomorrow morning", "today", "in 2 hours") are interpreted in this t…
webhookobjectWebhook configuration for task completion notification
NameTypeReqDescription
dataobjectTask output payload (instance-authored shape)
environmentobject
errorstring
messagestring
pendingbooleanTrue when the task is still running — poll get_task_status
sessionIdstring
statusstringPresent on guardrail results: 'awaiting_input'
successboolean
taskIdstring|null
typestringResult type, e.g. 'task_completed', 'task_failed', 'guardrail_trigger'

No examples provided.

create_agent ~968

Create a scheduled agent — a recurring or one-time automation that runs on a timer in a real Chrome browser. Two modes. WORKFLOW MODE: pass workflowId plus a schedule — the platform copies everything else (prompt, starting URL, output contract, model, proxy, policy, files) from the workflow and bakes your variables into the prompt; results and memory stay centralised on the workflow. STANDALONE MODE: omit workflowId and provide name, prompt (a Goal / Ground rules / Stages / Output browsing runbook — see the prompt field description), and a schedule; the connection's environment is used automatically. Ask the user only what it should do and when it should run, in plain language — pick sensible defaults for everything else and state them; never ask about environments or technical settings. Results are delivered to your connected chat and appear in session history.

NameTypeReqDescription
environmentIdstringSTANDALONE MODE, rarely needed — OMIT it: the connection-bound environment (or your only one) is applied automatically; never ask the user to choose. Workflow mode always uses the workflow's deployed…
expiresAtstringISO 8601 date-time after which the agent auto-pauses (recurring schedules).
memorystringSTANDALONE MODE: the agent's private notebook, shown to it every run and updated automatically after each run. Seed ONLY durable facts the next run must know (target descriptions, preferences, known…
namestringAgent name. Required standalone; defaults to the workflow title in workflow mode.
outputSchemaobject|arraySTANDALONE MODE: JSON Schema object (structured) or column-name array (structured_csv).
outputTypestringSTANDALONE MODE: output contract (same rules as create_workflow).
promptstringSTANDALONE MODE (required there): The task the browser agent runs, written as a BROWSING RUNBOOK. Structure it as: `Goal:` — one sentence naming the outcome. `Ground rules (every stage, every turn):`…
scheduleobjectyesWhen the agent fires. Required.
startingUrlstringSTANDALONE MODE: page Chrome opens at the start of each run.
variablesobjectWORKFLOW MODE, and only when the workflow's prompt actually contains {{variables}}: values for them, BAKED IN at deploy and reused every run (stored variableValues defaults fill gaps). Every template…
workflowIdstringWORKFLOW MODE: 24-hex id of the workflow to deploy (from list_workflows). The prompt, starting URL, output contract, model, proxy, policy, and files are all copied from it.
NameTypeReqDescription
agentIdstringyes
modestringyes
namestringyes
nextRunAtstring|nullISO 8601 timestamp of the first fire
notesarray
schedulestringHumanized schedule
successbooleanyes
timezonestring
workflowobjectPresent in workflow mode: the workflow this agent was deployed from

No examples provided.

create_session ~410

Create a persistent session in a real Chrome browser running in a WebRun cloud environment (docs.webrun.ai), for multi-step workflows. Returns a sessionId for subsequent commands. With an initial task the browser may act on third-party websites immediately.

NameTypeReqDescription
debugCbooleanEnable debug mode on the instance (default: false)
environmentIdstringEnvironment ID for persistent profile session. Use list_environments to find available IDs. Without this, a disposable instance is used.
modestringSession mode (default: default)
modelstringOptional model name or profile key (from global config). Falls back to the configured default.
policyIdstringPolicy ID to apply automation guardrails (domain restrictions, capability controls, LLM role). Optional.
proxyobjectProxy configuration. WebRun-managed: { source: "WebRun", country: "GB" }. Custom: { source: "custom", type: "http"|"socks", host, port, username?, password? }. Omit for no proxy.
reach_out_modestringControls proactive chat-platform messages (Telegram/WhatsApp/Slack/Discord/Teams) to bot users on the same environment. Default: "off" — no messages are sent unless this is set explicitly. "guardrail…
taskobjectInitial task configuration
timezonestringIANA timezone name for the session, e.g. "America/New_York", "Europe/London", "Asia/Tokyo". Date/time-sensitive instructions (e.g. "tomorrow morning", "today", "in 2 hours") are interpreted in this t…
NameTypeReqDescription
environmentobjectEnvironment this session is bound to, when one was requested
messagestring
sessionIdstringyesSession ID for subsequent commands
streamingobjectLive-view endpoints for the running browser
taskIdstring|nullTask ID when an initial task was provided

No examples provided.

create_workflow ~1,941

Create a new saved workflow. READINESS BAR: if you could not execute the prompt yourself as a human in a browser — which site, which records, which fields, delivered where, matched to each recipient how — it is not ready; first collect the missing business facts from the user (see the TASK INTERVIEW in the server instructions), then create. Requires title and promptTemplate — write the prompt as a browsing runbook following the Goal / Ground rules / Stages / Output contract in the promptTemplate field description. For tasks that must handle each new item exactly once (new messages, forward once, skip seen), set workListEnabled + listType 'monitor' AND author memoryContract {mode:'dedupe', key, emit} — the platform injects the tracking; never write memory steps into the prompt. Created in the connection's environment automatically — omit environmentId and never ask the user to choose one. Write the user's concrete values (names, URLs, numbers) directly into the prompt; use {{variables}} ONLY when the user explicitly wants a reusable template with per-run inputs. Everything else is optional and defaults sensibly — do not quiz the user about settings. A supplied schedule is stored as a setting only — the workflow does not run on a timer until deployed via create_agent; use trigger_workflow to run it now.

NameTypeReqDescription
compatibleToolsarraySites/tools the workflow uses: [{ name, loginUrl, domain, role }].
conciergeNotifystringWhere the concierge announces results (e.g. 'Telegram', 'Slack', 'WhatsApp', 'Microsoft Teams', 'concierge').
departmentstringFree-text department label (e.g. "inventory").
deployedPolicyIdstringPolicy id to run under (must be owned by you).
destinationobjectResult destination chip: { type, sub, description }. Types seen: 'custom-api', 'slack', 'sheets', 'email', 'messaging', 'telegram', 'crm'.
environmentIdstringRarely needed — OMIT it: the connection's bound environment (or your only environment) is applied automatically. Pass only when the user explicitly names a different environment. Never ask the user t…
fileDeferredbooleanDashboard flag: file selection deferred to run time.
flowobjectDashboard flow diagram: { trigger: {kind, phrase}, steps: [{ primary: {label, domain}, verb }] }.
listTypestringWork-list traversal policy: 'static' (one sweep), 'dynamic' (list refreshes each cycle), 'monitor' (persistent parents + consume-once children).
memorystringThe agent's private notebook: shown to it at the start of every run, updated automatically after each run. Seed it ONLY with durable facts the next run must already know — the exact description of a…
memoryContractobjectTracking policy — AUTHOR THIS whenever the task must remember what it already handled (forward once, skip seen items, only new messages): { mode: 'dedupe', key: 'what uniquely identifies one handled…
memoryEnabledbooleanPersist per-workflow agent memory across runs (default true).
modelstringModel profile key. Omit for the account default.
orchestrateFirstbooleanDiscovery mode: one run gathers the WHOLE work list up front, later runs claim one item each.
outputSchemaobject|arrayJSON Schema object (outputType "structured") or array of column-name strings (outputType "structured_csv").
outputTypestringOutput contract: 'text' (default), 'structured' (JSON matching outputSchema), 'structured_csv' (rows for the outputSchema column names).
policyOptedOutbooleanOpt this workflow out of the environment's default policy.
promptTemplatestringyesThe task the browser agent runs, written as a BROWSING RUNBOOK. Structure it as: `Goal:` — one sentence naming the outcome. `Ground rules (every stage, every turn):` — bullet invariants when the task…
proxyobjectProxy for runs. {source:"WebRun", country?} or {source:"custom", type:"http"|"socks", host, port, username?, password?}. Custom passwords are encrypted at rest and never returned.
publicDraftIdstringDashboard public-draft correlation id.
reachOutModestring|nullProactive-chat policy for runs: 'off', 'guardrail_only', or 'full'. Omit (or pass null) to inherit the account default (MCP-initiated runs treat inherit as 'off').
refineMessagesarrayDashboard builder refinement thread rows: [{ role, content }].
requiredFilesarrayPer-run file attachments. Each row may name its own environmentId; ownership is enforced per-file at dispatch.
roiHourlyRatenumber|nullHourly rate for the ROI card.
roiMinutesPerTasknumber|nullMinutes saved per run (dashboard ROI card).
scheduleobjectSaved schedule setting. NOTE: record-only — the workflow does NOT run on a timer until deployed as a scheduled agent (dashboard or Telegram bot).
shortDescriptionstringOne-line summary shown in workflow lists.
skillsarrayWorkflow-scoped skill entries (dashboard shape).
startingUrlstringPage Chrome opens at the start of each run. Omit to let the prompt decide.
templateVariablesarrayONLY for explicitly dynamic workflows (the user asked for a reusable template): metadata for the {{variables}} used in promptTemplate (drives the dashboard fill-in UI). Omit entirely when the prompt…
timezonestringIANA timezone for runs of this workflow (e.g. "America/New_York").
titlestringyesWorkflow title (shown on the dashboard).
triggerobjectHow the workflow is meant to be invoked (informational — see notes). Defaults to {type:'manual', source:'manual'}.
triggerPhrasestringNatural-language phrase that invokes this workflow in chat.
useCaseTagsarrayCategorisation tags.
variableValuesobjectONLY for explicitly dynamic workflows: default values for {{variables}}, keyed by variable name. NOTE: applied only when triggering via MCP trigger_workflow (merged under caller-supplied variables);…
wizardPresetobjectDashboard wizard preset: { technology, useCases[], destination, destinationSub }.
workListEnabledbooleanWork-list mode: the agent works a page list one item per run, reporting each back. SET THIS (with listType 'monitor') for watch-and-handle-once tasks — 'forward each new message', 'reply to new comme…
NameTypeReqDescription
environmentobject
notesarrayCaveats the caller should relay (e.g. the schedule is record-only)
slugstringyes
successbooleanyes
titlestringyes
workflowIdstringyes

No examples provided.

get_task_status ~65

Check the status of a task previously started in a browser session. Use to poll for completion or detect guardrails. Read-only: reports on the task without affecting it.

NameTypeReqDescription
sessionIdstringyesSession ID
taskIdstringyesTask ID to check
NameTypeReqDescription
dataobjectTask output payload when completed (instance-authored shape)
messagestring
sessionIdstring
statusstringyesTask/session state: 'completed', 'failed', 'awaiting_input', 'pending', 'active', 'paused', 'orphaned', or 'not_found'
taskIdstring
typestringRaw result type when the task finished

No examples provided.

get_workflow ~114

Full detail of one workflow: prompt template, {{variables}} and their defaults, trigger + schedule, run settings (starting URL, timezone, model, proxy, output contract, files), memory state, and any pending logins. Identify by workflowId or exact title. Read-only; proxy credentials are masked.

NameTypeReqDescription
titlestringExact workflow title (case-insensitive) — alternative to workflowId
workflowIdstring24-hex workflow id (from list_workflows or create_workflow)
NameTypeReqDescription
environmentIdstring|null
notesarray
outputTypestring
promptTemplatestringyes
scheduleobject|null
scheduleDescriptionstring|null
slugstringyes
titlestringyes
totalTriggersnumber
triggerobject|null
variablesarray
workflowIdstringyes

No examples provided.

guardrail_response ~135

Respond to a guardrail trigger when the browser agent needs human input (credentials, clarification, approval). The response is handed to the live agent, which continues acting on it.

NameTypeReqDescription
filesarrayOptional file IDs to attach (from /files/upload). Max 5 files.
newStatestringHow to continue: 'resume' (default) provides the requested input and continues the task; 'deny' declines the request (response text optional).
responsestringYour response/instructions to the agent. Required when newState is 'resume'.
sessionIdstringyesSession ID
NameTypeReqDescription
messagestringWhat happened and what to do next (poll get_task_status)
sessionIdstring
successbooleanyes
taskIdstring|null

No examples provided.

list_agents ~92

List the account's scheduled agents (cron deployments): schedule, status, next/last run, and whether each is standalone or deployed from a workflow. Scoped to the bound environment when this connection has one; pass scope "all" for every environment. Read-only.

NameTypeReqDescription
scopestring'environment' (default when bound) lists agents in the bound environment; 'all' lists every agent on the account.
NameTypeReqDescription
agentsarrayyes
countnumberyes
scopestringyes

No examples provided.

list_environments ~69

List available browser environments (persistent profiles) for this account. Returns environment IDs needed for persistent sessions in browser_task or create_session. Read-only. NOTE: workflows and agents use the connection's environment automatically — you rarely need this tool for those, and should not ask the user to choose an environment.

Input schema present but exposes no named parameters.

NameTypeReqDescription
boundEnvironmentobject
countnumberyes
environmentsarrayyes
hintstring

No examples provided.

list_sessions ~20

List all active browser sessions for this account. Read-only.

Input schema present but exposes no named parameters.

NameTypeReqDescription
countnumberyes
sessionsarrayyes

No examples provided.

list_workflows ~104

List the user's saved workflows (prompt-templated browser automations, docs.webrun.ai). Shows each workflow's title, schedule, {{variables}}, and run stats. Scoped to the bound environment when this connection has one; pass scope "all" for every environment. Read-only.

NameTypeReqDescription
scopestring'environment' (default when this connection is bound to one) lists workflows deployed to the bound environment; 'all' lists every workflow on the account.
NameTypeReqDescription
countnumberyes
scopestringyes
workflowsarrayyes

No examples provided.

pause_agent ~48

Pause an active scheduled agent — it stops firing until resumed. Get agentId from list_agents.

NameTypeReqDescription
agentIdstringyes24-hex agent id (from list_agents or create_agent)
NameTypeReqDescription
agentIdstringyes
messagestring
namestring
statusstringyes
successbooleanyes

No examples provided.

pause_session_task ~37

Pause the task currently running in a browser session. Resume it later with resume_session_task.

NameTypeReqDescription
sessionIdstringyesSession ID
NameTypeReqDescription
actionstringyesThe control action that was applied
messagestringyes
sessionIdstringyes
successbooleanyes

No examples provided.

resume_agent ~74

Resume a paused scheduled agent — recomputes its next run and reactivates it. A completed work-list agent restarts with a fresh full pass. Refuses if the agent's expiry has passed (extend it on the dashboard first).

NameTypeReqDescription
agentIdstringyes24-hex agent id (from list_agents)
NameTypeReqDescription
agentIdstringyes
messagestring
namestring
nextRunAtstring|null
statusstringyes
successbooleanyes

No examples provided.

resume_session_task ~29

Resume a previously paused task in a browser session.

NameTypeReqDescription
sessionIdstringyesSession ID
NameTypeReqDescription
actionstringyesThe control action that was applied
messagestringyes
sessionIdstringyes
successbooleanyes

No examples provided.

screenshot ~41

Capture a screenshot of the current browser page in an active session. Returns the screenshot as an inline image. Read-only.

NameTypeReqDescription
sessionIdstringyesSession ID
NameTypeReqDescription
errorstring
messagestring
sessionIdstring
successboolean

No examples provided.

send_task ~166

Send a new task to an existing browser session (from create_session). The real Chrome browser may navigate, fill forms, and submit data on third-party websites as the task requires.

NameTypeReqDescription
filesarrayOptional file IDs to attach (from /files/upload). Max 5 files.
outputSchemaobjectJSON Schema for structured output (required if outputType is structured_json)
outputTypestringResponse format
promptstringyesTask description
secretsarrayDomain-matched secrets [{match, fields}] (not stored)
sessionIdstringyesSession ID from create_session
terminateOnCompletionbooleanAuto-terminate after task (default: false)
webhookobjectWebhook configuration
NameTypeReqDescription
dataobjectTask output payload (instance-authored shape)
environmentobject
errorstring
messagestring
pendingbooleanTrue when the task is still running — poll get_task_status
sessionIdstring
statusstringPresent on guardrail results: 'awaiting_input'
successboolean
taskIdstring|null
typestringResult type, e.g. 'task_completed', 'task_failed', 'guardrail_trigger'

No examples provided.

stop_session_task ~37

Cancel the task currently running in a browser session, keeping the session alive for new tasks.

NameTypeReqDescription
sessionIdstringyesSession ID
NameTypeReqDescription
actionstringyesThe control action that was applied
messagestringyes
sessionIdstringyes
successbooleanyes

No examples provided.

terminate_session ~38

End a browser session and free its resources. The session and any running task cannot be resumed afterwards.

NameTypeReqDescription
sessionIdstringyesSession ID
NameTypeReqDescription
actionstringyesThe control action that was applied
messagestringyes
sessionIdstringyes
successbooleanyes

No examples provided.

trigger_workflow ~172

Run a workflow now in its deployed environment. Drives a real Chrome browser: the run may navigate, fill forms, and submit data on third-party websites as the workflow's prompt requires. Pass values for the workflow's {{variables}} in `variables` (stored variableValues defaults fill any gaps). Returns a sessionId — poll get_task_status for the result.

NameTypeReqDescription
forcebooleanWork-list workflows only: when the list reports complete, re-open it for a fresh full pass.
titlestringExact workflow title (case-insensitive) — alternative to workflowId
variablesobjectValues for the workflow's {{variables}}, keyed by exact variable name. Merged over the workflow's stored variableValues defaults.
workflowIdstring24-hex workflow id
NameTypeReqDescription
listCompletebooleanWork-list workflows: every item has been visited (no run started)
messagestring
sessionIdstringPoll get_task_status with this id
successbooleanyes
taskIdstring|null
workflowIdstringyes

No examples provided.

update_workflow ~1,788

Update an existing workflow. Supply workflowId plus only the fields to change: prompt, trigger, schedule, run settings, variables, presentation. Object and array fields are replaced whole; pass null to clear an optional field. Renaming via title keeps the slug stable. The stored schedule stays a saved setting — scheduled agents already deployed from this workflow keep their own timing. promptTemplate follows the same Goal / Ground rules / Stages / Output runbook contract as create_workflow (see that field's description).

NameTypeReqDescription
compatibleToolsarraySites/tools the workflow uses: [{ name, loginUrl, domain, role }].
conciergeNotifystringWhere the concierge announces results (e.g. 'Telegram', 'Slack', 'WhatsApp', 'Microsoft Teams', 'concierge').
departmentstringFree-text department label (e.g. "inventory").
deployedPolicyIdstringPolicy id to run under (must be owned by you).
destinationobjectResult destination chip: { type, sub, description }. Types seen: 'custom-api', 'slack', 'sheets', 'email', 'messaging', 'telegram', 'crm'.
environmentIdstringMove the workflow to a different environment you own.
fileDeferredbooleanDashboard flag: file selection deferred to run time.
flowobjectDashboard flow diagram: { trigger: {kind, phrase}, steps: [{ primary: {label, domain}, verb }] }.
listTypestringWork-list traversal policy: 'static' (one sweep), 'dynamic' (list refreshes each cycle), 'monitor' (persistent parents + consume-once children).
memorystringThe agent's private notebook: shown to it at the start of every run, updated automatically after each run. Seed it ONLY with durable facts the next run must already know — the exact description of a…
memoryContractobjectTracking policy — AUTHOR THIS whenever the task must remember what it already handled (forward once, skip seen items, only new messages): { mode: 'dedupe', key: 'what uniquely identifies one handled…
memoryEnabledbooleanPersist per-workflow agent memory across runs (default true).
modelstringModel profile key. Omit for the account default.
orchestrateFirstbooleanDiscovery mode: one run gathers the WHOLE work list up front, later runs claim one item each.
outputSchemaobject|arrayJSON Schema object (outputType "structured") or array of column-name strings (outputType "structured_csv").
outputTypestringOutput contract: 'text' (default), 'structured' (JSON matching outputSchema), 'structured_csv' (rows for the outputSchema column names).
policyOptedOutbooleanOpt this workflow out of the environment's default policy.
promptTemplatestringThe task the browser agent runs, written as a BROWSING RUNBOOK. Structure it as: `Goal:` — one sentence naming the outcome. `Ground rules (every stage, every turn):` — bullet invariants when the task…
proxyobjectProxy for runs. {source:"WebRun", country?} or {source:"custom", type:"http"|"socks", host, port, username?, password?}. Custom passwords are encrypted at rest and never returned.
publicDraftIdstringDashboard public-draft correlation id.
reachOutModestring|nullProactive-chat policy for runs: 'off', 'guardrail_only', or 'full'. Omit (or pass null) to inherit the account default (MCP-initiated runs treat inherit as 'off').
refineMessagesarrayDashboard builder refinement thread rows: [{ role, content }].
requiredFilesarrayPer-run file attachments. Each row may name its own environmentId; ownership is enforced per-file at dispatch.
roiHourlyRatenumber|nullHourly rate for the ROI card.
roiMinutesPerTasknumber|nullMinutes saved per run (dashboard ROI card).
scheduleobjectSaved schedule setting. NOTE: record-only — the workflow does NOT run on a timer until deployed as a scheduled agent (dashboard or Telegram bot).
shortDescriptionstringOne-line summary shown in workflow lists.
skillsarrayWorkflow-scoped skill entries (dashboard shape).
startingUrlstringPage Chrome opens at the start of each run. Omit to let the prompt decide.
templateVariablesarrayONLY for explicitly dynamic workflows (the user asked for a reusable template): metadata for the {{variables}} used in promptTemplate (drives the dashboard fill-in UI). Omit entirely when the prompt…
timezonestringIANA timezone for runs of this workflow (e.g. "America/New_York").
titlestringWorkflow title (shown on the dashboard).
triggerobjectHow the workflow is meant to be invoked (informational — see notes). Defaults to {type:'manual', source:'manual'}.
triggerPhrasestringNatural-language phrase that invokes this workflow in chat.
useCaseTagsarrayCategorisation tags.
variableValuesobjectONLY for explicitly dynamic workflows: default values for {{variables}}, keyed by variable name. NOTE: applied only when triggering via MCP trigger_workflow (merged under caller-supplied variables);…
wizardPresetobjectDashboard wizard preset: { technology, useCases[], destination, destinationSub }.
workListEnabledbooleanWork-list mode: the agent works a page list one item per run, reporting each back. SET THIS (with listType 'monitor') for watch-and-handle-once tasks — 'forward each new message', 'reply to new comme…
workflowIdstringyes24-hex id of the workflow to update (from list_workflows or create_workflow). Required — the title property here is the NEW title for renames, never an identifier.
NameTypeReqDescription
changesarrayyesHuman-readable field: old → new summaries of what was applied (empty when everything supplied matched the current values)
notesarrayCaveats to relay (record-only schedule, linked scheduled agents, prompt-structure advice)
slugstring
successbooleanyes
titlestring
workflowIdstringyes

No examples provided.