intentic
Create your workspace
Integrations

Your own browser

An extension that lets your sandbox work in the browser you are already signed into — on the sites you allow, one at a time, while you watch every click.

On this page(7 sections)

Why this exists next to the sandbox's own browser

Your sandbox already has a Chromium with logged-in profiles, and for most work it is the better tool: it runs while nobody is at the keyboard. What it can never be is you — your passkey, your employer's SSO, your bank's device check, the sites that refuse a datacentre address. Those are not a matter of having the right cookie; they are a matter of being the browser the account was enrolled on.

So this borrows that browser rather than impersonating it, without copying its profile or sign-ins as part of normal use. Content from a site you allow is sent to the sandbox so the agent can understand and operate that page. A site's session cookies leave only through the separate hand-over action, behind an off-by-default switch and an in-page confirmation, and you are sitting in front of the thing while it happens.

Connecting one

Add Your Chrome (or Your Edge) under Sandbox → Capabilities, then pressConnect on its card. You get a one-time code that expires in about ten minutes.

Install the extension in the browser you want to connect and paste the code into its popup. If that browser is the one you are reading this in, you paste nothing: the card hands the code to the extension directly and the popup lights up with Connect.

The extension then holds one outbound connection to your sandbox while the browser is open. No port is opened on your network, and there is nothing to configure on your router.

Which sites, and who decides

Not the sandbox. Sites are Chrome's own optional host permissions, and Chrome only grants one when a person clicks in the extension's own window — so the agent cannot grant itself a site, however it is asked to. When it needs one it leaves a request: the toolbar icon shows !, and the popup names the site with the reason the agent gave. You answer read onlyor read and act, and you can take either back in the extension or in Chrome's settings.

A tab on a site you have not allowed is not merely off limits: your browser withholds its address from the extension altogether, so a connected browser does not disclose what else you have open. The agent's tab listing says exactly that, rather than showing blanks.

What the card decides

These are on the capability's card in your sandbox, and the extension is what enforces them:

  • Read the page (on by default) — Its elements and its text, on a site you allowed. Off leaves the connection inert, and the card says so.
  • Click and type (on by default) — On by default, unlike a computer's pointer control, because driving the page IS this connector — a browser that may only look is a worse way to fetch a URL. The grant that bounds it is per site.
  • Take screenshots (off by default) — The visible tab as an image. Off by default because a page reading is a list the extension built, and a screenshot is whatever that window happens to be showing.
  • Hand sessions to the sandbox (off by default) — The one switch that copies a credential rather than borrowing the browser holding it. Needs your click on the page every single time as well.
  • Ask before acting (sensitive by default) — When you are asked in the page first: on anything that smells of money, deletion or a password (the default), on everything, or never.

Watching it work

Every action draws a line in the corner of the tab it happened in: the agent clicked "Send". On a page that deals in passwords, payment or deletion, it asks before it acts — in the page, next to the thing it is about — and a question nobody answers is a no.

Pause in the popup refuses every tool call until you resume, and the toolbar icon says so while it is paused. The popup also keeps the last two hundred actions, so "what did it just do" has an answer that is not a guess. Nothing typed into a page is recorded there — only that something of that length was.

Handing a site over

A browser has to be open to be borrowed, which is the one thing a long job cannot rely on. So there isconnect_site: it copies one site's sign-in into your sandbox's own browser, against an account that already exists there, and from then on the agent can work on that site with your laptop shut.

It needs the switch on the card, your confirmation on the page every time, and it never shows the agent what moved — the answer it gets back is a count and a site name. Worth knowing before you use it: some sites end a session that starts appearing from a second place.

Ending it

Revoke on the card drops the extension's key and cuts its connection immediately; the extension stays installed and can be paired again. Remove takes the capability with it. From the browser's side, pausing, revoking a site, or uninstalling the extension all work without touching the sandbox, which is the right way round: it is your browser.

  • Your own machine: the same idea for a whole device: a shell, files and the screen.
  • Capabilities: everything else a sandbox can be connected to, and what each one may touch.
  • Privacy: what the extension stores, what leaves your browser, and what we never receive.
More in Integrations

Type to search every page, in the docs and the API reference.