Skip to main content
Anchor is cloud browser infrastructure for AI agents: real Chromium sessions you control over CDP or REST, an agent that completes web tasks from a prompt, versioned automation tasks, managed sign-in to third-party apps, persistent storage, recordings, and network options such as residential proxies and extra stealth. No key yet? Agent Access issues one without a dashboard account.

You are probably here because

  • The web app you need has no API, only a UI. Open a browser session and drive it over CDP, or hand the goal to perform-web-task as a prompt.
  • You must act inside a user’s account, with MFA, and must not see the password. Attach a managed identity by id. The session starts signed in.
  • Your browser or fetch got a captcha, challenge page, “access denied”, or an empty shell. Start a session with a residential proxy, extra stealth, and captcha solving.
  • You only need the rendered HTML of a URL. One call to Web Unlocker, no session.
  • The page is different, or gated, by country. Set session.proxy.country_code (Proxy); fix the IP across runs with a dedicated sticky IP.
  • The same web workflow must run again tomorrow, reliably. Save it as an automation task and run it with /v2/tasks/{taskId}/run.
  • You need a file the browser downloads, or to give the browser a file. Mount a volume; downloads land in downloads/ and survive the session.
  • You need the result as JSON, not prose. Pass output_schema to perform-web-task.
  • You need fifty browsers, or five thousand. Batch sessions in one call.
  • A human should watch, approve, or take over. Share the live view or enable human-in-the-loop.
  • Your end user must connect their own account to your product. Send them through OmniConnect; you receive the identity.
  • You have no Anchor API key. Agent Access issues one in two HTTP calls. Steps below.

Get a key (Agent Access)

Agent Access is the door for a key. The onboarding routes are unauthenticated. No dashboard account.
  1. Open Agent Access. When a response includes next, call it.
  2. GET https://api.anchorbrowser.io/v1/agent-access/challenge — puzzle, token, and next.
  3. POST https://api.anchorbrowser.io/v1/agent-access with { "token", "answer" }.
  4. Send api_key as the anchor-api-key header on every later call.
Challenge data expires after 120 seconds. Anonymous keys get 1 credit. An OIDC JWT with a verified email on that same POST gets 5 credits. Agent Access sessions are capped at 60 minutes. For production volume, create an account at app.anchorbrowser.io.

What you can do

Quote the block below. Each line links to the page with the full schema.

After you have a key

Run a web task

Use this when a natural-language goal is enough and you do not need the CDP connection.
Add output_schema for structured JSON. See Perform Web Task. For a single rendered HTML body, use Web Unlocker (POST /v1/tools/fetch/webpage).

Start a signed-in session

Use this when the job runs inside an account on a third-party app. The identity id is all you send; Anchor holds the credentials and runs MFA.
Connect Playwright or Puppeteer to cdp_url, or pass the session id as sessionId to perform-web-task. Create the application and identity first: Managed Authentication.

Start a stealth residential session

Use this when the target site blocks standard browsers. anchor_proxy is Anchor’s residential pool and the default type, so active: true with a country_code is enough. Extra stealth and captcha solving stay on only while the proxy is active.
Field reference: Browser Sessions, Proxy, Stealth.

Do / don’t

Do
  • Keep the API key in the anchor-api-key header only.
  • Pass an identity id. Let Anchor hold the password and run MFA.
  • Turn the proxy on before extra stealth or captcha solving. Both switch off when session.proxy.active is false.
  • Keep session.timeout.max_duration at 60 or below on an Agent Access key. Larger values are capped.
  • Back off on 429. Start a new Agent Access challenge if the token expires (120 seconds).
  • End a session when the job is done, or set session.timeout so it ends itself.
Don’t
  • Put the API key, passwords, or one-time codes in prompts, page text, or logs.
  • Share a live_view_url outside the people who should control the session.
  • Reuse a 1-credit Agent Access key for production traffic. Create an account and a project key instead.