Execution guide

Browser Use

Browser Use gives an agent a browser it can observe and control: navigate, inspect elements, fill forms, manage tabs and capture screenshots. A worker owns each live session. The dashboard lets you inspect its activity, review recordings and temporarily take human control.

This is station-browser-use. The separate browser runtime runs Station jobs inside a Web Worker or service worker. A Browser Use session also does not require a sandbox workspace.

The agent observes, acts, then observes again
  1. Agent applicationScoped toolsThe host grants a worker, sessions and profiles. The model chooses an allowed action.
  2. Station workerSession managerRoutes the action to its owning browser and enforces capacity and control leases.
  3. Browser adapterPage + contextRuns the action and returns page data or screenshot pixels for the next decision.
Human takeover: an exclusive, expiring control lease pauses competing automation. Releasing it returns control to the agent.
Feed observations back to the agent after each meaningful action. Website content is untrusted input, not new instructions for the agent.

Choose where the browser runs

BackendExecutionImportant boundary
PlaywrightLocal Chromium with structured actions, profiles, files, diagnostics and traces.Trusted host workload; browser processes do not isolate tenants from the worker OS.
Container PlaywrightOne Docker or Podman container per session; retained profile storage when configured.Operator-managed engine, image, seccomp, egress policy and storage quotas.
Bun WebViewOwned Bun subprocess using the supported WebView runtime.Smaller capability set. Check capabilities before using advanced browser commands.
Browserbase / SteelProvider-managed session controlled over Playwright CDP.Provider credentials, profile grants, session limits and cleanup stay with the operator.

Adapters expose capabilities; an application must check them instead of assuming every backend supports every command. Hosted proxies and challenge detection can help diagnose access failures, but do not guarantee CAPTCHA-free access. Remote downloads and trace exports are currently disabled pending provider-specific artifact handling. See the remote browser guide.

Give an agent browser tools

Create one toolset per authorized workflow. Bind connection details and grants in your application; the model must not choose credentials or tenant identity.

import { BrowserUseClient, createBrowserAgentTools } from "station-browser-use/agent"; const tools = createBrowserAgentTools({  client: new BrowserUseClient({    baseUrl: "https://station.example.com",    stationId: "tenant-browser-worker",    apiKey: process.env.STATION_EXECUTION_KEY!,  }),  maxSessions: 1,  profileIds: ["research"], // Explicit grant; omit for ephemeral sessions.});try {  // Mount name, description and inputSchema in your agent framework.  // Call tool.execute(input, { signal }) for each selected tool.  // Send result.images through the model's native image channel.  await runYourAgent(tools); // Your application's agent loop.} finally {  await tools.close();}

The tools cover open, sessions, navigate, observe, interact, screenshot, checkpoint, resume and close. Structured interactions include semantic locators, frames, page selection, pointer input and file transfer where supported. Screenshots are image results: stringifying base64 into text does not give the model vision. The Foundry example demonstrates that bridge.

Prefer roles, labels and test IDs to fragile CSS paths. Inspect again after navigation or a page update, because old element positions can be stale. Confirm the result of a consequential action before proceeding. A lost response does not prove a click or upload failed; reconcile the session instead of blindly repeating it.

Session, profile and checkpoint are different

Persist the account; recreate the browser
  1. OpenGranted profileLoad retained cookies and browser storage into one exclusively owned session.
  2. WorkLive sessionTabs, JavaScript, requests and control leases belong to the running browser.
  3. Close + reopenNew sessionReuse persisted profile data after release. Authentication may still need renewal.
A checkpoint records sanitized page URLs and open options. Resuming creates a new session; it cannot restore live DOM, memory, forms or pending requests.

Keep one profile per tenant and account. A browser closing is not an account logout. Profiles contain authentication material and must be protected like credentials. With Steel, wait for profile release and the provider's READY state before reuse. Browser session lifetime and account lifetime are separate.

WhatsApp QR linking through Steel and the dashboard was exercised locally. That does not establish reliable authenticated profile reuse or verified TikTok/Instagram automation. Uploading a file is also separate from publishing it. Upload commands currently accept at most 16 files and 4 MiB of decoded data; large media workflows need additional artifact handling.

Capture a frame every five seconds

Configure recording storage and limits on the worker, then start recording explicitly. This example assumes an already configured adapter.

import { BrowserSessionManager } from "station-browser-use"; const browsers = new BrowserSessionManager(adapter, 4, {  recordingRootDir: "/data/browser-recordings",  stateRootDir: "/data/browser-state",  intervalMs: 5_000,  maxFrames: 120,  maxTotalBytes: 64 * 1024 * 1024,});const session = await browsers.open({ profileId: "research" });const recording = browsers.startRecording(session.id);// ...your browser actions...await browsers.stopRecording(recording.id);await browsers.closeSession(session.id);// Review saved frames in the dashboard's Recordings page.

Recordings are timestamped PNG frames, not continuous video. Busy actions can skip captures, storage or frame limits stop recording, and capture ticks do not keep an idle session alive. At a five-second cadence, 120 frames represent roughly ten minutes if no capture is skipped. Configured disk storage preserves captured frames across worker restarts; it does not keep the browser running.

Operate from the dashboard

Open Browser Use → worker → session. Use its action controls to inspect or operate the selected page, Live for periodic screenshots and human takeover, and Recordings for playback. The page is an observation and control surface; closing the dashboard does not close the remote browser.

KeepWhere it livesWhat it does not restore
ProfileConfigured local/container storage or a granted provider profile.Guaranteed login validity, running scripts or all open tabs.
RecordingWorker recording root, with retention and byte limits.The session itself, or activity between captured frames.
Checkpoint and auditSeparate configured state root, bounded by retention limits.Exact application state or automatic replay of unfinished mutations.
Download / trace artifactSession-scoped artifact store where supported.Durability after session closure. Export needed artifacts beforehand.

Keep profile, recording and state roots separate and assign them to one logical worker. Live sessions remain on their owner; shared queue storage does not migrate them. Worker restarts interrupt browsers. Explicitly reopen or resume after cleanup, and inspect unknown action outcomes before retrying.