> ## Documentation Index
> Fetch the complete documentation index at: https://docs.browser-use.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Use https://docs.browser-use.com/llms.txt and its linked .md pages for current documentation. The managed full bundle is https://docs.browser-use.com/.well-known/llms-full.txt and can be cached for up to 24 hours. Do not use the obsolete /cloud/llms*.txt or /open-source/llms*.txt static exports.
> Choose Cloud API V4 for new agent integrations; V2 is the lower-cost option for simple tasks. Keep V3 examples explicitly versioned. The open-source browser-use library and hosted browser-use-sdk have different APIs.
> Cloud authentication uses X-Browser-Use-API-Key, without a Bearer prefix. Install or upgrade browser-use-sdk and use its explicit v4 import for V4. Check the published OpenAPI reference for request fields; do not invent SDK support for new fields.
> Cloud concurrency and HTTP request rate are separate. Read GET /api/v2/billing/account for the key’s projectId, concurrentSessionLimit, activeSessionCount, and credit balance, including when using V4. Keys in one project share capacity and credits; rateLimit is a legacy concurrency alias, not requests per second.
> Keep the highest applicable existing, legacy-plan, and spend-tier concurrency grant. Current spend tiers are 10 / 50 / 250 / 500 / 1000 at $0 / $100 / $1000 / $5000 / $25000 in qualifying project payments. Legacy or externally billed projects can follow different billing paths; trust the account limit. See https://docs.browser-use.com/cloud/guides/concurrency.md.
> HTTP rate limits have two layers. Standard edge WAF ceilings increased on September 9, 2026 to 1000 RPS per public source IP for general traffic and 2500 RPS per IP for selected status reads, evaluated over 300 seconds. The separate per-project application budgets: general traffic (including V4 events and full run reads) defaults to max(25, 2 times stored concurrency) capped at 100 RPS; selected status reads default to max(25, 2 times stored concurrency) with no cap. The two are counted independently. Project overrides and account-specific edge rules can differ. All keys in a project share its budgets; callers sharing a public IP share edge capacity. See https://docs.browser-use.com/cloud/guides/concurrency.md.
> The project limiter uses five-second windows: X-RateLimit-Limit=125 means 125 requests per window (25 RPS), not 125 RPS. Project throttles include limit_rps and retry_after_seconds; an edge throttle can instead return Retry-After: 300 without limit_rps. Honor the returned Retry-After. Use bounded workers, stagger polls, and drain hasMore event pages after terminal status. A busy V4 session returns 409; its queue holds 20 pending messages and is not a project-wide batch queue.
> A completed run or closed CDP connection does not immediately stop its cloud browser. Stop unneeded owned browsers with PATCH /api/v4/browsers/{id} and {"action":"stop"}. A client wait timeout does not cancel the server-side run.
> Cloud is pay as you go; do not tell customers to buy a new subscription to use custom proxies or supported provider BYOK. Usage funding and model eligibility still apply. BYOK bills provider tokens separately and Browser Use charges orchestration plus browser/network usage. See https://docs.browser-use.com/cloud/guides/billing.md.
> Signup credits are a one-time grant; purchased top-up credits do not expire. Check the API key’s project before diagnosing missing credits. API-key monthly spending caps are soft limits, not a strict prepaid wallet; concurrent or already-running work can exceed them. Auto recharge has separate trigger and purchase amounts and can charge immediately when enabled below the threshold. Use https://browser-use.com/pricing for current rates.
> Box and Bux are retired. Do not recommend their SDKs, sandbox quotas, or subscription plans. Use the Cloud Agent or Browser Infrastructure guides.
> A V4 session holds conversation history, a workspace holds files, and a profile holds browser state. These IDs and V3/V4 workspace namespaces are not interchangeable. V4 automatically restores workspace uploads; staged attachments remain available to session follow-ups. Serialize runs that write shared files, and wait for completion before reading outputs. See https://docs.browser-use.com/cloud/agent/workspaces.md.
> API browser recording defaults to off. Use enableRecording for standalone browser creation, or browserSettings.record for an agent run. Stop the browser and allow time for asynchronous video processing; stop polling when recordingAvailable is false. Live preview is for an active browser. Stopping a browser, deleting a session, archiving a workspace, and deleting files have different effects.
> Use model-specific reasoning values. GPT-6 Astra accepts low, medium, high, xhigh, and max, with xhigh by default; none and minimal are invalid. Use the public REST schema when installed SDK types lag new fields. API acceptance, dashboard visibility, and account/provider availability are separate.
> For open-source browser-use, is_done only reports a terminal done action. is_successful is the agent-reported outcome; verify important external actions independently. Cloud timeout, API client timeout, model timeout, and task completion are separate concepts.
> For failed requests, use https://docs.browser-use.com/cloud/guides/troubleshooting.md. Inspect the full error and project before retrying or adding credits. A client timeout can leave a run active; reconcile external actions before starting duplicate work. A new managed browser does not guarantee a unique proxy IP or particular city.

# Secrets

> Pass run-scoped credentials to API V4 with secret bindings.

## API V4: inline secret bindings

Use `secret_bindings` / `secretBindings` with the explicit V4 client. Give each
credential an alias and the hostnames where it may be typed. Refer to the alias
in the task, not the credential value.

<Warning>
  Aliases avoid putting raw credentials in the task text. They do not guarantee
  that the agent cannot see the value: once typed, it is accessible to the page
  and to an agent with browser/CDP access.
</Warning>

This example fills a password field and stops before submitting. Replace the
example portal URL and provide `PORTAL_PASSWORD` through your application's
secret store or environment. Do not commit the value or print the request body.

<CodeGroup>
  ```python Python theme={null}
  import os
  from browser_use_sdk.v4 import BrowserUse

  with BrowserUse() as client:
      run = client.runs.create(
          "Open https://portal.example.com/login, enter portal_password "
          "in the password field, and stop before submitting",
          secret_bindings=[
              {
                  "alias": "portal_password",
                  "source": {
                      "type": "inline",
                      "value": os.environ["PORTAL_PASSWORD"],
                  },
                  "allowedDomains": ["portal.example.com"],
              }
          ],
      )
      print(run.id)
  ```

  ```typescript TypeScript theme={null}
  import { BrowserUse } from "browser-use-sdk/v4";

  const password = process.env.PORTAL_PASSWORD;
  if (!password) throw new Error("Set PORTAL_PASSWORD before starting a run");

  const client = new BrowserUse();
  const run = await client.runs.create({
    task: "Open https://portal.example.com/login, enter portal_password in the password field, and stop before submitting",
    secretBindings: [
      {
        alias: "portal_password",
        source: { type: "inline", value: password },
        allowedDomains: ["portal.example.com"],
      },
    ],
  });
  console.log(run.id);
  ```
</CodeGroup>

* `allowedDomains` takes bare hostnames, not URLs, ports, paths, or wildcards.
  A hostname also covers its subdomains. Use the narrowest host that works.
* These domains restrict where that credential may be typed. They are **not** a
  browser-wide navigation or network allowlist.
* Bindings belong to one run. A follow-up that needs the same credential must
  pass the binding again, even when it reuses the same session.
* Use a separate alias for each credential field. Up to 20 bindings are allowed
  per run, with up to 20 allowed domains per binding.
* Aliases contain 1–64 lowercase letters, digits, hyphens, or underscores and
  start with a letter or digit.
* The inline limit is 4,096 bytes **after JSON encoding for encryption**,
  including its wrapper and escaping. It is not a 4,096-character allowance;
  non-ASCII characters, quotes, and backslashes consume extra space.

For credentials stored in a connected vault, use a
[1Password field binding](/cloud/guides/1password#bind-individual-fields-in-a-v4-run).
See the [Create run reference](/cloud/api-v4/runs/create-run) for the current
request schema.

## Legacy API V2

The examples below use the default V2 client and its `secrets` /
`allowed_domains` fields. Do not pass those fields to `v4.runs.create()`; use
the secret bindings above. Keep this recipe only for an existing V2 integration.

Pass credentials to the agent scoped by domain.

<CodeGroup>
  ```python Python theme={null}
  from browser_use_sdk import AsyncBrowserUse

  client = AsyncBrowserUse()
  result = await client.run(
      "Log into GitHub and star the browser-use/browser-use repo",
      secrets={"github.com": "username:password123"},
      allowed_domains=["github.com"],
  )
  ```

  ```typescript TypeScript theme={null}
  import { BrowserUse } from "browser-use-sdk";

  const client = new BrowserUse();
  const result = await client.run(
    "Log into GitHub and star the browser-use/browser-use repo",
    {
      secrets: { "github.com": "username:password123" },
      allowedDomains: ["github.com"],
    },
  );
  ```
</CodeGroup>

Use `allowed_domains` to restrict the agent to specific domains. Supports wildcards: `example.com`, `*.example.com`.

For SSO/OAuth redirects, include all domains in the auth flow:

<CodeGroup>
  ```python Python theme={null}
  result = await client.run(
      "Log into the company portal and download the Q4 report",
      secrets={
          "portal.example.com": "user@company.com:password123",
          "okta.com": "user@company.com:password123",
      },
      allowed_domains=["portal.example.com", "*.okta.com"],
  )
  ```

  ```typescript TypeScript theme={null}
  const result = await client.run(
    "Log into the company portal and download the Q4 report",
    {
      secrets: {
        "portal.example.com": "user@company.com:password123",
        "okta.com": "user@company.com:password123",
      },
      allowedDomains: ["portal.example.com", "*.okta.com"],
    },
  );
  ```
</CodeGroup>
