Brotto
It asks before it does anything you can't undo — and you can see exactly what it did.
Tell Brotto a task in plain English and it carries that out in the browser tab you're already signed in to. Your inbox, your bank, your admin panel. Not a cloud browser you've never logged into, and not a screenshot of a page it can't read.
An agent holding your cookies
One wrong click and an agent with your sessions can do a lot of damage as you. Three things are built around that, and none of them can be switched off.
An agent you can disable the safety on is an agent you cannot leave running. That is the whole argument for having the gates at all.
It stops and asks before anything irreversible
Before it sends an email, takes a payment, deletes something, publishes or changes a password — and before it visits a domain for the first time. The card names the action, so approving it is a decision and not a gesture.
No setting turns this offIt writes down what it did
Every run produces a per-session record — each observation, prompt, action, approval and timing — in a document on your disk. That is what lets you read a run back afterwards, resume one that was interrupted, or delete it outright. It is a record, not a chat transcript.
A file, not a databaseIt tells you why it couldn't act
When a button is off-screen, covered by a cookie banner, or disabled, Brotto says so on the line the model reads — and records the reason without a coordinate, so it never retries the same wrong click.
A reason, not a retryA run, start to finish
Brotto adding a branch protection ruleset to this repository. Every shot is the real extension, in a real browser, on a public repo.
Note where it stops. Not once at the end — twice mid-run, because both were decisions only you could make.
Booking a flight spends your money, so Brotto stops and asks. It cannot approve this itself, and neither can anything you install later.
https://kayak.com/checkout
Two decisions, and everything else follows
Most browser agents run somewhere you have never logged in. A cloud browser has no cookie jar, so every site starts at the sign-in wall — and no reputation, so the sites you actually care about serve it a bot challenge.
It drives your tab, not a cloud browser
Your cookies, your MFA, your SSO: simply there. Nothing to sign in to, because it is already signed in.
It reads the accessibility tree, not pixels
Roles, labels, values and stable references — the structure a screen reader already navigates by. No vision model, no image tokens.
Three screens
What it offers when the page is idle, what it remembers, and what it will refuse to touch. All seven screens, including one run in four moments.
One container, one extension
The container holds the agent loop; it never launches a browser. About 510 MB, most of which is the model provider SDKs rather than Chromium.
Everything it keeps — session history, your blocklist, your remembered model — lands in one Docker volume on your disk.
git clone https://github.com/suryanshgupta9933/Brotto.git
cd brotto
cp .env.example .env # set AGENT_SECRET to any long random string
docker compose up -d
Then build and load the extension:
cd clients/brotto-extension
npm ci && npm run build
In Chrome, open chrome://extensions, turn on
Developer mode, and Load unpacked →
clients/brotto-extension/dist. Then paste
AGENT_SECRET into Settings → Connection and your model key
under Settings → Model. The key is held in memory for the run and never
written to disk.
| Licence | Apache 2.0 — read it, fork it, ship it |
| Cost | Nothing, beyond the model calls you make |
| Your data | Audit files on your disk. The server transits page text and never stores it. |
| Providers | Eight, or any OpenAI-compatible endpoint you run |
| Chrome only | chrome.debugger has no Firefox equivalent |
Full instructions, honest limitations and the roadmap are on GitHub.
Not built yet
Ordered by what unblocks the most people. Two of these are the reason a person who doesn't write code cannot use Brotto yet, and removing them is the top priority rather than a someday item.
The store listing clears
The extension becomes one click to install. That takes the install from six steps to one, and it needs nothing from us but a review.
Remove the last step
A one-command installer for the container, then a hosted option — at which point there is nothing left to run yourself.
Canvas surfaces
Google Sheets genuinely draws to a canvas and is the one place Brotto is blind. Worth checking separately; Docs renders a real DOM.
A published benchmark
Until it scores real runs, any reliability number in this space is a guess — including ours. The harness measures perception and actions with no model in the loop.
Routines
Saved, reusable tasks — every weekday, summarise these — and re-running or resuming from the record.
Pro
Multi-tab parallelism, a speed pack, routines and per-run cost caps. Brotto stays Apache 2.0, and the free build is the whole product as it stands.
No operator between the agent and your documents, because there is no operator
The browser runs on your machine. The agent loop runs on a server you run, so page observations transit it — that is inherent to the design. What you choose is that nobody is on the other end.
Page text is redacted first
Credentials, API keys, bearer tokens, card numbers and government identifiers are stripped before it reaches the provider — in code, on every task, with no setting to disable it.
Nothing but a digest reaches disk
A run leaves a 200-character digest of each page rather than a copy. What you typed and the model's prose about it do persist in the record.
Your key never touches disk
Held in memory for the run, by Brotto, anywhere. There is no account, no credit balance and nothing to top up.
Deletion is yours
Every session has a delete button with a confirmation, and
DELETE /v1/sessions takes the lot.
The long versions are separate documents, and putting detail there is the right call rather than a sign this page is hiding something: Privacy and Security.
The parts that are harder than they look
Two essays on the parts of this that took the most work.
- An agent holding your cookies 2026-10-09 What an agent with your sessions can do as you, the three gates that stop it, and the fact that all of them are made of strings.
- The browser is not a picture 2026-10-08 On accessibility trees versus screenshots, and on the gap between a reference that resolves and a reference that can be clicked.