Semantic tools
Tabs, navigate, ARIA snapshot, click, type, press key, and screenshot. No arbitrary scripts or raw CDP.
Run Chromium in Docker, give the agent semantic tools instead of raw scripts, restrict where it can navigate, and let a person take over through a password-protected desktop that shares the same browser.
The browser runs in your Docker, under your policy, and is destroyed when the run ends.
A DockerBrowserClient backed by a sandbox client starts Chromium with your workspace, network, and resources.
Wait for the automation and desktop capabilities before connecting.
createBrowserTools() picks the tools and the navigation policy for this connection.
Pass the tools to an Agent. It reads a snapshot before each action.
Disconnect and destroy the browser, or stop it and resume it later.
Tabs, navigate, ARIA snapshot, click, type, press key, and screenshot. No arbitrary scripts or raw CDP.
Lock navigation to exact origins. Private and reserved IP literals are rejected on the first URL and every redirect.
A noVNC desktop shares the agent’s Chromium. A renewable lease pauses new agent actions while you drive.
Non-root Chromium with its sandbox on, seccomp, and dropped capabilities. It never falls back to --no-sandbox.
Choose the tools and the origins. Everything else is denied.
1import { Agent } from '@anvia/core/agent'2import { DockerBrowserClient, createBrowserTools } from '@anvia/browser'3import { DockerSandboxClient } from '@anvia/sandbox'45const browserClient = new DockerBrowserClient({6 sandboxClient: new DockerSandboxClient(),7 image: process.env.ANVIA_BROWSER_IMAGE!,8})9const browser = await browserClient.createBrowser({10 workspace: { type: 'ephemeral' },11 network: { mode: 'bridge' },12})13await browser.waitForCapabilities({ capabilities: ['automation', 'desktop'], timeoutMs: 30_000 })1415const connection = await browser.connect({ timeoutMs: 30_000 })16const tools = createBrowserTools({17 connection,18 tools: ['browser_navigate', 'browser_snapshot', 'browser_click', 'browser_type'],19 navigation: { mode: 'origins', origins: ['https://app.example.com'] },20})21const agent = new Agent({22 id: 'browser-agent',23 model,24 instructions: 'Inspect a snapshot before every browser action.',25 tools,26})Human takeover does not authenticate users or authorize product operations. The navigation policy does not block third-party subresources, and Docker bridge networking is not SSRF isolation. Requires Node 20.12+ and Docker.
Start from the guide, run the example, or look at what else Anvia handles.