Browser Automation
Libraries and SDKs that let an agent open pages, click, type, and read the web through a real browser.
How to read this category
These profiles cover libraries and SDKs that open real pages in a browser engine, then click, type, and read as part of an agent or test workflow.
The four published profiles split two ways. Playwright and Puppeteer are deterministic drivers: your code decides every step, and the same script runs the same way twice. Browser Use and Stagehand are AI-assisted layers: a model helps decide actions from instructions, which absorbs layout changes but makes runs less predictable and adds model cost per step.
Start with a deterministic driver when the workflow is stable and the stakes of a wrong click are real. Reach for an AI-assisted layer only when page layouts vary enough that maintaining hand-written selectors becomes the larger burden, and keep a person reviewing anything that spends money, sends messages, or changes records.
The verified profiles
Playwright
Open source, Apache-2.0A browser automation framework that drives Chromium, Firefox, and WebKit with a single API for tests, scripts, and AI agents.
Best for: Teams that need one API across Chromium, Firefox, and WebKit, with a test runner and an MCP server from the same project.
By Microsoft. Checked 2026-10-03.
View profile →Puppeteer
Open source, Apache-2.0A JavaScript library that controls Chrome and Firefox through a high-level API for automation, scraping, and testing.
Best for: JavaScript teams that want direct Chrome control, screenshots, PDFs, and page automation without a test-runner layer.
By Google. Checked 2026-10-03.
View profile →Browser Use
Open source, MITAn open-source Python library that lets an LLM agent open pages, click, type, and fill forms from a plain task description.
Best for: Builders who want an agent to handle varied web tasks from a task description, with custom tools and a choice of model.
By Browser Use. Checked 2026-10-03.
View profile →Stagehand
Open source, MITA browser agent SDK that extracts data and interacts with any site through act, observe, and extract calls.
Best for: Developers who want explicit, readable agent steps with self-healing actions and structured extraction, in TypeScript, Python, or Go.
By Browserbase. Checked 2026-10-03.
View profile →Side by side on sourced facts
| Tool | Pricing model | License | Deployment | MCP support | Checked |
|---|---|---|---|---|---|
| Playwright | Open source | Apache-2.0 | Self-hosted library, Local browser | Official MCP server (@playwright/mcp) | 2026-10-03 |
| Puppeteer | Open source | Apache-2.0 | Self-hosted library, Local browser | Via chrome-devtools-mcp | 2026-10-03 |
| Browser Use | Open source | MIT | Self-hosted library, Hosted cloud (optional) | Documented MCP path | 2026-10-03 |
| Stagehand | Open source | MIT | Self-hosted library, Hosted cloud (optional), Hosted MCP server (optional) | Hosted MCP server (Browserbase) | 2026-10-03 |
Every cell traces to the tool profile, which traces to the official repository, package page, and documentation checked on the date shown. Pricing cells name the model, not a price: vendor prices change, so check the profile for the sourced pricing summary and the official pricing link.
What actually decides the choice
- Engine coverage decides first: WebKit work points at Playwright, Chrome-centered work is served by all four, and Puppeteer covers Chrome and Firefox through the DevTools Protocol or WebDriver BiDi.
- Determinism versus flexibility is the real tradeoff. Scripted drivers are auditable and cheap to run; AI-assisted layers self-heal on layout changes but depend on the model you connect.
- MCP support differs in kind, not just presence: an official package, a hosted server, a documented path, or a separate MCP project. Match the transport your agent client actually speaks.
- Infrastructure is yours with every option here. Browsers, scaling, proxies, and sign-in state live on your machine or your cloud account, not on the tool.
How this archive is ordered, and why it is short
Profiles appear in the order they passed the AgentsUse review gate, not in a tested quality ranking. AgentsUse has not run head-to-head benchmarks for this category, so this page does not claim a winner. The comparison table is the ranking tool: sort by the dimension your job cannot compromise on, then read the full profiles for limitations.
This archive currently lists 4 verified profiles. AgentsUse normally asks for eight published profiles before opening a category archive. This one opens early, on the record, because every listed profile passed the full tool gate and readers comparing real choices need the side-by-side surface now, not a longer unvetted list later. The archive grows as more tools pass review. See how verification works.
Read before you give these tools real work
Agent Tool Permissions Done Right
Every tool you grant an AI agent is risk you accept. How to think in blast radius, tier permissions, gate irreversible actions, and audit what agents actually did.
Read guide →Agent Security Risks You Must Handle
Agents read untrusted content, run code, and call APIs - a new attack surface. The risks that actually materialize, explained plainly, with working mitigations.
Read guide →Back to the tools directory, the category index, or the guides.