Agent-Browser with Kernel Cloud Browsers
This skill documents best practices for using agent-browser's built-in Kernel provider (-p kernel) for cloud browser automation.
When to Use This Skill
Use this skill when you need to:
- Automate websites using
agent-browser -p kernelcommands - Handle bot detection on sites with aggressive anti-bot measures
- Persist login sessions across automation runs using profiles
- Work with iframes including cross-origin payment forms
- Get live view URLs for debugging or manual intervention
- Find the underlying Kernel session ID for advanced Playwright scripting
- Create site-specific automation skills for new websites
References
- Creating Site-Specific Skills [blocked] - Guide for building automation skills for specific websites
Prerequisites
Load the kernel-cli skill for Kernel CLI installation and authentication.
Environment Variables
Set these before your first agent-browser -p kernel call. The CLI holds state between invocations.
Recommended Configuration
Set options explicitly; agent-browser reads them when it creates the provider session.
Profile Persistence
Warning:
KERNEL_PROFILE_NAMEdoesn't work with-p kernelin agent-browser 0.33.0. It sendsprofileas a string instead of the object required by Kernel, so session creation fails with HTTP 400. It also doesn't setsave_changes. Profiles must be pre-created.
Until this is fixed upstream, create the browser with the Kernel CLI and attach agent-browser over CDP. Don't combine -p kernel with --cdp.
Don't print or share CDP_URL; it grants browser access. Deleting the CLI-created session finalizes --save-changes, so later sessions can reuse the authenticated profile.
Basic Usage
For provider-managed sessions, use -p kernel with each command. For the profile/CDP workaround, reuse the same --session name and don't add -p kernel.
Semantic Selectors (Recommended)
Instead of ephemeral @e refs that change on every page load, use semantic selectors via the find command for more stable, readable automation:
When to Use Which Selector
Recommendation: Use find for production automation. Use @e refs for exploration and quick prototyping, then convert to semantic selectors.
Find the Kernel Session and Live View
Match agent-browser's CDP endpoint to the active Kernel session. Compare the URL without its query string: the CLI and agent-browser can hold different short-lived jwt query values for the same session. The endpoint's scheme, host, and path remain stable. This is more reliable than guessing from creation time when several sessions share a profile. This workflow requires jq.
Do not print or share the CDP URL; it grants browser access. Share a live view URL only with the intended user. A headless session has no live view. If you use --session <name>, include it on every agent-browser command, including get cdp-url.
Handling Bot Detection
Stealth and Proxy Routing
Stealth is opt-in in current agent-browser releases. Set KERNEL_STEALTH=true before the first command for a session; changing it later does not reconfigure the running browser.
A stealth browser can use Kernel's default stealth proxy. If that proxy causes a site-specific network or reputation failure and direct metro egress is acceptable, change the running session without disabling stealth:
Direct egress changes the public IP and can reduce anti-bot protection. Prefer the default proxy unless testing shows it is the problem. For a configured Kernel proxy, use --proxy-id <proxy-id>; remove it with --clear-proxy.
Manual Login Fallback
If automated login fails:
- Resolve
SESSION_IDusing the CDP-matching workflow above. - Run
kernel browsers view "$SESSION_ID"and give the URL only to the intended user. - Ask the user to complete login, then continue in the same agent-browser session.
- To persist the login, use the CLI-created profile/CDP workflow above. Close agent-browser, then delete the Kernel session so
--save-changesfinalizes.
JavaScript Fallback for Tricky Elements
Some elements (especially on bot-protected sites) don't respond to standard commands:
Anti-Bot Form Fields
Some payment processors (e.g., Point and Pay) use decoy form fields. Only fill fields matching specific patterns:
Handling Iframes
Same-Origin Iframes
Use the frame command to switch context:
Cross-Origin Iframes
Try agent-browser frame first; current releases can switch into iframe context, including many cross-origin frames. If an out-of-process or payment iframe still fails, resolve SESSION_ID and use Kernel's Playwright executor:
Return to the main document with agent-browser -p kernel frame main after frame interactions.
Waiting Strategies
Smart waits are critical for fast, reliable automation. Using condition-based waits instead of fixed timeouts can reduce execution time by 50%+ while improving reliability.
Smart Waits (Recommended)
Fixed Waits (Last Resort)
Element Refs Best Practices
Element refs (@e1, @e2, etc.) are ephemeral and change:
- After page navigation
- After significant DOM updates
- Between browser sessions
Always take a fresh snapshot before interacting:
Filtering Snapshots
Login Patterns
Single-Page Form (Optimized)
Username and password on the same page:
Two-Step Form (Optimized)
Username first, then password on a second screen:
Modal Login
Login form appears in a modal overlay:
Fallback: JavaScript for Tricky Modals
Some modals don't expose accessible labels:
Handling New Tabs
Some links open in new tabs:
Screenshots and Debugging
Session Management
Cleanup
Close the same named agent-browser session you opened. This saves profile changes and deletes its Kernel browser:
If agent-browser is unavailable or close fails, delete the orphan explicitly:
Do not use close --all when unrelated agent-browser sessions may be running.
Multiple Sessions
Run parallel browser sessions with named sessions:
Common Gotchas
- Refs change after navigation: Re-snapshot after links, submissions, or major DOM updates.
- Wait for outcomes: Use URL, text, load-state, or JavaScript conditions after asynchronous actions.
- Provider settings are launch-time settings: Close the current session before changing
KERNEL_HEADLESS,KERNEL_STEALTH, or timeout. - Profile persistence needs the CDP workaround:
KERNEL_PROFILE_NAMEis currently broken. Close agent-browser, then delete the CLI-created Kernel session to finalize--save-changes. - Stealth is not sufficient for every site: Compare proxy routing, use manual login, or fall back to direct Playwright for difficult frames.


