Brotto

Brotto

It asks before it does anything you can't undo — and you can see exactly what it did.

Tell Brotto a task in plain English and it carries that out in the browser tab you're already signed in to. Your inbox, your bank, your admin panel. Not a cloud browser you've never logged into, and not a screenshot of a page it can't read.

Chrome Web Store · Under review One click to install as soon as it clears.
Steps14
Active377.3s
Context41.2%
OutcomeDone
Twenty-five seconds of one real run — the plan it wrote, the domain consent, the approval card, and the answer it came back with. No cuts, no staging.
Why you can leave it running

An agent holding your cookies

One wrong click and an agent with your sessions can do a lot of damage as you. Three things are built around that, and none of them can be switched off.

An agent you can disable the safety on is an agent you cannot leave running. That is the whole argument for having the gates at all.

Gate 01

It stops and asks before anything irreversible

Before it sends an email, takes a payment, deletes something, publishes or changes a password — and before it visits a domain for the first time. The card names the action, so approving it is a decision and not a gesture.

No setting turns this off
Gate 02

It writes down what it did

Every run produces a per-session record — each observation, prompt, action, approval and timing — in a document on your disk. That is what lets you read a run back afterwards, resume one that was interrupted, or delete it outright. It is a record, not a chat transcript.

A file, not a database
Gate 03

It tells you why it couldn't act

When a button is off-screen, covered by a cookie banner, or disabled, Brotto says so on the line the model reads — and records the reason without a coordinate, so it never retries the same wrong click.

A reason, not a retry
The one that bites

A run, start to finish

Brotto adding a branch protection ruleset to this repository. Every shot is the real extension, in a real browser, on a public repo.

Note where it stops. Not once at the end — twice mid-run, because both were decisions only you could make.

Brotto Connected
Find me the cheapest direct flight to Lisbon in November
Opened Google Flights and set the destination to Lisbon (LIS) Step 12 · 28.4s
Approval needed

Booking a flight spends your money, so Brotto stops and asks. It cannot approve this itself, and neither can anything you install later.

https://kayak.com/checkout

Deny Approve
Read the three cheapest direct results Step 13 · 26.1s
Why it's built this way

Two decisions, and everything else follows

Most browser agents run somewhere you have never logged in. A cloud browser has no cookie jar, so every site starts at the sign-in wall — and no reputation, so the sites you actually care about serve it a bot challenge.

Your machine Chrome extension A pure actuator. Handed a target, asked for a box model.
Your machine Container The agent loop. Chrome suspends idle MV3 workers, so the loop does not live here.
Your provider Any of eight Anthropic, OpenAI, Gemini, MiniMax, OpenRouter, DeepSeek, Groq, or your own.

It drives your tab, not a cloud browser

Your cookies, your MFA, your SSO: simply there. Nothing to sign in to, because it is already signed in.

It reads the accessibility tree, not pixels

Roles, labels, values and stable references — the structure a screen reader already navigates by. No vision model, no image tokens.

In the panel

Three screens

What it offers when the page is idle, what it remembers, and what it will refuse to touch. All seven screens, including one run in four moments.

The Brotto panel idle, offering what the open page could be asked to do
Idle. The panel offers what the page in front of you could be asked to do.
Brotto settings: connection, secret key, blocked sites and model provider
Yours. Your model key, your server, and the list of sites Brotto refuses outright.
Self-host

One container, one extension

The container holds the agent loop; it never launches a browser. About 510 MB, most of which is the model provider SDKs rather than Chromium.

Everything it keeps — session history, your blocklist, your remembered model — lands in one Docker volume on your disk.

git clone https://github.com/suryanshgupta9933/Brotto.git
cd brotto

cp .env.example .env      # set AGENT_SECRET to any long random string
docker compose up -d

Then build and load the extension:

cd clients/brotto-extension
npm ci && npm run build

In Chrome, open chrome://extensions, turn on Developer mode, and Load unpacked → clients/brotto-extension/dist. Then paste AGENT_SECRET into Settings → Connection and your model key under Settings → Model. The key is held in memory for the run and never written to disk.

LicenceApache 2.0 — read it, fork it, ship it
CostNothing, beyond the model calls you make
Your dataAudit files on your disk. The server transits page text and never stores it.
ProvidersEight, or any OpenAI-compatible endpoint you run
Chrome onlychrome.debugger has no Firefox equivalent

Full instructions, honest limitations and the roadmap are on GitHub.

Next

Not built yet

Ordered by what unblocks the most people. Two of these are the reason a person who doesn't write code cannot use Brotto yet, and removing them is the top priority rather than a someday item.

01 · Soon

The store listing clears

The extension becomes one click to install. That takes the install from six steps to one, and it needs nothing from us but a review.

02 · Planned

Remove the last step

A one-command installer for the container, then a hosted option — at which point there is nothing left to run yourself.

03 · Planned

Canvas surfaces

Google Sheets genuinely draws to a canvas and is the one place Brotto is blind. Worth checking separately; Docs renders a real DOM.

04 · Planned

A published benchmark

Until it scores real runs, any reliability number in this space is a guess — including ours. The harness measures perception and actions with no model in the loop.

05 · Planned

Routines

Saved, reusable tasks — every weekday, summarise these — and re-running or resuming from the record.

06 · Not released

Pro

Multi-tab parallelism, a speed pack, routines and per-run cost caps. Brotto stays Apache 2.0, and the free build is the whole product as it stands.

Where your data goes

No operator between the agent and your documents, because there is no operator

The browser runs on your machine. The agent loop runs on a server you run, so page observations transit it — that is inherent to the design. What you choose is that nobody is on the other end.

Page text is redacted first

Credentials, API keys, bearer tokens, card numbers and government identifiers are stripped before it reaches the provider — in code, on every task, with no setting to disable it.

Nothing but a digest reaches disk

A run leaves a 200-character digest of each page rather than a copy. What you typed and the model's prose about it do persist in the record.

Your key never touches disk

Held in memory for the run, by Brotto, anywhere. There is no account, no credit balance and nothing to top up.

Deletion is yours

Every session has a delete button with a confirmation, and DELETE /v1/sessions takes the lot.

The long versions are separate documents, and putting detail there is the right call rather than a sign this page is hiding something: Privacy and Security.

Writing

The parts that are harder than they look

Two essays on the parts of this that took the most work.

  • An agent holding your cookies 2026-10-09 What an agent with your sessions can do as you, the three gates that stop it, and the fact that all of them are made of strings.
  • The browser is not a picture 2026-10-08 On accessibility trees versus screenshots, and on the gap between a reference that resolves and a reference that can be clicked.