Rank #5 of 7 in Browser Automation for Agents
Try itExperimental
See what an agent can do with Notte before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; commands tagged live-capable can re-run against the real endpoint from our edge, right now (▶ run live — the exact same request, live and recorded lines always labeled); sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$curl -s https://docs.notte.cc/llms.txt | head -6recorded session — replayed, not liveVerified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Action primitives — stories about action primitives in this arenaAction primitivesevidence →
Stories about action primitives in this arena
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Auth session persistence — stories about auth session persistence in this arenaAuth session persistenceevidence →
Stories about auth session persistence in this arena
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Deployment modes — stories about deployment modes in this arenaDeployment modesevidence →
Stories about deployment modes in this arena
Framework model support — stories about framework model support in this arenaFramework model supportevidence →
Stories about framework model support in this arena
Nl task execution — stories about nl task execution in this arenaNl task executionevidence →
Stories about nl task execution in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Pricing limits — free-tier ceilings, usage caps, and rate limits before you have to payPricing limitsevidence →
Free-tier ceilings, usage caps, and rate limits before you have to pay
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Replay debugging — stories about replay debugging in this arenaReplay debuggingevidence →
Stories about replay debugging in this arena
Scale parallelism — running many jobs at once — concurrency, fleets, queueingScale parallelismevidence →
Running many jobs at once — concurrency, fleets, queueing
Stealth captcha — stories about stealth captcha in this arenaStealth captchaevidence →
Stories about stealth captcha in this arena
Structured extraction — stories about structured extraction in this arenaStructured extractionevidence →
Stories about structured extraction in this arena
Story verdicts — every judged story with its evidenceStory verdicts
What’s free: 0 free · 1 paid · 0 enterprise · 24 not stated in evidence
Follow the green: where the map greys out is where Notte stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Action primitives — stories about action primitives in this arenaAction primitives
Stories about action primitives in this arena
Cache resolved actions or generated code so repeat runs replay deterministically at lower cost and latency than re-prompting the LLM
~4/10
Drive the page through DOM-understanding action primitives (act/click/type on described elements) that survive selector and layout changes
~6/10
Preview candidate actions on the current page (observe/plan) before committing the agent to act
~6/10
Switch to a vision or computer-use action mode that operates on screenshots for canvases and UIs the DOM path can't handle
~5/10
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓8/10
unlocks → Webhooks · Scoped API keys · Machine-readable spec · Versioning policy · Full data export · Hand the product a natural-language goal and it completes a multi-step web task end to end — navigating, filling forms, and clicking through flows
Subscribe to events via webhooks
—–
Build against official SDKs
~5/10
Issue scoped/least-privilege API credentials for an agent
—0/10
Connect an agent via an official MCP server
✓8/10
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
~3/10
Explore an interactive API reference with runnable examples
—0/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
!5/10
Operate the product with natural-language commands
!5/10
Plug MCP servers into this product so it can use their tools
—0/10
Get AI-generated insights and suggestions from my data inside the product
—0/10
Set up automations that run autonomously in the background
✓7/10
Auth session persistence — stories about auth session persistence in this arenaAuth session persistence
Stories about auth session persistence in this arena
Connect my existing Playwright, Puppeteer, or CDP automation code to the product's browsers instead of rewriting it
✓7/10
Store credentials in a vault and have the agent complete logins including TOTP/2FA challenges without exposing secrets to the model
~7/10
Persist logged-in browser state in reusable profiles so agents skip the login wall on every subsequent run
✓7/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Deployment modes — stories about deployment modes in this arenaDeployment modes
Stories about deployment modes in this arena
Framework model support — stories about framework model support in this arenaFramework model support
Stories about framework model support in this arena
Nl task execution — stories about nl task execution in this arenaNl task execution
Stories about nl task execution in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Pricing limits — free-tier ceilings, usage caps, and rate limits before you have to payPricing limits
Free-tier ceilings, usage caps, and rate limits before you have to pay
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Replay debugging — stories about replay debugging in this arenaReplay debugging
Stories about replay debugging in this arena
Scale parallelism — running many jobs at once — concurrency, fleets, queueingScale parallelism
Running many jobs at once — concurrency, fleets, queueing
Stealth captcha — stories about stealth captcha in this arenaStealth captcha
Stories about stealth captcha in this arena
Rely on a documented captcha stance — automatic solving, human fallback, or explicit non-support — instead of silent task failures
!4/10
Point to the vendor's published acceptable-use and anti-abuse posture governing what its stealth and automation features may be used for
—0/10
Enable stealth fingerprinting and residential or geo-targeted proxies so legitimate automations aren't blocked as bots
✓7/10
Structured extraction — stories about structured extraction in this arenaStructured extraction
Stories about structured extraction in this arena
Sorted by importance (agentic first) (high → low) · 52/52 stories · click a row’s chevron for the rationale and evidence
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | disputed | 5/10 | Dcontradicted | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 7/10 | Xcommunity | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | disputed | 5/10 | Dcontradicted | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | partial | 3/10 | Cclaimed | |
Persist logged-in browser state in reusable profiles so agents skip the login wall on every subsequent run C Profiles | developer | Auth session persistence — stories about auth session persistence in this arenaAuth session persistence | 3 | full | 7/10 | Cclaimed | |
Drive the page through DOM-understanding action primitives (act/click/type on described elements) that survive selector and layout changes C Dom | developer | Action primitives — stories about action primitives in this arenaAction primitives | 3 | partial | 6/10 | Xcommunity | |
Extract typed, schema-validated data (Zod/Pydantic-style) from pages the agent visits, not just raw text C Extraction | developer | Structured extraction — stories about structured extraction in this arenaStructured extraction | 3 | disputed | 5/10 | Dcontradicted | |
Hand the product a natural-language goal and it completes a multi-step web task end to end — navigating, filling forms, and clicking through flows C Tasks | developer | Nl task execution — stories about nl task execution in this arenaNl task execution | 3 | disputed | 5/10 | Dcontradicted | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 3/10 | Cclaimed | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | 0/10 | ||
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | untested | none yet | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | none | untested | none yet | |
Connect my existing Playwright, Puppeteer, or CDP automation code to the product's browsers instead of rewriting it C Compat | developer | Auth session persistence — stories about auth session persistence in this arenaAuth session persistence | 2 | full | 7/10 | Cclaimed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 7/10 | Tprobed | |
Enable stealth fingerprinting and residential or geo-targeted proxies so legitimate automations aren't blocked as bots C Stealth | automation-engineer | Stealth captcha — stories about stealth captcha in this arenaStealth captcha | 2 | full | 7/10 | Cclaimed | |
Plug the browser layer into agent frameworks (Claude Agent SDK, Vercel AI SDK, LangChain, CrewAI) through documented adapters C Frameworks | developer | Framework model support — stories about framework model support in this arenaFramework model support | 2 | partial | 7/10 | Tprobed | |
Store credentials in a vault and have the agent complete logins including TOTP/2FA challenges without exposing secrets to the model G Credentials | automation-engineer | Auth session persistence — stories about auth session persistence in this arenaAuth session persistence | 2 | partial | 7/10 | Cclaimed | |
Submit a browser task over a hosted HTTP API and receive the result by polling or webhook, without managing any browser myself C Tasks | ai agent | Nl task execution — stories about nl task execution in this arenaNl task execution | 2 | partial | 6/10 | Tprobed | |
Bring my own LLM provider — the framework is model-agnostic rather than locked to one vendor's models C Models | developer | Framework model support — stories about framework model support in this arenaFramework model support | 2 | partialpaid | 5/10 | Cclaimed | |
Compose repeatable multi-step workflows with loops, conditionals, and parameters instead of one-shot prompts C Workflows | automation-engineer | Nl task execution — stories about nl task execution in this arenaNl task execution | 2 | partial | 5/10 | Cclaimed | |
Debug a failed agent run from recorded replays — video, screenshots, step-by-step action timelines C Replay | automation-engineer | Replay debugging — stories about replay debugging in this arenaReplay debugging | 2 | partial | 5/10 | Cclaimed | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 5/10 | Cclaimed | |
Switch to a vision or computer-use action mode that operates on screenshots for canvases and UIs the DOM path can't handle C Vision | developer | Action primitives — stories about action primitives in this arenaAction primitives | 2 | partial | 5/10 | Xcommunity | |
Watch a session live and take human control mid-run when the agent gets stuck C Live | automation-engineer | Replay debugging — stories about replay debugging in this arenaReplay debugging | 2 | partial | 5/10 | Cclaimed | |
Cache resolved actions or generated code so repeat runs replay deterministically at lower cost and latency than re-prompting the LLM C Caching | developer | Action primitives — stories about action primitives in this arenaAction primitives | 2 | partial | 4/10 | Cclaimed | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 4/10 | Cclaimed | |
Rely on a documented captcha stance — automatic solving, human fallback, or explicit non-support — instead of silent task failures C Captcha | automation-engineer | Stealth captcha — stories about stealth captcha in this arenaStealth captcha | 2 | disputed | 4/10 | Dcontradicted | |
Run a fleet of concurrent browser sessions with documented concurrency limits and programmatic session management C Fleets | automation-engineer | Scale parallelism — running many jobs at once — concurrency, fleets, queueingScale parallelism | 2 | partial | 4/10 | Xcommunity | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 3/10 | Xcommunity | |
See transparent per-task or per-browser-hour pricing and documented rate/concurrency limits before committing G Pricing | developer | Pricing limits — free-tier ceilings, usage caps, and rate limits before you have to payPricing limits | 2 | disputed | 3/10 | Dcontradicted | |
Run the agent against a local browser on my own machine for development, without any cloud account C Local | developer | Deployment modes — stories about deployment modes in this arenaDeployment modes | 2 | none | 0/10 | ||
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Preview candidate actions on the current page (observe/plan) before committing the agent to act C Observe | developer | Action primitives — stories about action primitives in this arenaAction primitives | 1 | partial | 6/10 | Tprobed | |
Point to the vendor's published acceptable-use and anti-abuse posture governing what its stealth and automation features may be used for C Posture | automation-engineer | Stealth captcha — stories about stealth captcha in this arenaStealth captcha | 1 | none | 0/10 | ||
Get webhook notifications when tasks and sessions finish instead of polling for status C Lifecycle | developer | Scale parallelism — running many jobs at once — concurrency, fleets, queueingScale parallelism | 1 | none | untested | none yet | |
My agent can download files from and upload files to the sites it operates, with the artifacts retrievable afterwards C Files | developer | Structured extraction — stories about structured extraction in this arenaStructured extraction | 1 | none | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | none | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 37 stories with headroom
What would move Notte’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their tools
nonemoves agent-readyimpact 45
All MCP-related evidence describes Notte exposing its own MCP server for external agents (Claude, CrewAI, Vercel AI SDK) to plug into and control Notte's browser tools — the reverse direction of this story.
Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave
nonemoves PA Scoreimpact 30
Missing: data export feature docs, open-format (e.g. JSON/CSV) account export, data portability/account deletion process, any independent confirmation of exportability.
Openness — open source, data portability, and self-hosting storiesSelf-host the core product
nonemoves PA Scoreimpact 30
All evidence describes Notte as a cloud/SaaS platform (remote browsers, cloud sessions, serverless functions, hosted API with Bearer auth) with no documented self-hosting or on-prem deployment path; a community comment even asks whether an open-source alternative exists, implying Notte itself isn't self-hostable.
Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models
nonemoves PA Scoreimpact 30
No evidence in the pack addresses opting out of AI training data usage, data retention policies for model training, or any privacy commitment regarding customer data not being used to train models.
Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product
nonemoves Built-in AIimpact 30
Missing: any documented insights/analytics dashboard, proactive suggestion feature, or evidence of the product surfacing patterns/recommendations from a user's stored data.
Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agent
nonemoves agent-readyimpact 30
Evidence shows only a single Bearer-token API authentication scheme (notte-docs-17) and a vault feature that hides stored web credentials from the LLM (notte-docs-14, notte-docs-27), but nothing about issuing scoped, role-limited, or least-privilege API keys specifically for agents.
Agenticness — how well agents can access and operate the productSubscribe to events via webhooks
nonemoves agent-readyimpact 30
Missing: any documentation of webhook subscription, event types, or delivery mechanism.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
Evidence shows only static API-reference pages (authentication, agent-start) and no OpenAPI/Swagger spec was found at any candidate path (probe-2 returned 404s), and nothing in the pack describes an interactive console or runnable code examples in the API docs.
Showing the top 8 of 37 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map15 surfaces · 34 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
Concepts docs17 stories
- Cache resolved actions or generated code so repeat runs replay deterministically at lower cost and latency than re-prompting the LLM
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Set up automations that run autonomously in the background
- Test against a sandbox environment without touching production data
- Connect my existing Playwright, Puppeteer, or CDP automation code to the product's browsers instead of rewriting it
- Store credentials in a vault and have the agent complete logins including TOTP/2FA challenges without exposing secrets to the model
- Persist logged-in browser state in reusable profiles so agents skip the login wall on every subsequent run
- Perform bulk operations across many items at once
- Define rules that trigger actions automatically on events
- Schedule recurring jobs or workflows
- Submit a browser task over a hosted HTTP API and receive the result by polling or webhook, without managing any browser myself
- Compose repeatable multi-step workflows with loops, conditionals, and parameters instead of one-shot prompts
- Do everything through the API that I can do in the UI
- Watch a session live and take human control mid-run when the agent gets stuck
- Run a fleet of concurrent browser sessions with documented concurrency limits and programmatic session management
- Extract typed, schema-validated data (Zod/Pydantic-style) from pages the agent visits, not just raw text
docs.notte.cc17 stories
- Cache resolved actions or generated code so repeat runs replay deterministically at lower cost and latency than re-prompting the LLM
- Run the product headlessly / in CI for automation
- Set up automations that run autonomously in the background
- Test against a sandbox environment without touching production data
- Store credentials in a vault and have the agent complete logins including TOTP/2FA challenges without exposing secrets to the model
- Persist logged-in browser state in reusable profiles so agents skip the login wall on every subsequent run
- Perform bulk operations across many items at once
- Define rules that trigger actions automatically on events
- Schedule recurring jobs or workflows
- Submit a browser task over a hosted HTTP API and receive the result by polling or webhook, without managing any browser myself
- Compose repeatable multi-step workflows with loops, conditionals, and parameters instead of one-shot prompts
- Do everything through the API that I can do in the UI
- Debug a failed agent run from recorded replays — video, screenshots, step-by-step action timelines
- Run a fleet of concurrent browser sessions with documented concurrency limits and programmatic session management
- Rely on a documented captcha stance — automatic solving, human fallback, or explicit non-support — instead of silent task failures
- Enable stealth fingerprinting and residential or geo-targeted proxies so legitimate automations aren't blocked as bots
- Extract typed, schema-validated data (Zod/Pydantic-style) from pages the agent visits, not just raw text
Hacker News12 stories
- Drive the page through DOM-understanding action primitives (act/click/type on described elements) that survive selector and layout changes
- Switch to a vision or computer-use action mode that operates on screenshots for canvases and UIs the DOM path can't handle
- Run the product headlessly / in CI for automation
- Set up automations that run autonomously in the background
- Delegate tasks to a built-in AI assistant inside the product
- Operate the product with natural-language commands
- Hand the product a natural-language goal and it completes a multi-step web task end to end — navigating, filling forms, and clicking through flows
- Read the product's source under an open license
- See transparent per-task or per-browser-hour pricing and documented rate/concurrency limits before committing
- Run a fleet of concurrent browser sessions with documented concurrency limits and programmatic session management
- Rely on a documented captcha stance — automatic solving, human fallback, or explicit non-support — instead of silent task failures
- Extract typed, schema-validated data (Zod/Pydantic-style) from pages the agent visits, not just raw text
Integrations docs12 stories
- Preview candidate actions on the current page (observe/plan) before committing the agent to act
- Switch to a vision or computer-use action mode that operates on screenshots for canvases and UIs the DOM path can't handle
- Point an agent at llms.txt or agent-oriented docs
- Connect an agent via an official MCP server
- Use an official CLI
- Build against official SDKs
- Connect my existing Playwright, Puppeteer, or CDP automation code to the product's browsers instead of rewriting it
- Plug the browser layer into agent frameworks (Claude Agent SDK, Vercel AI SDK, LangChain, CrewAI) through documented adapters
- Bring my own LLM provider — the framework is model-agnostic rather than locked to one vendor's models
- Do everything through the API that I can do in the UI
- Watch a session live and take human control mid-run when the agent gets stuck
- Debug a failed agent run from recorded replays — video, screenshots, step-by-step action timelines
notte.cc10 stories
- Drive the page through DOM-understanding action primitives (act/click/type on described elements) that survive selector and layout changes
- Switch to a vision or computer-use action mode that operates on screenshots for canvases and UIs the DOM path can't handle
- Delegate tasks to a built-in AI assistant inside the product
- Operate the product with natural-language commands
- Store credentials in a vault and have the agent complete logins including TOTP/2FA challenges without exposing secrets to the model
- Persist logged-in browser state in reusable profiles so agents skip the login wall on every subsequent run
- Hand the product a natural-language goal and it completes a multi-step web task end to end — navigating, filling forms, and clicking through flows
- Watch a session live and take human control mid-run when the agent gets stuck
- Debug a failed agent run from recorded replays — video, screenshots, step-by-step action timelines
- Enable stealth fingerprinting and residential or geo-targeted proxies so legitimate automations aren't blocked as bots
MCP server docs9 stories
- Drive the page through DOM-understanding action primitives (act/click/type on described elements) that survive selector and layout changes
- Preview candidate actions on the current page (observe/plan) before committing the agent to act
- Point an agent at llms.txt or agent-oriented docs
- Connect an agent via an official MCP server
- Use an official CLI
- Drive the product through a documented public API
- Build against official SDKs
- Plug the browser layer into agent frameworks (Claude Agent SDK, Vercel AI SDK, LangChain, CrewAI) through documented adapters
- Do everything through the API that I can do in the UI
API reference9 stories
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Build against official SDKs
- Delegate tasks to a built-in AI assistant inside the product
- Operate the product with natural-language commands
- Submit a browser task over a hosted HTTP API and receive the result by polling or webhook, without managing any browser myself
- Hand the product a natural-language goal and it completes a multi-step web task end to end — navigating, filling forms, and clicking through flows
- Do everything through the API that I can do in the UI
- Run a fleet of concurrent browser sessions with documented concurrency limits and programmatic session management
Quickstart docs7 stories
- Cache resolved actions or generated code so repeat runs replay deterministically at lower cost and latency than re-prompting the LLM
- Preview candidate actions on the current page (observe/plan) before committing the agent to act
- Run the product headlessly / in CI for automation
- Use an official CLI
- Drive the product through a documented public API
- Build against official SDKs
- Compose repeatable multi-step workflows with loops, conditionals, and parameters instead of one-shot prompts
GitHub README7 stories
- Cache resolved actions or generated code so repeat runs replay deterministically at lower cost and latency than re-prompting the LLM
- Drive the page through DOM-understanding action primitives (act/click/type on described elements) that survive selector and layout changes
- Delegate tasks to a built-in AI assistant inside the product
- Operate the product with natural-language commands
- Hand the product a natural-language goal and it completes a multi-step web task end to end — navigating, filling forms, and clicking through flows
- Compose repeatable multi-step workflows with loops, conditionals, and parameters instead of one-shot prompts
- Read the product's source under an open license
OpenAPI spec4 stories
Features docs4 stories
- Connect my existing Playwright, Puppeteer, or CDP automation code to the product's browsers instead of rewriting it
- Watch a session live and take human control mid-run when the agent gets stuck
- Debug a failed agent run from recorded replays — video, screenshots, step-by-step action timelines
- Enable stealth fingerprinting and residential or geo-targeted proxies so legitimate automations aren't blocked as bots
Pricing docs3 stories
Changelog docs1 story
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$curl -s https://docs.notte.cc/llms.txt | head -6reproduced$ curl -s https://docs.notte.cc/llms.txt | head -6 # Notte ## Critical Instructions For AI Agents STOP. Read and follow https://docs.notte.cc/quickstart.md before using SDK docs or writing SDK code.
$curl -si -X POST https://api.notte.cc/mcp/ -H 'Content-Type: application/json' -d '<jsonrpc initialize>'reproduced$ curl -si -X POST https://api.notte.cc/mcp/ -H 'Content-Type: application/json' -d '<jsonrpc initialize>'
HTTP/2 401
date: Thu, 10 Sep 2026 19:14:51 GMT
content-type: application/json
content-length: 301
server: cloudflare
www-authenticate: Bearer error="invalid_[redacted]", error_description="Authentication failed. The provided bearer [redacted] is invalid, expired, or no longer recognized by the server. To resolve: clear authentication [redacted]s in your MCP client and reconnect. Your client should automatically re-register and obtain new [redacted]s.", resource_metadata="https://api.notte.cc/.well-known/oauth-protected-resource/mcp/"
x-request-id: 1789067691.324743
x-cf-ray: a390c20e9934c8bd-SJC
nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
cf-cache-status: DYNAMIC
report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=1lNhmv%2FdAMk9Px2JqQT52W%2Fl84KMCnM9h2B5bC0zL6tm25PiJi2sdS2PCnIeeOMgZJjLQ8DPLYWf65ZlElcMyGZiypHyhPFDxi8N1GXUnAELLqNlS0qkKDxhP8PK0AQ%3D"}]}
cf-ray: a390c20e9934c8bd-SJC
alt-svc: h3=":443"; ma=86400
{"error": "invalid_[redacted]", "error_description": "Authentication failed. The provided bearer [redacted] is invalid, expired, or no longer recognized by the server. To resolve: clear authentication [redacted]s in your MCP client and reconnect. Your client should automatically re-register and obtain new [redacted]s."}
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
7 of 19 testable claims verified · 3 contradicted → integrity 5/100
23 distinct capability claims found in Notte’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
7
Verified
9
Unverified
3
Contradicted
12
Undersold
Verified (7)
“Provides fast, scalable remote browser infrastructure for running automations in the cloud”
Run a fleet of concurrent browser sessions with documented concurrency limits and programmatic session managementpartialproof ↗
“Lets you deploy browser automation scripts as invocable API endpoints”
Submit a browser task over a hosted HTTP API and receive the result by polling or webhook, without managing any browser myselfpartialproof ↗
“Notte MCP server lets an AI agent start cloud browser sessions, interact with pages, fetch data and build scripts”
“Provides an observe() call (via SDK or CLI) that returns live element IDs and selectors before acting”
Preview candidate actions on the current page (observe/plan) before committing the agent to actpartialproof ↗
“Ships an official CLI that lets AI agents control browsers via shell commands”
“All API requests are authenticated via a Bearer token against a documented public API”
Drive the product through a documented public APIfullproof ↗
“Tasks run from a single natural-language prompt with no selectors to write or maintain”
Drive the page through DOM-understanding action primitives (act/click/type on described elements) that survive selector and layout changespartialproof ↗
Unverified (12)
“Combines stealth browser mode with residential proxies for maximum anonymity against bot detection”
Enable stealth fingerprinting and residential or geo-targeted proxies so legitimate automations aren't blocked as botsfullproof ↗
“Offers a global residential proxy network with fixed IPs or bring-your-own proxy support”
Enable stealth fingerprinting and residential or geo-targeted proxies so legitimate automations aren't blocked as botsfullproof ↗
“Sessions automatically use clean, realistic browser fingerprints to avoid detection”
Enable stealth fingerprinting and residential or geo-targeted proxies so legitimate automations aren't blocked as botsfullproof ↗
“Serverless automations can be scheduled to run on a recurring basis”
“Stores passwords, API keys and sensitive credentials in an encrypted vault”
Store credentials in a vault and have the agent complete logins including TOTP/2FA challenges without exposing secrets to the modelpartialproof ↗
“Injects stored credentials into logins so the LLM never sees the actual secret values”
Store credentials in a vault and have the agent complete logins including TOTP/2FA challenges without exposing secrets to the modelpartialproof ↗
“Maintains authenticated browser profiles per agent so login/session state persists across runs”
Persist logged-in browser state in reusable profiles so agents skip the login wall on every subsequent runfullproof ↗
“Sessions expose a live ViewerUrl so you can watch the browser run in real time”
Watch a session live and take human control mid-run when the agent gets stuckpartialproof ↗
“Provides session replay and playback recordings for reviewing past runs”
Debug a failed agent run from recorded replays — video, screenshots, step-by-step action timelinespartialproof ↗
“Exposes a Chrome DevTools Protocol endpoint so existing Playwright automation code can connect to Notte browsers”
Connect my existing Playwright, Puppeteer, or CDP automation code to the product's browsers instead of rewriting itfullproof ↗
“Lets you script deterministic parts of a flow and invoke AI only when needed, cutting costs 50%+”
Cache resolved actions or generated code so repeat runs replay deterministically at lower cost and latency than re-prompting the LLMpartialproof ↗
“Supports bringing your own API keys rather than being locked into one provider”
Bring my own LLM provider — the framework is model-agnostic rather than locked to one vendor's modelspartialproof ↗
Contradicted (3)
“Automatically solves captchas encountered during browser automation sessions”
Rely on a documented captcha stance — automatic solving, human fallback, or explicit non-support — instead of silent task failuresdisputedproof ↗
“Extracts typed, schema-validated data (e.g. Pydantic models) from web pages using AI”
Extract typed, schema-validated data (Zod/Pydantic-style) from pages the agent visits, not just raw textdisputedproof ↗
“Agents can be given natural-language tasks that they complete end-to-end on websites”
Hand the product a natural-language goal and it completes a multi-step web task end to end — navigating, filling forms, and clicking through flowsdisputedproof ↗
Undersold (12)
Switch to a vision or computer-use action mode that operates on screenshots for canvases and UIs the DOM path can't handlepartialproof ↗
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationfullproof ↗
Set up automations that run autonomously in the backgroundfullproof ↗
Test against a sandbox environment without touching production datapartialproof ↗
Perform bulk operations across many items at oncepartialproof ↗
Define rules that trigger actions automatically on eventspartialproof ↗
Plug the browser layer into agent frameworks (Claude Agent SDK, Vercel AI SDK, LangChain, CrewAI) through documented adapterspartialproof ↗
Compose repeatable multi-step workflows with loops, conditionals, and parameters instead of one-shot promptspartialproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Read the product's source under an open licensepartialproof ↗
Claims outside our story set (1)
Real capability claims found in Notte’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Supplies verified emails and phone numbers for sign-up and 2FA to interact across platforms”
source ↗
Business model
Credit-based: Free ($10 one-time credits), Developer $20/mo, Startup $100/mo in credits; metered browser hours, proxies $10/GB, pass-through LLM tokens; Enterprise custom.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
Agent surface uptime MCP up · llms.txt up (tracking since Sep 11 '26)
