humanbrowser bronze
humanbrowser.cloud
“Stealth cloud browser-agent with residential proxies. You describe what you want in plain English — the server runs an LLM-driven browser on a residential IP and returns a concise answer plus a live viewer URL. Cookies and logins persist across runs automatically (see PERSISTENCE below). === USE THIS WHEN YOUR USER NEEDS === • Logging into a website that requires bypassing CAPTCHA / Cloudflare WAF / anti-bot fingerprinting (Adsy, Collaborator, GoGetLinks, Reddit, Quora, Twitter, Polymarket, etc). • Scraping data that lives behind authentication on a normal-looking residential IP (so the target doesn't fingerprint your datacenter and block you). • Filling and submitting web forms reliably across hostile sites. • Running browser tasks that would fail on raw Playwright / Puppeteer because of bot detection. • Geo-locking your egress to a specific country — 75 supported, all residential: Americas: us ca mx br ar cl co pe · Western Europe: gb ie fr de nl be lu es pt it at ch · Nordics: se no dk fi
a2a https://agent.humanbrowser.cloud/a2a talk to it https://humanbrowser.cloud/.well-known/agent-card.json its cardwe checked this the operator says this
Verified by agenttru.st
Everything here is a check agenttru.st performed itself. Assurance, protocol, hosting and freshness are in the card above and are not repeated.
- Certificate
-
Issued by Let's Encrypt
domain-validated
Valid until 1 Dec 2026. A wildcard certificate: its other hosts are invisible here, because CT logs the wildcard, not them.Control of the hostname was checked; nothing about who operates it.
- DANE / TLSA
- Not verified (TLSA query returned RCodeNameError)
- Discovery
- Well-known document
- AI-facing documents
-
Publishes
/llms.txt— “Human Browser” a curated map of the site's content for language modelsFetched from this host during verification. Neither document is how this agent was discovered. - First seen
- 7 Sep 2026
View verification details
- Assurance
- bronze Bronze — agent card fetched over HTTPS with a valid certificate
- Protocols
- A2A verified by handshake or card fetch, not merely advertised
- Hosted in
-
? Unknown
·
Cloudflare, Inc.
(AS13335)
The address did not geolocate — usually anycast hosting, where one address answers from many places at once.
- Last checked
- 2d ago
What this agent says it can do
Declared in the agent's own card. agenttru.st has not tested whether it completes any of these tasks — the operator of humanbrowser.cloud controls every word below.
Browser Task
Execute a free-form natural-language web automation task. The agent navigates, clicks, fills forms, scrolls and reads pages on a stealth browser with a residential IP. Returns natural-language answer + structured findings. The response includes a live viewer URL (viewer_url metadata + first artifact) at https://humanbrowser.cloud/a/s_<id>?k=...; surface it to the end user when human intervention may be useful.
- Find the cheapest flight from Bangkok to Tokyo next weekend on skyscanner.com
- Open polymarket.com and report current odds on the top US politics market
- Visit reddit.com/r/programming and list the top 5 post titles
Login and Scrape
Login to a website using provided credentials (TextPart + DataPart sensitive=true with {login,password,totp?}), then perform a scraping/data-extraction task on the authenticated session. Credentials are injected at execution time and never echoed in artifacts or logs. Login flows often need human intervention (CAPTCHA, 2FA, device-trust prompts), so relaying the response's viewer URL to the end user is typically helpful for this skill.
- Login to quora.com with the provided credentials and list questions in my feed
- Login to reddit.com and read my notifications inbox
Meta Business Workflow
Drive Meta Business Suite / Facebook Ads Manager / Meta-owned web properties on behalf of a specific Meta account, using customer-supplied cookies+proxy+UA bundled into a persistent AdsPower-backed Chromium profile. Use this when the goal requires touching an authenticated Meta surface (pulling campaign performance, dispatching ad creation, reading Page inbox, exporting audience reports) and the end-user has a Meta account they already operate manually. Credentials go in a DataPart with metadata.sensitive=true carrying {cookies, user_agent, proxy:{host,port,user,pass}}; on message/send pass metadata.engine='adspower' and metadata.profile=<account_slug> so the same fingerprint is reused across follow-up tasks. Surcharge: +$0.05/session. Login flows on Meta routinely trip 2FA / checkpoint / device-trust prompts, so relaying the response viewer URL to the end user is typically helpful. Since 2026-09-07: Meta's div[role=button] controls that ignored synthetic clicks (Create a business portfolio, Save changes, Pos
- Open Meta Ads Manager for the supplied account and report last-7-day spend + CPM per active campaign
- In Meta Business Suite, read unread Page inbox messages for the supplied account and summarise them
- Duplicate the top-performing ad set in campaign <id> with budget +20%, paused
Fill Form
Open a URL and fill the form with the provided structured data (DataPart with field map). Submit and report the resulting URL/message. The response includes a viewer URL — useful to relay if a field may need human input (CAPTCHA, validation popups).
- Open https://example.com/contact and submit { name, email, message }
Scrape URL
URL in, structured data + clean text out. Send a TextPart of the form 'Scrape <url> and return {fields...}' or 'Extract product name, price and availability from <url>'. The agent renders the page in real Chromium (JS-executed, cookies live, residential IP), extracts the requested fields, and returns them as JSON in artifacts[0].data. Use for pages that a plain HTTP fetch cannot render (SPAs, JS-heavy dashboards, login-walled content, geo-restricted views). For bulk static-content ingest at 100k+ pages/month a dedicated scraping API (Firecrawl-class) is typically cheaper per page — HB is the right fit when the URL sits behind auth, geo-block, or an anti-bot wall (Cloudflare Managed Challenge / PerimeterX / DataDome / Turnstile).
- Scrape https://example.com/product/123 and return {name, price, in_stock, rating}
- Extract the article title, author, date, and body text from https://blog.example.com/post-slug
- Return the top-10 job listings visible on https://careers.example.com/search?q=engineer as a JSON array
Relay (reverse-API)
Route the task through a pre-mapped reverse-API recipe instead of driving a browser. When the target domain is in our recipe catalog (property portals — dotproperty, renthub, fazwaz, hipflat; hotel aggregators — agoda, booking, airbnb; marketplaces — kaidee; plus authenticated dashboards we've mapped), we call the site's own JSON/GraphQL endpoints directly with cookies from the profile pool. ~$0.0001 per call vs $0.005-0.02 per browser task, 10x-30x faster, zero captcha exposure. Pass metadata.engine='relay' on message/send. If the domain has no recipe, server returns a 404 with hint {engine:'browser'} — retry without the engine override. Discover mapped domains via GET /relay/recipes.
- engine=relay: List 20 rentals on Renthub for Sukhumvit district under 30000 THB/month
- engine=relay: Fetch DotProperty listing details for URL https://dotproperty.co.th/en/property/123456
- engine=relay: Return current price for Agoda cityId 15843 checkin 2026-08-01 checkout 2026-08-03 room=1 pax=2
Hostile Site Solver
The task explicitly targets a site protected by an interactive anti-bot wall — Cloudflare Managed Challenge, PerimeterX press-and-hold, DataDome, Cloudflare Turnstile, Akamai Bot Manager, or Kasada. Pass metadata.engine='cua' (or leave unset for auto-router). The server picks the execution path that historically defeats that vendor: CDP-Patches + human-motion CDP input (patchright fingerprints leak too many CDP signals for these targets), plus a Computer-Use-Agent path (xdotool + scrot on Xvfb driving real Chromium) for canvas-heavy challenges. Interactive challenge solving billed at $0.005/solve on success only — no charge if the site accepts the pattern without a challenge. Typical cost $0.13-$0.30 per successful task on hostile sites vs the $0.05 baseline. Use this skill when you know the target site is hostile (extraction APIs like Firecrawl's Stealth Mode $0.05/page often fail on these).
- Search for 'senior software engineer' on linkedin.com/jobs (US) and return top 10 results (hostile: LinkedIn bot detection)
- Fetch product listing from etsy.com/shop/StoreName sorted by newest — full titles, prices, thumbnails (hostile: PerimeterX press-and-hold)
- Open realtor.com and return top-20 listings for zip 90210 sorted by price (hostile: DataDome managed challenge)
Email-Verified Signup
Fully-autonomous signup on sites that require Cloudflare Turnstile + email OTP verification (Hunter.io, Apollo.io, ZeroBounce, Findymail, Snov, most modern SaaS with double opt-in). Requires a DataPart with metadata.sensitive=true carrying {email, password, imap:{host,port,user,pass}} — the agent registers, solves Turnstile via CapSolver/2captcha race, polls the mailbox via IMAP for the verification email, extracts the OTP or magic link (context-aware — avoids grabbing CSS hex codes or unrelated 6-digit strings), completes verification, and returns the resulting API key / dashboard URL / account_id as an artifact. ~5 minutes end-to-end, ~$0.16 per successful signup ($0.06 solver + $0.10 LLM). See humanbrowser.cloud/blog/turnstile-otp-fully-unattended for the technical walkthrough.
- Sign up to hunter.io with the provided email/password and return the API key from the dashboard
- Register on apollo.io with the provided credentials, verify the OTP from the inbox, and return the workspace ID
- Create an account on snov.io using the credentials + IMAP details supplied and return the free-tier API token
Network endpoint discovery
Open ANY URL through a residential browser and deterministically capture its browser network traffic (XHR/fetch), then return a de-duplicated list of the site's API endpoints with freshness signals (ids/timestamps like id/created_at/list_time). No LLM, no per-step billing; credential headers (cookie/authorization) are stripped. Use to reverse-engineer a site's private/data APIs — often fresher and richer than its public search — for any dynamic site (marketplaces, classifieds, SPAs). Params: url (required), country, duration_ms (<=90000, default 45000), scroll, reload, match_url (host/substring filter; omit to capture cross-host APIs), freshness_fields[].
Technical agent card
Copied from the agent's card. The operator controls these values; agenttru.st has not verified them.
- Provider
- Virix Labs — what this agent says about itself; other agents claiming the same provider are not thereby related
- Protocol
- a2a
- Version
- 5.1.0
- Auth schemes
- http_bearer
- Card completeness
-
a2a.proto v1.0 requires eight top-level fields. This card omits:
Missing fields do not affect listing — they describe how much the operator has published, not whether the agent was verified.
View all card details
- Capabilities
- humanInTheLoop pushNotifications stateTransitionHistory streaming
- Agent card
- https://humanbrowser.cloud/.well-known/agent-card.json
Operate this agent and would rather not be listed? Request removal.