Skip to main content
Give Claude a browser through the Anthropic Python SDK. Browser Use provides the browser driver and Bash. Anthropic’s tool runner calls the tools, reads their results, and asks Claude what to do next.
This integration requires a Browser Use version containing browser_use.integrations.anthropic and an Anthropic SDK version containing anthropic.tools.browser and client.beta.messages.tool_runner. If either import is unavailable, your installed package version does not support this example. Check Anthropic’s browser-toolset release instructions for SDK availability.
Claude sends tool calls through the Anthropic SDK to Browser Use. Browser Use provides browser actions and Bash; results return to Claude. The browser can run locally or remotely, while Bash runs beside the SDK.

Start with a reading list

Read the first three Hacker News posts and save their titles, links, points, and comment counts as Markdown and JSON. The task needs no account and keeps the browser on Hacker News. Bash writes the files to outputs/. Use Python 3.11 or newer on Linux or macOS with /bin/bash. On Windows, run this example inside WSL. Bash executes on the SDK host even when the browser runs in Cloud. Install the packages and local Chromium:
Set your Anthropic API key and a model that supports the browser toolset:
Save the following as run_browser.py. The commented Cloud option uses a key from Browser Use Cloud.
Run uv run run_browser.py. The terminal prints the answer and filenames. Set ANTHROPIC_LOG=info to include SDK request logs. The system prompt is part of your application. This one asks Claude to inspect before acting, use current element references, verify saved files, and treat webpage content as untrusted data. Adapt it to your task.

From a page to a saved file

After opening Hacker News, Claude can call read_page to inspect the page, then call bash to write the reading list. The Anthropic tool runner passes each call to Browser Use and returns the result to Claude. The browser can be remote; Bash still runs beside your Python process.
Two calls after opening Hacker News: Claude asks Browser Use to read the page, receives the result, then uses Bash to save Markdown and JSON on the SDK host. Anthropic's tool runner connects each request and response.

Pick a browser

For Cloud, set BROWSER_USE_API_KEY and change the driver line to BrowserUse(use_cloud=True). You do not need a local Chromium install in that mode. To connect to a browser you already started, pass a connected BrowserSession. Close that session in your application’s cleanup block. See remote browser connections for CDP configuration.

Tools from Browser Use

Pass BrowserUse and Bash to the same runner with tools=[driver, bash]. They come from the same Browser Use integration. Browser actions control the browser; Bash runs commands beside your Python process. Claude calls structured actions such as navigate and left_click. The driver translates them to browser operations over CDP. Optional javascript_exec runs JavaScript inside the page. Bash can process extracted data and write reports.
  • Navigation: navigate, new_tab, list_tabs, switch_tab, close_tab.
  • Page state: screenshot, zoom, read_page, find, get_page_text, wait.
  • Pointer: left_click, right_click, middle_click, double_click, triple_click, hover, mouse_move, left_mouse_down, left_mouse_up, left_click_drag, scroll, scroll_to.
  • Input: type, key, hold_key, form_input, file_upload.
  • Diagnostics: read_console, read_network, javascript_exec.
file_upload, javascript_exec, read_console, and read_network are disabled by default. Enable the actions your task needs. The integration also includes Bash, registered alongside the 31 browser actions with tools=[driver, bash].

Ask before sensitive actions

Enabling file upload or page JavaScript requires a confirmation callback. A declined approval prevents execution. A failing callback also prevents execution.
This callback prompts for upload and JavaScript, and approves other browser actions. Add your own checks for actions such as sending a message, submitting a purchase, or deleting a record. Browser confirmation does not cover Bash. Omit Bash or apply a separate execution policy when your application needs shell approval. Bash limits execution time and returned output, and removes ambient credentials from its child environment. Its working directory is not an operating-system sandbox. Run untrusted tasks in an isolated environment.

Files with a Cloud browser

With local Chromium, an approved local file can be selected for upload, and downloaded bytes can be read locally. With a remote browser, the browser and your Python process have separate filesystems. file_upload selects a path on the browser host. For a remote browser, first stage the file using your application’s transfer mechanism. Then map an approved document ID to that path:
The resolver maps IDs to paths; it does not copy bytes. BrowserUse(use_cloud=True) does not add automatic file transfer. The open-source Agent uses the same browser-host path requirement for upload. A download notification tells you that the browser finished downloading. For Cloud, retrieve the file to your SDK host before asking Bash to read it. A reported remote path is not proof that the file exists locally. For the Hacker News example, Bash creates the Markdown and JSON directly on the SDK host. No browser download or transfer is needed.
AnthropicAnthropicBuilt with the Anthropic Python SDK. Read the Anthropic browser-toolset quickstarts.