Steel
Also known as: Steel Browser, Steel.dev
Open source browser infrastructure for AI agents: cloud or self-hosted Chromium sessions with stealth, CAPTCHA solving, persistent profiles and step-by-step agent traces.
Steel is open source browser infrastructure for AI agents: isolated cloud Chromium sessions an agent drives to navigate, click, fill forms and read pages, through a REST API, Node and Python SDKs, a CLI, or CDP connections for Playwright, Puppeteer and Selenium. The core runtime, Steel Browser, is open source and self-hosts with Docker, a one-click Railway deploy or a clustered setup; the managed cloud runs browsers in a single region, us-east.
Steel is built for production web work. Profiles persist cookies, local storage, extensions and auth context across sessions, and a Credentials API stores logins with envelope encryption and injects them into sessions, with TOTP support, without letting the agent read the secrets back. Proxies, stealth settings, dedicated IPs, mobile mode and CAPTCHA solving keep automations from being blocked.
For debugging and oversight, Agent Traces turns each recorded session into a timeline of the agent's actions synced to video, exportable as markdown or JSON and available through the API, alongside console and network logs; an embeddable live view lets a person take control of a running session. Installable skills teach coding agents to use Steel, debug failed sessions and harden reliability, and a cookbook covers dozens of frameworks and languages.
Pricing is usage-based on top of three plans: Launch at $0 plus usage with $30 of one-time credits, Scale at $250 a month plus usage with $100 of monthly credits, Enterprise SSO and a HIPAA-ready BAA, and custom Enterprise plans with reserved browser pools and sessions up to 24 hours. Browser hours run $0.10 on Launch and $0.08 on Scale, billed by the minute, and an inactivity timeout releases idle sessions.
Vendor details
Canonical URL
https://steel.dev
Category
Agent infrastructure
Subcategory
Browser infrastructure
Funding status
Independent. The core runtime, Steel Browser, is open source (github.com/steel-dev/steel-browser) and self-hostable, alongside a managed cloud.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
REST API with official Node and Python SDKs and a CLI, plus CDP connections for Playwright, Puppeteer and Selenium. Documented integrations give agents a Steel browser inside Vercel AI SDK, LangGraph, CrewAI, Pydantic AI, Mastra, OpenAI Agents SDK, Claude Agent SDK, Browser Use, Stagehand, Hermes Agent and Claude, OpenAI and Gemini computer use; the Credentials API injects stored logins; installable agent skills for coding agents; scrape, screenshot and PDF tools.
In practice
Your agent needs to browse real websites, not brittle scrapes. You create a Steel session over the API, connect Playwright via Chrome DevTools Protocol, and the agent navigates, clicks, and extracts with anti detection handled.
An agent keeps getting lost mid task and you cannot tell why. Steel's live Session Viewer with replays lets you watch the exact page state it saw, turning debugging into inspection instead of guessing.
Compliance requires keeping browsing data private. You self host the open source Steel container in your own environment, so sessions and cookies never leave your infrastructure.
Sources & related URLs
Agentic Index coverage score
7.0 / 14 capabilities · 50%
| Integrations & Tool Calling | Full |
|---|---|
|
Steel connects agents to outside tools and systems two ways. A named integration catalog gives the agent a Steel browser as a tool inside more than twenty frameworks and agents (Vercel AI SDK, LangGraph, CrewAI, Pydantic AI, Mastra, OpenAI Agents SDK, Claude Agent SDK, Browser Use, Stagehand, Hermes Agent and others), and the Credentials API lets the agent act in outside systems under stored logins: credentials are stored with envelope encryption, injected into a session's logins with TOTP support, and isolated so the agent cannot read them back. Sourcedocs.steel.dev/integrationsread 2026-09-23 |
|
| Workflow Orchestration | Not documented |
|
Multi-step and multi-agent workflows are not something Steel runs itself. It manages a browser session's lifecycle (create, keep alive, release on an inactivity timeout or an explicit call), which is how one browser runs. The cookbook's multi-step recipes run in the customer's chosen engine (CrewAI, LangGraph, Temporal, Restate, Convex), and no workflow runtime or step chaining of Steel's own is documented. Sourcedocs.steel.dev/overview/sessions-api/session-lifecycleread 2026-09-23 |
|
| Knowledge Grounding & RAG | Not documented |
|
Retrieval over the customer's own content is not part of the product: no knowledge base, index, vector store or grounding layer of Steel's own is documented. Steel's scrape, screenshot and PDF tools turn live web pages into HTML, markdown and images for the customer's own pipeline, which is extraction from the public web rather than retrieval over the customer's documents. Sourcedocs.steel.dev/overview/browser-tools/overviewread 2026-09-23 |
|
| Human Oversight & Guardrails | Partial |
|
Human intervention is built in: Steel's human-in-the-loop guide embeds a session's live view with interactive=true and showControls=true, so a person can take control of a running browser to enter credentials, solve a CAPTCHA, or verify and correct what the agent did. No approval gate, pause primitive, action allow list or policy guardrail is documented, and when to hand control to a person is decided in the customer's own code. Sourcedocs.steel.dev/overview/sessions-api/human-in-the-loopread 2026-09-23 |
|
| Security, Identity & Governance | Partial |
|
Enterprise SSO through the customer's identity provider comes on the Scale and Enterprise plans, per Steel's pricing and limits page. The Credentials API protects each credential with its own AES-256-GCM key wrapped by an organization-specific KMS key and keeps secrets out of the agent's reach after injection, and Scale and Enterprise offer a HIPAA-ready BAA. No trust center, security page, certification badge or attestation such as a SOC 2 report is published, a BAA is a contract rather than an attestation, and SSO appears only as a plan feature with no roles or permissions documented. Sourcedocs.steel.dev/overview/pricinglimitsread 2026-09-23 |
|
| Observability & Auditability | Full |
|
The agent's own behavior is recorded step by step. Agent Traces turns each recorded session into a timeline of agent activity (one row per action with verb, target, page URL and timestamp, expandable to page, element, pointer, keyboard or error detail), synced to the session recording and built from what happened in the browser rather than what the agent claimed. Traces export as markdown, JSON or a ZIP with screenshots and are served by a REST endpoint, sessions carry console and network logs, and data retention runs by plan (7 days on Launch, 14 on Scale, custom on Enterprise). Capture of the agent's prompts and an audit log separate from the traces are not documented. Sourcedocs.steel.dev/overview/agent-traces/overviewread 2026-09-23 |
|
| Memory & State Persistence | Not documented |
|
No memory the agent reads, with a stated scope and lifetime, is documented. What Steel keeps between runs is the browser's state: Profiles persist cookies, local storage, extensions and auth context across sessions, session context can be captured from one run and replayed into the next, and the Credentials API stores logins for injection. Each is loaded by the browser at session start rather than read by the agent as context to decide, so it works as a saved browser login rather than as agent memory. Sourcedocs.steel.dev/overview/profiles-api/overviewread 2026-09-23 |
|
| Deployment & Data Residency | Full |
|
Steel can run in the customer's own environment: the open source Steel Browser runtime and API self-host in the customer's infrastructure with Docker, a one-click Railway deploy, or a clustered setup, with guides for each. The managed cloud itself is a fixed single region. The session configuration page says Steel runs browsers in one region, us-east, and rejects any other region value, so a buyer who needs a different hosting location gets it only by self-hosting. Proxy geolocation changes the IP a site sees, not where the browser runs. Sourcedocs.steel.dev/overview/self-hosting/dockerread 2026-09-23 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
Ready-made starting points ship in two forms: five installable agent skills for coding agents (steel-browser, steel-developer, steel-reliability, steel-session-debugging and a skill creator) and a cookbook of starter projects across frameworks and languages. The skills teach the customer's own agent to use Steel and the starters are examples a developer builds from; neither is a catalog of agents a buyer adopts to do work. Sourcedocs.steel.dev/overview/skills/available-skillsread 2026-09-23 |
|
| Triggers & Channel Coverage | Not documented |
|
A browser starts only when a caller creates a session through the API, SDK or CLI; no event, schedule, webhook or inbound queue of Steel's own starts agent work. The scheduled recipes in the cookbook run on the customer's scheduler (Convex crons, Temporal workflows), not on Steel. Sourcedocs.steel.dev/overview/sessions-api/overviewread 2026-09-23 |
|
| Model Flexibility & Routing | Not documented |
|
Steel runs no model the buyer chooses. The model lives in the customer's agent, whether Claude, OpenAI or Gemini computer use or a framework the customer runs, and each integration page shows that agent calling a Steel browser, so model choice and routing sit with the customer's agent rather than with Steel. Sourcedocs.steel.dev/integrationsread 2026-09-23 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
Steel is callable from outside through a documented REST API (api.steel.dev, with an API reference covering sessions, profiles, files, extensions, credentials, CAPTCHAs, browser tools and agent traces, authenticated by API key), official Node and Python SDKs, a CLI, and CDP connections for Playwright, Puppeteer and Selenium. The open source Steel Browser exposes the same API when self-hosted. Sourcedocs.steel.dev/api-referenceread 2026-09-23 |
|
| Testing, Debugging & Optimization | Partial |
|
Debugging after a run goes wrong is supported: the Session Debugging skill has a coding agent collect evidence on a failed session and diagnose it, handing off to the Reliability skill when the fix is bot detection, CAPTCHA, proxy, profile or retry strategy. This is debugging rather than testing, and no evaluation harness, scored test cases or quality gate is documented. Sourcedocs.steel.dev/overview/skills/available-skills/steel-session-debuggingread 2026-09-23 |
|
| Browser & Computer Use | Full |
|
Operating a real browser for agents is Steel's product: isolated cloud browser sessions an agent drives to navigate, click, fill forms and read pages, through CDP with Playwright, Puppeteer or Selenium or through Claude, OpenAI and Gemini computer-use agents, with mobile mode, stealth, proxies, CAPTCHA solving and persistent profiles for production use. Sourcedocs.steel.dev/overview/intro-to-steelread 2026-09-23 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Steel released a native browser plugin for Hermes Agent. The integration provides Hermes with cloud browser sessions, live session viewing, page extraction capabilities, and built-in controls for per-site proxies and CAPTCHA solving.
Bears on: Integrations
View sourceSteel Browser is now available within Stripe Projects. The integration provides agents with on-demand cloud browser sessions for executing live web tasks directly within the Stripe ecosystem.
Bears on: Integrations
View sourcePricing
Launch $0 plus usage · Scale $250/mo plus usage · browser hours from $0.08
Metered usage: browser hours billed by the minute, proxy bandwidth per GB, CAPTCHA solves and browser tools calls per thousand, drawn first from plan credits
Included quota
Open source self host is free (you pay only your own infrastructure). The managed cloud gives free credits to start, then Launch, Scale, and Enterprise plans meter browser session usage against plan credits and rates, with an inactivity timeout that releases idle sessions.
What is public
Plan prices, metered rates, the free cloud credits and the open source self host path are public; Enterprise rates are custom.
Billing mechanics
Free open source self host, or managed cloud plans (Launch, Scale, Enterprise) that meter browser session time and usage credits, with an inactivity timeout to stop billing idle or crashed sessions.
Cost watchouts
Proxies and CAPTCHA solving on Launch need a $10 paid deposit before use; session length is capped by plan (15 minutes on Launch, 1 hour on Scale), and data retention is 7 or 14 days unless Enterprise. Self-hosting moves the cost to your own infrastructure.
Variable cost rationale
Cost is metered usage across browser hours, proxy bandwidth, CAPTCHA solves and browser tools, so concurrency, session length and anti-bot needs drive nearly all of it; self-hosting the open source build removes the vendor bill.
Overage / add-ons
Cloud usage meters browser session time and credits against the plan; self host has no vendor metering beyond your own infrastructure.
Sales call required
Mixed (some tiers require a call)
Free / trial
Launch at $0 a month with $30 in one-time usage credits valid 90 days; the open source Steel Browser is free to self host
Lowest paid plan
Scale $250 a month plus usage
Commercial notes
Independent open source browser API for AI agents, with a self host Docker path and a managed cloud.
Key ambiguities
Rates differ by plan and by meter (browser hours, proxy bandwidth, CAPTCHA solves, browser tools), so total cost depends on the mix a workload uses; Enterprise rates are custom.
Related vendors
- AgentOps — Agent observability and debugging platform: open source SDKs trace…
- Agno — Python agent framework and AgentOS runtime (formerly Phidata) for…
- AIsa — Resource and payment gateway for AI agents: one key to 110+ models…
- AlphaBitCore — AI control plane for regulated financial firms: one gateway enforces…
- Anchor Browser — Cloud hosted browser infrastructure that lets AI agents operate real…
- Apify — Cloud platform and marketplace of more than 73,000 ready-to-run…
Alternatives to Steel
The closest documented capability profiles to Steel among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Kernel8.5 / 14Adds documented Workflow Orchestration
- Browserless8.5 / 14Adds documented Workflow Orchestration
- Prefactor4.5 / 14A lighter documented profile than Steel
- AgentOps5.0 / 14Adds documented Model Flexibility & Routing
- Hyperbrowser8.0 / 14Adds documented Workflow Orchestration and Memory & State Persistence, among othersSteel vs Hyperbrowser →
- Lakera7.0 / 14Fuller documented coverage on Human Oversight & Guardrails and Security, Identity & Governance
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded