{
  "schema_version": "agentpmt.docs.v1",
  "generated_at": "2026-07-21T09:21:24.583Z",
  "release_id": "645ba065961f3e4869733f1c5ebbd86e4233149ebb79daf3c648378a1d5336d2",
  "id": "docs-05b8813249e54a9e",
  "page_url": "https://www.agentpmt.com/docs/tool-specific/astrobrowse",
  "markdown_url": "https://www.agentpmt.com/docs/tool-specific/astrobrowse?format=agent-md",
  "json_url": "https://www.agentpmt.com/docs/tool-specific/astrobrowse?format=agent-json",
  "source_path": "content/docs/astrobrowse.mdoc",
  "updated_at": "2026-07-20T00:03:00.792Z",
  "headings": [
    {
      "depth": 2,
      "id": "ways-to-connect",
      "title": "Ways To Connect"
    },
    {
      "depth": 3,
      "id": "mcp-integration",
      "title": "MCP Integration"
    },
    {
      "depth": 3,
      "id": "restapi",
      "title": "RestAPI"
    },
    {
      "depth": 3,
      "id": "schema",
      "title": "Schema"
    },
    {
      "depth": 2,
      "id": "enable-astrobrowse",
      "title": "Enable AstroBrowse"
    },
    {
      "depth": 3,
      "id": "auto-approve-all-tools",
      "title": "Auto Approve All Tools"
    },
    {
      "depth": 3,
      "id": "enable-for-a-specific-agent",
      "title": "Enable For A Specific Agent"
    },
    {
      "depth": 2,
      "id": "connect-your-tailscale-account",
      "title": "Connect Your Tailscale Account"
    },
    {
      "depth": 3,
      "id": "what-youll-need",
      "title": "What you'll need"
    },
    {
      "depth": 3,
      "id": "step-1-install-tailscale-on-your-exit-node-device",
      "title": "Step 1 — Install Tailscale on your exit-node device"
    },
    {
      "depth": 3,
      "id": "step-2-enable-exit-node-mode",
      "title": "Step 2 — Enable exit-node mode"
    },
    {
      "depth": 3,
      "id": "step-3-create-a-reusable-auth-key",
      "title": "Step 3 — Create a reusable auth key"
    },
    {
      "depth": 3,
      "id": "step-4-connect-the-credential-in-agentpmt",
      "title": "Step 4 — Connect the credential in AgentPMT"
    },
    {
      "depth": 3,
      "id": "step-5-assign-the-credential-to-an-agent-group",
      "title": "Step 5 — Assign the credential to an agent group"
    },
    {
      "depth": 3,
      "id": "step-6-try-it",
      "title": "Step 6 — Try it"
    },
    {
      "depth": 2,
      "id": "manage-authenticated-sites",
      "title": "Manage Authenticated Sites"
    },
    {
      "depth": 3,
      "id": "site-authentication",
      "title": "Site Authentication"
    },
    {
      "depth": 2,
      "id": "agent-prompts",
      "title": "Agent Prompts"
    },
    {
      "depth": 2,
      "id": "browser-takeover",
      "title": "Browser Takeover"
    },
    {
      "depth": 2,
      "id": "tracking-and-auditing",
      "title": "Tracking and Auditing"
    },
    {
      "depth": 3,
      "id": "activity-logging-and-audit-trails",
      "title": "Activity Logging and Audit Trails"
    }
  ],
  "related_products": [],
  "related_workflows": [],
  "doc": {
    "title": "AstroBrowse",
    "description": "Comprehensive guide to AstroBrowse - a web automation tool for authenticated browsing, site management, and AI agent integration.",
    "category": "Tool Specific",
    "image": null,
    "full_path": "tool-specific/astrobrowse",
    "body_markdown": "# AstroBrowse\n\nAstroBrowse is a cloud based browser tool that enables AI agents to access websites as you without needing a login or password. All outgoing traffic runs through your own network via Tailscale. (Set up a free Tailscale account [HERE](https://tailscale.com/))\n\n## Ways To Connect\n\nAstroBrowse supports MCP and RestAPI connection methods to integrate with your AI agents and workflows.\n\n### MCP Integration\n\nAstroBrowse connects to any agent harness via the Model Context Protocol (MCP).\n\nFor detailed information about connecting agents via MCP, see the [MCP Integration section](https://www.agentpmt.com/docs/getting-started/connect-an-agent#mcp-integration) in our Connect An Agent guide.\n\n### RestAPI\n\nFor custom integrations and advanced workflows, AstroBrowse provides a REST API that allows programmatic control over browsing sessions, site management, and audit trails.\n\nFor complete REST API documentation and authentication details, see [Programmatic Access](https://www.agentpmt.com/docs/api-reference/programmatic-access).\n\n### Schema\n\nFor the full AstroBrowse API schema and endpoint reference, visit the [AstroBrowse marketplace page](https://www.agentpmt.com/marketplace/astrobrowse-authenticated-agentic-browser) and click the tab that says Schema.\n\n![AstroBrowse marketplace page showing the Schema tab selected to view the API schema and endpoint reference](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/schema.6815b16d5b2b.png)\n\n_On the AstroBrowse marketplace page, click the Schema tab to view the full API schema and endpoint reference._\n\n## Enable AstroBrowse\n\nBefore your agents can use AstroBrowse, make it available to an Agent Group. You can either auto-approve every tool for the group, or enable AstroBrowse specifically.\n\n### Auto Approve All Tools\n\nSet your Agent Group to Auto Approve All Tools so AstroBrowse (and any other tools you add) are available without per-tool approval.\n\n![AgentPMT Agent Group settings showing the Auto Approve All Tools option enabled](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/tailscale-autoapprove-all-tools.a78ab35e080c.png)\n\n_Set your Agent Group to Auto Approve All Tools to make every tool available without per-tool approval._\n\n### Enable For A Specific Agent\n\nTo enable AstroBrowse on its own, open the AstroBrowse product page, click **AI Agent**, and click **Enable For Agent**.\n\n![AstroBrowse product page showing the AI Agent option and Enable For Agent button](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/tailscale-enable-for-agent.c6fb66618fb8.png)\n\n_On the AstroBrowse product page, click AI Agent and then Enable For Agent._\n\n## Connect Your Tailscale Account\n\nAstroBrowse routes all outgoing browser traffic through your own network via a Tailscale exit node, so destination sites see your residential ISP IP instead of a datacenter address. Setup is one-time per device; AgentPMT reuses it for every subsequent browser session.\n\n### What you'll need\n\n- A Tailscale account — the personal **Free** plan at [tailscale.com](https://tailscale.com/) is plenty.\n- One device on your home network that stays online while your agents are browsing — a laptop, desktop, NAS, or Raspberry Pi all work. This becomes your exit node.\n\n### Step 1 — Install Tailscale on your exit-node device\n\nOpen [tailscale.com/download](https://tailscale.com/download) on the device that will be your exit node and run the installer for its OS. After installation, sign in with the same Tailscale account you'll use for AgentPMT.\n\n### Step 2 — Enable exit-node mode\n\nTell Tailscale this device is willing to route traffic out to the internet for other devices on your tailnet (including the AgentPMT browser).\n\n- **Windows / Linux**: open a terminal and run:\n  \n  ```bash\n  tailscale up --advertise-exit-node\n  ```\n- **macOS**: in the Tailscale menu bar app, choose **Exit Nodes → Run Exit Node**.\n- **iOS / Android / NAS**: follow [Tailscale's exit-node setup guide](https://tailscale.com/kb/1103/exit-nodes) for your platform.\n\nThen open the Tailscale admin console at [login.tailscale.com/admin/machines](https://login.tailscale.com/admin/machines), find your device, click **Edit route settings**, and tick **Use as exit node**. Save.\n\n![Tailscale admin console Machines page showing the list of devices to choose an exit machine from](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/tailscale-choose-exit-machine.1d1675476568.png)\n\n_In the Tailscale admin console, find the device that will act as your exit node._\n\n![Tailscale machine menu with the Edit route settings option highlighted](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/tailscale-edit-route-settings.db4920db02e8.png)\n\n_Open the device's Edit route settings menu._\n\n![Tailscale route settings dialog with the Use as exit node checkbox ticked](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/tailscale-use-as-exit-node.4669cf52584e.png)\n\n_Tick Use as exit node and save._\n\nNote the device's short name in the **Machine** column (for example, `spark-3b02`) — you'll paste it into AgentPMT in Step 4.\n\n### Step 3 — Create a reusable auth key\n\nIn the Tailscale admin console, go to **Settings → Keys → Generate auth key** and configure:\n\n- **Reusable**: ON. Required — AgentPMT re-registers the browser against your tailnet each time it provisions a session.\n- **Pre-approved**: ON. Required — without this you'd have to approve the browser manually every time.\n- **Ephemeral**: OFF.\n- **Expiration**: 90 days is the default and fine to start with. You can rotate at any time without disrupting an active session.\n- **Tags**: optional. Leave blank unless you've configured ACL tags.\n\nClick **Generate key** and copy the `tskey-auth-…` value. AgentPMT won't show it back after you save it, so paste it now.\n\n![Tailscale admin console Settings menu showing the Keys page where you generate an auth key](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/tailscale-generate-auth-key.0e58f3c1aac8.png)\n\n_In Settings → Keys, choose Generate auth key._\n\n![Tailscale auth key generation dialog with the Reusable and Pre-approved options enabled](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/tailscale-reusable-key.87b4a4e86728.png)\n\n_Make sure the key is Reusable and Pre-approved, then generate it._\n\n### Step 4 — Connect the credential in AgentPMT\n\nIn the AgentPMT dashboard, go to **Credentials → Add → Tailscale Browser Egress** and fill in:\n\n- **Tailscale auth key**: the `tskey-auth-…` value from Step 3.\n- **Exit node name**: the short name from Step 2 (for example, `spark-3b02`).\n- **Auth key expires on**: the date you set in Step 3, formatted as `YYYY-MM-DD` (for example, `2026-09-01`). AgentPMT emails you 14 days, 3 days, and 1 day before this date so you have time to rotate.\n\nSave. The credential is encrypted at rest and never displayed back.\n\n![AgentPMT dashboard showing the Credentials tab where Tailscale browser egress credentials are managed](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/tailscale-credentials-tab.576f70ed800e.png)\n\n_Open the Credentials tab in the AgentPMT dashboard._\n\n![AgentPMT new credential dialog with the Tailscale option selected, showing fields for the auth key, exit node name, and expiration date](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/tailscale-new-credential.d889f31cac9e.png)\n\n_Choose Tailscale and enter the auth key, exit node name, and expiration date._\n\n### Step 5 — Assign the credential to an agent group\n\nAdd the Tailscale credential to the agent group that will run your browser sessions, then select the credential you just created.\n\n![AgentPMT agent group settings showing where to add credentials to the group](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/tailscale-add-to-agent-group.fe6f24b66a87.png)\n\n_Add the Tailscale credential to the agent group that will run your browser sessions._\n\n![AgentPMT credential picker showing the newly created Tailscale credential selected for the agent group](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/tailscale-choose-credential.aafc1ed97bff.png)\n\n_Choose the Tailscale credential you just created._\n\n### Step 6 — Try it\n\nOpen any agent or workflow that uses the Tailscale browser product. The first session takes a few seconds longer than usual while AgentPMT spins up a dedicated Tailscale daemon bound to your tailnet. After that there's no extra delay.\n\nTo confirm your home IP is what destinations see, ask the agent to navigate to `https://ipv4.icanhazip.com` inside a session and read the page back. The IP shown should match your home network's public IP.\n\n## Manage Authenticated Sites\n\nAstroBrowse allows you to manage and maintain authenticated sessions across multiple websites, enabling your AI agents to access protected content and perform actions on your behalf.\n\n### Site Authentication\n\nLogin to any sites you want your agent to access using the virtual browser in your dashboard.\n\n![AstroBrowse dashboard showing how to add a site by logging in through the virtual browser](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/add-site.936be5c8acc5.png)\n\n_Add a site by logging into it through the virtual browser in your AgentPMT dashboard._\n\nLogin through the virtual browser to create a session. The session is isolated, encrypted, and saved in AgentPMT. Your passwords are not saved and are not visible to AgentPMT or your AI agent.\n\n![AstroBrowse saving a new site session after login through the virtual browser](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/saving-new-site.a19725f9b8bc.png)\n\n_After you log in, the isolated session is encrypted and saved in AgentPMT — your password is never stored or visible._\n\nPermanently revoke a website at any time to destroy the session, preventing an agent from logging in until you re-add it.\n\n![AstroBrowse dashboard showing how to permanently revoke a website and destroy its saved session](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/revoke-site.3b652bafbb19.png)\n\n_Revoking a website destroys its session, so no agent can log back in until you re-add the site._\n\n## Agent Prompts\n\nAn agent can choose to use the AstroBrowse tool on their own when they need it. If your agent isn't finding the tool you can give them specific details by clicking 'AI Agent' and 'Copy prompt for LLM' on the AstroBrowse tool page.\n\n![AstroBrowse tool page showing the AI Agent option and Copy prompt for LLM button for giving an agent specific tool details](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/agentprompt.b2743d77c1e4.png)\n\n_If your agent isn't finding AstroBrowse on its own, use 'AI Agent' → 'Copy prompt for LLM' on the tool page to give it the specific details it needs._\n\n## Browser Takeover\n\nAstroBrowse keeps the AI agent in control of the browser session by default. When the agent encounters a step it cannot complete on its own — such as a CAPTCHA or a complex verification flow — it can request human assistance and send a link that lets a person step in and finish that specific action, after which control returns to the agent.\n\n![AstroBrowse browser takeover request showing the agent asking a human to complete a step it cannot handle, with a link the person can use to take over](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/browser-takeover-request.25e405d963e9.png)\n\n_When the agent cannot complete a step, it sends a takeover request with a link so a human can finish that action and hand control back._\n\n## Tracking and Auditing\n\nComprehensive tracking and auditing features ensure transparency and compliance in automated browsing activities.\n\n### Activity Logging and Audit Trails\n\nEvery action performed through AstroBrowse is logged, and those logs feed audit reports for compliance, analysis, and troubleshooting.\n\n![AstroBrowse agent activity dashboard showing logged sessions, actions taken, pages visited, and errors](https://www.agentpmt.com/docs-assets/images/screenshots/astrobrowse/agent_activity_dashboard.795d5fb6de39.png)\n\n_The AstroBrowse agent activity dashboard surfaces every logged session and action for audit and review._\n\nLogged details include:\n\n- Timestamp and session details\n- Actions taken and pages visited\n- Data accessed and modified\n- Errors and exceptions\n"
  }
}
