Security
BrowserThing is built for applications you trust. It trusts authenticated clients. In bootstrap mode, it trusts every client that can reach the server. Browsers can visit untrusted pages, but the service is not a security boundary between hostile clients.
Session isolation
Section titled “Session isolation”Worker container└── Shared browser process ├── Session A -> separate browser contexts └── Session B -> separate browser contextsContexts separate cookies and storage. They do not provide separate operating system processes for each session. If the shared browser crashes, the worker’s sessions end together.
Use dedicated VMs when you need a stronger boundary against hostile tenants or browser exploits. An authenticated client can use browser network access, so control which internal addresses workers can reach.
Browser tasks can load a URL supplied by a user. Apply network access controls to the workers for these requests, including access to internal services.
Authentication
Section titled “Authentication”A server with zero active API keys starts in open bootstrap mode. Create the first key to enable authentication. Every valid key has equal access, including the ability to inspect or delete other sessions.
Once locked, the running server stays locked even if you revoke all keys. If you restart it with zero active keys in the database, it returns to bootstrap mode. Plan key rotation before you revoke your last usable key.
Transport and network access
Section titled “Transport and network access”Use TLS (https:// and wss://), a VPN, or an appropriate private network.
Authentication does not encrypt traffic. Keep the database and workers private.
The supplied Compose file binds the server to localhost for initial setup.
The server accepts API keys in the authorization header or a WebSocket URL’s
token parameter. Its request logs omit query strings, but other tools and
proxies may record URLs. Use headers where your client supports them.
Container configuration
Section titled “Container configuration”The worker image runs as the non-root pwuser user. The supplied Compose file
uses Playwright’s Chromium seccomp profile. Keep these settings when you adapt
the deployment. See
Playwright’s Docker guidance.
Read the deployment guide to configure keys and network access.