Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To use a plugin with Vercel’s Agent Browser, add its npm package or GitHub repository with agent-browser plugin add, inspect the configuration, then invoke it using the command path for its declared capability. A credential provider, browser provider, launch mutator, and generic command plugin do not all run through the same command.
What Agent Browser plugins do
Agent Browser plugins extend the CLI through external executables. A plugin is configured with a name, a command, and one or more capabilities; it is not necessarily built into Agent Browser itself. That distinction matters: installing a package registers how Agent Browser can call it, but does not make every plugin use the same invocation syntax or establish that the package is safe.
The documented plugin references can resolve from npm or GitHub. Plain package names and scoped names such as @company/name refer to npm packages; references in owner/repo form refer to GitHub repositories. See the Agent Browser configuration guide for the current command and configuration details.
Install a plugin
Run the add command from the project where you want the plugin configured. These are documentation examples, not endorsements or confirmation that each package is currently maintained or available:
#1 Best Overall
agent-browser plugin add agent-browser-plugin-vault --name vault
agent-browser plugin add @company/agent-browser-plugin-vault --name vault
agent-browser plugin add org/agent-browser-plugin-cloud-browser
The first two examples illustrate npm package references; the third uses GitHub’s owner/repo form. The add command writes project configuration by default. Add --global when you want the plugin configured for your user account instead:
agent-browser plugin add agent-browser-plugin-vault --name vault --global
Packages that provide a plugin.manifest can expose their plugin names and capabilities for discovery. If a package has no manifest, the configuration guide says to specify its capability during installation with --capability <name>. Check the package’s own documentation for the exact capability it implements rather than guessing.
Where plugin configuration lives and how precedence works
Agent Browser reads user-level configuration from ~/.agent-browser/config.json and project-level configuration from ./agent-browser.json. Project values override user values. Project plugin entries are appended after user entries, and when the same plugin name is present in both, the later project entry resolves.
Free tools Windows power users keep installed
One-click scans. No signup required.
Here is the shape of a manual project-level entry:
{
"plugins": [
{
"name": "vault",
"command": "agent-browser-plugin-vault",
"capabilities": ["credential.read"]
}
]
}
Use project configuration when a repository needs a specific plugin setup; use --global when you want the setting available across your own projects. Treat project configuration as executable integration setup, not as a trust review: verify the package and command before allowing it to run.
Environment variables take precedence over configuration, and CLI flags take precedence over both. AGENT_BROWSER_PLUGINS can replace configuration discovery with a JSON array of plugin entries. The exact environment-variable and flag interactions are documented in the configuration reference.
Inspect the plugin before invoking it
After installation, list the configured plugins and inspect the one you intend to use:
agent-browser plugin list
agent-browser plugin show vault
Confirm the resolved name, executable command, and declared capabilities. This helps catch a missing entry, a naming mismatch, or a capability different from what you expected before the plugin is invoked. Agent Browser’s security guidance treats plugins as separate executables and recommends understanding their permissions.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Run the plugin using its capability
Use the capability declared by the plugin to choose the invocation route. The dedicated workflows for core capabilities are not interchangeable with generic plugin run.
Credential provider: credential.read
A credential provider supplies credentials to an Agent Browser login workflow. Invoke it with auth login:
agent-browser auth login work --credential-provider vault --item work-login
Replace work, vault, and work-login with the login profile, configured provider name, and item reference you actually use. Agent Browser’s authentication workflow says returned credentials are used for that login and are not saved locally by Agent Browser.
Rank #3
Do not put passwords, vault tokens, or other secret material in plugin command arguments. The authentication guidance warns against this; use the vault vendor’s login/session mechanism or an appropriate environment outside Agent Browser configuration.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsBrowser provider: browser.provider
A browser provider supplies a CDP WebSocket URL. Select it through the regular Agent Browser command with --provider:
agent-browser --provider cloud-browser open https://example.com
Use the configured provider name, not necessarily the package name. Provider-specific setup, authentication, availability, and costs depend on the external provider; the Agent Browser documentation establishes the integration path, not a ranking or comparative audit of providers. The official configuration documentation includes provider integrations such as AgentCore, Browser Use, Browserbase, Browserless, Kernel, and Remote Agent Browser.
Launch mutator: launch.mutate
A launch mutator can append local browser launch arguments, extensions, or initialization scripts before Chrome starts. There is no general-purpose plugin run step for this capability. Configure the plugin and use the ordinary browser launch workflow; the mutator participates in launch.
Generic command or custom capability
For a plugin declaring command.run or a custom capability, use plugin run with its name, capability type, and JSON payload. The command reference illustrates this invocation shape as follows:
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchagent-browser plugin run captcha captcha.solve --payload '{"siteKey":"...","url":"https://example.com"}'
This is only an example of the protocol shape. It does not establish that a CAPTCHA-solving plugin is available, suitable, or permitted on any particular site. Check the plugin’s documentation and the site’s rules before using a capability that interacts with challenges or access controls.
For current syntax, see Agent Browser commands.
Use a credential provider with an already prepared page
For a login that begins from an active page—for example, after a user has completed a stateful navigation step—the authentication workflow supports --no-navigate. It prevents the initial login navigation, but does not promise that submitting the login form will not navigate.
agent-browser auth login work --credential-provider vault --item work-login --no-navigate
The command requires an active top-level HTTP or HTTPS page. Agent Browser compares the page’s scheme, host, and effective port with the effective credential URL. Paths, query strings, and fragments may differ. If the origins do not match, the command will not fill credentials. If automatic form detection does not fit a particular login page, the login command also supports per-login selector overrides; use the current authentication reference for the available options.
Add confirmation gates for sensitive capabilities
For sensitive plugin operations, Agent Browser’s security policy can require confirmation for a capability. The documentation shows policy entries in this form:
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →--confirm-actions plugin:vault:credential.read
--confirm-actions plugin:cloud-browser:browser.provider
--confirm-actions plugin:stealth:launch.mutate
Choose the policy name to match the configured plugin and capability. A confirmation gate adds an approval step; it does not replace checking the executable, package source, or permissions. The security guide also says saved authentication profiles are encrypted with AES-256-GCM. If AGENT_BROWSER_ENCRYPTION_KEY is unset, a key is generated on first use at ~/.agent-browser/.encryption-key. Back up that key if you need portability, or set the variable explicitly.
Best Value
Choosing a plugin source and scope
Before adding a plugin, assess it against the work it will do rather than choosing by package name alone:
- Capability: determine whether you need credential retrieval, a hosted browser connection, launch customization, or a custom command.
- Source: decide whether the package or repository is the intended one, and check the maintainership and documentation of that specific project.
- Scope: choose project-level configuration for a repository-specific setup or user-level configuration for your own broader use.
- Sensitivity: consider whether the plugin can access credentials, alter browser launch behavior, or route work through a hosted provider. Use confirmation gates where appropriate.
The official documentation explains capabilities, scopes, and policy controls, but does not provide comparative security audits or quality rankings for third-party plugins. Make that trust decision for the particular executable you install.
Troubleshooting plugin setup and use
The plugin does not appear in the list
- Run
agent-browser plugin listand inspect the target withagent-browser plugin show <name>. - Check whether you added it project-wide or globally, and whether you are running the command from the project whose
agent-browser.jsonyou edited. - If the package has no manifest, confirm that you supplied the required
--capability <name>during add, or add a correctly formed manual entry. - Check whether
AGENT_BROWSER_PLUGINSis overriding normal config discovery.
The command is rejected or does the wrong kind of work
Compare the invocation with the declared capability. Credential providers use auth login --credential-provider; browser providers use --provider; launch mutators participate in launch; generic commands use plugin run. Do not assume every plugin has a generic run command.
Credential login does not fill the page
- With
--no-navigate, check that an active top-level page is open and that scheme, host, and effective port match the effective credential URL. - If the page is not prepared for the profile’s login flow, omit
--no-navigateso the normal initial navigation can occur. - If the form controls cannot be detected automatically, review the login command’s selector override options in the authentication reference.
- Keep credentials out of command-line arguments and plugin configuration.
A confirmation prompt appears
Check whether a --confirm-actions policy covers that plugin and capability. This is expected when confirmation has been configured; approve only if you understand the requested action.
Or skip the browser setup:
If your task is to retrieve a clean website screenshot rather than extend Agent Browser, ScreenshotNeo is a direct screenshot API and MCP server for developers. A single GET request can return a PNG, JPEG, WebP, or PDF. Before capture, it accepts consent banners like a visitor and removes 60+ known consent platforms, newsletter popups, and chat widgets; each of those steps can be turned off. Only clean shots are billed: bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, with the outcome reflected in X-Page-Verdict and X-Billed headers. Its MCP server exposes take_screenshot, get_page_info, and capture_pdf for AI agents.
Install the ScreenshotNeo API documentation for the request details, then make a one-call request:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
The request uses an API key and URL; set your key before running it, and change the target URL as needed. ScreenshotNeo’s free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Sign up for ScreenshotNeo and get 1,000 screenshots a month free, with no card required.
Recommended Free Tools
Frequently Asked Questions
Does every Agent Browser plugin use agent-browser plugin run?
No. That command is for generic command or custom capabilities; credential providers, browser providers, and launch mutators have dedicated workflows.
Can I use a plugin globally instead of for one project?
Yes. Add --global to agent-browser plugin add to target user-level configuration.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

