What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Session isolation means separating browser state and agent memory so one user, task, or trust domain cannot see or reuse another’s cookies, storage, credentials, downloads, or retained instructions. A separate browser tab is not enough. Build an explicit boundary, enforce it in your browser runtime and application, then verify process, filesystem, network, and secret-store controls independently.

What session isolation must protect

AI agents and scrapers increasingly run inside authenticated browser sessions. A page can contain hostile instructions, a poisoned tool response, or data intended to make an agent reveal information. Chrome for Developers warns that agents operating in a user’s authenticated session need protections against malicious input from untrusted content (Agent security considerations for WebMCP, June 9, 2026). Treat page text, tool manifests, comments, and API responses as data—not as authority.

Define the boundary before choosing a mechanism. Decide whether separation is required per user, account, task, website, or sensitivity level, and list every asset that must not cross it:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Cookies and server-side session identifiers
  • Local storage, session storage, cache, IndexedDB, and profile files
  • Agent conversation history, retrieved content, and long-term memory
  • Downloads, temporary files, screenshots, and exported data
  • API keys, authorization headers, and other credentials
  • Processes, network destinations, and secret stores

No single browser feature protects all of these assets. Playwright browser contexts provide a browser-state boundary; they do not by themselves prove host, filesystem, network, or secret isolation.

#1 Best Overall

Two boundaries: browser state and agent memory

Browser-state isolation

Create one independent browser context for each concurrent tenant or task. A context should have its own cookies, local and session storage, cache, permissions, viewport, and lifecycle. Close it when the job ends, and do not reuse persistent profile directories across trust domains. Playwright documents contexts as isolated environments (Browser contexts and isolation).

Separate tabs are not equivalent: tabs in one context normally share cookies and other origin state. Verify the exact behavior and persistence settings of the framework version you deploy.

Agent-memory isolation

Namespace short-term transcripts, retrieval caches, summaries, and long-term memory by tenant and session. Apply expiration and size limits, review content before persisting it, and prevent material retrieved from one trust domain from becoming trusted memory in another. Memory should carry provenance and sensitivity labels so a later task can reject data it is not authorized to read.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A reference implementation with Playwright

The following Node.js pattern creates a fresh context per task, loads credentials supplied by the application, and destroys state in a finally block. It is a browser boundary, not a complete sandbox.

  1. Keep authentication material in a server-side secret manager; do not place raw tokens in prompts, logs, or memory.
  2. Launch a browser according to your runtime’s documented process and container controls.
  3. Create one context for the task and avoid shared persistent profiles.
  4. Allow only the domains and actions the task needs.
  5. Close the context and delete task artifacts when finished.
import { chromium } from 'playwright';

export async function runTask({ url, storageState, allowedHost }) {
  const browser = await chromium.launch({ headless: true });
  const context = await browser.newContext({
    storageState,                 // tenant-specific, short-lived state
    serviceWorkers: 'block',
    acceptDownloads: false
  });
  try {
    const page = await context.newPage();
    const target = new URL(url);
    if (target.hostname !== allowedHost) throw new Error('Host not allowed');
    await page.goto(target.href, { waitUntil: 'domcontentloaded', timeout: 30000 });
    return await page.title();
  } finally {
    await context.close();
    await browser.close();
  }
}

For high-risk workloads, run browser processes in a hardened container or VM with a read-only image, restricted egress, isolated temporary storage, and a narrowly scoped secret broker. Confirm those guarantees from your hosting and runtime documentation; a context API cannot supply them.

Least privilege for browser tools and agents

Expose only operations required for the job. Separate read actions from writes, restrict navigation and downloads to named resources, and require an authorization step outside the model for purchases, account changes, message sending, or data deletion. OWASP’s AI Agent Security Cheat Sheet states: “Grant agents the minimum tools required for their specific task.”

Validate proposed actions in a policy layer that can inspect the destination, current user, resource, and operation. Do not let a webpage’s instructions override system policy. Tool output should be escaped, labeled as untrusted, and excluded from memory unless it passes validation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protecting session credentials

Apply application-layer controls described in OWASP’s Session Management Cheat Sheet:

  • Use HTTPS for the entire session.
  • Set cookies with Secure so they are sent only over HTTPS and HttpOnly so page scripts cannot read them through document.cookie.
  • Set SameSite=Strict or SameSite=Lax explicitly. SameSite=None requires Secure and is not a substitute for CSRF tokens.
  • Keep cookie scope narrow. Omit Domain when origin-only scope is appropriate; Path alone is not a reliable boundary between applications on one host.
  • Regenerate the session identifier after login or any privilege change and invalidate the old identifier.
  • Enforce idle and absolute expiration, invalidate sessions server-side on logout or expiry, and avoid retaining sensitive state unnecessarily.
  • Never log raw session IDs. For correlation, use a salted hash instead.

Timeout values depend on application risk and usability; OWASP’s illustrative ranges are not universal defaults. Document your threat model and test expiry while a task is active, idle, and after logout.

Operational lifecycle and verification

Creation and cleanup

Assign every context and memory namespace a non-secret task ID, owner, trust level, creation time, and expiry. Reject requests that omit a tenant or policy. Close contexts on success, failure, cancellation, and worker termination. Scrub temporary downloads and screenshots according to retention policy.

Boundary tests

Run two sessions with deliberately different marker values and verify that none cross:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Cookies, local/session storage, cache, IndexedDB, and service-worker data
  • Agent transcript, retrieval results, summaries, and persisted memory
  • Downloads, screenshots, environment variables, and authorization headers
  • Permitted network destinations and filesystem paths

Repeat after crashes, retries, worker reuse, browser restart, and scale-out. Inspect logs and traces for tokens. Separately test process, filesystem, egress, and secret-store controls; the reviewed browser-context documentation does not certify those controls for a particular deployment.

Common failure modes and fixes

“The agent saw another user’s account”

Cause: shared persistent profile, reused context, or storage state copied between tenants. Fix: create a new context and tenant-specific storage state per task; delete shared profiles and add cross-tenant marker tests.

“A new tab still had the old login”

Cause: tabs share their browser context. Fix: create a separate context, not merely a page.

“A prompt injection changed the requested action”

Cause: page content or tool output was treated as instructions. Fix: label retrieved data as untrusted, constrain tools, and enforce destination and operation checks outside the model.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Logout did not end access”

Cause: client deletion without server-side invalidation, or an unexpired copied token. Fix: revoke the session server-side, rotate identifiers after privilege changes, and test replay of the old token.

“Secrets appeared in diagnostics”

Cause: raw cookies, headers, URLs, or session IDs in logs or memory. Fix: redact at collection, hash identifiers with a salt for correlation, and set retention limits.

“Isolation worked locally but failed in production”

Cause: different browser persistence, worker reuse, container sharing, or network policy. Fix: run the same boundary tests in the deployed configuration and document guarantees from the runtime and host.

Choosing controls for your threat model

Boundary Minimum control Verify separately
Per tab Usually insufficient for users or trust domains Cookie and storage sharing
Per task or user browser state Fresh browser context and lifecycle cleanup Cookies, storage, cache, downloads
Agent memory Tenant/session namespaces, expiry, review before persistence Cross-session retrieval and poisoning
Credentials HTTPS, Secure/HttpOnly/SameSite, rotation, server revocation Replay, logout, privilege changes, logs
Host and network Container/VM, filesystem and egress policy, secret broker Processes, files, destinations, secret access
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

For jobs that only need a clean website image or PDF, ScreenshotNeo provides a one-request screenshot API and an MCP server for Claude, Cursor, and other MCP clients. Before capture it accepts consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers report the page verdict and billing status.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ScreenshotNeo supports full-page and element captures, device presets or custom viewports, dark mode, retina scale, PDF options, custom CSS and JavaScript, clicks, waits, request blocking, headers, cookies, user agents, authorization, timezone, geolocation, transparent backgrounds, resizing, TTL caching, signed links, asynchronous webhooks, bulk capture of up to 100 URLs per call, usage reporting, and an OpenAPI specification. These features do not replace tenant and credential isolation in your own agent system; keep each API key and output namespace scoped appropriately.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for options and response headers. Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is included on every plan, and yearly billing provides two months free. Sign up for the free plan to try it.

FAQ

Does session isolation stop prompt injection?

No. It limits the damage and data exposure. You still need untrusted-content handling, least privilege, and external authorization checks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is a separate browser context a sandbox?

No. It separates browser state. Confirm process, filesystem, network, and secret-store isolation in your deployment.

Should session IDs be encrypted in logs?

Do not log raw IDs. OWASP recommends a salted hash when correlation is necessary.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.