What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Session isolation means separating browser state and agent memory so one user, task, or trust domain cannot see or reuse another’s cookies, storage, credentials, downloads, or retained instructions. A separate browser tab is not enough. Build an explicit boundary, enforce it in your browser runtime and application, then verify process, filesystem, network, and secret-store controls independently.
What session isolation must protect
AI agents and scrapers increasingly run inside authenticated browser sessions. A page can contain hostile instructions, a poisoned tool response, or data intended to make an agent reveal information. Chrome for Developers warns that agents operating in a user’s authenticated session need protections against malicious input from untrusted content (Agent security considerations for WebMCP, June 9, 2026). Treat page text, tool manifests, comments, and API responses as data—not as authority.
Define the boundary before choosing a mechanism. Decide whether separation is required per user, account, task, website, or sensitivity level, and list every asset that must not cross it:
Recommended Free Tools
- Cookies and server-side session identifiers
- Local storage, session storage, cache, IndexedDB, and profile files
- Agent conversation history, retrieved content, and long-term memory
- Downloads, temporary files, screenshots, and exported data
- API keys, authorization headers, and other credentials
- Processes, network destinations, and secret stores
No single browser feature protects all of these assets. Playwright browser contexts provide a browser-state boundary; they do not by themselves prove host, filesystem, network, or secret isolation.
#1 Best Overall
Two boundaries: browser state and agent memory
Browser-state isolation
Create one independent browser context for each concurrent tenant or task. A context should have its own cookies, local and session storage, cache, permissions, viewport, and lifecycle. Close it when the job ends, and do not reuse persistent profile directories across trust domains. Playwright documents contexts as isolated environments (Browser contexts and isolation).
Separate tabs are not equivalent: tabs in one context normally share cookies and other origin state. Verify the exact behavior and persistence settings of the framework version you deploy.
Agent-memory isolation
Namespace short-term transcripts, retrieval caches, summaries, and long-term memory by tenant and session. Apply expiration and size limits, review content before persisting it, and prevent material retrieved from one trust domain from becoming trusted memory in another. Memory should carry provenance and sensitivity labels so a later task can reject data it is not authorized to read.
A reference implementation with Playwright
The following Node.js pattern creates a fresh context per task, loads credentials supplied by the application, and destroys state in a finally block. It is a browser boundary, not a complete sandbox.
- Keep authentication material in a server-side secret manager; do not place raw tokens in prompts, logs, or memory.
- Launch a browser according to your runtime’s documented process and container controls.
- Create one context for the task and avoid shared persistent profiles.
- Allow only the domains and actions the task needs.
- Close the context and delete task artifacts when finished.
import { chromium } from 'playwright';
export async function runTask({ url, storageState, allowedHost }) {
const browser = await chromium.launch({ headless: true });
const context = await browser.newContext({
storageState, // tenant-specific, short-lived state
serviceWorkers: 'block',
acceptDownloads: false
});
try {
const page = await context.newPage();
const target = new URL(url);
if (target.hostname !== allowedHost) throw new Error('Host not allowed');
await page.goto(target.href, { waitUntil: 'domcontentloaded', timeout: 30000 });
return await page.title();
} finally {
await context.close();
await browser.close();
}
}
For high-risk workloads, run browser processes in a hardened container or VM with a read-only image, restricted egress, isolated temporary storage, and a narrowly scoped secret broker. Confirm those guarantees from your hosting and runtime documentation; a context API cannot supply them.
Least privilege for browser tools and agents
Expose only operations required for the job. Separate read actions from writes, restrict navigation and downloads to named resources, and require an authorization step outside the model for purchases, account changes, message sending, or data deletion. OWASP’s AI Agent Security Cheat Sheet states: “Grant agents the minimum tools required for their specific task.”
Validate proposed actions in a policy layer that can inspect the destination, current user, resource, and operation. Do not let a webpage’s instructions override system policy. Tool output should be escaped, labeled as untrusted, and excluded from memory unless it passes validation.
Protecting session credentials
Apply application-layer controls described in OWASP’s Session Management Cheat Sheet:
- Use HTTPS for the entire session.
- Set cookies with
Secureso they are sent only over HTTPS andHttpOnlyso page scripts cannot read them throughdocument.cookie. - Set
SameSite=StrictorSameSite=Laxexplicitly.SameSite=NonerequiresSecureand is not a substitute for CSRF tokens. - Keep cookie scope narrow. Omit
Domainwhen origin-only scope is appropriate;Pathalone is not a reliable boundary between applications on one host. - Regenerate the session identifier after login or any privilege change and invalidate the old identifier.
- Enforce idle and absolute expiration, invalidate sessions server-side on logout or expiry, and avoid retaining sensitive state unnecessarily.
- Never log raw session IDs. For correlation, use a salted hash instead.
Timeout values depend on application risk and usability; OWASP’s illustrative ranges are not universal defaults. Document your threat model and test expiry while a task is active, idle, and after logout.
Operational lifecycle and verification
Creation and cleanup
Assign every context and memory namespace a non-secret task ID, owner, trust level, creation time, and expiry. Reject requests that omit a tenant or policy. Close contexts on success, failure, cancellation, and worker termination. Scrub temporary downloads and screenshots according to retention policy.
Boundary tests
Run two sessions with deliberately different marker values and verify that none cross:
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitches- Cookies, local/session storage, cache, IndexedDB, and service-worker data
- Agent transcript, retrieval results, summaries, and persisted memory
- Downloads, screenshots, environment variables, and authorization headers
- Permitted network destinations and filesystem paths
Repeat after crashes, retries, worker reuse, browser restart, and scale-out. Inspect logs and traces for tokens. Separately test process, filesystem, egress, and secret-store controls; the reviewed browser-context documentation does not certify those controls for a particular deployment.
Common failure modes and fixes
“The agent saw another user’s account”
Cause: shared persistent profile, reused context, or storage state copied between tenants. Fix: create a new context and tenant-specific storage state per task; delete shared profiles and add cross-tenant marker tests.
“A new tab still had the old login”
Cause: tabs share their browser context. Fix: create a separate context, not merely a page.
“A prompt injection changed the requested action”
Cause: page content or tool output was treated as instructions. Fix: label retrieved data as untrusted, constrain tools, and enforce destination and operation checks outside the model.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match“Logout did not end access”
Cause: client deletion without server-side invalidation, or an unexpired copied token. Fix: revoke the session server-side, rotate identifiers after privilege changes, and test replay of the old token.
“Secrets appeared in diagnostics”
Cause: raw cookies, headers, URLs, or session IDs in logs or memory. Fix: redact at collection, hash identifiers with a salt for correlation, and set retention limits.
“Isolation worked locally but failed in production”
Cause: different browser persistence, worker reuse, container sharing, or network policy. Fix: run the same boundary tests in the deployed configuration and document guarantees from the runtime and host.
Choosing controls for your threat model
| Boundary | Minimum control | Verify separately |
|---|---|---|
| Per tab | Usually insufficient for users or trust domains | Cookie and storage sharing |
| Per task or user browser state | Fresh browser context and lifecycle cleanup | Cookies, storage, cache, downloads |
| Agent memory | Tenant/session namespaces, expiry, review before persistence | Cross-session retrieval and poisoning |
| Credentials | HTTPS, Secure/HttpOnly/SameSite, rotation, server revocation | Replay, logout, privilege changes, logs |
| Host and network | Container/VM, filesystem and egress policy, secret broker | Processes, files, destinations, secret access |
Or skip the browser setup
For jobs that only need a clean website image or PDF, ScreenshotNeo provides a one-request screenshot API and an MCP server for Claude, Cursor, and other MCP clients. Before capture it accepts consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers report the page verdict and billing status.
Free tools Windows power users keep installed
One-click scans. No signup required.
ScreenshotNeo supports full-page and element captures, device presets or custom viewports, dark mode, retina scale, PDF options, custom CSS and JavaScript, clicks, waits, request blocking, headers, cookies, user agents, authorization, timezone, geolocation, transparent backgrounds, resizing, TTL caching, signed links, asynchronous webhooks, bulk capture of up to 100 URLs per call, usage reporting, and an OpenAPI specification. These features do not replace tenant and credential isolation in your own agent system; keep each API key and output namespace scoped appropriately.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for options and response headers. Python:
Best Value
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is included on every plan, and yearly billing provides two months free. Sign up for the free plan to try it.
FAQ
Does session isolation stop prompt injection?
No. It limits the damage and data exposure. You still need untrusted-content handling, least privilege, and external authorization checks.
Is a separate browser context a sandbox?
No. It separates browser state. Confirm process, filesystem, network, and secret-store isolation in your deployment.
Should session IDs be encrypted in logs?
Do not log raw IDs. OWASP recommends a salted hash when correlation is necessary.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

