Browser Takeover — Jump In When the Web Agent Gets Stuck
August 15, 2026
Some things on the web are built specifically so that software can't get past them: image-puzzle CAPTCHAs, "approve on your phone" prompts, passkeys, QR sign-ins, a login for an account you never saved to the Vault. Until now the browser agent hit one of these and stopped. Now it hands the live browser to you — you clear the step in a few seconds, click Done, and the agent picks up exactly where it left off, on the same page, in the same session.
What you can do
- Take over the live browser when the agent asks. When the web agent hits a wall a human has to clear, a "Browser Needs You" window opens with the agent's actual browser embedded inside it. Solve the CAPTCHA, tap the passkey prompt, approve the login on your phone, scan the QR code, or sign in with an account that isn't in the Vault — then click Done. The agent re-reads the page and continues the task without repeating what you just did.
- Know it's private. Nothing you type or click inside the takeover window is visible to the assistant — it's a direct view of the browser, not a transcript. Passwords, codes, and card numbers you enter during a takeover never enter the conversation.
- Leave an optional note. A one-line note field ("signed in", "use the second account", "skipped the newsletter popup") is passed to the agent when you click Done, so it knows what changed.
- Skip if you can't help right now. Click Skip (or let the countdown run out — 5 minutes by default) and the agent re-checks the page once, then stops and tells you exactly what a human needs to do so you can come back to it later.
- Let the automatic CAPTCHA solver try first. The agent now waits up to 30 seconds for the built-in solver on every challenge before asking you. It never guesses at puzzles, never claims a CAPTCHA passed unless the page actually moved on, and only asks for a takeover after the solver has had its one chance.
- Watch the browser any time. While a browser task is running, the tool card shows a "Watch live browser" link that opens the live view in a new tab — and switches to "Open live browser to sign in / clear the challenge" the moment a takeover is waiting on you.
- Continue on the same browser across follow-up calls in the conversation. The agent's browser now stays parked between browser calls in the same chat — same tabs, cookies, and logins — for 10 minutes after each call (sliding), up to a 60-minute hard limit from when it was opened. That's what makes multi-step flows work: log in → the agent reads the verification code from your inbox with another tool → enter it on the page that's still open. Every result tells you when the parked browser expires.
- Start clean when you want to. Ask for a fresh browser (
fresh_session: true) to throw away the parked one and begin logged out — useful for switching accounts or testing a signed-out view. - More time to hand over one-time codes. When the agent asks you for a typed value (OTP, CVV, a code from your phone) it now waits 3 minutes instead of 60 seconds — and if you skip, it stops cleanly with the current page URL instead of retrying, so you can fetch the value and continue with a follow-up message.
Where this shows up
You ask Alfrada to pull last month's invoices from a supplier portal. It logs in from the Vault, gets a "select all squares with traffic lights" puzzle, waits for the solver, and the puzzle stays up. Instead of a dead end you get the Browser Needs You window — you clear the puzzle in ten seconds, click Done, and the invoices land in your session.
You want the agent to update your listing on a marketplace that uses passkeys. It reaches the sign-in page and hands you the browser; you tap your passkey prompt, click Done, and the agent finishes the edits — it never needed, or saw, your credentials.
You ask it to book something on a site whose login sends a code to your email. It signs in, stops at "enter the code", the mail tool reads the code from your inbox, and the next browser call types it into the same page — the browser never closed in between.
Try it
- "Log in to the supplier portal from the Vault and download every invoice from July. If you hit a CAPTCHA the solver can't clear, hand it to me."
- "Sign in to my Notion via the browser — it uses a passkey, so give me the browser when you reach the sign-in page."
- "Go to the marketplace, start the login, then read the verification code from my inbox and enter it — keep the same browser open."
- "Start a fresh, logged-out browser and check what our pricing page looks like to a visitor."
Heads up
- Cloud sessions only. Takeover needs Alfrada's cloud browser with a live view. On a local desktop (Redbox) browser the agent reports that takeover is unavailable and tells you what to do by hand instead.
- One takeover per challenge, one solver wait per challenge. The agent won't loop — if you skip, it stops and reports rather than trying again.
- Nothing persists across conversations by default. The parked browser lives for the length of your chat's activity (10 minutes idle, 60 minutes maximum) and is torn down afterwards, cookies included. Cancelling a run always closes the browser. If the API restarts, parked browsers are lost and the next call simply starts a new one.
- The takeover window is a direct browser view. It's intentionally not recorded into the conversation — if you want the agent to know what you did, use the note field.