Anthropic announced beta Python and TypeScript SDK classes for browser and computer use on October 7, 2026. Developers can connect their own browser or desktop automation to SDK-managed dispatch, configured policies and approval callbacks. The release notes also establish the distinction: the underlying toolsets launched in August; this update adds helper classes for implementing them.
For builders, the useful choice is how much execution control to hand to the SDK. Use its runner when the standard dispatch and failure rules fit; retain a custom loop when your workflow needs additional coordination. Either way, you still supply the runtime and its permissions.
Choose the smallest interface that can finish the task
For simple retrieval, start with an appropriate read-only API or web tool. Choose the browser toolset for page interaction, forms and tabs. Use the computer toolset when the task must operate a desktop application or move between applications. This is a task-based recommendation, not a performance ranking.
Check the exact tool version, not just model availability. Anthropic currently lists the browser toolset on the Claude API and Google Cloud. The computer compatibility guidance likewise places computer_toolset_20260801 on those platforms; other listed platforms offer earlier beta computer tools. Neither client toolset is currently available in Claude Managed Agents.
Pin a checked SDK release, then implement the driver
The October 7 releases Python 1.12.0 and TypeScript 0.132.0 contain the helper exports. PyPI and npm also confirm both distributions; Python 1.12.0 requires Python 3.10 or later. These are source-checked versions, not a claim about the earliest compatible releases or a completed integration test.
Python exposes the browser base class through anthropic.tools.browser, as shown in its tagged exports. The desktop equivalent is documented under anthropic.tools.computer. These imports identify the extension points; they do not create a browser or desktop:
from anthropic.tools.browser import BetaAbstractBrowserToolset20260801
from anthropic.tools.computer import BetaAbstractComputerToolset20260801Follow the Python browser driver contract in this order:
Subclass the base class and connect an application-supplied automation backend. Implement only the actions your task needs; unimplemented members are normally advertised as disabled.
Implement
_browser_stateto report every open tab and relevant changes. Honor each action’stab_idand identify the active tab accurately.Pass your URL policy, file policy where needed, and
confirmcallback into the constructor. Put the driver instance in the runner’stoolslist.Own shutdown explicitly. The runner does not close the toolset; your driver should call the base
closebefore closing its backend.
TypeScript imports both classes from @anthropic-ai/sdk/helpers/beta/toolsets (tagged exports). Its browser guide requires a browserState constructor callback. Implement actions as prototype methods, not arrow-function fields, and spell the typing method type_. Validate runtime inputs; TypeScript annotations are not execution-time checks.
Define permissions at three separate layers
Use separate driver, network and approval controls before connecting the toolsets to a real account. The following is a proposed implementation checklist based on the documented boundaries, not a claim that the SDK supplies a complete sandbox.
Control | What the SDK does | What your application must supply |
|---|---|---|
Navigation | Consistent URL parsing, request interception and destination restrictions. | |
Network | Container or provider egress rules, including local and private-address controls. | |
Session identity | A separate, minimally privileged session; no everyday signed-in profile. | |
Consequential actions | A reviewable action preview and a decision about who may authorize it. | |
Files | Controlled upload storage and an explicitly configured download location. |
The SDK security guide explains why a URL callback is insufficient: redirects, clicked links and page-generated requests can bypass that callback. Enforce restrictions in the driver and deployment, including loopback, private networks and cloud metadata destinations. Network rules also do not replace scheme checks for addresses such as file: or javascript:.
Keep the model-calling process and its API credentials outside the controlled environment. For desktop sessions, Anthropic recommends dedicated minimal-privilege containers or VMs without host mounts. Treat page and screen content as untrusted. These are deployment requirements, not properties gained by importing a helper class.
For uploads, the shipped Python file policy checks allowed roots and permitted document IDs. Its download setting controls which paths may be exposed to the model; it does not tell the browser where to save files. Keep upload and download storage separate. With a remote browser, checks on the SDK host do not establish what the remote machine will read. Enforce paths there or leave uploads disabled.
Approval needs current context. The browser callback receives the last reported tab URL, which may be stale, and cannot infer what a click means. The callback contract therefore does not guarantee that the page reviewed is the page acted upon. Our recommendation: show the destination, intended effect and relevant input, then require renewed approval if the target changes before execution. The application must implement that check.
For a broader method of deciding what information and authority a workflow should receive, see our guide to mapping agent data flows before granting access.
Review execution overrides as permission changes
A subtle implementation trap appears in the tagged browser helper source: overriding execute makes every member count as implemented. A logging or forwarding subclass can therefore advertise default-enabled actions its backend cannot serve. Disable unsupported members explicitly through configs.
Policies and approval also run before the override. Changing the input there does not automatically repeat those checks. Treat input rewriting as an authorization-sensitive operation, even when the hook began as instrumentation.
Desktop drivers need coordinate and approval checks
Desktop coordinates refer to the full screenshot, not a zoom crop. If capture and display sizes differ, translate coordinates in both directions and keep capture geometry stable. Reject out-of-range points rather than moving them to a nearby valid point. The TypeScript desktop contract also assigns field validation, duration limits, repeat limits and image sizing to the driver. Return sanitized errors: raw exception text can reach the model.
The Python desktop guide requires confirm when type, key or hold_key is enabled. That requirement does not make clicks harmless or create a human-review interface. A click can send a message; typing into a terminal can run a command. Gate actions according to the applications and accounts the desktop can reach, not only their method names.
Choose runner semantics deliberately
The SDK runner executes a toolset’s actions sequentially and skips its remaining actions in that turn after a failure or refusal. Other tools can still run. A custom loop must route by toolset_name as well as member name, return a result for every call—including skipped calls—and preserve those failure rules. The manual-loop guidance provides the result-handling pattern.
The design implication is that a toolset-local stop is not a workflow-wide abort. If a failed browser action invalidates a later desktop or shell step, your application must cancel that dependent work. Set application-level turn and wall-clock limits too.
Start consequential pilots without eager execution. The streaming guide says run_tools_eagerly (TypeScript: runToolsEagerly) can start actions before the response finishes. Configured checks still run, but a started action cannot be rolled back when the response is truncated. Before retrying a send or purchase after a timeout, reconcile whether it already happened.
Use a narrow pilot with explicit acceptance cases
The next step is a disposable environment and synthetic task data. These are proposed checks, not tests performed for this article:
Attempt a denied navigation and an out-of-scope redirect; neither should reach the forbidden destination.
Change the target after approval; require a fresh decision before a consequential action.
Try an upload path outside the permitted storage, including a remote-path mismatch; reject it before the browser reads the file.
Supply invalid coordinates and oversized images; handle them before a wrong click or rejected API request.
Fail the first action in a batch; verify skipped results and your application’s cancellation of dependent work.
Interrupt a consequential action; determine its actual outcome before allowing any retry.
Budget from the actual model and enabled members. Anthropic estimates roughly 6,600 input tokens for default browser definitions, with additional usage from images and results. That is a documentation estimate, not our measurement or an exact count for every model. Use token counting and response usage for your configuration; runtime hosting is a separate cost.
Methodology: AI-assisted reporting and implementation analysis based on Anthropic documentation, tagged SDK source and package metadata, rechecked October 7, 2026. No browser workflow, SDK import, benchmark or security test was executed. The announcement gives a calendar date, not a verified time of day.
