
n8n Browser Use: What It Does and How to Lock It Down
n8n Browser Use lets the n8n Assistant drive your real, logged-in Chrome through a Chrome extension, and since n8n 2.43.0 it's on for every user by default. It exists mostly to click through third-party admin consoles and set up credentials for you. It is not the Browser Use community node. If you don't want it on your instance, set N8N_INSTANCE_AI_BROWSER_USE_ENABLED=false and restart.
What Is n8n Browser Use, Exactly?
On October 6, n8n shipped 2.43.0 with a one-line changelog entry: "Release Browser Use to all users." That line removed a PostHog feature flag. Before it, Browser Use only showed up on instances that were in the experiment, which is why a thread on the n8n forum titled "What is this and how can I try it?" got the answer "there's probably nothing to test right now." Now there is, and almost nobody has written down what it does.
Here's the short version. The n8n Assistant (the agent in the editor's side chat that builds and edits workflows) gets a new connection type. You install the n8n Browser Use extension (about 7,000 users when I checked), hit Connect browserin the Assistant's + menu, and the agent can now open tabs, read pages and click around in your actual Chrome. The test plan in the release PR shows the intended use: "Walk me through the Slack admin to get my OAuth Client ID and Client Secret."
That's the pitch: the most annoying part of n8n, hunting for API keys in someone else's dashboard, handed to the agent. It's a good idea. It also means an LLM is operating a browser that's logged into everything you are.
Is It the Same as the Browser Use Node?
No, and Google makes this confusing. Search "n8n browser use" and most of page one is about the community node from the Browser Use company. Different product, different risk:
| n8n Browser Use (native) | Browser Use node | |
|---|---|---|
| Who makes it | n8n, built into the editor | Browser Use, community node |
| Where the browser runs | Your own Chrome, your profile | Browser Use cloud |
| Where you use it | n8n Assistant chat only | Any workflow, or as an AI Agent tool |
| Main job | Clicking through consoles to set up credentials | Scraping and web tasks at runtime |
| Cost | Your Assistant model tokens | Browser Use API credits |
| Turn it off | N8N_INSTANCE_AI_BROWSER_USE_ENABLED=false | Uninstall the community package |
If you want a browser as a step in a production workflow, the native feature isn't it. It lives in the editor chat and needs your Chrome open. For runtime browsing, the node or an API is still the answer, and an API beats both whenever one exists. I measured that gap in computer-use agents vs structured APIs.
What Can the Agent Actually Do in My Browser?
I pulled the n8n 2.43.3 source to find out, because the UI doesn't say. The browser toolkit lives in @n8n/mcp-browser, and its README is blunt: it "gives AI agents full control over Chrome" using "their actual profile, cookies, and sessions." I counted 32 tools:
navigate, back, forward, reload, tab_open, tab_list, tab_focus, tab_close
click, type, press, hover, drag, select, scroll, upload, dialog, wait
snapshot, screenshot, content, pdf, console, network
cookies, storage, evaluate <- the ones to think about
capture_secret, create_credential <- the reason it exists
connect, disconnectbrowser_evaluate runs JavaScript in the page. browser_cookies and browser_storageread session state. On paper that's everything needed to lift a session out of your browser. So the guardrails matter, and there are three:
- Per-domain approval.Every tool call that touches a new host stops and asks: deny once, allow once, or allow for session. This rides on the Assistant's
fetchUrlpermission, which defaults torequire_approval. Set it toblockedand every browser call fails with "Browser access blocked by admin." - Credential writes ask every time.
browser_create_credentialis gated bycreateCredential, and there's deliberately no allow-for-session option. One click per credential. - Secret redaction. Tool output passes through 73 regex patterns ported from gitleaks (Anthropic, OpenAI, AWS, Stripe keys, private keys and so on) before the model sees it. Captured secrets go to an in-memory buffer and straight into the credential, not into the chat.
The weak spot is "allow for session." Once you click it for a domain, the agent stops asking about that host for the rest of the session, including reads of its cookies. Combine that with a page that contains instructions aimed at the model, and you have the exact prompt-injection setup I wrote about in n8n prompt injection defense. Click "allow once" and accept the extra prompts.
How Do I Connect n8n Browser Use?
- Run n8n 2.43.0 or later with the Assistant configured. Check Settings > n8n Agent: the Browser Use toggle has to be on (it is by default).
- Use desktop Chrome or another Chromium browser. The editor checks for the Blink engine and hides the feature on phones and tablets, including an iPad in desktop mode.
- Install the extension in a dedicated Chrome profile. More on that below.
- Open the Assistant, click +, then Connect browser. n8n mints a one-time link with a
bu_token. It's valid for 5 minutes until the first connect. After that the session holds until you disconnect or n8n restarts. - Ask for something specific."Open the Google Cloud console and create OAuth credentials for this workflow" works better than "set up Google."
One thing changed in the same release: the "Set up automatically" option on the credential card is now hidden for everyone. You can still ask for browser-based setup in the chat. It just isn't a one-click button anymore.
Why Won't the Extension Connect to Self-Hosted n8n?
This is where self-hosters will lose an evening. The extension doesn't talk to n8n over normal HTTP. It opens a WebSocket to /browser-use/extension/<sessionId>, and n8n builds that address like this:
// packages/cli/src/modules/instance-ai/browser/instance-ai-browser-session.service.ts
const base = new URL(this.urlService.getInstanceBaseUrl());
const scheme = base.protocol === 'https:' ? 'wss' : 'ws';
return `${scheme}://${base.host}`; // host only, path droppedFour ways that breaks:
- No public base URL. The base URL comes from
N8N_EDITOR_BASE_URL, thenWEBHOOK_URL, then protocol + host + port. Behind a proxy with none of those set, the extension triesws://localhost:5678and fails. - Subpath installs. If n8n lives at
example.com/n8n/, the path gets dropped and the extension connects towss://example.com/browser-use/.... Your proxy has to route/browser-use/at the domain root to n8n, or it lands on whatever else lives there. - The proxy eats the upgrade. nginx needs the Upgrade and Connection headers forwarded on that path. Cloudflare Tunnel passes WebSockets by default, and in the 2.43.3 code a plain HTTP hit on those routes gets a
426from n8n. A 404 or your proxy's error page means the path isn't reaching n8n at all. - The link expired. Five minutes. Generate a new one.
# nginx: same server block as the editor
location /browser-use/ {
proxy_pass http://127.0.0.1:5678;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_read_timeout 3600s;
}One more I'd test before trusting it: the browser session lives in memory on the n8n process that created it, and the agent reaches it over 127.0.0.1. On a multi-main setup behind a load balancer, the extension's WebSocket needs to land on that same main. I haven't run it in multi-main, so treat that as a question, not a finding. If you're already fighting proxies on other self-hosted tools, my ComfyUI reverse proxy write-up covers the Cloudflare side.
Should You Leave n8n Browser Use On?
On a solo or dev instance, yes, with a separate Chrome profile. On a shared or client instance, turn it off until you've decided who gets it.
The profile is the real control. Make a Chrome profile called something like "n8n agent," log it into only the consoles you set up credentials in (Google Cloud, Slack admin, HubSpot developer), and install the extension there and nowhere else. Then the worst an over-eager approval can expose is a handful of admin sessions you meant to share anyway, not your email and bank.
On client instances I'd flip the switch off at the env level, because the UI toggle can be flipped back by any admin:
# docker-compose.yml, n8n service
environment:
- N8N_INSTANCE_AI_BROWSER_USE_ENABLED=false
- N8N_EDITOR_BASE_URL=https://n8n.client.com/There's a related switch, N8N_INSTANCE_AI_LOCAL_GATEWAY_DISABLED, for the Assistant's local computer tools (filesystem and shell through the local gateway). Different channel, same question. If you're already gating what agents can do, the approval pattern in n8n human-in-the-loop approvals is the same idea applied to your own workflows.
How I Checked This
My own n8n runs in Docker on a Mac mini behind a Cloudflare Tunnel, and it's still on 2.38.3, so this isn't a "I've used it for a month" review. It's the checklist I ran before upgrading. I read the 2.43.3 tag directly: the browser session service, the MCP browser toolkit, the permission gate, the config class and the release PR (#39762). My instance already sets N8N_EDITOR_BASE_URL and WEBHOOK_URLto the public https host, so the base URL trap doesn't apply to me. The profile decision does. For how this compares with Anthropic's own browser tooling, see Claude's browser use tool vs computer use.
n8n Browser Use FAQ
What is n8n Browser Use?
A feature of the n8n Assistant, on for all users since n8n 2.43.0, that lets the AI agent in the editor control your own Chrome through the n8n Browser Use extension. Its main job is walking through third-party consoles to set up credentials.
Is n8n Browser Use the same as the Browser Use node?
No. The Browser Use community node (n8n-nodes-browser-use-cloud) is made by Browser Use, runs a cloud browser, and is a step inside a workflow. n8n Browser Use is built into n8n, drives your local Chrome, and only works in the Assistant chat.
How do I turn off n8n Browser Use?
Set N8N_INSTANCE_AI_BROWSER_USE_ENABLED=false and restart, or switch off the Browser Use toggle in Settings > n8n Agent. Either one removes Connect browser from the Assistant for every user.
Can n8n Browser Use see my cookies and logged-in sessions?
Yes. It runs in your real Chrome profile and has tools for cookies, local storage, page content, network requests and running JavaScript. Domain approvals and secret redaction limit it, but use a separate Chrome profile if your main one is logged into banking or client admin panels.
Why won't the n8n Browser Use extension connect?
Usually one of four things: the connect link is older than 5 minutes, N8N_EDITOR_BASE_URL points at localhost or http, the reverse proxy doesn't pass WebSocket upgrades on /browser-use/, or n8n runs under a subpath while the extension connects at the domain root.
Upgrading a Team n8n to 2.43?
I'll check your proxy, base URL and Assistant permissions, decide with you who gets Browser Use, and lock down the rest before the upgrade goes live. Tell me what you're running.
Behavior described from the n8n 2.43.3 source and the 2.43.0 release notes, read 10 October 2026. Tool count, redaction pattern count and permission defaults can change in later releases.
Related Posts
n8n
n8n Task Request Timed Out After 60 Seconds: How to Fix
The n8n Code node error means no task runner picked up the task; your code never started. I reproduced it on n8n 2.38.3 with external runners: broker on 127.0.0.1, a mismatched auth token, and the log line that tells each cause apart.
n8n
n8n Respond to Webhook: Timeouts and Empty Replies
An n8n Respond to Webhook node can only answer while the caller is still listening, so most timeouts are the sender giving up, not n8n. Tested on 2.38.3: a skipped branch returns an empty 200, an early error returns a generic 500, and ack-first answers in 94 ms.
n8n
n8n Execution Data Redaction: What It Actually Hides
n8n execution data redaction hides node payloads when someone reads an execution, but it doesn't stop n8n storing them. The database rows stay unencrypted, backups keep them, and Code node console.log output is never redacted. The settings that actually keep PII out of n8n are free on every edition.