SafeCoBrowser
Built for Claude Code & Codex developers
Local-first · macOS

SafeCoBrowser

AI co-browsing, under your control

A macOS browser that lets your own AI agent act on your logged-in sessions — under per-tab, revocable, audited permission. The agent is off by default and never sees more than you grant. Bring your own Claude Code or Codex over MCP or the built-in CLI.

AIAgent & CLI reference — drive SafeCoBrowser over MCP or CLI

Linux (x64): AppImage · tar.gz

Version 1.0·macOS 14 or later · Linux x64 (Electron)·Bring your own agent
Off by default — the AI sees nothing until you invite it, and Stop AI revokes instantly

Native, not Electron

The Mac App Store build is a rewrite in Swift and SwiftUI — no Electron, no bundled browser engine — for macOS 14 or later. Same product and the same guarantees: the per-tab permission ladder, granting that is never retroactive, instant revoke, approval cards for anything that acts, a hash-chained audit log, and MCP over 127.0.0.1 behind a bearer token.

On Linux, the Electron build above is the one to use — it is maintained and stays the supported option there.

Permission, not access

Everything the agent can do is granted by you, gated per tab, shown before it happens, and written to the log.

Per-tab AI modes: Off, Read, Inspect, Assist, Developer
AI is off by default — no retroactive leak of the blind period
Approve or reject every click, fill, and script
Instant Stop AI — revokes in-flight and future calls
Bring your own agent over a local MCP server or the built-in CLI
Hash-chained, tamper-evident audit log of every action
Isolated containers — a clean room per client or project
Record reusable recipes — replay them, or let your agent read them as how-tos
Privacy filter — redact your name, address, or account numbers from the screen and the agent
Downloads land in each container’s own folder — the agent never sees the files
The agent never gets your cookies, passwords, or profile
The SafeCoBrowser app window — per-tab AI mode, Stop AI, auto-approve, and Activity controls in the toolbar

Permission modes

Five modes. You decide how far.

Set per tab, by you. Each tier unlocks a little more — and the agent can never raise its own level.

01

Off

Default. The AI sees nothing — SafeCoBrowser is a normal browser.

02

Read

Read the page: URL, text, links, and screenshots.

03

Inspect

Inspect elements and read the console and network.

04

Assist

Click and fill — each action behind your approval.

05

Developer

Run JavaScript in the page — full control, always approved.

Trust is the product

Letting an AI act on your logged-in accounts only works if you stay in control. SafeCoBrowser treats that as the default, not a setting.

Off by default

The agent sees nothing until you grant a mode for a tab — and enabling it never exposes what happened while it was blind, like your login.

Instant, real revoke

Stop AI bumps a session epoch that is re-checked at execution time, so in-flight and future calls fail closed the moment you pull access.

Never your profile

The agent only ever gets brokered tools — never the cookie store, saved passwords, or the browser profile on disk.

SafeCoBrowser

Bring your AI into the browser — on your terms

Off by default, granted per tab, killable instantly, and fully logged. Point your own Claude Code or Codex at it and stay in control.

Linux (x64) — download directly: AppImage · tar.gz

Version 1.0 · macOS 14 or later · Linux x64 (Electron)