Give a coding agent (Claude Code, Codex, Cursor and others) a real browser inside a disposable sandbox with nothing but the cua MCP server. Discover an image, create a browser sandbox, read, click, fill and screenshot pages, teleport a signed-in session with consent, and clean up.
Once Cua is installed, a coding agent can browse the web with no other tool or
setup. The browser runs inside a sandbox, never on your machine: a local
container (gVisor when installed), a VM, or a Cua Fleet sandbox. The agent
drives it through the sandbox's own Cua Driver, whose typed browser tools the
cua MCP server reaches with call_tool.
images_list returns the image catalog the
image catalog details is generated from:
each image's OS, container or VM form, runtimes, whether it ships cua-spacesd,
and its browsers. browser_tools: true marks the images whose browser the
Cua Driver browser tools drive.
cat = await agent.ok("images_list", {"browser": True})images = [i for i in cat["images"] if i["browser_tools"]]
sandbox_create with browser: true starts the canonical Linux image
(ghcr.io/trycua/linux:24.04), launches Chromium with a fresh throwaway
profile inside it, binds the window for the browser tools and, with url,
opens a first page. Pass on: "cloud" to run it on Cua Fleet. It returns the
sandbox id and the session, target_id and tab_id every browser call
takes.
To browse as you on a site you are signed in to, the agent can teleport that
site's session from your browser (Firefox or Chrome) into the sandbox with
teleport_browser_session. It names the exact sites; nothing is selected by
default and there is no "all sessions" option. The first call moves nothing:
it returns what would move and a consent requirement, which the agent shows
you. Only your explicit approval moves those sites' sessions into the
sandbox. Delete the sandbox, or sign out there, to end them.
tests/e2e/browse/e2e_browse.py
runs every step above as an MCP client (the official MCP Python SDK) against
cua mcp, with no model in the loop. CI runs it in the container lane.
Reading pages (outline, refs, text, a scoped query), navigation, clicks,
typing and filling, Enter, hover, scroll, drag, uploads (browser_set_input_files),
downloads (browser_download), page dialogs (browser_dialog) and tab
screenshots. They drive Chromium-family browsers over the Chrome DevTools
Protocol. Firefox ships in the image too; drive it with the desktop tools
(computer_screenshot, computer_click). Waiting is a bounded loop of reads;
there is no JavaScript eval, network interception or cookie editing tool.