Anthropic's Python and TypeScript SDKs now include beta classes for Claude's browser use and computer use tools. You subclass one, write a method per action against your own browser or desktop, and the SDK runs the tool loop, your URL and file policies and your approval callback. The browser, the network controls and host isolation stay your job.
What Anthropic released
The SDK toolsets were announced by Anthropic on 7 October 2026 in the Claude API release notes, with a full guide, Browser and computer use with the SDK toolsets. There are two classes, both in beta: one for the browser use tool and one for the computer use tool. Python also gets async versions.
The underlying browser use tool is generally available on the Claude API and Google Cloud, and not on Amazon Bedrock, Claude Platform on AWS or Microsoft Foundry, according to its documentation. It works with current models including Claude Sonnet 5.5, Opus 5.5 and Haiku 5.5.
What changed for developers
Before this release, a team using browser use had to write the whole client side itself: read each tool call, route it to the right browser action, check it, run it and build the tool_result. The new classes take over that plumbing:
- One method per action. Your subclass implements members such as
navigate,screenshotandleft_click. A member you don't implement is sent to the API as disabled. - Policies run before your code. The SDK calls your URL policy before every
navigate, your file policy before uploads, and yourconfirmcallable before each call. - Risky members are gated.
javascript_execandfile_uploadare off by default, and enabling either without aconfirmcallable is a configuration error. For the computer class, the same applies totype,keyandhold_key. - Early start. With streaming and
run_tools_eagerly, a call can start while Claude's response is still streaming. Calls on one toolset still run one at a time, in order. - Both toolsets in one request. The tool runner routes each call to the browser or computer instance, and a failed computer call doesn't skip the turn's browser calls.
Browser Use, Browserbase, Daytona and E2B have published their own integrations, and a minimal Chrome DevTools Protocol example sits in the claude-quickstarts repository. Anthropic says plainly that the example isn't production code.
What the SDK does not do for you
This is the part to read before adopting it. The guide lists six steps to run the toolset safely, and the SDK applies only three of them (the URL policy, confined uploads and downloads, and gated actions). The other three are yours:
Request interception. The URL policy sees only navigate calls. A link Claude clicks, a redirect or a request the page makes never reaches it, so your driver has to check requests itself.
Network egress. Without a URL policy the SDK checks no URL at all, and the API doesn't filter what Claude opens. Even with one, a redirect can reach loopback, the cloud metadata address or private ranges. Egress rules on the container can block the last two, not loopback. The SDK also doesn't check URL schemes, so refusing file: and javascript: is your driver's job.
Host isolation. Anthropic recommends a dedicated, minimal-privilege container or VM per session, a fresh browser profile with no signed-in accounts, and the code that holds your API key running outside it.
Two more gaps matter for agents that act. An approval is based on the last state report, and the page can change before the call runs. For computer use, confirm receives the tool and its input but not the screen, so it can't tell what a click at given coordinates will do. Gate by application, not by click.
What it means for cost and governance
Cost. Declaring the browser toolset with its default members adds about 6,600 input tokens to each request, and screenshots are billed as image input. Disable members you don't need with configs, and keep screenshot history short. Our guide to controlling AI agent running costs covers the wider budget.
Prompt injection. Anthropic runs classifiers on what the browser returns, but the SDK guide notes they don't currently run on browser toolset requests sent through Amazon Bedrock. Treat every page, tab title and download name as untrusted input, as described in the AI agent attack surface.
Audit and approval. The confirm callable is a natural place to log and approve consequential actions. Pair it with an audit trail of what the agent did and a clear rule for stopping a wrong action.
When to adopt it and when to wait
Adopt it if you already run, or plan to run, Claude browser or computer use on the Claude API or Google Cloud. It removes routing and result-building code you would otherwise maintain, and its defaults are stricter than a hand-written loop.
Wait, or keep your own loop, if you are on Amazon Bedrock or Microsoft Foundry, where the browser use tool isn't available, or if you need a stable interface, since both classes are beta. And before choosing a browser at all, check whether the task has an API: should an AI agent use a browser or an API walks through that choice.
Frequently asked questions
What are the Claude SDK browser and computer use toolsets?
They are beta classes in Anthropic's Python and TypeScript SDKs, announced on 7 October 2026, for the browser use and computer use tools. You subclass one and write a method for each action against your own browser or desktop automation. The SDK routes each call, runs your URL and file policies and approval callback, and builds the result Claude reads.
Does the SDK include a browser or a desktop?
No. The SDK includes no browser, no desktop, no ready-made driver and no URL policy. You supply the automation, for example a wrapper around Playwright for the browser or a VNC client for a desktop. Anthropic publishes a minimal example that is not meant for production, and partners including Browserbase, Browser Use, Daytona and E2B publish their own integrations.
Is the browser use tool available on Amazon Bedrock?
Not according to Anthropic's documentation, which lists the browser use tool as generally available on the Claude API and Google Cloud only, and not available on Amazon Bedrock, Claude Platform on AWS or Microsoft Foundry. Teams standardised on Bedrock should check availability again before building on it, and keep any existing approach until then.
Is a URL policy enough to keep the browser safe?
No. The URL policy checks only the URLs Claude passes to navigate. Links Claude clicks, redirects and requests a page makes bypass it, and the SDK doesn't check URL schemes. Anthropic's guide pairs it with request interception in your driver, egress rules on the container and an isolated browser host for each session, and those parts are yours to build.
How much does browser use add to each request?
Declaring the browser toolset with its default members adds roughly six thousand six hundred input tokens per request, according to Anthropic's pricing notes, before any page content. Screenshots are billed as image input and text results such as page reads add more. Turning off members you don't need reduces the overhead, and the token counting endpoint gives the exact figure in advance.



