> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neo.projectdiscovery.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Attach to a browser session

> Authorize access to a browser session's live stream / control channel.

Verifies the caller owns the session (the manifest must exist on the
user's sandbox), then mints a short-lived, scoped Neo token and returns
an opaque stream URL. For cloud (Kernel/Browserbase) sessions a direct
`liveViewUrl` is also returned — the provider's embeddable live view
page, which skips the sandbox stream hop. Raw transport secrets
(provider CDP URLs, sandbox CDP URL, API keys) are never returned.

The token is scoped to {user, thread, sessionRef, operation} with a short
TTL; clients re-attach to refresh it.




## OpenAPI

````yaml https://neo.api.projectdiscovery.io/api/openapi.json post /api/v1/browser/sessions/{session_ref}/attach
openapi: 3.1.0
info:
  contact:
    name: ProjectDiscovery
    url: https://neo.projectdiscovery.io
  description: Neo API Server - Security agent orchestration platform
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Neo API
  version: 1.0.0
servers:
  - description: Production
    url: https://neo.api.projectdiscovery.io
  - description: Development
    url: https://neo.api.dev.projectdiscovery.io
  - description: Local development
    url: http://localhost:8080
security: []
tags:
  - description: Task execution and management
    name: Tasks
  - description: Agent listing and management
    name: Agents
  - description: Public agent directory
    name: Agent Directory
  - description: User file storage management
    name: Files
  - description: User working memory management
    name: Memory
  - description: Scheduled and recurring task management
    name: Schedules
  - description: Knowledge base and semantic search
    name: Knowledge
  - description: Encrypted user credentials and API keys
    name: Secrets
  - description: Neo API key management for programmatic access
    name: API Keys
  - description: User profile and account information
    name: User
  - description: Task and LLM usage tracking
    name: Usage
  - description: Bring Your Own Key provider management
    name: BYOK
  - description: Model discovery and capabilities
    name: Models
  - description: Third-party integrations
    name: Integrations
  - description: Skill knowledge documents for agent prompts
    name: Skills
  - description: Team management and member invitations
    name: Teams
  - description: Prompt library management and discovery
    name: Prompts
  - description: Slack bot integration for workspace installation and OAuth
    name: Slack
  - description: GitHub integration for PR reviews and repository management
    name: GitHub
  - description: Vulnerability issue tracking and management
    name: Issues
  - description: Subscription billing and plans
    name: Billing
  - description: Project management and member assignments
    name: Projects
  - description: SSH key pair generation and management for remote server access
    name: SSH Keys
  - description: Codebase structural analysis and mapping
    name: Codemaps
  - description: AI-generated codebase documentation and security analysis
    name: CodeWiki
  - description: Captured HTTP traffic query and replay
    name: Network Events
  - description: Vulnerability triage for HackerOne, GitHub, and Security Inbox
    name: Triage
  - description: >-
      Application-internal endpoints used by the Neo UI. Not part of the public
      customer API surface.
    name: Internal
paths:
  /api/v1/browser/sessions/{session_ref}/attach:
    post:
      tags:
        - Browser
      summary: Attach to a browser session
      description: >
        Authorize access to a browser session's live stream / control channel.


        Verifies the caller owns the session (the manifest must exist on the

        user's sandbox), then mints a short-lived, scoped Neo token and returns

        an opaque stream URL. For cloud (Kernel/Browserbase) sessions a direct

        `liveViewUrl` is also returned — the provider's embeddable live view

        page, which skips the sandbox stream hop. Raw transport secrets

        (provider CDP URLs, sandbox CDP URL, API keys) are never returned.


        The token is scoped to {user, thread, sessionRef, operation} with a
        short

        TTL; clients re-attach to refresh it.
      operationId: post-v1-browser-sessions-attach
      parameters:
        - description: Opaque browser session reference (brs_<hex>)
          in: path
          name: session_ref
          required: true
          schema:
            type: string
        - description: Optional project ID for project sandbox scope (requires membership)
          in: query
          name: project_id
          required: false
          schema:
            format: uuid
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/BrowserSessionAttachRequest'
        required: false
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BrowserSessionAttachResponse'
          description: Stream authorization with a short-lived token
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Unauthorized - valid authentication required
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Browser session not found for this user
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Internal server error
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  schemas:
    BrowserSessionAttachRequest:
      properties:
        operation:
          default: view
          description: >-
            Access scope: 'view' (read-only live view) or 'control' (view +
            input).
          enum:
            - view
            - control
          type: string
      type: object
    BrowserSessionAttachResponse:
      properties:
        engine:
          description: '''chrome'' or ''lightpanda''.'
          type: string
        expiresAt:
          description: Token expiry (RFC3339).
          format: date-time
          type: string
        liveViewUrl:
          description: |
            Direct provider live view URL (cloud sessions only). Embeddable
            page with no API keys; preferred over streamUrl when present since
            it skips the sandbox stream hop.
          type: string
        mode:
          description: '''cloud'' or ''local''.'
          type: string
        profileId:
          description: Reusable profile reference, if any.
          type: string
        sessionRef:
          description: Opaque browser session reference (brs_<hex>).
          type: string
        status:
          description: 'Lifecycle status: ''active'', ''closed'', or ''error''.'
          type: string
        streamUrl:
          description: Neo-authorized stream URL (relative) carrying the short-lived token.
          example: /api/v1/browser/sessions/brs_abc/stream?token=...
          type: string
        token:
          description: Short-lived scoped Neo stream token.
          type: string
      required:
        - sessionRef
        - mode
        - status
        - streamUrl
        - token
        - expiresAt
      type: object
    ErrorResponse:
      properties:
        code:
          description: >
            Stable machine-readable error code — branch on this rather than

            matching the human `error`/`message` strings. Domain codes include

            `user_spending_cap_reached`, `project_spending_cap_reached`, and

            `insufficient_neo_credits`; otherwise it mirrors the error kind

            (e.g. `forbidden`, `invalid_request`, `not_exists`,
            `already_exists`).
          example: user_spending_cap_reached
          type: string
        error:
          example: Bad request
          type: string
        error_id:
          description: Correlation id for a specific error instance, when present.
          type: string
        kind:
          description: Coarse error category (e.g. "forbidden request", "invalid request").
          example: forbidden request
          type: string
        message:
          description: |
            Human-readable detail (the kind prefixed to the error). For display,
            not for branching.
          type: string
      required:
        - error
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT authentication token
      scheme: bearer
      type: http
    ApiKeyAuth:
      description: Neo API key (neo_sk_* prefix)
      in: header
      name: X-Api-Key
      type: apiKey

````