> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neo.projectdiscovery.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a standalone browser session

> Create a standalone browser session the user can log into interactively
(no task thread required).

Sessions are cloud by default (Kernel: stealth and captcha support on
by default, resource-scoped profile persistence for captured auth) —
many concurrent sessions without sizing up the sandbox — falling back
to sandbox-local Chrome when cloud is unavailable. The
user's default sandbox is resolved (auto-starting it if needed), a
pinned agent-browser daemon is attached there, and a redacted manifest
with `createdBy: "ui"` is written to the sandbox task directory. The
returned `sessionRef` can later be referenced from a task so the agent
reuses the warm, logged-in browser.

Only opaque references and redacted metadata are returned — never
transport URLs, API keys, cookies, or auth headers.




## OpenAPI

````yaml https://neo.api.projectdiscovery.io/api/openapi.json post /api/v1/browser/sessions
openapi: 3.1.0
info:
  contact:
    name: ProjectDiscovery
    url: https://neo.projectdiscovery.io
  description: Neo API Server - Security agent orchestration platform
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Neo API
  version: 1.0.0
servers:
  - description: Production
    url: https://neo.api.projectdiscovery.io
  - description: Development
    url: https://neo.api.dev.projectdiscovery.io
  - description: Local development
    url: http://localhost:8080
security: []
tags:
  - description: Task execution and management
    name: Tasks
  - description: Agent listing and management
    name: Agents
  - description: Public agent directory
    name: Agent Directory
  - description: User file storage management
    name: Files
  - description: User working memory management
    name: Memory
  - description: Scheduled and recurring task management
    name: Schedules
  - description: Knowledge base and semantic search
    name: Knowledge
  - description: Encrypted user credentials and API keys
    name: Secrets
  - description: Neo API key management for programmatic access
    name: API Keys
  - description: User profile and account information
    name: User
  - description: Task and LLM usage tracking
    name: Usage
  - description: Bring Your Own Key provider management
    name: BYOK
  - description: Model discovery and capabilities
    name: Models
  - description: Third-party integrations
    name: Integrations
  - description: Skill knowledge documents for agent prompts
    name: Skills
  - description: Team management and member invitations
    name: Teams
  - description: Prompt library management and discovery
    name: Prompts
  - description: Slack bot integration for workspace installation and OAuth
    name: Slack
  - description: GitHub integration for PR reviews and repository management
    name: GitHub
  - description: Vulnerability issue tracking and management
    name: Issues
  - description: Subscription billing and plans
    name: Billing
  - description: Project management and member assignments
    name: Projects
  - description: SSH key pair generation and management for remote server access
    name: SSH Keys
  - description: Codebase structural analysis and mapping
    name: Codemaps
  - description: AI-generated codebase documentation and security analysis
    name: CodeWiki
  - description: Captured HTTP traffic query and replay
    name: Network Events
  - description: Vulnerability triage for HackerOne, GitHub, and Security Inbox
    name: Triage
  - description: >-
      Application-internal endpoints used by the Neo UI. Not part of the public
      customer API surface.
    name: Internal
paths:
  /api/v1/browser/sessions:
    post:
      tags:
        - Browser
      summary: Create a standalone browser session
      description: |
        Create a standalone browser session the user can log into interactively
        (no task thread required).

        Sessions are cloud by default (Kernel: stealth and captcha support on
        by default, resource-scoped profile persistence for captured auth) —
        many concurrent sessions without sizing up the sandbox — falling back
        to sandbox-local Chrome when cloud is unavailable. The
        user's default sandbox is resolved (auto-starting it if needed), a
        pinned agent-browser daemon is attached there, and a redacted manifest
        with `createdBy: "ui"` is written to the sandbox task directory. The
        returned `sessionRef` can later be referenced from a task so the agent
        reuses the warm, logged-in browser.

        Only opaque references and redacted metadata are returned — never
        transport URLs, API keys, cookies, or auth headers.
      operationId: post-v1-browser-sessions
      parameters:
        - description: >-
            Optional project ID to create the session on the project sandbox
            (requires membership)
          in: query
          name: project_id
          required: false
          schema:
            format: uuid
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateBrowserSessionRequest'
        required: false
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BrowserSessionManifest'
          description: The created browser session manifest
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Unauthorized - valid authentication required
        '429':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Concurrent browser session limit reached for the user's plan
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Internal server error
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  schemas:
    CreateBrowserSessionRequest:
      properties:
        label:
          description: Optional user-assigned display name, persisted in the manifest.
          example: MetaMask login
          type: string
        navigate_to:
          description: >-
            Optional initial URL to open after launch (e.g. a login page).
            Defaults to about:blank.
          example: https://example.com/login
          type: string
      type: object
    BrowserSessionManifest:
      properties:
        artifactsDir:
          description: Sandbox directory for session artifacts (e.g. screenshots).
          type: string
        capturedTabs:
          description: >-
            Open tabs captured from the live session, used to restore the
            working set when a cloud session resumes to about:blank.
            Sandbox-resident only.
          items:
            $ref: '#/components/schemas/BrowserSessionCapturedTab'
          type: array
        createdAt:
          description: ISO timestamp when the session was first created.
          type: string
        createdBy:
          description: '''agent'' or ''ui''.'
          type: string
        engine:
          description: '''chrome'' or ''lightpanda'' (local only).'
          example: chrome
          type: string
        label:
          description: User-assigned display name for UI-created sessions.
          example: MetaMask login
          type: string
        lastAttachedAt:
          description: ISO timestamp the session was last attached/resumed.
          type: string
        lastCapturedAt:
          description: ISO timestamp the tab set was last captured.
          type: string
        manifestPath:
          description: Sandbox-relative manifest path (audit/debug; no secrets).
          type: string
        mode:
          description: '''cloud'' (Kernel/Browserbase) or ''local'' (sandbox).'
          example: cloud
          type: string
        profileId:
          description: Reusable profile reference; absent for ephemeral/isolated sessions.
          type: string
        provider:
          $ref: '#/components/schemas/BrowserSessionProvider'
        recordingsEnabled:
          type: boolean
        schemaVersion:
          description: Manifest schema version.
          type: integer
        sessionRef:
          description: Opaque Neo-issued reference (brs_<hex>) exposed to UI/agents.
          example: brs_0f1e2d3c4b5a69788796a5b4
          type: string
        startUrl:
          description: Full initial URL a UI session was created with (UI sessions only).
          example: https://app.uniswap.org
          type: string
        status:
          description: 'Lifecycle status: ''active'', ''closed'', or ''error''.'
          example: active
          type: string
        target:
          $ref: '#/components/schemas/BrowserSessionTarget'
        threadId:
          description: Task thread this session belongs to.
          type: string
        updatedAt:
          description: ISO timestamp when the manifest was last written.
          type: string
        userId:
          description: Owning user id.
          type: string
      required:
        - sessionRef
        - threadId
        - mode
        - status
      type: object
    ErrorResponse:
      properties:
        code:
          description: >
            Stable machine-readable error code — branch on this rather than

            matching the human `error`/`message` strings. Domain codes include

            `user_spending_cap_reached`, `project_spending_cap_reached`, and

            `insufficient_neo_credits`; otherwise it mirrors the error kind

            (e.g. `forbidden`, `invalid_request`, `not_exists`,
            `already_exists`).
          example: user_spending_cap_reached
          type: string
        error:
          example: Bad request
          type: string
        error_id:
          description: Correlation id for a specific error instance, when present.
          type: string
        kind:
          description: Coarse error category (e.g. "forbidden request", "invalid request").
          example: forbidden request
          type: string
        message:
          description: |
            Human-readable detail (the kind prefixed to the error). For display,
            not for branching.
          type: string
      required:
        - error
      type: object
    BrowserSessionCapturedTab:
      properties:
        active:
          description: Whether this was the foreground tab at capture time.
          type: boolean
        title:
          description: Tab title at capture time.
          type: string
        url:
          description: Full tab URL, persisted verbatim (sandbox-resident only).
          type: string
      required:
        - url
      type: object
    BrowserSessionProvider:
      properties:
        contextId:
          description: Browserbase persistent context id (cloud only).
          type: string
        kind:
          description: >-
            Provider kind: 'kernel' or 'browserbase' (cloud), or 'sandbox'
            (local).
          example: kernel
          type: string
        profileName:
          description: >-
            Kernel profile name backing the session's persistent auth state
            (cloud only).
          type: string
        sessionId:
          description: Provider's own session identifier (never a URL or token).
          type: string
      required:
        - kind
      type: object
    BrowserSessionTarget:
      properties:
        hostname:
          description: Hostname only — no path, query, userinfo, or secrets.
          example: example.com
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT authentication token
      scheme: bearer
      type: http
    ApiKeyAuth:
      description: Neo API key (neo_sk_* prefix)
      in: header
      name: X-Api-Key
      type: apiKey

````