> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neo.projectdiscovery.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Save a browser session's auth state into its profile

> Persist the session's captured auth state (cookies, local storage)
into its resource-scoped cloud profile immediately, so other sessions
for the same resource can start from it without waiting for this
session to be deleted or expire.

The cloud provider only flushes profile state on session termination,
so this terminates the current cloud browser (persisting the profile)
and transparently recreates a session from that profile under the
same `sessionRef`, re-attaching its daemon and rewriting the manifest.
Open tabs are not carried over; logins are. Clients should re-attach
after this call to pick up the new live view.

Only supported for Kernel cloud sessions; returns 400 otherwise.




## OpenAPI

````yaml https://neo.api.projectdiscovery.io/api/openapi.json post /api/v1/browser/sessions/{session_ref}/persist
openapi: 3.1.0
info:
  contact:
    name: ProjectDiscovery
    url: https://neo.projectdiscovery.io
  description: Neo API Server - Security agent orchestration platform
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Neo API
  version: 1.0.0
servers:
  - description: Production
    url: https://neo.api.projectdiscovery.io
  - description: Development
    url: https://neo.api.dev.projectdiscovery.io
  - description: Local development
    url: http://localhost:8080
security: []
tags:
  - description: Task execution and management
    name: Tasks
  - description: Agent listing and management
    name: Agents
  - description: Public agent directory
    name: Agent Directory
  - description: User file storage management
    name: Files
  - description: User working memory management
    name: Memory
  - description: Scheduled and recurring task management
    name: Schedules
  - description: Knowledge base and semantic search
    name: Knowledge
  - description: Encrypted user credentials and API keys
    name: Secrets
  - description: Neo API key management for programmatic access
    name: API Keys
  - description: User profile and account information
    name: User
  - description: Task and LLM usage tracking
    name: Usage
  - description: Bring Your Own Key provider management
    name: BYOK
  - description: Model discovery and capabilities
    name: Models
  - description: Third-party integrations
    name: Integrations
  - description: Skill knowledge documents for agent prompts
    name: Skills
  - description: Team management and member invitations
    name: Teams
  - description: Prompt library management and discovery
    name: Prompts
  - description: Slack bot integration for workspace installation and OAuth
    name: Slack
  - description: GitHub integration for PR reviews and repository management
    name: GitHub
  - description: Vulnerability issue tracking and management
    name: Issues
  - description: Subscription billing and plans
    name: Billing
  - description: Project management and member assignments
    name: Projects
  - description: SSH key pair generation and management for remote server access
    name: SSH Keys
  - description: Codebase structural analysis and mapping
    name: Codemaps
  - description: AI-generated codebase documentation and security analysis
    name: CodeWiki
  - description: Captured HTTP traffic query and replay
    name: Network Events
  - description: Vulnerability triage for HackerOne, GitHub, and Security Inbox
    name: Triage
  - description: >-
      Application-internal endpoints used by the Neo UI. Not part of the public
      customer API surface.
    name: Internal
paths:
  /api/v1/browser/sessions/{session_ref}/persist:
    post:
      tags:
        - Browser
      summary: Save a browser session's auth state into its profile
      description: |
        Persist the session's captured auth state (cookies, local storage)
        into its resource-scoped cloud profile immediately, so other sessions
        for the same resource can start from it without waiting for this
        session to be deleted or expire.

        The cloud provider only flushes profile state on session termination,
        so this terminates the current cloud browser (persisting the profile)
        and transparently recreates a session from that profile under the
        same `sessionRef`, re-attaching its daemon and rewriting the manifest.
        Open tabs are not carried over; logins are. Clients should re-attach
        after this call to pick up the new live view.

        Only supported for Kernel cloud sessions; returns 400 otherwise.
      operationId: post-v1-browser-sessions-persist
      parameters:
        - description: Opaque browser session reference (brs_<hex>)
          in: path
          name: session_ref
          required: true
          schema:
            type: string
        - description: Optional project ID for project sandbox scope (requires membership)
          in: query
          name: project_id
          required: false
          schema:
            format: uuid
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BrowserSessionManifest'
          description: The rewritten browser session manifest (new provider session)
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Session is not a Kernel cloud session
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Unauthorized - valid authentication required
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Browser session not found for this user
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Internal server error
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  schemas:
    BrowserSessionManifest:
      properties:
        artifactsDir:
          description: Sandbox directory for session artifacts (e.g. screenshots).
          type: string
        capturedTabs:
          description: >-
            Open tabs captured from the live session, used to restore the
            working set when a cloud session resumes to about:blank.
            Sandbox-resident only.
          items:
            $ref: '#/components/schemas/BrowserSessionCapturedTab'
          type: array
        createdAt:
          description: ISO timestamp when the session was first created.
          type: string
        createdBy:
          description: '''agent'' or ''ui''.'
          type: string
        engine:
          description: '''chrome'' or ''lightpanda'' (local only).'
          example: chrome
          type: string
        label:
          description: User-assigned display name for UI-created sessions.
          example: MetaMask login
          type: string
        lastAttachedAt:
          description: ISO timestamp the session was last attached/resumed.
          type: string
        lastCapturedAt:
          description: ISO timestamp the tab set was last captured.
          type: string
        manifestPath:
          description: Sandbox-relative manifest path (audit/debug; no secrets).
          type: string
        mode:
          description: '''cloud'' (Kernel/Browserbase) or ''local'' (sandbox).'
          example: cloud
          type: string
        profileId:
          description: Reusable profile reference; absent for ephemeral/isolated sessions.
          type: string
        provider:
          $ref: '#/components/schemas/BrowserSessionProvider'
        recordingsEnabled:
          type: boolean
        schemaVersion:
          description: Manifest schema version.
          type: integer
        sessionRef:
          description: Opaque Neo-issued reference (brs_<hex>) exposed to UI/agents.
          example: brs_0f1e2d3c4b5a69788796a5b4
          type: string
        startUrl:
          description: Full initial URL a UI session was created with (UI sessions only).
          example: https://app.uniswap.org
          type: string
        status:
          description: 'Lifecycle status: ''active'', ''closed'', or ''error''.'
          example: active
          type: string
        target:
          $ref: '#/components/schemas/BrowserSessionTarget'
        threadId:
          description: Task thread this session belongs to.
          type: string
        updatedAt:
          description: ISO timestamp when the manifest was last written.
          type: string
        userId:
          description: Owning user id.
          type: string
      required:
        - sessionRef
        - threadId
        - mode
        - status
      type: object
    ErrorResponse:
      properties:
        code:
          description: >
            Stable machine-readable error code — branch on this rather than

            matching the human `error`/`message` strings. Domain codes include

            `user_spending_cap_reached`, `project_spending_cap_reached`, and

            `insufficient_neo_credits`; otherwise it mirrors the error kind

            (e.g. `forbidden`, `invalid_request`, `not_exists`,
            `already_exists`).
          example: user_spending_cap_reached
          type: string
        error:
          example: Bad request
          type: string
        error_id:
          description: Correlation id for a specific error instance, when present.
          type: string
        kind:
          description: Coarse error category (e.g. "forbidden request", "invalid request").
          example: forbidden request
          type: string
        message:
          description: |
            Human-readable detail (the kind prefixed to the error). For display,
            not for branching.
          type: string
      required:
        - error
      type: object
    BrowserSessionCapturedTab:
      properties:
        active:
          description: Whether this was the foreground tab at capture time.
          type: boolean
        title:
          description: Tab title at capture time.
          type: string
        url:
          description: Full tab URL, persisted verbatim (sandbox-resident only).
          type: string
      required:
        - url
      type: object
    BrowserSessionProvider:
      properties:
        contextId:
          description: Browserbase persistent context id (cloud only).
          type: string
        kind:
          description: >-
            Provider kind: 'kernel' or 'browserbase' (cloud), or 'sandbox'
            (local).
          example: kernel
          type: string
        profileName:
          description: >-
            Kernel profile name backing the session's persistent auth state
            (cloud only).
          type: string
        sessionId:
          description: Provider's own session identifier (never a URL or token).
          type: string
      required:
        - kind
      type: object
    BrowserSessionTarget:
      properties:
        hostname:
          description: Hostname only — no path, query, userinfo, or secrets.
          example: example.com
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT authentication token
      scheme: bearer
      type: http
    ApiKeyAuth:
      description: Neo API key (neo_sk_* prefix)
      in: header
      name: X-Api-Key
      type: apiKey

````