| title | Changelog |
|---|---|
| description | Updates and improvements |
import { YouTubeVideo } from '/snippets/youtube-video.mdx';
For API library updates, see the [Node SDK](https://github.com/onkernel/kernel-node-sdk/blob/main/CHANGELOG.md), [Python SDK](https://github.com/onkernel/kernel-python-sdk/blob/next/CHANGELOG.md), and [Go SDK](https://github.com/onkernel/kernel-go-sdk/blob/main/CHANGELOG.md) changelogs.<Update label="July 31" tags={["Product", "Docs"]}>
- Released
@onkernel/eve-extensionv0.1.3, a Kernel-powered browser extension for Vercel's Eve agent. - Published a Codex plugin packaging for the Kernel skills repo, so Codex users can install the full Kernel skill set the same way Claude Code and Cursor users can.
- Added a
get_telemetryaction to the MCP server'smanage_browserstool for reading archived browser telemetry — including for deleted sessions and events captured before telemetry was turned off — with category filters, time windows, and pagination. - Expanded managed auth: browser telemetry is now configurable per connection and captured on timeline events, the health-check interval is adjustable from the dashboard, and health checks and their replays now appear on the connection timeline alongside logins and re-auths.
- Extended
@onkernel/cua-agentwith Claude Opus 5 and Moonshot Kimi K3 computer-use providers, semantic browser waits (waitForconditions instead of fixed sleeps), verified browser action plans, and gated Anthropic's nativecomputer_20260701/browser_20260701tools by model. - Added named markers to browser replay recordings, exposed as MP4 chapters so playback jumps directly to key moments.
- Extended the CLI
browser-poolscommands with telemetry configuration, matchingbrowsers create/update. - Improved
kernel upgradein the CLI to refresh the Homebrew tap before upgrading to pick up latest version, and made CLI commands fail fast on interactive prompts in non-interactive shells to avoid hanging scripts. - Added a complete audit log download helper to the Go, Node, and Python SDKs.
- Added support for solving PerimeterX / HUMAN "Press & Hold" challenges in stealth-mode browsers.
- Added customer-supplied CA bundles to custom proxies for BYO TLS-terminating (MITM) proxies.
- Improved
kernel audit-logs searchoutput to show user IDs as a separate column. - Shipped inline text editing and document bookmarks (with a public bookmarks agent API) in just-html.
- Published new integration guides for Claude Code + Desktop, the Claude Agent SDK, and the Vercel Eve extension.
- Documented custom proxy CA bundles for BYO MITM setups, audit log search and export, per-user profile persistence through browser pools, and managed auth tab ownership.
- Added a bots and agents overview and reframed the "Unsupported Websites" FAQ entry as bot-detection education.
- Refreshed the reference docs with
execute_playwright_codepassthrough and the newmanage_replaysMCP tool, plus a CLI reference sync with the current command set. - Added a Chrome policy use case for blocking DevTools, reorganized Chrome Policies into an Advanced section, and added browser telemetry to the pricing feature matrix.
<Update label="July 17" tags={["Product", "Docs"]}>
- Launched browser telemetry: capture events from inside a browser session — console output, network activity, page lifecycle, user interactions, captcha solves, and operational signals like crashes — then stream them live or pull them later for analysis, with opt-in control over which categories you capture. Alongside the launch, we added an in-VM OTLP export sink and OTel-compatible support in the browser events API, so telemetry can be shipped to any OpenTelemetry-compatible collector.
- Added new Grok 4.5 and Meta Muse Spark computer-use providers to
@onkernel/cua-agent, along with a--proxyflag for routing the agent's browser through a Kernel proxy, configurable retries on transient provider errors, and opt-in recovery when a provider returns an exact-empty response. - Gave
kernel audit-logsin the CLI adownloadsubcommand for chunked bulk exports and the ability to exclude multiple HTTP methods fromsearch, so audit workflows can pull large windows without hitting pagination caps. - Improved cold-start performance: reduced Chromium restart time, and cut ~5s off session creation for profile-restore paths by fixing a chromium-launcher port check that blocked on stale sockets.
- Set the default fill-rate for new browser pools created from the dashboard or CLI to 25%, so pools warm up more predictably out of the box.
refresh_on_profile_updatenow defaults totruewhen a browser pool has a profile attached, and auto-unsets when the profile is removed, so pooled sessions stay in sync with the underlying profile without manual configuration.- Expanded managed auth: the dashboard can now manage credential fields and TOTP secrets directly, and reauth now selects an already signed-in account on the SSO account chooser, so re-authentications can complete without human intervention when the browser is already signed in.
- Shipped a Cmd+K command palette to the dashboard for jump-to-anywhere navigation.
- Published
hermes-browser-plugin, a new Kernel cloud browser provider plugin for Hermes Agent. - Improved just-html with section deeplinks, comment permalinks, and a public integration-discovery metadata endpoint, so shared docs are easier to navigate, link, and index by agents.
- Published a new Zero Data Retention page covering Kernel's ZDR posture.
- Documented a "managed proxy without CAPTCHA solver" pattern for stealth BYO proxy setups.
- Moved the scaling guide into Introduction as a dedicated Scale page.
- Documented in the browser telemetry guide which categories are disabled under BAA.
<Update label="July 10" tags={["Product", "Docs"]}>
- Consolidated on-demand and browser-pool concurrency into a single unified concurrency limit that counts
browsers.create()sessions and pool reservations against one org cap.max_pooled_sessionsis deprecated;max_concurrent_sessionsnow covers both. Rolling out gradually. - Shipped
kernel audit-logs searchin the CLI for querying the org audit log by time window, HTTP method, service, auth strategy, and user, with table or JSON output.GETrequests are excluded by default to keep the signal on mutations. - Added a
refresh_on_profile_updateflag to browser pools (SDK, CLI--refresh-on-profile-update, and dashboard). Opted-in pools automatically flush their idle browsers when the pool's managed-auth profile re-authenticates, so pooled sessions stay logged in after a re-auth. - Extended
@onkernel/cua-agentwith action-plane modes —computer,browser, andhybrid— plussetMode()and a/moderuntime switcher, and wired in support for Anthropic's shipped nativecomputer_20260701andbrowser_20260701tools. - Exposed
profile_idandextension_idson browser pool reads, and returned an SHA-256 checksum for uploaded extensions. - Added the ability to inspect credential value keys and remove specific values on managed-auth credential updates.
DELETE /org/api_keys/{id}now returns400 cannot_delete_current_keywhen the target key is the one authenticating the request, so scripts and Terraform-style provisioners can't brick their own credentials mid-run.
- Documented the unified concurrency limit and marked
max_pooled_sessionsdeprecated across pricing, projects, and the CLI reference. - Documented the new
refresh_on_profile_updatebrowser pool flag. - Added a proxy health check reference to the proxies overview.
<Update label="July 3" tags={["Product", "Docs"]}>
- Shipped
kernel extensions get <id-or-name>in the CLI for extension metadata lookups, with table or JSON output. - Extended CLI browser telemetry with
kernel browsers telemetry events <id>for paginated historical reads and a--replay=allflag onbrowsers telemetry streamto replay from the oldest retained event. - Simplified browser pool profiles to id/name-only, dropping the
--save-changesflag onbrowser-pools create/update; single-sessionbrowsers create --save-changesis unaffected. - Extended
@onkernel/cua-aiwith computer-use support for theclaude-sonnet-5model. - Threaded
previous_response_idthrough the Tzafon and OpenAI computer-use providers in@onkernel/cua-ai, so multi-turn runs send only the latest screenshot delta instead of replaying the full history each turn. - Rebuilt the dashboard managed-auth connection detail page around an overview/history/config tab layout, with a pinned stats row and a full event timeline (logins, re-auths, health checks) filterable by type.
- Brought mobile proxy creation into the dashboard, with country, state, and city targeting.
- Expanded the dashboard pool create/edit dialogs with tablet (
768x1024) and mobile (390x844) viewport presets.
- Published a Computer Use overview page covering the shared screenshot-predict-execute loop and a guide for building custom agents with
@onkernel/cua-agent. - Clarified that browsers released back into a pool with the default
reuse: truekeep their original configuration, and thatbrowserPools.update()only rebuilds idle browsers whendiscard_all_idle: trueis passed.
<Update label="June 26" tags={["Product", "Docs"]}>
- Added a
playwright_executetool to@onkernel/cua-agentfor combining computer use with Playwright automation, plus support forgemini-3.5-flashas a CUA model. - Extended the MCP server's browser pool tool with SDK parity fields (
start_url,chrome_policy,kiosk_mode, profile and viewport settings,fill_rate_per_minute) and a structured acquire/release workflow. Added parity for actions acrossmanage_apps(delete_deployment, app/deployment search),manage_proxies(get,checkwith optionalcheck_url),manage_profiles(get, paginated search), andmanage_projects(get_limits,update_limits). - Added a
start_urlparameter to browser poolacquire, letting each acquired session override the pool's default start URL. - Added
--chrome-policyflags tobrowsers create/updateandbrowser-pools create/updatein the CLI for setting Chrome popup, PDF, and homepage behavior from the terminal. - Extended
kernel browsers updatein the CLI with--nameand--tagparameters, so a running session's name and tags can be changed after creation alongside the existingbrowsers create/acquireflags. - Brought custom session names and tags into the dashboard: the launch dialog now accepts an initial set of tags, sessions can be renamed and re-tagged after creation, and tag chips on the sessions list are click-to-filter — so the names and tags set via the API are actionable from the UI, making it easier to find a specific session out of many concurrent ones.
- Added an API key rotate endpoint (
POST /org/api_keys/{id}/rotate) that issues a replacement key, copies the rotated key's name and project scope, and keeps the old key working for a configurable grace period (default 7 days). - Shipped a
generate-videoskill for producing smooth, deterministic MP4 videos from a web scene — used internally for launch and explainer clips.
- Enabled dark mode on the docs.
- Added a common use cases section to the policy.json page with
browsers.create()examples for popup blocking, PDF inline rendering, and homepage overrides. - Documented
X-Kernel-Project-Idheader resolution rules and direct project and extension lookups on the Projects page. - Documented the API key rotate endpoint, including the optional
days_to_expireandexpire_in_daysparameters.
<Update label="June 12" tags={["Product", "Docs"]}>
- Released the Kernel × Claude Managed Agents cookbook, a public recipe for running parallel computer-use agent swarms with Claude Managed Agents on Kernel cloud browsers, with API keys secured via Vaults.
- Shipped a
kernel-browser-harnessskill for setting up Kernel browser sessions inside Claude Code with persistent session IDs across calls. - Extended
kernel browsers acquirein the CLI withnameandtagsparameters, so pooled browsers can be labeled at acquisition time alongsidebrowsers create. - Made browser telemetry categories opt-in. The
--telemetryflag (andtelemetryrequest config) now records only the categories you list; enabling telemetry without specifying categories ships a small default set instead of every category.
- Published a new browser telemetry guide covering categories, the stream API, and event shapes.
- Wrote a Claude Managed Agents integration guide with a link to the public cookbook.
- Documented the org-wide default per-project concurrency cap on the Projects page.
- Expanded the CLI reference to include several previously missing subcommands.
<Update label="June 5" tags={["Product", "Docs"]}>
- Browser sessions now play audio by default, and the browser replay recording API gained a
record_audiooption to capture that audio in replay videos. - Extended browser telemetry to the CLI: use
--telemetry=all|off|<list>onbrowsers createandbrowsers updateto configure telemetry per session, andkernel browsers telemetry stream <id>to tail live events with category and type filters and SSE resume support. - Added API key management commands to the CLI for creating, listing, retrieving, updating, and deleting org API keys directly from the terminal.
- Expanded the MCP server from 10 to 16 tools, adding managed auth (
manage_auth_connections,manage_credentials,manage_credential_providers),browser_curlfor HTTP(S) through a live browser, API key management, and project management. MCP-created browser sessions also now accept the same configuration as the API. - Browser sessions can now be given a custom name at create time, making them easier to identify in the dashboard and audit logs.
- Improved
kernel statusto distinguish between the API being down versus unreachable.
- Reorganized the MCP server documentation into per-page navigation for easier browsing.
- Expanded and regrouped the CLI reference to match the MCP docs structure.
- Added Go SDK code examples across the docs.
- Added a managed auth CLI reference page.
- Clarified that ISP proxies provide a static IP across sessions.
<Update label="May 28" tags={["Product", "Docs"]}>
- Soft-launched auth.md, a discovery file that lets agents sign up for a Kernel account or fetch an API key for an existing user account on their own. Point your agent at the URL and it can self-provision. Based on the new auth.md protocol from WorkOS.
- Added browser telemetry as a first-class request config. Pass
telemetry.enabled(and per-category toggles) onbrowsers.create()orbrowsers.update()to capture telemetry for the session, and stream it live fromGET /browsers/{id}/telemetry/stream(SSE). - Exposed API key management in the Node, Python, and Go SDKs. Create, list, retrieve, update, and delete keys on
/org/api_keysprogrammatically. - Promoted
can_reauth_reasononManagedAuthto a typed enum (14 documented values likerequires_totp_without_secret,no_viable_plans,requires_external_action) so SDK consumers can branch on it directly instead of string comparisons. - Added an Auto Re-Auth / Needs Human capability chip to each row on the dashboard
/authpage, with a tooltip mapping eachcan_reauth_reasonto a human-readable explanation. - Added TOTP secret key support to managed auth credentials, so one-time passwords are generated automatically during login and re-authentication. No human intervention required.
- Updated the live view loading screen to a progress bar for clearer visual feedback during browser startup.
- The
/projects/*endpoints are now routed under/org/projects/*. The previous paths are deprecated.
- Added new Create, Control, and Observe introductory guides covering the core primitives for getting started with browser automation.
- Expanded the Control guide with three patterns for combining computer use with
playwright.execute: exposeplaywright.executeas a tool, checkpoint state between CUA steps, and drop the agent once selectors stabilize for replay at scale. - Documented the new
health_checksandauto_reauthconnection flags on managed-auth connections, including defaults, how they interact (auto_reauth only applies while health_checks is on), and a create-time example with both disabled. - Updated the MCP server tool reference to match the current API.
- Clarified that stealth mode's default proxy is ISP, not residential. ISP proxies use residential ASNs on datacenter infrastructure.
<Update label="May 21" tags={["Product", "Docs"]}>
- Added auto standby to browser pool instances — pools can now automatically suspend when idle and resume on the next incoming request, reducing costs without manual intervention.
- Launched new browser configuration options on
browsers.create()and browser pool definitions:chrome_policyandstart_urlfor opening directly to a specified URL on launch. The corresponding--start-urlflag is available in the CLI. - Exposed full Projects CRUD in the public API, so projects can be created, updated, and deleted programmatically alongside the existing list endpoint.
- Managed auth improvements: Added health check and automatic re-authentication controls to the managed auth API, letting you configure check intervals and reauth triggers per connection. Sessions are now automatically recorded — when a connection enters
NEEDS_AUTHon the dashboard, a "View last login attempt" link routes directly to the session replay, and /auth rows now show a re-auth capability chip. Also, broader SSO and OAuth provider coverage, support for Google's two-step mobile prompt flow, per-connection post-login wait configuration (post_login.wait_ms), automatic SSO provider brand icons in auth dialogs, MFA alternatives displayed on the external action waiting screen, and a post-login browser refresh before the profile snapshot is captured for cleaner saved sessions. - Extended
proxy.check()with an optionalurlparameter for testing reachability against a specific target domain before assigning the proxy. This is useful for catching proxies that pass generic health checks but are blocked on your target site. - End of life'd persistent browsers. If you were using persistence, we suggest
timeout_secondswith Profiles.
- Added a new hCaptcha page documenting beta support for hCaptcha solving.
- Refreshed managed auth documentation for May 2026: new dedicated connection lifecycle page covering health checks and re-authentication, a shared connection configuration reference, documented
success_url/error_urlquery parameters for the hosted UI,start_urlreferences across browser and pool docs, a reorganized sidebar, and new FAQ entries for short-session reauth and multi-step login forms. - Clarified that managed residential proxy IPs are stable within a session but are not guaranteed to persist across sessions.
- Updated the Yutori integration guide to Navigator n1.5.
- Clarified that profile updates do not propagate to idle browser pool instances — pools must be recycled for profile changes to take effect.
<Update label="May 8" tags={["Product", "Docs"]}>
- Released
@onkernel/managed-auth-react, a drop-in React component library for embedding managed auth flows directly into your app. Ship a Kernel-powered login experience without rebuilding the credential entry, MFA, and SSO dialogs yourself. - Added a Docker Sandboxes mixin kit for running Kernel inside Docker's AI sandboxes (
sbx). The kit ships the Kernel CLI, Claude Code skills, and a proxy-managed auth header pre-configured, so agents inside the sandbox can call the Kernel API while your realKERNEL_API_KEYstays on the host. - Extended Projects: profile, browser pool, extension, and credential names are now scoped per-project, and the
GET /projectsAPI and dashboard project selector support server-side search and pagination. - Made the 1Password credential dropdown searchable in managed auth dialogs.
- Improved managed auth autofill reliability on multi-step sign-in pages.
- Added
-o jsonoutput tokernel browsers playwright executein the CLI, matching the otherbrowserssubcommands, so script runs can be piped into other tooling.
- Documented in the computer controls docs that computer controls screenshots are faster than CDP screenshots on WebGL-heavy pages.
- Updated
kernel-cliskill examples in the Kernel skills repo and documented the return value ofplaywright executeso agents can use the result in follow-on steps.
<Update label="May 1" tags={["Product", "Docs"]}>
- Added
kernel browsers curlcommand to the CLI for making HTTP requests directly from a browser session using browser's cookies, session state, and network identity. - Extended Projects support to the CLI and MCP server — use the
--projectflag to scope CLI commands to a specific project, and MCP tools now resolve projects by name. - Improved mouse movement timing with Gaussian-distributed delays between movements for more natural-looking interactions.
- Improved managed auth UX: MFA prompts now display which channel (email or phone) the verification code was sent to, and
--credential-autonow defaults to enabled when--credential-provideris set. - Added a dedicated
switchMFA option type so generic method-switcher links ("Use another method", "Try another way") are distinguished from buttons that name a specific method, improving auto-click reliability on multi-step MFA pages. - Managed auth CUA flow now resolves external credentials (e.g. 1Password) via auto-lookup.
- Managed auth connections now expose
browser_session_idso callers can inspect or terminate the underlying browser session via the/browsersAPI. - Added a
diff-profile-archivesskill to the Kernel skills repo for comparing Chrome profile archives directly with a coding agent.
- Added documentation for the new
kernel browsers curlcommand, along with thekernel profiles downloadandkernel profiles deletecommands. - Documented IP rotation behavior for residential, ISP, and datacenter proxies.
- Added a How browser pools work walkthrough (declaration vs acquisition, fixed capacity, releasing browsers) and a new browser creation performance troubleshooting page.
<Update label="April 24" tags={["Product", "Docs"]}>
- Launched Projects so you can keep
productionandstagingseparate, split resources between teams, scope API keys to a single environment, and cap concurrency per project so one workload can't exhaust your org quota. Existing resources have been moved into a Default project, so nothing changes for current workloads. - Kernel is now a Cloudflare Web Bot Auth partner. Kernel browsers can cryptographically identify themselves to Cloudflare-protected sites, so Kernel traffic isn't blocked.
- Anti-detection features are now on by default for all Kernel browsers. Stealth mode now specifically adds the managed ISP proxy and CAPTCHA solver (both opt-out), and non-stealth browsers fully support custom proxies.
- Revamped the managed auth hosted login page: all available sign-in options (password fields, SSO providers, MFA, alternate sign-in methods) now render together on a single page, so end users can pick the path they want, instead of being funneled through one at a time.
- Managed auth input fields now display contextual helper text when the site surfaces hints, reducing user confusion on multi-step logins.
- The "Save credentials after login" option is now automatically disabled when 1Password is selected as the credential source, since those credentials are already managed externally.
- Kernel now supports WebSocket connections through its API, enabling
process attachand other long-lived streaming workflows. - Exceeding invocation concurrency limits now returns a 429 response immediately, for faster and more actionable feedback.
- Rewrote the stealth mode and bot detection overview pages to clarify the new anti-detection defaults, and added a "Bring your own proxy" section to the proxies overview.
<Update label="April 17" tags={["Product", "Docs"]}>
- Managed auth now scrolls to find and click submit buttons that are below the initial viewport.
- Added a Tzafon Northstar computer use template to the CLI for building Northstar-based browser agents.
- Browser search now matches by pool name in addition to session ID, profile, and proxy.
- Added an enterprise option to remove the Kernel logo from the live view loading screen.
- Eliminated live view scrollbar flickering on mobile viewports.
- Fixed Safari clipboard paste issues in live view iframes.
- Added a new Tzafon Northstar integration guide.
- Updated the bot anti-detection page to document smooth Bezier curve mouse movements, and renamed the Chrome policy configuration page in the nav for clarity.
- Added documentation for smooth typing with typo injection — new
smoothandtypo_chanceparameters for human-liketypeTextbehavior. - Updated DPA subprocessor list URLs to point to the new trust center at
trust.kernel.sh.
<Update label="April 10" tags={["Product", "Docs"]}>
- Improved live view scroll feel for smoother, more natural scrolling.
- We removed idle disk space charges for browser pools on the startup tier too, so you'll no longer be billed for storage when your pools aren't in use.
- Improved browser creation speed when loading profiles by reducing the CDP ready wait to near-instant.
- Added human-like smooth typing to cloud browsers, with optional typo injection for more natural-looking interactions.
- Launched a Cursor Marketplace plugin bundling all Kernel skills, an MCP server for cloud browser management, and best practices.
- Documented MFA token auto-retry behavior for managed auth sessions.
- Added a new policy.json page to the Reserved Browsers documentation.
- Clarified that profiles can have multiple auth connections.
- Added a Headful + GPU acceleration option to the pricing calculator.
<Update label="April 3" tags={["Product", "Docs"]}>
- Added spending cap management to the dashboard billing page, allowing org admins to set and update spending limits directly from the UI. Currently in limited preview.
- Enhanced browser stealth with additional evasion techniques.
- Fixed navigator fingerprint gaps (
maxTouchPoints,userAgentDatabrands,screen.availHeight) to better match real desktop Chrome behavior. - Added
disable_default_proxyoption for stealth browsers, allowing users to disable the default proxy on stealth-mode browsers. - Improved error responses for browser process start failures.
- Added API rate limiting documentation.
- Documented the
disable_default_proxyoption for stealth browsers. - Updated live view embedding docs with iframe focus tips, clipboard sharing guidance, and CSP configuration.
- Documented managed auth re-authentication triggers.
<Update label="March 27" tags={["Product", "Docs"]}>
- Added support for custom Chrome
policy.jsonon browser pools, enabling users to configure Chrome settings like popups, PDF behavior, and homepage without manual workarounds. - Updated the CLI to prioritize API key authentication over OAuth, and added new commands and flags.
- Improved browser pool acquisition speed.
- Improved CDP proxy reconnect behavior after Chromium restart, preventing broken browser sessions.
- Corrected Safari clipboard sync in the dashboard live view, resolving copy/paste issues for users viewing browser sessions from Safari.
- Improved mouse movement in live view.
- Added an FAQ entry for debugging managed auth sessions.
- Updated Managed Auth documentation to cover CUA support, the PATCH endpoint, and auto-allowed SSO domains.
<Update label="March 20" tags={["Product", "Docs"]}>
- Launched GPU acceleration for cloud browsers. GPU acceleration attaches a virtual GPU to your cloud browser, dramatically speeding up agents on sites that use canvases, are heavy on visualizations, or rely on WebGL. In our internal benchmarks, GPU-accelerated browsers hit 60 fps —6x faster than regular browsers— making browsing feel faster pretty much everywhere on the internet. GPU acceleration is available as a research preview on Startup and Enterprise plans.
- Increased Chromium's default maximum connections per proxy to 16, improving throughput for proxy-based browser sessions.
- Updated the live view logo and favicon to reflect the latest Kernel branding.
- Updated OpenAI CUA templates to use Kernel's native Computer Controls API instead of Playwright for improved reliability and performance.
- Fixed an issue where deleted browser sessions couldn't be listed or downloaded in session replays via the CLI.
- Added new docs for GPU acceleration.
- Added ZIP code targeting documentation for residential proxies.
- Clarified download behavior for programmatic file downloads.
- Reorganized documentation to make Managed Auth and Browser Pools more prominent and accessible.
<Update label="March 13" tags={["Product", "Docs"]}>
- Added WebDriver BiDi support for cloud browsers through a new partnership with Vibium. AI agents can now use Vibium to connect to Kernel and navigate pages, fill forms, click buttons, and take screenshots across thousands of cloud browsers running in parallel.
- Launched Kernel Eval Protocol, an open-source repo that pairs Kernel Browser Pools with Fireworks RFT and Eval Protocol to evaluate and fine-tune VLM browser agents using reinforcement learning.
- Added a
usagefield to the browser session details API response, which returns session metrics likeuptime_ms. Use this to track session duration and build billing or analytics workflows around your browser usage. - Extended smooth Bezier curve mouse movements to click and drag operations, and added
--smoothand--duration-msflags to themove-mousecommand in the CLI for more natural-looking browser interactions. - Improved headless viewport resize performance by using a CDP fast path, reducing resize time from ~5 seconds to ~10 milliseconds.
- Added support for runtime proxy configuration swapping, enabling you to change a browser's proxy settings mid-session without restarting.
- Added a new Vibium integration guide with CLI examples and setup instructions.
- Added smooth mouse movement and drag documentation with CLI one-liner examples.
- Improved Web Bot Auth page readability with clearer formatting.
<Update label="March 6" tags={["Product", "Docs"]}>
- Added support for mobile and tablet viewports, enabling browser automation at phone and tablet screen sizes.
- Added a
kernel statuscommand to the CLI for checking API and service health at a glance. - Added a
--forceflag tokernel browsers updatefor resizing the viewport during an active recording, which gracefully stops and restarts the recording. - Improved Managed Auth MFA handling by resolving MFA options by label, type, or display string for more reliable multi-factor authentication flows.
- Enhanced auth connection output in the CLI with richer details from
kernel auth connections getandkernel auth connections list. - Added a Pool column and
--queryflag tokernel browsers listin the CLI for easier filtering and identification of pooled browsers. - Updated the Anthropic computer use template to default to use claude-sonnet-4-6 for improved agent performance.
- Fixed start session replay error.
- Updated localStorage to persist across profile sessions.
- Fixed scroll notch count handling in computer use templates.
- Fixed an anti-echo guard issue that could cause video sync problems in live view.
- Renamed "Scaling in Production" to Reserved Browsers and added a new On-Demand Browsers section for clearer guidance on browser provisioning strategies.
- Added mobile and tablet viewport configurations with supported screen sizes and usage guidance.
- Added proxy-bypass-hosts documentation for configuring proxy bypass lists on browser pools.
- Documented the
--forceflag for viewport resizing during active recordings. - Added viewport configuration examples to browser pool documentation.
<Update label="February 27" tags={["Product", "Docs"]}>
- We launched our new look! Our visual identity has been updated across our website, product, and docs.
- Important: Persistent browser functionality will be end-of-life'd as of May 18th. If you're using this functionality, you've received an email from us with next steps. Please reach out for further support.
- Improved the MCP server by adding 21 new tools covering browser pools, computer controls, proxies, extensions, and more. Consolidated 36 individual tools into 10 streamlined tools and enhanced the computer_action tool to support executing multiple actions in a single call.
- Added API support for clipboard operations, enabling programmatic copy/paste between your automation code and the remote browser.
- Introduced human-like Bezier curve mouse movements for more natural-looking browser interactions that better evade bot detection.
- Added an option to disable live view logging, reducing noise when debugging browser sessions.
- Added
kernel deploy deleteandkernel app deletecommands to the CLI for removing deployments and apps. - Added server-side session ID search to the dashboard, allowing users to find past browser sessions by ID without loading them all locally.
- Added profile pagination and search to the dashboard and CLI, fixing crashes for users with large numbers of profiles.
- Pre-installed ssh and websocat in browser images for easier debugging and WebSocket testing.
- Added more fonts to browser images for better rendering of international content.
- Improved profile upload performance by buffering zstd archives in memory instead of writing to temp files.
- Added a new Yutori computer use integration guide with setup instructions and code examples.
- Clarified viewport configuration recommendations with guidance on choosing the right resolution for your use case.
<Update label="February 20" tags={["Product", "Docs"]}>
- Added mouse position tracking to the CLI, enabling retrieval of current mouse coordinates.
- Updated Yutori computer use templates to support the n1-latest model for improved agent performance.
- Updated Managed Auth by adding subdomain-based sign-in support, better error handling for
401 Unauthorizedand410 Goneresponses, and enhanced error messaging with structured error codes and actionable guidance. - Improved browser display by auto-toggling Chromium app mode on small viewports for a cleaner, more immersive experience.
- Fixed screen resize accuracy by removing unnecessary rounding in
ChangeScreenSizeto ensure pixel-perfect display dimensions.
- Enhanced secrets documentation with practical examples for LLM-powered applications and detailed guidance for deploying apps with environment file configurations.
<Update label="February 13" tags={["Product", "Docs"]}>
- Launched [Web Bot Auth](/browsers/bot-detection/web-bot-auth) in partnership with Vercel, enabling agents to cryptographically sign requests and prove they're legitimate instead of getting blocked by bot detection. - Released [Managed Auth](/auth/overview), simplifying authentication by securely logging into any site without custom auth flows or exposing credentials to the LLM, and maintaining up-to-date credentials. - Added a `POST /computer/batch` [endpoint](https://kernel.sh/docs/api-reference/browsers/execute-a-batch-of-computer-actions-sequentially) for executing multiple computer actions in a single API call, reducing round-trip latency for complex automations. - Improved the [CLI](https://github.com/onkernel/cli) by adding new commands for managing auth connections, supporting `-o json` output for `kernel ssh --setup-only`, allowing pool names as positional arguments in `kernel browser-pools create`, and enabling file exclusions when publishing extensions. - Improved input reliability with context-aware timing in key press and mouse drag operations. - Fixed an issue where stealth mode browsers couldn't access plain HTTP websites due to forced HTTPS redirects.- Clarified pricing for headful browser sessions.
- Added comprehensive Managed Auth documentation, including billing guidance.
<Update label="February 6" tags={["Product", "Docs"]}>
- Added a
/jsonendpoint to the CDP proxy, enabling native PlaywrightconnectOverCDP()connections. - Launched an API to get the current cursor position, which is useful for debugging and building adaptive automation logic.
- Released an API to retrieve browser session IDs associated with a specific invocation.
- Added SSH access to Kernel browsers for debugging, running commands, and tunneling your local development server to the browser.
- Enabled support for the 1280x800 viewport size, which improves click coordinate accuracy.
- The Live View clipboard now syncs correctly between browser and local machine.
- Chrome address autofill prompts are now automatically disabled.
- Added a pricing calculator to help you estimate costs based on your plan, session length, and browser type.
- Clarified file access limitations and browser session deletion behavior.
<Update label="January 30" tags={["Product", "Docs"]}>
- We changed the default search engine for Kernel browsers to DuckDuckGo, which reduces CAPTCHA friction during web searches.
- We updated the Gemini Computer Use Python and TypeScript templates to use Kernel's Computer Controls API.
- We released skills for Kernel, so you can easily build browser agents directly from Claude Code.
- We published a Scaling in Production guide with recommendations and best practices for handling high-concurrency workloads. Read it to learn how and when to use browser pools versus on-demand browsers, and see code samples for production implementations.
- Added a new integration guide for Agent Browser, Vercel's headless browser automation CLI, which has built-in support for Kernel browsers.
<Update label="January 23" tags={["Product"]}>
- [Browser pools](/browsers/pools/overview) are now generally available for our Startup and Enterprise plans! Make your startup times even faster with a fleet of instant browsers that come pre-loaded with the logins, cookies, and extensions your agents depend on. - We improved the Browsers page user experience. Enjoy instant clickability of browser cards, shift+click range selection, preserved view state when switching between grid and list views, a live toggle for auto-refresh, keyboard shortcut support (Cmd+B / Ctrl+B to toggle sidebar), and more. - We added support for viewing [replays](/browsers/replays) of deleted browser sessions. Deleted browsers now navigate to their detail page, which shows the replay player with multiple replays displayed as tabs. The API now supports fetching deleted browser details using new query parameters. - Overhauled our [Anthropic Computer Use template](https://github.com/onkernel/cli/tree/main/pkg/templates/typescript/anthropic-computer-use) to use Kernel's [Computer Controls](/browsers/computer-controls) API instead of Playwright, improving reliability and performance. - We improved the [live view](/browsers/live-view) experience to show a clear "disconnected" screen when a browser is destroyed, instead of leaving users on a blank page.<Update label="January 16" tags={["Product", "Docs"]}>
- Added a Past Sessions view to the dashboard showing your 100 most recent browser sessions; provided context about the session history limit.
- Improved browser session stability to reduce premature disconnections and WebSocket failures.
- Updated Playwright examples on the File I/O page with a more streamlined approach for uploads and downloads.
<Update label="January 9" tags={["Product", "Docs"]}>
- Introduced a new Hobbyist plan, which provides affordable access to features like session replays, uploading and downloading files, and using custom Chrome extensions.
- Updated the Gemini Computer Use template to use Stagehand V3, resolving compatibility issues.
- Added support for Actor and Thinker OpenAGI models, with guidance on when to use each approach.
- Added new Claude Agent SDK templates for TypeScript and Python that demonstrate browser automation using Kernel's Playwright execution API.
- Added documentation for the OpenAGI Lux integration using the
kernel createmethod, including examples for bothAsyncDefaultAgentandTaskerAgent. - Improved file I/O documentation with code examples for uploading and downloading files from remote browsers.
<Update label="December 19" tags={["Product"]}>
- Added a new
kernel mcp installcommand to the Kernel CLI that automatically configures the Kernel MCP server for AI development tools like Cursor, Claude, and Visual Studio Code. - Added a new Python template to the Kernel CLI for OpenAGI's Lux computer use model, supporting both AsyncDefaultAgent and TaskerAgent with Kernel browser session management.
- Improved CLI performance when looking up browsers by using a direct API call instead of fetching the full list of browsers.
- Fixed bug where headless browsers started with no pages. Headless browsers now initialize with an initial page.
- Fixed bug where replay start and end times were not being returned by the API.
<Update label="December 12" tags={["Product", "Docs"]}>
- Refreshed our Vercel template with an enhanced UI and AI agent example
- Deprecated the "persistent" feature from browsers in favor of using extended
timeout_secondswith Profiles; addednamefield to browsers for easier identification - Unified browser creation tools by porting Create Kernel App functionality into the Kernel CLI
- Improved replay videos to include full video length metadata, enabling timestamp navigation and deep linking
- Added OpenAGI integration guide to the Computer Use integrations section
<Update label="December 5" tags={["Product", "Docs"]}>
- Added option to include ephemeral and deleted browsers when listing sessions via API
- Updated the maximum timeout available from 24 hours to 72 hours of no CDP activity
- Updated the maximum async invocation duration from 15 minutes to 1 hour
- Improved error messaging when invalid invocation IDs are provided
- Stagehand v3: Added code example for using Stagehand v3 with Kernel browsers
- Vercel AI SDK integration: Expanded Vercel integration documentation for the
@onkernel/ai-sdkpackage - Live view: Added code example showing how to embed browser live views in an iFrame
- CAPTCHA handling in stealth mode: Added documentation on CAPTCHA handling behavior with Cloudflare challenges