PuppyIP Resource Center
AI Development & Automation 6 min read Published 2026-10-08

Claude's browser and computer SDK beta: the tool loop is handled, but do you still need a driver?

Building your own Claude browser or desktop agent now takes less tool-loop plumbing. Anthropic's Python and TypeScript SDKs have beta toolset classes that dispatch calls, run the checks you configure and construct results. You still supply the browser or desktop and the driver that actually performs actions. Start with one small task in an isolated environment.

Claude SDK Browser Use Computer Use Python TypeScript

Service eligibility and regional restrictions

PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.

Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.

Key Takeaways

  • The October 7 addition is a beta SDK wrapper, rather than a complete application that takes over your computer after installation. It is also separate from a hosted browser service.
  • Implement methods such as navigation, screenshots and clicks; the SDK routes model tool calls to them. Members you leave unimplemented are generally sent to the API as disabled.
  • URL policies, file policies and approval callbacks work only when configured as documented. Request interception, network isolation and the browser host remain your responsibility.
  • Check what the driver actually did before expanding the task. With eager execution during streaming, an interrupted response does not mean an action that already started was undone.

Which layer does the SDK take off your hands?

Anthropic's October 7, 2026 release notes announce browser and computer toolset classes in the Python and TypeScript SDKs, in beta. Developers can subclass them to connect their own automation methods to Claude's tool calls without assembling every tool result from scratch.

The SDK dispatches calls, runs supplied policies, invokes approval functions and constructs tool_result responses. Use the official tool runner or your own loop. These are development components: the official documentation explicitly says they do not include a browser, desktop, ready-made driver or default URL policy.

If you already use Playwright, what must you implement?

Wrap your browser automation in a driver, implement methods such as navigate, screenshot and left_click as needed, and provide browser state reports. The backend in the official example is a wrapper supplied by the caller. It is not Playwright or Chromium installed for you by the SDK.

Pass the driver instance as one of the tools. Unimplemented members are generally marked disabled; configs can adjust member switches. Avoid enabling actions your driver cannot perform merely to make the request look complete. The official minimal CDP example is also explicitly described as unsuitable for production.

Should you choose the browser or computer toolset?

For tasks confined to browser navigation, reading pages, managing tabs or taking screenshots, consider the browser toolset first. It has browser state reports and accepts URL and file policies. Evaluate the computer toolset when you need the entire desktop; it does not have the browser toolset's URL policy or state reports.

A computer driver must convert between screenshot dimensions and display coordinates and check whether clicks, scrolling or keystrokes can be executed. The SDK does not resize screenshots for you or turn out-of-bounds arguments into safe values. Adding an SDK wrapper therefore does not establish that an existing desktop driver is compatible.

Does a URL policy control every network request?

Without a supplied URL policy, the SDK does not check navigation URLs. With one, it checks only the URL passed to navigate. Link clicks, redirects and requests made by the page still require driver interception and network rules. A URL allowlist is not complete network isolation.

The official recommendation is a separate, limited-permission container or virtual machine for each browser session, with access to private networks, loopback and cloud metadata restricted. File policies inspect the filesystem of the SDK process. Upload paths for a remote browser need separate controls on the machine that actually hosts it.

Does an approval callback automatically show a human confirmation dialog?

No. You supply the confirm function, and the SDK executes or rejects a call based on its return value. Your application also implements the human approval interface. Sending a message or making a purchase may consist of ordinary clicks and text input, so approvals cannot focus only on tools explicitly named payment or send.

Approval uses the most recently reported page state, which may subsequently change. The official documentation also warns that inputs modified in the execute extension hook are not checked again by the SDK. Your implementation must keep the approved target, action and inputs consistent.

What should you verify before expanding the task?

For example, start by asking an agent to open a known public reference page in an isolated browser and return its title and a screenshot. Check the navigation result, active tab and source before adding clicks or file capabilities. This is integration advice, not an installation or execution test performed by PuppyIP; a successful demonstration does not prove that real account workflows are ready.

After a tool fails, the official runner skips subsequent calls to the same toolset in that turn. A custom loop must also respond correctly to those unexecuted calls. ToolError can be returned as an error result while the loop continues; a ToolsetUsageError, such as configuration misuse, stops execution and returns control to the caller. These failures should not all be treated as retryable.

With run_tools_eagerly enabled, calls may begin before the model response finishes. Actions already started may still occur if output then reaches a limit or the loop exits early. Check the actual outcome: stopping consumption of the response does not undo browser or desktop actions.

Sources

Frequently Asked Questions

What is the minimum Python or TypeScript package version with these classes?

The review behind this article confirmed the current official SDK documentation and the October 7 release entry, but did not independently establish minimum versions for either package. Check your installed package and exported classes against the linked SDK guide. A version number from another SDK release date should not be presented as the minimum for this addition.

Can browser use and computer use be included in the same request?

Yes. Supply both instances and the runner dispatches calls using toolset_name. A failure in one toolset skips its later calls in that turn; it does not automatically stop the other toolset. Custom loops must maintain failure state separately for each.

Do these host checks still matter with a hosted browser service?

Check the service's network reach, isolation and recording retention terms. A local file-path policy in the SDK process does not automatically protect the remote browser's filesystem. Keep connection URLs, service keys and private paths in raw exceptions out of model inputs and logs.