Claude in Chrome: What the Browser Agent Can Do (2026)
Vorec Team · 2026-10-06 · About 7 min read
Most AI assistants tell you which button to press. Claude in Chrome presses it. Anthropic's browser extension reads the page you're on and, with your permission, clicks, types, navigates and fills in forms.
That changes who does the work in a browser, and it raises questions about safety and permissions. It also matters to anyone who documents web software, because an agent that can operate a browser can also walk through a workflow while it's being recorded.
This page sets out what Anthropic's documentation says Claude in Chrome does today, what controls come with it, what Anthropic warns about, and how it relates to recording tutorials.
Checked 6 October 2026 against Anthropic's own pages: Get started with Claude in Chrome, the permissions guide, Use Claude in Chrome safely, admin controls, the release notes and the Claude Code docs on using Claude Code with Chrome. We didn't install the extension for this article, so this describes Anthropic's documentation, not our own test. The header image is a screenshot of Claude Support's "Get started with Claude in Chrome" page, captured 6 October 2026; it shows documentation, not the extension in use.
What It Does
According to Anthropic's getting-started page, when you open the Claude side panel, Claude "sees what's on the page and can act on it": reading, clicking, typing, navigating and filling forms. The page compares this to the way a person would use the browser.
The documented features include:
- Multi-tab work, with the tabs Claude opens grouped and colour-coded so you can tell them from your own
- Shortcuts, including scheduled ones, for tasks you repeat
- Workflow recording in the classic side panel: you record the steps yourself and Claude learns to repeat them
- Console inspection, file uploads and visual page context
To see the page, Claude takes screenshots of the tabs it's working in. The extension's permission list explains that its debugger access is what lets it control the browser, "clicking buttons, typing text, and taking screenshots".
Who Can Use It
Anthropic's getting-started page says Claude in Chrome is available on all paid plans: Pro, Max, Team and Enterprise. It works in Claude's Cowork and Claude Code, and as a beta in the Chrome side panel.
A few details from the same page:
- On Max and Team, the side panel runs as a Cowork session; that experience is rolling out to Pro. On Enterprise it depends on what the admin has enabled.
- The extension works in Chrome, not on mobile and not in other Chromium-based browsers.
- Workflow recording is in the classic side panel only. It isn't available in the Cowork side-panel session.
How It Got Here
From Anthropic's release notes:
| Date | What changed |
|---|---|
| 26 August 2025 | Experimental Chrome extension introduced |
| 16 September 2025 | Expanded to 10,000 Max users, with longer workflows and reusable shortcuts |
| 29 September 2025 | Remaining Max waitlist admitted; multi-tab support |
| 24 November 2025 | Beta for all Max subscribers; scheduled tasks |
| 18 December 2025 | Beta for all paid plans, including Pro, Team and Enterprise; Claude Code integration, workflow recording and admin controls |
The getting-started article currently shows a date of 26 August 2026. That's the page's own date, not the launch; the launch entry in the release notes is 26 August 2025.
The Three Permission Modes
Anthropic's permissions guide describes three ways to let Claude act:
| Mode | What happens |
|---|---|
| Manual approval | In the classic side panel, Claude first proposes a plan, naming the sites it will visit and the actions it will take, for you to review or change before it starts. In the Cowork side panel there's no up-front plan; Claude asks for approval before each action. |
| Automatically approve | Claude keeps working without stopping at each step, and reviews each action for safety, such as checks for data exfiltration or prompt injection. This is the default in the Cowork side panel. |
| Skip all approvals | Claude doesn't pause, and nothing checks its actions automatically. Anthropic says to use it only when you completely trust every action and tool involved. |
Site access can be granted for one action or kept, and revoked later in settings. The guide separates two lists. Regardless of mode, Claude needs your explicit permission to change permission settings, grant authorizations or enter potentially sensitive information into a website. And regardless of permissions, it's prohibited from making purchases or financial transactions, creating accounts, handling sensitive card or ID data, downloading files from untrusted sources and making permanent deletions, among other things.
The prompts aren't identical everywhere. Classic, Cowork and Claude Code each handle approval a little differently.
What Anthropic Warns About
Anthropic's safety page names prompt injection as a central risk. That's text on a webpage, email or document written to steer the agent into doing something you didn't ask for. Anthropic says it runs classifiers on incoming content and actions, and that those defences can fail. A malicious page could still cause unintended actions or leak data.
Two other points from the same page:
- Whatever is visible in a tab Claude is working in ends up in its screenshots and becomes part of the conversation. Anthropic says Claude can't filter sensitive content out automatically.
- Anthropic recommends sticking to trusted sites, limiting site access, and using a separate browser profile to keep sensitive accounts apart.
The admin-controls page adds that zero data retention isn't supported for Claude in Chrome. Team and Enterprise owners can turn the extension on or off for the organisation and set site allowlists and blocklists.
None of these controls is a guarantee. Treat permission prompts and classifiers as risk reduction, and keep a person in the loop for anything that matters.
Recording: Workflows, GIFs and Tutorials
"Recording" means three different things around Claude in Chrome, and they're easy to mix up.
1. Recording a workflow (classic side panel). You do the steps; Claude learns them and repeats them later as a shortcut. The recording teaches the agent. It doesn't produce a video for people to watch.
2. Recording a demo GIF (Claude Code). The Claude Code documentation includes a "Record a demo GIF" feature. You ask Claude to record a browser interaction sequence, and it saves the result as a GIF. The docs warn that the recording captures everything visible in the browser, including account details on logged-in pages, so you should review it before sharing. Anthropic documents this through the Claude Code integration. We didn't find it described as a control in every side panel, and we didn't establish when it launched.
3. Recording a narrated tutorial. Anthropic's documentation doesn't describe either feature as producing a voiced, edited walkthrough. A GIF has no audio track, and a recorded workflow is instructions for the agent. A narrated tutorial is a separate job.
This is our reading of the docs, not Anthropic's framing: a browser agent is useful for doing the workflow consistently, and a tutorial tool is useful for explaining it to people.
Where Vorec Fits
Agent-driven recording is part of how Vorec works, through its own macOS recorder and CLI rather than a browser extension. The agent plans the walkthrough and drives the capture; see Claude Code demo videos for that workflow.
Vorec records your screen. It has its own macOS recorder, and an AI agent can drive it for you through the Claude Code plugin, capturing locally for you to review before anything is uploaded. It then drafts narration matched to the workflow it captured and generates the voiceover, so nothing is spoken into a microphone. In the editor you can add smooth cursor motion, cursor-follow zoom and click-based auto-zoom, and freeze-sync can hold a frame to give an explanation time to finish. You can also generate a written step-by-step guide from the same capture, with annotatable screenshots. Narration regenerates in supported languages on eligible plans, without re-recording. You can upload an existing recording instead if you already have one.
The same caution applies as with any browser agent. Whatever's on screen ends up in the recording, so use a clean test account and check the take before you upload. Our screen-recording privacy checklist covers it.
Plans start at $9 a month, after a 7-day trial with 100 credits and no credit card. Trial includes up to 3 projects; exports carry a watermark. See Vorec pricing.
Quick Answers
What is Claude in Chrome?
Anthropic's Chrome extension that lets Claude read webpages and act on them, clicking, typing, navigating and filling forms, with permission controls.
Is Claude in Chrome free?
No. Anthropic's getting-started page lists it for paid plans: Pro, Max, Team and Enterprise.
Is Claude in Chrome safe to use?
Anthropic documents permission modes, safety checks on actions and admin controls, but its safety page says defences against prompt injection can fail. It recommends trusted sites, limited access and a separate browser profile for sensitive accounts.
Can Claude in Chrome record a video?
The Claude Code integration documents recording a browser interaction as a GIF. The classic side panel can record a workflow for Claude to repeat. Anthropic's docs don't describe either as producing a narrated video.
Related: Computer-use agents explained, Playwright MCP, AI agents and screen recording and What are agent skills?.
Want the recording to narrate itself? Record with Vorec, or upload one you already have, and get a narrated tutorial plus a written guide. Start free.