Claude in Chrome: What the Browser Agent Can Do (2026)

Vorec Team · 2026-10-06 · About 7 min read

Most AI assistants tell you which button to press. Claude in Chrome presses it. Anthropic's browser extension reads the page you're on and, with your permission, clicks, types, navigates and fills in forms.

That changes who does the work in a browser, and it raises questions about safety and permissions. It also matters to anyone who documents web software, because an agent that can operate a browser can also walk through a workflow while it's being recorded.

This page sets out what Anthropic's documentation says Claude in Chrome does today, what controls come with it, what Anthropic warns about, and how it relates to recording tutorials.

Checked 6 October 2026 against Anthropic's own pages: Get started with Claude in Chrome, the permissions guide, Use Claude in Chrome safely, admin controls, the release notes and the Claude Code docs on using Claude Code with Chrome. We didn't install the extension for this article, so this describes Anthropic's documentation, not our own test. The header image is a screenshot of Claude Support's "Get started with Claude in Chrome" page, captured 6 October 2026; it shows documentation, not the extension in use.

What It Does

According to Anthropic's getting-started page, when you open the Claude side panel, Claude "sees what's on the page and can act on it": reading, clicking, typing, navigating and filling forms. The page compares this to the way a person would use the browser.

The documented features include:

To see the page, Claude takes screenshots of the tabs it's working in. The extension's permission list explains that its debugger access is what lets it control the browser, "clicking buttons, typing text, and taking screenshots".

A browser window with an AI side panel taking actions on a web form

Who Can Use It

Anthropic's getting-started page says Claude in Chrome is available on all paid plans: Pro, Max, Team and Enterprise. It works in Claude's Cowork and Claude Code, and as a beta in the Chrome side panel.

A few details from the same page:

How It Got Here

From Anthropic's release notes:

DateWhat changed
26 August 2025Experimental Chrome extension introduced
16 September 2025Expanded to 10,000 Max users, with longer workflows and reusable shortcuts
29 September 2025Remaining Max waitlist admitted; multi-tab support
24 November 2025Beta for all Max subscribers; scheduled tasks
18 December 2025Beta for all paid plans, including Pro, Team and Enterprise; Claude Code integration, workflow recording and admin controls

The getting-started article currently shows a date of 26 August 2026. That's the page's own date, not the launch; the launch entry in the release notes is 26 August 2025.

The Three Permission Modes

Anthropic's permissions guide describes three ways to let Claude act:

ModeWhat happens
Manual approvalIn the classic side panel, Claude first proposes a plan, naming the sites it will visit and the actions it will take, for you to review or change before it starts. In the Cowork side panel there's no up-front plan; Claude asks for approval before each action.
Automatically approveClaude keeps working without stopping at each step, and reviews each action for safety, such as checks for data exfiltration or prompt injection. This is the default in the Cowork side panel.
Skip all approvalsClaude doesn't pause, and nothing checks its actions automatically. Anthropic says to use it only when you completely trust every action and tool involved.

Site access can be granted for one action or kept, and revoked later in settings. The guide separates two lists. Regardless of mode, Claude needs your explicit permission to change permission settings, grant authorizations or enter potentially sensitive information into a website. And regardless of permissions, it's prohibited from making purchases or financial transactions, creating accounts, handling sensitive card or ID data, downloading files from untrusted sources and making permanent deletions, among other things.

The prompts aren't identical everywhere. Classic, Cowork and Claude Code each handle approval a little differently.

What Anthropic Warns About

Anthropic's safety page names prompt injection as a central risk. That's text on a webpage, email or document written to steer the agent into doing something you didn't ask for. Anthropic says it runs classifiers on incoming content and actions, and that those defences can fail. A malicious page could still cause unintended actions or leak data.

Two other points from the same page:

The admin-controls page adds that zero data retention isn't supported for Claude in Chrome. Team and Enterprise owners can turn the extension on or off for the organisation and set site allowlists and blocklists.

None of these controls is a guarantee. Treat permission prompts and classifiers as risk reduction, and keep a person in the loop for anything that matters.

A permission prompt asking a person to approve an AI agent's next browser action

Recording: Workflows, GIFs and Tutorials

"Recording" means three different things around Claude in Chrome, and they're easy to mix up.

1. Recording a workflow (classic side panel). You do the steps; Claude learns them and repeats them later as a shortcut. The recording teaches the agent. It doesn't produce a video for people to watch.

2. Recording a demo GIF (Claude Code). The Claude Code documentation includes a "Record a demo GIF" feature. You ask Claude to record a browser interaction sequence, and it saves the result as a GIF. The docs warn that the recording captures everything visible in the browser, including account details on logged-in pages, so you should review it before sharing. Anthropic documents this through the Claude Code integration. We didn't find it described as a control in every side panel, and we didn't establish when it launched.

3. Recording a narrated tutorial. Anthropic's documentation doesn't describe either feature as producing a voiced, edited walkthrough. A GIF has no audio track, and a recorded workflow is instructions for the agent. A narrated tutorial is a separate job.

This is our reading of the docs, not Anthropic's framing: a browser agent is useful for doing the workflow consistently, and a tutorial tool is useful for explaining it to people.

Where Vorec Fits

Agent-driven recording is part of how Vorec works, through its own macOS recorder and CLI rather than a browser extension. The agent plans the walkthrough and drives the capture; see Claude Code demo videos for that workflow.

Vorec records your screen. It has its own macOS recorder, and an AI agent can drive it for you through the Claude Code plugin, capturing locally for you to review before anything is uploaded. It then drafts narration matched to the workflow it captured and generates the voiceover, so nothing is spoken into a microphone. In the editor you can add smooth cursor motion, cursor-follow zoom and click-based auto-zoom, and freeze-sync can hold a frame to give an explanation time to finish. You can also generate a written step-by-step guide from the same capture, with annotatable screenshots. Narration regenerates in supported languages on eligible plans, without re-recording. You can upload an existing recording instead if you already have one.

The same caution applies as with any browser agent. Whatever's on screen ends up in the recording, so use a clean test account and check the take before you upload. Our screen-recording privacy checklist covers it.

Plans start at $9 a month, after a 7-day trial with 100 credits and no credit card. Trial includes up to 3 projects; exports carry a watermark. See Vorec pricing.

Quick Answers

What is Claude in Chrome?

Anthropic's Chrome extension that lets Claude read webpages and act on them, clicking, typing, navigating and filling forms, with permission controls.

Is Claude in Chrome free?

No. Anthropic's getting-started page lists it for paid plans: Pro, Max, Team and Enterprise.

Is Claude in Chrome safe to use?

Anthropic documents permission modes, safety checks on actions and admin controls, but its safety page says defences against prompt injection can fail. It recommends trusted sites, limited access and a separate browser profile for sensitive accounts.

Can Claude in Chrome record a video?

The Claude Code integration documents recording a browser interaction as a GIF. The classic side panel can record a workflow for Claude to repeat. Anthropic's docs don't describe either as producing a narrated video.

Related: Computer-use agents explained, Playwright MCP, AI agents and screen recording and What are agent skills?.

Want the recording to narrate itself? Record with Vorec, or upload one you already have, and get a narrated tutorial plus a written guide. Start free.

← Back to blog