Official agent skill

Derive API Client from Browser Traffic

by vercel-labs in vercel-labs/agent-browser

Records a site's browser traffic into a HAR file, then builds a standalone client or CLI that calls its internal endpoints directly with no browser.

OfficialApache-2.0Auto-check passedDevelopment

Install Derive API Client from Browser Traffic

skills CLI
$ npx skills add vercel-labs/agent-browser --skill derive-client -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vercel-labs/agent-browser derive-client --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vercel-labs/agent-browser.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skill-data/derive-client .claude/skills/derive-client && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
derive-client
GitHub stars
44k
Used in
2 other repos
Token cost
~1.3k tokens
SKILL.md length
536 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
Apache-2.0

At a glance

Records a site's browser traffic into a HAR file, then builds a standalone client or CLI that calls its internal endpoints directly with no browser.

  • Works in 5 steps: Record → Identify endpoints → Extract shapes and auth → …
  • Turning a site with no public API into a scriptable CLI
  • SKILL.md covers Workflow, 1. Record, 2. Identify endpoints and 3. Extract shapes and auth, plus 3 more sections
  • Calls jq

What it does

The idea is that driving a browser suits the first visit to a site and not the hundredth. You record the site's network traffic once with agent-browser's HAR capture, which embeds text response bodies such as JSON, HTML and JS by default, so endpoint shapes can be studied offline afterward. The workflow runs Record, Identify, Extract and then further steps; the excerpt shows the first three.

While recording, you exercise every flow the client should support and repeat each at least twice with different inputs, so that comparing the recorded URLs shows which parts are parameters. Log in before starting capture so credentials stay out of the recording. Flags control whether binary bodies are embedded, with a per-body cap of 2 MB. jq queries then pick out the JSON API calls, skipping telemetry paths, third-party analytics domains and static assets, and pull the request shapes, response schemas and auth material for each real endpoint.

When your agent uses it

  • Turning a site with no public API into a scriptable CLI
  • Recording browser traffic to study a site's endpoints offline
  • Replacing repeated browser automation with direct HTTP calls
  • Separating the real API calls from analytics noise in a recording

Example prompts

  • “Derive a CLI for this site from a recorded session of searching and opening detail pages.”
  • “Record the network requests while I paginate the results, then list the real API endpoints.”
  • “Reverse engineer this dashboard's API so we can stop driving the browser each time.”

Requirements

  • The agent-browser CLI
  • jq for querying the HAR file
  • Access to the target site, with a login if it needs one
  • Pre-approved tools (allowed-tools): Bash(agent-browser:*), Bash(npx agent-browser:*)

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Record
  2. Identify endpoints
  3. Extract shapes and auth
  4. Generate the client
  5. Verify

What it can do on your machine

Read from SKILL.md and the folder at commit 0207911. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(agent-browser:*)
    • Bash(npx agent-browser:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Derive API Client from Browser Traffic loads about 1.3k tokens when it runs. Until then it costs about 125 tokens; SKILL.md has 536 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~125
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vercel-labs/agent-browser at commit 0207911, republished under its Apache-2.0 licence (© vercel-labs). 536 words, ~1,343 tokens.

Download SKILL.mdSave it as .claude/skills/derive-client/SKILL.md (or your agent's skills folder).
name
derive-client
description
Reverse-engineer a website's internal API by recording browser traffic into a HAR file, then generate a standalone client or CLI that calls the endpoints directly, with no browser needed after the first recording. Use when asked to "derive a client", "build a CLI for <site>", "reverse engineer this site's API", "record network requests", "turn this site into an API", or when the same site will be automated repeatedly and direct HTTP calls would beat driving the browser every time.
allowed-tools
Bash(agent-browser:*), Bash(npx agent-browser:*)

Derive an API client from a recorded session

Driving a browser is the right tool for the first visit and the wrong tool for the hundredth. This skill records a site's network traffic once while you use it, then turns the captured requests into a standalone client (script, CLI, or library) that talks to the site's internal API directly.

The recording alone contains everything needed: agent-browser embeds text response bodies (JSON/HTML/JS) in the HAR by default, so endpoint shapes can be studied offline after the browser is closed.

Workflow

1. Record     Start HAR capture, drive the flows you want in the client
2. Identify   Find the real API endpoints among the noise
3. Extract    Pull request shapes, response schemas, and auth material
4. Generate   Write the client, one function per flow
5. Verify     Call every endpoint for real before declaring done

1. Record

bash
agent-browser network har start          # embeds text response bodies by default
# ... drive the site: search, open a detail page, paginate, etc. ...
agent-browser network har stop /tmp/site.har
  • Exercise every flow the client should support, and run each one at least twice with different inputs (two search terms, two detail pages). Diffing the recorded URLs reveals which parts are parameters.
  • If the site needs login, log in before starting the HAR so credentials don't land in the recording unnecessarily. The session cookies are exported separately in step 3.
  • --content all embeds binary bodies too (base64); --content none disables embedding. Per-body cap is 2 MB.

While the session is still open, agent-browser network requests and network request <id> give the same data interactively — but only the HAR survives navigation and browser close, so prefer it for anything multi-page.

2. Identify endpoints

Query the HAR with jq:

bash
# All JSON API calls: method, URL, status
jq -r '.log.entries[]
  | select(.response.content.mimeType | test("json"))
  | "\(.request.method) \(.response.status) \(.request.url)"' /tmp/site.har

Ignore analytics and infrastructure noise: telemetry endpoints (/collect, /track, /beacon, /log), third-party domains (google-analytics, segment, sentry, datadog, intercom, hotjar), and static assets. The real API is usually first-party, JSON, and correlates with the actions you performed.

3. Extract shapes and auth

bash
# Full detail for one endpoint: request headers, POST body, response body
jq '.log.entries[] | select(.request.url | test("api/search"))
  | {request: {method: .request.method, headers: .request.headers,
     postData: .request.postData.text},
     response: .response.content.text}' /tmp/site.har
  • Response schema: read .response.content.text — this is the real payload, use it to derive types.
  • Auth: compare request headers across endpoints. Look for authorization, cookie, x-csrf-token, x-api-key, and site-specific x-* headers. Replay only the ones that matter — test by omission in step 5.
  • Cookies: export the live session with agent-browser cookies get --json > cookies.json for the client to load at runtime. Never hardcode cookie values into generated source.
Show full SKILL.md (220 more words)Show less

4. Generate the client

  • One function per recorded flow (search(query), getItem(id)), typed from the observed response bodies.
  • Auth material (cookies, bearer tokens) loads from a file or environment variable, with a clear error telling the user to re-run the browser login when it expires.
  • Reproduce the headers the API actually requires — some sites 403 without a matching user-agent, referer, or x-requested-with.
  • Keep pagination, sort, and filter parameters that appeared in the recorded query strings as function options.

5. Verify

Call every generated function against the live API and compare the response shape with the recording. Common failures:

SymptomCauseFix
401/403Expired or missing sessionRe-login via agent-browser, re-export cookies
403/419 on writesCSRF token is per-session or per-formFetch the token endpoint first, or keep that flow browser-driven
Works then breaksSigned/expiring request paramsFall back to the browser for that step; derive the rest
Different shape than HARA/B tests or geo-dependent responsesRe-record and treat the union as optional fields

Caveats

  • Internal APIs are unversioned and change without notice — keep the HAR so the client can be re-derived.
  • Respect the site's terms of service and rate limits; add delays for bulk fetching.
  • HAR files contain live session credentials (cookies, tokens, POST bodies). Treat them like secrets: keep them out of version control and delete them when done.

© vercel-labs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skill-data/derive-client of vercel-labs/agent-browser.

Open the folder on GitHubat commit 0207911

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in vercel-labs/agent-browser, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Derive API Client from Browser Traffic next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Derive API Client from Browser Traffic compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Derive API Client from Browser Traffic this skillvercel-labs/agent-browser44k2 repos~1.3kAutomated safety check: PassApache-2.0
OpenCLI Adapter Authorjackwener/OpenCLI30k1 repos~3.4kAutomated safety check: PassApache-2.0
Firecrawl Interact Integrationfirecrawl/firecrawl190k1 repos~731Automated safety check: PassISC
OpenCLI Adapter Autofixjackwener/OpenCLI30k1 repos~3.2kAutomated safety check: PassApache-2.0
Kimi WebbridgeMoonshotAI/kimi-code7.8k—~3.6kAutomated safety check: PassMIT
Readme GuidelinesCelestoAI/celesto1k—~763Automated safety check: PassApache-2.0

Similar skills

  • OpenCLI Adapter Author

    jackwener/OpenCLI

    Walks through writing an OpenCLI adapter for a new site or a new command on an existing one, from first recon and field decoding to coding and verification.

    30k GitHub starsUsed in 1 repo~3.4k tokens
    DevelopmentAuto-check passed
  • Guides adding Firecrawl's /interact endpoint to product code for pages that need clicks, forms, pagination or logged-in flows beyond plain scraping.

    190k GitHub starsUsed in 1 repo~731 tokens
    Data & AnalyticsAuto-check passed
  • OpenCLI Adapter Autofix

    jackwener/OpenCLI

    Repairs a broken OpenCLI site adapter after a command fails: collects a trace, patches only the adapter, retries, and files an upstream GitHub issue once fixed.

    30k GitHub starsUsed in 1 repo~3.2k tokens
    DevelopmentAuto-check passed
  • Kimi Webbridge

    MoonshotAI/kimi-code

    Kimi Browser Extension(Kimi 浏览器扩展,原 Kimi WebBridge)lets AI control the user's real browser — navigate, click, type, read, screenshot, and interact with any website using the user's actual login…

    7.8k GitHub stars~3.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Readme Guidelines

    CelestoAI/celesto

    Review or write README content for open-source projects. An agent skill from CelestoAI/celesto.

    1k GitHub stars~763 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Bun 1.4 Builtins Guide

    code-yeongyu/senpi

    Points the agent at Bun 1.4 built-in APIs before it installs an npm package, so image, browser, markdown, cron, PTY and test work uses what Bun already ships.

    472 GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed

More from vercel-labs/agent-browser

All 10 skills in this repo
  • Agent Browser CLI

    vercel-labs/agent-browser

    Official

    Browser automation CLI for AI agents. Use when the user needs to interact with websites, including navigating pages, filling forms, clicking buttons, taking…

    44k GitHub starsUsed in 24 repos~864 tokens
    Auto-check passed
  • Dogfood Exploratory QA

    vercel-labs/agent-browser

    Official

    Explores a web app with the agent-browser CLI to find bugs and UX problems, then writes a report with screenshots, repro videos and step-by-step reproduction for each issue.

    44k GitHub starsUsed in 8 repos~2.7k tokens
    Auto-check passed
  • Electron App Automation

    vercel-labs/agent-browser

    Official

    Automates Electron desktop apps such as VS Code, Slack or Discord by connecting agent-browser to their Chrome DevTools Protocol port.

    44k GitHub starsUsed in 5 repos~1.7k tokens
    Auto-check passed
  • Slack Browser Automation

    vercel-labs/agent-browser

    Official

    Drives the Slack web app with the agent-browser CLI to check unread channels, search, read channel details and extract information, with screenshots as evidence.

    44k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Core Guide for agent-browser

    vercel-labs/agent-browser

    Official

    Core usage guide for the agent-browser CLI: the snapshot-and-ref workflow for navigating, clicking, filling forms, extracting data and running parallel sessions.

    44k GitHub starsUsed in 4 repos~9.5k tokens
    Auto-check passed
  • WebMCP Tool Generator

    vercel-labs/agent-browser

    Official

    Builds and validates experimental WebMCP tools that expose a web page's real workflows to agents, with a manifest, init script and evals compared against accessibility-tree automation.

    44k GitHub starsUsed in 1 repo~752 tokens
    Auto-check passed

Questions about Derive API Client from Browser Traffic

What does Derive API Client from Browser Traffic do?

Records a site's browser traffic into a HAR file, then builds a standalone client or CLI that calls its internal endpoints directly with no browser. The idea is that driving a browser suits the first visit to a site and not the hundredth. You record the site's network traffic once with agent-browser's HAR capture, which embeds text response bodies such as JSON, HTML and JS by default, so endpoint shapes can be studied offline afterward.

When should I use Derive API Client from Browser Traffic?

Derive API Client from Browser Traffic fits situations like: turning a site with no public API into a scriptable CLI; recording browser traffic to study a site's endpoints offline; replacing repeated browser automation with direct HTTP calls; separating the real API calls from analytics noise in a recording.

How do I install Derive API Client from Browser Traffic in Claude Code?

Run `npx skills add vercel-labs/agent-browser --skill derive-client -a claude-code`. Or copy the skill folder (skill-data/derive-client in vercel-labs/agent-browser) into .claude/skills/derive-client in your project. Claude Code loads it when a task matches its description.

How do I install Derive API Client from Browser Traffic in Codex?

Run `npx skills add vercel-labs/agent-browser --skill derive-client -a codex`. Or copy the skill folder (skill-data/derive-client in vercel-labs/agent-browser) into .agents/skills/derive-client in your project. Codex loads it when a task matches its description.

Can I use Derive API Client from Browser Traffic in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vercel-labs/agent-browser --skill derive-client -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/derive-client, .gemini/skills/derive-client, .github/skills/derive-client and .opencode/skills/derive-client in your project.

What does Derive API Client from Browser Traffic need to run?

Going by SKILL.md and its folder, Derive API Client from Browser Traffic needs the command-line tools its instructions call (jq). Our summary lists: The agent-browser CLI; jq for querying the HAR file; Access to the target site, with a login if it needs one. Its frontmatter pre-approves these tools: Bash(agent-browser:*), Bash(npx agent-browser:*).

Does Derive API Client from Browser Traffic access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Derive API Client from Browser Traffic safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Derive API Client from Browser Traffic use?

Derive API Client from Browser Traffic is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Derive API Client from Browser Traffic use?

About 1.3k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Derive API Client from Browser Traffic?

Skills that share tags, products or a category with Derive API Client from Browser Traffic: OpenCLI Adapter Author (jackwener/OpenCLI, 30k stars), Firecrawl Interact Integration (firecrawl/firecrawl, 190k stars), OpenCLI Adapter Autofix (jackwener/OpenCLI, 30k stars) and Kimi Webbridge (MoonshotAI/kimi-code, 7.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Derive API Client from Browser Traffic?

vercel-labs (a GitHub organization, an official publisher) maintains it in vercel-labs/agent-browser, which has 43,634 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 8, 2026.

Source: vercel-labs/agent-browser on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.