Access Protected Vercel Deployment
vercel/vercel-plugin
Access and test Vercel deployments protected by Vercel Authentication, SSO, or Deployment Protection.
Opens Vercel deployments behind Deployment Protection in agent-browser, using a short-lived OIDC token instead of a static bypass secret or a public exception.
$ npx skills add vercel-labs/agent-browser --skill protected-vercel-deployments -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vercel-labs/agent-browser protected-vercel-deployments --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vercel-labs/agent-browser.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skill-data/protected-vercel-deployments .claude/skills/protected-vercel-deployments && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "protected-vercel-deployments" agent skill from https://github.com/vercel-labs/agent-browser/tree/main/skill-data/protected-vercel-deployments into .claude/skills/protected-vercel-deployments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protected-vercel-deployments", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vercel-labs/agent-browser/tree/main/skill-data/protected-vercel-deploymentsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vercel-labs/agent-browser --skill protected-vercel-deployments -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vercel-labs/agent-browser protected-vercel-deployments --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vercel-labs/agent-browser.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skill-data/protected-vercel-deployments .agents/skills/protected-vercel-deployments && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "protected-vercel-deployments" agent skill from https://github.com/vercel-labs/agent-browser/tree/main/skill-data/protected-vercel-deployments into .agents/skills/protected-vercel-deployments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protected-vercel-deployments", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vercel-labs/agent-browser --skill protected-vercel-deployments -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vercel-labs/agent-browser protected-vercel-deployments --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vercel-labs/agent-browser.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skill-data/protected-vercel-deployments .cursor/skills/protected-vercel-deployments && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "protected-vercel-deployments" agent skill from https://github.com/vercel-labs/agent-browser/tree/main/skill-data/protected-vercel-deployments into .cursor/skills/protected-vercel-deployments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protected-vercel-deployments", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vercel-labs/agent-browser.git --path skill-data/protected-vercel-deployments--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vercel-labs/agent-browser --skill protected-vercel-deployments -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vercel-labs/agent-browser protected-vercel-deployments --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vercel-labs/agent-browser.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skill-data/protected-vercel-deployments .gemini/skills/protected-vercel-deployments && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "protected-vercel-deployments" agent skill from https://github.com/vercel-labs/agent-browser/tree/main/skill-data/protected-vercel-deployments into .gemini/skills/protected-vercel-deployments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protected-vercel-deployments", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vercel-labs/agent-browser protected-vercel-deploymentsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vercel-labs/agent-browser --skill protected-vercel-deployments -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vercel-labs/agent-browser.git skills-src && mkdir -p .github/skills && cp -r skills-src/skill-data/protected-vercel-deployments .github/skills/protected-vercel-deployments && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "protected-vercel-deployments" agent skill from https://github.com/vercel-labs/agent-browser/tree/main/skill-data/protected-vercel-deployments into .github/skills/protected-vercel-deployments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protected-vercel-deployments", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vercel-labs/agent-browser --skill protected-vercel-deployments -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vercel-labs/agent-browser protected-vercel-deployments --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vercel-labs/agent-browser.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skill-data/protected-vercel-deployments .opencode/skills/protected-vercel-deployments && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "protected-vercel-deployments" agent skill from https://github.com/vercel-labs/agent-browser/tree/main/skill-data/protected-vercel-deployments into .opencode/skills/protected-vercel-deployments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protected-vercel-deployments", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
protected-vercel-deploymentsOpens Vercel deployments behind Deployment Protection in agent-browser, using a short-lived OIDC token instead of a static bypass secret or a public exception.
When a preview or production URL redirects to a Vercel login page or returns a protection 401 or 403, this skill gets the agent through using your existing Vercel identity and a short-lived OIDC token. It rules out disabling Deployment Protection, making the deployment public or asking for a static bypass secret first.
For a preview of the same project, a local development token works through the default Trusted Sources self-access rule. The agent confirms the identity with vc whoami, requires Vercel CLI 53.3.0 or newer because older releases print the token to stderr, mints the token with vc project token and injects it into a named agent-browser session as a header scoped to the target origin. The token is never printed, pasted into source or saved in an env file, and vc link is avoided because it pulls variables into .env.local.
Trusted Sources configuration is needed for a protected production target, a caller from another project or team, customized self-access rules, or a TRUSTED_SOURCES_ENVIRONMENT_MISMATCH error.
Read from SKILL.md and the folder at commit 0207911. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(agent-browser:*)Bash(npx agent-browser:*)Bash(vc:*)Bash(vercel:*)From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
vercelFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use vercel, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
VERCEL_TOKENVERCEL_AUTOMATION_BYPASS_SECRETVERCEL_OIDC_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Protected Vercel Deployments loads about 1.7k tokens when it runs. Until then it costs about 91 tokens; SKILL.md has 804 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
ns also pull development variables into `.env.local` when linking.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from vercel-labs/agent-browser at commit 0207911, republished under its Apache-2.0 licence (© vercel-labs). 804 words, ~1,707 tokens.
.claude/skills/protected-vercel-deployments/SKILL.md (or your agent's skills folder).Use the caller's existing Vercel identity and a short-lived OIDC token. Do not disable Deployment Protection, make the deployment public, or ask for a static bypass secret first.
A local development token for the target project can access that project's protected Preview deployments through the default Trusted Sources self-access rule. No Trusted Sources configuration is normally required.
Confirm the local identity and Vercel CLI version:
vc whoami
vc --versionRequire Vercel CLI 53.3.0 or newer before running vc project token. Versions 50.25.0 through 53.2.x write the token to stderr, so command substitution captures nothing and the credential can appear in logs. If the installed version is older, stop and ask the user to upgrade it. Do not attempt to capture or recover the token from stderr.
Set the target project and scope explicitly. If they cannot be inferred safely, ask the user. In a directory whose existing .vercel/project.json link has been verified against the target, vc project token without a project name is also valid. Do not run vc link merely to get an OIDC token: current Vercel CLI versions also pull development variables into .env.local when linking.
Create a named browser session, mint a development OIDC token with the Vercel CLI, then inject it without printing or persisting it:
export AGENT_BROWSER_SESSION="$(agent-browser session id --scope worktree --prefix vercel-preview)"
export VERCEL_PREVIEW_URL="https://my-app.vercel.app"
export VERCEL_PROJECT="my-app"
export VERCEL_SCOPE="my-team"
(
TOKEN="$(vc project token "$VERCEL_PROJECT" --scope "$VERCEL_SCOPE")"
test -n "$TOKEN"
agent-browser open "$VERCEL_PREVIEW_URL" --headers \
"{\"x-vercel-trusted-oidc-idp-token\":\"$TOKEN\"}"
)
agent-browser snapshot -iContinue the normal workflow in that same session. The header is scoped to the target origin and applies to the document, scripts, styles, fonts, and in-page requests. If the browser session is closed or restarted, repeat the authenticated open command.
Never print the token, paste it into source, or save it in an environment file.
Trusted Sources configuration is needed when:
TRUSTED_SOURCES_ENVIRONMENT_MISMATCH.There is no supported Vercel CLI or public REST API for editing Trusted Sources rules. An authorized human must open the target project's Settings → Deployment Protection → Trusted Sources and add only the required caller and environment mapping. A local token has the development environment, so protected Production access requires development to production.
Stop and hand off the exact rule to the human. Do not use browser automation to change access control, and do not broaden unrelated environment mappings. Retry the authenticated open after the human confirms the rule is saved.
The same-project development to Preview path should run without human intervention when the Vercel CLI is already authenticated and the target project and scope are known. A human is needed only when:
VERCEL_TOKEN; interactive vc login requires the user;53.3.0 and must be upgraded before token minting;vc project protection instead of requiring dashboard interaction.The agent can diagnose each case and state the exact action required, then continue after the user confirms completion.
Send the Vercel-issued token as:
x-vercel-trusted-oidc-idp-token: <VERCEL_OIDC_TOKEN>Do not substitute x-vercel-oidc-token. That header carries workload identity into a Vercel Function; it does not authenticate an inbound request through Deployment Protection.
vercel.com/login: Deployment Protection did not accept the request.TRUSTED_SOURCES_ENVIRONMENT_MISMATCH: the token is valid, but its caller environment cannot reach the target environment.401 or 403 after protection passes: debug the application's own authentication separately.404 on a deliberately missing route: the request passed Deployment Protection and reached the application.Use Protection Bypass for Automation only when OIDC is not viable or the tool cannot send the Trusted Sources header. Enabling or rotating it changes access control, so obtain explicit authorization first. Create a dedicated secret so it can be rotated independently, keep it in an environment variable, and pass it as a header:
vc project protection enable <project> --protection-bypass \
--protection-bypass-secret "$VERCEL_AUTOMATION_BYPASS_SECRET"
agent-browser open "$VERCEL_PREVIEW_URL" --headers \
"{\"x-vercel-protection-bypass\":\"$VERCEL_AUTOMATION_BYPASS_SECRET\",\"x-vercel-set-bypass-cookie\":\"true\"}"The cookie directive creates a reusable _vercel_jwt cookie. Treat saved browser state containing that cookie as a credential.
vercel share CLI command. Shareable Links are intended for people and are not the automation path.vercel curl is useful for HTTP requests, but it cannot render and interact with a page.© vercel-labs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skill-data/protected-vercel-deployments of vercel-labs/agent-browser.
Open the folder on GitHubat commit 0207911
Protected Vercel Deployments next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Protected Vercel Deployments this skillvercel-labs/agent-browser | 44k | — | ~1.7k | Automated safety check: Notes | Apache-2.0 | |
| Access Protected Vercel Deploymentvercel/vercel-plugin | 301 | — | ~1.9k | Automated safety check: Notes | Custom licence | |
| Deployambient-code/platform | 131 | — | ~2.6k | Automated safety check: Pass | MIT | |
| Authvercel/vercel-plugin | 301 | — | ~6.4k | Automated safety check: Notes | Custom licence | |
| Frontmcp Configagentfront/frontmcp | 146 | — | ~7k | Automated safety check: Pass | Apache-2.0 | |
| Nuxt Studiosecondsky/claude-skills | 227 | — | ~2.8k | Automated safety check: Pass | MIT |
vercel/vercel-plugin
Access and test Vercel deployments protected by Vercel Authentication, SSO, or Deployment Protection.
ambient-code/platform
Deploy, update manifests, and troubleshoot the ambient-ui component.
vercel/vercel-plugin
Authentication integration guidance — Clerk (native Vercel Marketplace), Better Auth, Descope, and Auth0 setup for Next.js applications, plus Sign in with Vercel, Vercel Passport, and Vercel KMS.
agentfront/frontmcp
A skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options.
secondsky/claude-skills
This skill should be used when the user asks to "set up Nuxt Studio", "configure Studio OAuth", "deploy Studio to Cloudflare", "add visual editor to Nuxt", "configure studio.domain.com subdomain"…
bytedance/deer-flow
Deploys a project to Vercel with one script and no login, then returns a live preview URL and a claim link for moving the deployment into your own Vercel account.
vercel-labs/agent-browser
Browser automation CLI for AI agents. Use when the user needs to interact with websites, including navigating pages, filling forms, clicking buttons, taking…
vercel-labs/agent-browser
Explores a web app with the agent-browser CLI to find bugs and UX problems, then writes a report with screenshots, repro videos and step-by-step reproduction for each issue.
vercel-labs/agent-browser
Automates Electron desktop apps such as VS Code, Slack or Discord by connecting agent-browser to their Chrome DevTools Protocol port.
vercel-labs/agent-browser
Drives the Slack web app with the agent-browser CLI to check unread channels, search, read channel details and extract information, with screenshots as evidence.
vercel-labs/agent-browser
Core usage guide for the agent-browser CLI: the snapshot-and-ref workflow for navigating, clicking, filling forms, extracting data and running parallel sessions.
vercel-labs/agent-browser
Records a site's browser traffic into a HAR file, then builds a standalone client or CLI that calls its internal endpoints directly with no browser.
Works with
Categories
Opens Vercel deployments behind Deployment Protection in agent-browser, using a short-lived OIDC token instead of a static bypass secret or a public exception. When a preview or production URL redirects to a Vercel login page or returns a protection 401 or 403, this skill gets the agent through using your existing Vercel identity and a short-lived OIDC token. It rules out disabling Deployment Protection, making the deployment public or asking for a static bypass secret first.
Protected Vercel Deployments fits situations like: A Vercel preview URL redirects to a login page during browser testing; A protected deployment returns 401 or 403 from Deployment Protection; testing a protected production deployment from another project or team.
Run `npx skills add vercel-labs/agent-browser --skill protected-vercel-deployments -a claude-code`. Or copy the skill folder (skill-data/protected-vercel-deployments in vercel-labs/agent-browser) into .claude/skills/protected-vercel-deployments in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vercel-labs/agent-browser --skill protected-vercel-deployments -a codex`. Or copy the skill folder (skill-data/protected-vercel-deployments in vercel-labs/agent-browser) into .agents/skills/protected-vercel-deployments in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vercel-labs/agent-browser --skill protected-vercel-deployments -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/protected-vercel-deployments, .gemini/skills/protected-vercel-deployments, .github/skills/protected-vercel-deployments and .opencode/skills/protected-vercel-deployments in your project.
Going by SKILL.md and its folder, Protected Vercel Deployments needs the command-line tools its instructions call (vercel) and credentials named VERCEL_TOKEN, VERCEL_AUTOMATION_BYPASS_SECRET and VERCEL_OIDC_TOKEN. Our summary lists: Vercel CLI 53.3.0 or newer; agent-browser; A Vercel login with access to the target project. Its frontmatter pre-approves these tools: Bash(agent-browser:*), Bash(npx agent-browser:*), Bash(vc:*), Bash(vercel:*).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Protected Vercel Deployments is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Protected Vercel Deployments: Access Protected Vercel Deployment (vercel/vercel-plugin, 301 stars), Deploy (ambient-code/platform, 131 stars), Auth (vercel/vercel-plugin, 301 stars) and Frontmcp Config (agentfront/frontmcp, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vercel-labs (a GitHub organization, an official publisher) maintains it in vercel-labs/agent-browser, which has 43,705 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 8, 2026.
Source: vercel-labs/agent-browser on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.