Official agent skill

Protected Vercel Deployments

by vercel-labs in vercel-labs/agent-browser

Opens Vercel deployments behind Deployment Protection in agent-browser, using a short-lived OIDC token instead of a static bypass secret or a public exception.

OfficialApache-2.0Auto-check: notesDevOps & Cloud

Install Protected Vercel Deployments

skills CLI
$ npx skills add vercel-labs/agent-browser --skill protected-vercel-deployments -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vercel-labs/agent-browser protected-vercel-deployments --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vercel-labs/agent-browser.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skill-data/protected-vercel-deployments .claude/skills/protected-vercel-deployments && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
protected-vercel-deployments
GitHub stars
44k
Token cost
~1.7k tokens
SKILL.md length
804 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
Apache-2.0

At a glance

Opens Vercel deployments behind Deployment Protection in agent-browser, using a short-lived OIDC token instead of a static bypass secret or a public exception.

  • A Vercel preview URL redirects to a login page during browser testing
  • SKILL.md covers Same-project preview, Other environments and callers, Human intervention boundaries and Use the correct header, plus 3 more sections
  • Calls vercel; needs VERCEL_TOKEN and VERCEL_AUTOMATION_BYPASS_SECRET
  • A protected deployment returns 401 or 403 from Deployment Protection

What it does

When a preview or production URL redirects to a Vercel login page or returns a protection 401 or 403, this skill gets the agent through using your existing Vercel identity and a short-lived OIDC token. It rules out disabling Deployment Protection, making the deployment public or asking for a static bypass secret first.

For a preview of the same project, a local development token works through the default Trusted Sources self-access rule. The agent confirms the identity with vc whoami, requires Vercel CLI 53.3.0 or newer because older releases print the token to stderr, mints the token with vc project token and injects it into a named agent-browser session as a header scoped to the target origin. The token is never printed, pasted into source or saved in an env file, and vc link is avoided because it pulls variables into .env.local.

Trusted Sources configuration is needed for a protected production target, a caller from another project or team, customized self-access rules, or a TRUSTED_SOURCES_ENVIRONMENT_MISMATCH error.

When your agent uses it

  • A Vercel preview URL redirects to a login page during browser testing
  • A protected deployment returns 401 or 403 from Deployment Protection
  • Testing a protected production deployment from another project or team

Example prompts

  • “Open my Vercel preview in agent-browser and check the dashboard page, it keeps redirecting to a Vercel login.”
  • “Why does this protected deployment return 401, and how can I test it without a bypass secret?”

Requirements

  • Vercel CLI 53.3.0 or newer
  • agent-browser
  • A Vercel login with access to the target project
  • Pre-approved tools (allowed-tools): Bash(agent-browser:*), Bash(npx agent-browser:*), Bash(vc:*), Bash(vercel:*)

What it can do on your machine

Read from SKILL.md and the folder at commit 0207911. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(agent-browser:*)
    • Bash(npx agent-browser:*)
    • Bash(vc:*)
    • Bash(vercel:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • vercel

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use vercel, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • VERCEL_TOKEN
    • VERCEL_AUTOMATION_BYPASS_SECRET
    • VERCEL_OIDC_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Protected Vercel Deployments loads about 1.7k tokens when it runs. Until then it costs about 91 tokens; SKILL.md has 804 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:24
    ns also pull development variables into `.env.local` when linking.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vercel-labs/agent-browser at commit 0207911, republished under its Apache-2.0 licence (© vercel-labs). 804 words, ~1,707 tokens.

Download SKILL.mdSave it as .claude/skills/protected-vercel-deployments/SKILL.md (or your agent's skills folder).
name
protected-vercel-deployments
description
Access and test Vercel deployments protected by Vercel Authentication, SSO, or Deployment Protection with agent-browser. Use when a preview or production URL redirects to a Vercel login page, returns a protection 401 or 403, or needs short-lived Trusted Sources OIDC authentication instead of a static bypass secret or public exception.
allowed-tools
Bash(agent-browser:*), Bash(npx agent-browser:*), Bash(vc:*), Bash(vercel:*)

Protected Vercel deployments

Use the caller's existing Vercel identity and a short-lived OIDC token. Do not disable Deployment Protection, make the deployment public, or ask for a static bypass secret first.

Same-project preview

A local development token for the target project can access that project's protected Preview deployments through the default Trusted Sources self-access rule. No Trusted Sources configuration is normally required.

Confirm the local identity and Vercel CLI version:

bash
vc whoami
vc --version

Require Vercel CLI 53.3.0 or newer before running vc project token. Versions 50.25.0 through 53.2.x write the token to stderr, so command substitution captures nothing and the credential can appear in logs. If the installed version is older, stop and ask the user to upgrade it. Do not attempt to capture or recover the token from stderr.

Set the target project and scope explicitly. If they cannot be inferred safely, ask the user. In a directory whose existing .vercel/project.json link has been verified against the target, vc project token without a project name is also valid. Do not run vc link merely to get an OIDC token: current Vercel CLI versions also pull development variables into .env.local when linking.

Create a named browser session, mint a development OIDC token with the Vercel CLI, then inject it without printing or persisting it:

bash
export AGENT_BROWSER_SESSION="$(agent-browser session id --scope worktree --prefix vercel-preview)"
export VERCEL_PREVIEW_URL="https://my-app.vercel.app"
export VERCEL_PROJECT="my-app"
export VERCEL_SCOPE="my-team"

(
  TOKEN="$(vc project token "$VERCEL_PROJECT" --scope "$VERCEL_SCOPE")"
  test -n "$TOKEN"
  agent-browser open "$VERCEL_PREVIEW_URL" --headers \
    "{\"x-vercel-trusted-oidc-idp-token\":\"$TOKEN\"}"
)

agent-browser snapshot -i

Continue the normal workflow in that same session. The header is scoped to the target origin and applies to the document, scripts, styles, fonts, and in-page requests. If the browser session is closed or restarted, repeat the authenticated open command.

Never print the token, paste it into source, or save it in an environment file.

Other environments and callers

Trusted Sources configuration is needed when:

  • a local development token must reach a protected Production deployment;
  • the caller belongs to another Vercel project or team;
  • the target project's self-access rules were customized; or
  • Vercel returns TRUSTED_SOURCES_ENVIRONMENT_MISMATCH.

There is no supported Vercel CLI or public REST API for editing Trusted Sources rules. An authorized human must open the target project's Settings → Deployment Protection → Trusted Sources and add only the required caller and environment mapping. A local token has the development environment, so protected Production access requires development to production.

Stop and hand off the exact rule to the human. Do not use browser automation to change access control, and do not broaden unrelated environment mappings. Retry the authenticated open after the human confirms the rule is saved.

Show full SKILL.md (408 more words)Show less

Human intervention boundaries

The same-project development to Preview path should run without human intervention when the Vercel CLI is already authenticated and the target project and scope are known. A human is needed only when:

  • the Vercel CLI has no authenticated identity and no existing VERCEL_TOKEN; interactive vc login requires the user;
  • the installed Vercel CLI is older than 53.3.0 and must be upgraded before token minting;
  • the correct target project or scope cannot be inferred safely for token minting;
  • a Trusted Sources rule must be added or changed; the dashboard is the only supported management surface, and this changes access control;
  • Secure Backend Access with OIDC Federation was disabled on the calling project and must be re-enabled in Settings → Security; or
  • the static-secret fallback must be enabled or rotated and the agent needs explicit authorization for that access-control change. After approval, the agent can use vc project protection instead of requiring dashboard interaction.

The agent can diagnose each case and state the exact action required, then continue after the user confirms completion.

Use the correct header

Send the Vercel-issued token as:

text
x-vercel-trusted-oidc-idp-token: <VERCEL_OIDC_TOKEN>

Do not substitute x-vercel-oidc-token. That header carries workload identity into a Vercel Function; it does not authenticate an inbound request through Deployment Protection.

Diagnose failures

  • Redirect to vercel.com/login: Deployment Protection did not accept the request.
  • TRUSTED_SOURCES_ENVIRONMENT_MISMATCH: the token is valid, but its caller environment cannot reach the target environment.
  • Application 401 or 403 after protection passes: debug the application's own authentication separately.
  • Application 404 on a deliberately missing route: the request passed Deployment Protection and reached the application.

Static-secret fallback

Use Protection Bypass for Automation only when OIDC is not viable or the tool cannot send the Trusted Sources header. Enabling or rotating it changes access control, so obtain explicit authorization first. Create a dedicated secret so it can be rotated independently, keep it in an environment variable, and pass it as a header:

bash
vc project protection enable <project> --protection-bypass \
  --protection-bypass-secret "$VERCEL_AUTOMATION_BYPASS_SECRET"

agent-browser open "$VERCEL_PREVIEW_URL" --headers \
  "{\"x-vercel-protection-bypass\":\"$VERCEL_AUTOMATION_BYPASS_SECRET\",\"x-vercel-set-bypass-cookie\":\"true\"}"

The cookie directive creates a reusable _vercel_jwt cookie. Treat saved browser state containing that cookie as a credential.

Avoid dead ends

  • There is no vercel share CLI command. Shareable Links are intended for people and are not the automation path.
  • vercel curl is useful for HTTP requests, but it cannot render and interact with a page.
  • Deployment Protection Exceptions make the domain public. Do not use them merely to unblock an agent.
  • Do not expose OIDC tokens, bypass secrets, authenticated URLs, or saved state in logs, screenshots, source files, or user-facing output.

© vercel-labs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skill-data/protected-vercel-deployments of vercel-labs/agent-browser.

Open the folder on GitHubat commit 0207911

Compare with similar skills

Protected Vercel Deployments next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Protected Vercel Deployments compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Protected Vercel Deployments this skillvercel-labs/agent-browser44k—~1.7kAutomated safety check: NotesApache-2.0
Access Protected Vercel Deploymentvercel/vercel-plugin301—~1.9kAutomated safety check: NotesCustom licence
Deployambient-code/platform131—~2.6kAutomated safety check: PassMIT
Authvercel/vercel-plugin301—~6.4kAutomated safety check: NotesCustom licence
Frontmcp Configagentfront/frontmcp146—~7kAutomated safety check: PassApache-2.0
Nuxt Studiosecondsky/claude-skills227—~2.8kAutomated safety check: PassMIT

Similar skills

  • Official

    Access and test Vercel deployments protected by Vercel Authentication, SSO, or Deployment Protection.

    301 GitHub stars~1.9k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Deploy

    ambient-code/platform

    Deploy, update manifests, and troubleshoot the ambient-ui component.

    131 GitHub stars~2.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Auth

    vercel/vercel-plugin

    Official

    Authentication integration guidance — Clerk (native Vercel Marketplace), Better Auth, Descope, and Auth0 setup for Next.js applications, plus Sign in with Vercel, Vercel Passport, and Vercel KMS.

    301 GitHub stars~6.4k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Frontmcp Config

    agentfront/frontmcp

    A skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options.

    146 GitHub stars~7k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Nuxt Studio

    secondsky/claude-skills

    This skill should be used when the user asks to "set up Nuxt Studio", "configure Studio OAuth", "deploy Studio to Cloudflare", "add visual editor to Nuxt", "configure studio.domain.com subdomain"…

    227 GitHub stars~2.8k tokensUpdated 11 days ago
    Backend & APIsAuto-check passed
  • Vercel Deploy

    bytedance/deer-flow

    Deploys a project to Vercel with one script and no login, then returns a live preview URL and a claim link for moving the deployment into your own Vercel account.

    84k GitHub starsUsed in 10 repos~797 tokens
    DevOps & CloudAuto-check passed

More from vercel-labs/agent-browser

All 10 skills in this repo
  • Agent Browser CLI

    vercel-labs/agent-browser

    Official

    Browser automation CLI for AI agents. Use when the user needs to interact with websites, including navigating pages, filling forms, clicking buttons, taking…

    44k GitHub starsUsed in 24 repos~864 tokens
    Auto-check passed
  • Dogfood Exploratory QA

    vercel-labs/agent-browser

    Official

    Explores a web app with the agent-browser CLI to find bugs and UX problems, then writes a report with screenshots, repro videos and step-by-step reproduction for each issue.

    44k GitHub starsUsed in 8 repos~2.7k tokens
    Auto-check passed
  • Electron App Automation

    vercel-labs/agent-browser

    Official

    Automates Electron desktop apps such as VS Code, Slack or Discord by connecting agent-browser to their Chrome DevTools Protocol port.

    44k GitHub starsUsed in 5 repos~1.7k tokens
    Auto-check passed
  • Slack Browser Automation

    vercel-labs/agent-browser

    Official

    Drives the Slack web app with the agent-browser CLI to check unread channels, search, read channel details and extract information, with screenshots as evidence.

    44k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Core Guide for agent-browser

    vercel-labs/agent-browser

    Official

    Core usage guide for the agent-browser CLI: the snapshot-and-ref workflow for navigating, clicking, filling forms, extracting data and running parallel sessions.

    44k GitHub starsUsed in 2 repos~9.5k tokens
    Auto-check passed
  • Official

    Records a site's browser traffic into a HAR file, then builds a standalone client or CLI that calls its internal endpoints directly with no browser.

    44k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed

Works with

Questions about Protected Vercel Deployments

What does Protected Vercel Deployments do?

Opens Vercel deployments behind Deployment Protection in agent-browser, using a short-lived OIDC token instead of a static bypass secret or a public exception. When a preview or production URL redirects to a Vercel login page or returns a protection 401 or 403, this skill gets the agent through using your existing Vercel identity and a short-lived OIDC token. It rules out disabling Deployment Protection, making the deployment public or asking for a static bypass secret first.

When should I use Protected Vercel Deployments?

Protected Vercel Deployments fits situations like: A Vercel preview URL redirects to a login page during browser testing; A protected deployment returns 401 or 403 from Deployment Protection; testing a protected production deployment from another project or team.

How do I install Protected Vercel Deployments in Claude Code?

Run `npx skills add vercel-labs/agent-browser --skill protected-vercel-deployments -a claude-code`. Or copy the skill folder (skill-data/protected-vercel-deployments in vercel-labs/agent-browser) into .claude/skills/protected-vercel-deployments in your project. Claude Code loads it when a task matches its description.

How do I install Protected Vercel Deployments in Codex?

Run `npx skills add vercel-labs/agent-browser --skill protected-vercel-deployments -a codex`. Or copy the skill folder (skill-data/protected-vercel-deployments in vercel-labs/agent-browser) into .agents/skills/protected-vercel-deployments in your project. Codex loads it when a task matches its description.

Can I use Protected Vercel Deployments in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vercel-labs/agent-browser --skill protected-vercel-deployments -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/protected-vercel-deployments, .gemini/skills/protected-vercel-deployments, .github/skills/protected-vercel-deployments and .opencode/skills/protected-vercel-deployments in your project.

What does Protected Vercel Deployments need to run?

Going by SKILL.md and its folder, Protected Vercel Deployments needs the command-line tools its instructions call (vercel) and credentials named VERCEL_TOKEN, VERCEL_AUTOMATION_BYPASS_SECRET and VERCEL_OIDC_TOKEN. Our summary lists: Vercel CLI 53.3.0 or newer; agent-browser; A Vercel login with access to the target project. Its frontmatter pre-approves these tools: Bash(agent-browser:*), Bash(npx agent-browser:*), Bash(vc:*), Bash(vercel:*).

Does Protected Vercel Deployments access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Protected Vercel Deployments safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Protected Vercel Deployments use?

Protected Vercel Deployments is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Protected Vercel Deployments use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Protected Vercel Deployments?

Skills that share tags, products or a category with Protected Vercel Deployments: Access Protected Vercel Deployment (vercel/vercel-plugin, 301 stars), Deploy (ambient-code/platform, 131 stars), Auth (vercel/vercel-plugin, 301 stars) and Frontmcp Config (agentfront/frontmcp, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Protected Vercel Deployments?

vercel-labs (a GitHub organization, an official publisher) maintains it in vercel-labs/agent-browser, which has 43,705 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 8, 2026.

Source: vercel-labs/agent-browser on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.