SafeCoBrowser
Permission layer for AI agents
Only for Mac
Free
Mac
Bring your own AI coding agent to your logged-in sessions. Access is off until you grant it, per tab, and one click takes it back. Local only, no account, no telemetry.
SafeCoBrowser is a native macOS browser that lets your own AI coding agent work on the sites you are already logged in to, without handing it your whole machine.
Connect Claude Code, Codex, or any MCP client. The agent can read a page, inspect the DOM, fill a form or click a button — but only on the tabs you allow, only at the level you choose, and only for as long as you allow it.
Built in Swift and SwiftUI. No Electron, no bundled browser engine, no cloud service.
OFF UNTIL YOU SAY OTHERWISE
Every tab starts with AI access switched off. An agent connected to SafeCoBrowser can see nothing at all until you raise a tab yourself, and each tab is separate — granting one leaves the rest invisible.
Access is a ladder, and you pick the rung:
• Off — no access
• Read — read the page text, take a screenshot
• Inspect — the above, plus DOM inspection, console and network reads
• Assist — the above, plus clicking and filling, each behind approval
• Developer — the above, plus running JavaScript, still behind approval
The agent cannot move itself up the ladder. No tool and no endpoint changes a tab's mode; only the toolbar can, and only you can use it.
GRANTING IS NOT RETROACTIVE
When you raise a tab, the agent sees the page from that moment forward. It does not receive scrollback, buffered console output, earlier network traffic, or anything captured while the tab was blocked. Log in first, grant afterwards, and the login was never visible.
STOP MEANS STOP
Stop AI revokes everything instantly — including calls already in flight. A read halfway through returns revoked rather than the page. A form being typed into stops mid-word. Access does not linger until the current operation finishes.
APPROVAL FOR ANYTHING THAT ACTS
Reading is quiet. Acting is not. Clicking, filling, navigating and running scripts each raise a card showing what is about to happen, and nothing happens until you approve it. For coordinate actions the card carries a screenshot with the target marked, so you approve a place on the page rather than a pair of numbers.
You can switch approvals off per tab when you are watching an agent work. Reading and script execution are separate switches: letting an agent click without asking never also lets it run JavaScript without asking.
A LOG YOU CAN CHECK AFTERWARDS
Every call is written to a hash-chained audit log — allowed and denied alike, with the tab, the mode and the outcome. The Activity panel shows it live. The chain detects later edits, deletions and reordering.
Sensitive values are kept out of it: what you type into a form is recorded as a fill, not as the text.
SEPARATE CONTAINERS
Tabs can run in separate containers, each with its own cookies and storage. Sign in to two accounts on the same site at once, or keep an agent's tab away from your everyday session. Deleting a container erases its storage.
PRIVACY FILTER
Define your own match-and-replace rules and matching text is redacted in the page itself, so the redaction covers the screen, screenshots, and anything the agent reads. Useful for keeping an account number out of a demo. It is a convenience, not a security boundary — the per-tab switch is the boundary.
WHAT THE AGENT NEVER GETS
No filesystem access. No access to the browser profile, the cookie store, or saved passwords. No way to open or close tabs. No way to change its own permissions. It gets a fixed set of 22 tools, each checked against the tab's current mode at the moment it runs.
PRIVATE BY DESIGN
SafeCoBrowser makes no calls of its own. There is no account, no sign-in, no telemetry and no analytics. The MCP listener binds to 127.0.0.1 and requires a bearer token the app generates, which you can regenerate to cut off a connected agent immediately.
REQUIREMENTS
macOS 14 or later. You supply the agent: SafeCoBrowser does not include one, does not call a model, and has no subscription of its own. Any MCP-capable client works; the app generates the one-line connection command.
Ratings & Reviews
- This app hasn’t received enough ratings or reviews to display an overview.
SEE WHAT YOUR AGENT CLICKS
When your AI agent clicks a button or types into a field, SafeCoBrowser now outlines it in orange for a moment, so you can see exactly what it acted on instead of working it out from what the page did next. A click at a screen position gets a ring on the spot.
The outline is drawn by the app on top of the page, not inside it. Your agent cannot see it in screenshots or page reads, and a website cannot hide or move it. It stays visible even when the click takes you to a new page.
The developer, TraLand.com, indicated that the app’s privacy practices may include handling of data as described below. For more information, see the developer’s privacy policy .
Data Not Collected
The developer does not collect any data from this app.
Accessibility
The developer has not yet indicated which accessibility features this app supports. Learn More
Information
- Seller
- Siu Lun Corley Chan
- Size
- 1.5 MB
- Category
- Developer Tools
- Compatibility
Requires macOS 14.0 or later.
- Mac
Requires macOS 14.0 or later.
- Mac
- Age Rating
4+
- 4+
- Copyright
- © 2026 FlowRun Ltd
