Coding agents are powerful, but they hit a wall when they need to interact with web apps behind enterprise SSO. Most solutions either launch a sterile headless browser with no login state or hijack the user's active Chrome window, triggering annoying remote debugging prompts and stealing focus. To solve this, developer Alexey Indeev has open-sourced Chrome Relay, a tool that allows agents like Claude Code, Codex, Cursor, and Paseo to drive background tabs in an everyday Chrome instance using existing user logins.

The Friction of Browser-Based Agents

Indeev identified four strict requirements for a viable agent-browser interface: it must work via CLI, use actual Chrome profiles, stay in the background, and be fast. Standard debugging ports fail the focus requirement by raising windows or triggering permission dialogs. Attempting to copy Chrome profiles to a separate browser instance fails the login requirement because Google sessions are bound to the device; copying cookies results in invalid sessions and forced sign-outs. Existing Playwright extensions and separate signed-in browsers only partially met these needs, leaving a gap for a unified solution.

How Chrome Relay Works

The architecture relies on a local relay service running on 127.0.0.1:9333 that bridges the agent's CLI commands to a Chrome MV3 extension. The extension uses the chrome.debugger API to control tabs but avoids the standard debugging port, thereby suppressing the 'Allow remote debugging?' prompt. Agent tabs are opened as inactive tabs within a collapsed 'Agents' group, ensuring the user's focus remains undisturbed. The relay isolates each agent to its own DevTools endpoint, preventing multiple concurrent agents from interfering with each other's tab visibility or actions.

Handling SSO and Edge Cases

When a site bounces through Google sign-in, the extension automatically clicks the account and Continue button if the correct profile is already active. Agents never type credentials themselves. If the authentication flow reaches a password, passkey, or 2-step verification screen, the process stops and alerts the user to sign in manually. The tool also handles 1Password interference; when Chrome drops the debugger due to an extension frame, the relay waits for re-attachment, causing a slight delay in command execution.

Security and Audit Controls

Security is handled through a per-machine secret and process verification. The relay only accepts connections from processes explicitly identified as Claude Code, Codex, Cursor, or Paseo, checking for specific markers set on child processes. Web pages are rejected even if they possess the correct secret. Every action is logged in an audit trail, recording clicks, page loads, and scripts, though typed text is stored only by length to protect sensitive credentials. The system currently supports macOS and Chrome, requiring Node.js 20+ and the agent-browser CLI for operation.

Key Takeaways

  • Chrome Relay enables agents to use existing Google SSO logins without copying profiles or losing session validity.
  • The tool operates entirely in the background, preventing focus theft and avoiding standard remote debugging prompts.
  • Access is restricted to specific agent processes (Claude Code, Codex, Cursor, Paseo) via local secret and process marker verification.
  • Performance is optimized for speed, with page loads averaging 0.6 seconds and command execution at 0.15 seconds.
  • The project is MIT-licensed and available on GitHub, with setup requiring manual extension loading in Chrome profiles.

The Bottom Line

Chrome Relay solves the 'last mile' problem for agentic development by bridging the gap between CLI-driven automation and authenticated browser environments. It is a critical infrastructure piece for developers who need their AI agents to interact with real-world applications without disrupting their workflow.