Headless Browser Agents vs. the Chrome You're Already Signed Into
I read the “AI Automation Without the Hype” post on Hacker News this week, then the n8n workflow masterclass writeup that followed it, then a listing for an $8,000 FastAPI automation suite somebody is actually selling. Different authors, different stacks, one shared assumption none of them bothers to state out loud: somewhere there’s a headless Chrome on a server, and that’s the thing doing the clicking.
That assumption carries most of the weight in these builds. It’s also where they tend to come apart, usually around week three, when the demo stops being a public site and has to touch an account you pay for.
A fresh browser is a browser that has never met you
Headless Chrome on a VPS boots clean. Every time. No cookies, no session tokens, no saved passwords, no extensions, no history, no device trust from the last time you logged in from your desk.
So you solve it. You stuff credentials into environment variables, or you register an OAuth app and go through the consent screens, or you serialize a cookie jar off a machine where you were logged in and inject it at startup like a transplant. Then Google rotates a token, or your SSO provider decides a sign-in from a Hetzner IP at 3am doesn’t smell like you, and the whole pipeline sits dark until somebody redoes the cookie dance by hand.
I have watched people rebuild that plumbing three separate times for three separate tools. The deliverable was never automation. The deliverable was a permanent, low-grade authentication maintenance job they assigned to themselves and then forgot to count as cost.
Cloudflare already knows
Headless leaks. Navigator properties that don’t line up, a plugin array that’s suspiciously empty, WebGL renderer strings that match a datacenter GPU nobody browses on, input timing that’s too clean, and an IP that belongs to a block full of other bots. Fingerprinting vendors have had years to catalog all of it and they are, frankly, better at their side of this than your stealth plugin is at yours.
Patched user agents buy months. Not permanence. We wrote more about why cloud browser agents keep failing Cloudflare, and the short version is that the block isn’t a bug in your script.
Your own Chrome, running on your laptop, on a residential connection, with a profile that has three years of history and a logged-in Gmail tab, does not trip any of that. Because it isn’t a signal. It’s just you.
Nobody is watching
This part bothers me more than the blocking does.
When the agent runs headless, the failure mode isn’t a crash. It’s an agent that misreads a modal, clicks whatever happened to be under the coordinates it computed, gets a 200 back, and writes “step 4 complete” to a log file that you will read on Thursday, by which point it has done the same wrong thing eleven more times on a schedule you set up yourself and were quite proud of.
Screenshots-on-error help. They help the way a security camera helps: you get to see the damage afterward.
Fine, headless wins at scale
Fifty concurrent sessions. A cron job at 3am with your laptop closed. Forty thousand product pages that need scraping by morning. Headless is correct for all of that, and anyone telling you to run those in a visible window is selling something.
A headed agent gets you one browser. Yours. Awake, unlocked, doing roughly one thing at a time while you watch. That’s a real ceiling and it doesn’t move.
But look at what actually sits in the middle of most people’s day. It isn’t 40,000 pages. It’s a Jira board, a Gmail thread, a vendor portal with a session that expires in twenty minutes, an internal admin panel with no public API and no plans for one. Volume: low. Authentication: mandatory. Headless is the wrong shape for every one of those, and it’s most of the work.
What the headed side buys you
Dassi runs in a Chrome side panel, in the browser you already have open, using the sessions you’re already signed into. There’s no credential vault to populate and no OAuth app to register, because the tab is already authenticated and the agent is simply looking at the same page you are. You can watch it work, and you can stop it. It’s in the Chrome Web Store, free, and it takes your own model key if you’d rather not route anything through us.
That’s not a replacement for a scraping fleet. It’s the other job entirely, the one where being you is the whole requirement. We’ve argued the same point from the other direction in Cloud Browser Agents Can’t See Your Tabs.
Relay.app shut down and its team landed on Google’s Chrome team. Everyone read that as a workflow-tool story. I think the interesting bit is which building they walked into.