{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "steel",
    "name": "Steel",
    "vendor": "Nen Labs, Inc.",
    "vendorUrl": "https://steel.dev",
    "kind": "http-api",
    "category": "browser",
    "summary": "Steel runs cloud browser sessions for AI agents, controlled through a REST API, a CDP WebSocket, SDKs, a CLI and an official MCP server. Its browser runtime, steel-browser, is open source and can be self-hosted.",
    "url": "https://www.anchorterminal.com/tools/steel",
    "markdownUrl": "https://www.anchorterminal.com/tools/steel.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/steel.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/steel.json",
    "repo": "https://github.com/steel-dev/steel-browser",
    "license": "Proprietary cloud service under Steel's terms. steel-browser and the Node and Python SDKs are Apache-2.0. The MCP server and the CLI are MIT",
    "transports": [
      "http",
      "stdio"
    ],
    "remoteUrl": "https://api.steel.dev",
    "packages": [
      {
        "registry": "npm",
        "name": "steel-sdk"
      },
      {
        "registry": "pypi",
        "name": "steel-sdk"
      },
      {
        "registry": "npm",
        "name": "@steel-dev/cli"
      }
    ],
    "auth": "api-key",
    "authNotes": "Self-serve API key from the dashboard at app.steel.dev, sent in the `steel-api-key` header. Keys are named, shown once and revoked by deletion, and the dashboard shows when each was last used. A global key covers the whole organisation, and `POST /v1/api-keys` lets a global key create keys bound to one project. No per-permission scopes were found. CDP connections pass the key as the `apiKey` query parameter on `wss://connect.steel.dev`. The x402 endpoints need no key. A self-hosted steel-browser needs no key.",
    "pricing": "freemium",
    "pricingNotes": "Launch is $0 plus usage with $30 of one-time credit valid for 90 days, and the quickstart says no card is required. Browser time is $0.10 an hour on Launch and $0.08 on Scale ($250 a month with $100 of monthly credit), billed by the minute and rounded up. Proxy traffic is $10 or $6 a GB, CAPTCHA solves $3 or $1 per 1,000, and scrape, screenshot and PDF calls $5 per 1,000. CAPTCHA solving and managed proxies on Launch need $10 of paid balance. The same three calls cost $0.01 each by x402. Enterprise is priced through sales. Self-hosted steel-browser is free (https://docs.steel.dev/overview/pricinglimits, checked 2026-10-08).",
    "priceSummary": "$0.01 / call",
    "where": "both",
    "x402": {
      "level": "yes",
      "evidence": "x402 version 2 on https://x402.steel.dev for scrape, screenshot and PDF at $0.01 a call in USDC on Base or Solana, with no account or API key (https://docs.steel.dev/integrations/x402). An unpaid POST to /v1/scrape on 2026-10-08 returned 402 with a payment-required header for 10000 base units on eip155:8453 and Solana mainnet. The header names https://api.paysponge.com/v1/scrape as the resource, so a third party appears to run the payment layer. Browser sessions and api.steel.dev aren't covered.",
      "endpoints": [
        {
          "url": "https://x402.steel.dev/v1/scrape",
          "priceUsd": 0.01,
          "network": "eip155:8453"
        },
        {
          "url": "https://x402.steel.dev/v1/screenshot",
          "priceUsd": 0.01,
          "network": "eip155:8453"
        },
        {
          "url": "https://x402.steel.dev/v1/pdf",
          "priceUsd": 0.01,
          "network": "eip155:8453"
        }
      ]
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 46988,
      "pypiWeekly": 63315,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.steel.dev",
    "llmsTxt": "https://docs.steel.dev/llms.txt",
    "openapi": "https://docs.steel.dev/openapi.json",
    "capabilities": [
      "browser.control",
      "browser.hosted",
      "browser.debug",
      "web.scrape",
      "web.fetch",
      "scraping.proxies",
      "scraping.anti-bot",
      "pdf.generate"
    ],
    "tags": [
      "official",
      "hosted",
      "self-hosted",
      "open-source",
      "freemium",
      "no-card",
      "x402",
      "openapi",
      "llms-txt",
      "mcp",
      "python",
      "typescript",
      "proxies",
      "status-page"
    ],
    "lastRelease": "2026-10-02",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 70.4,
      "grade": "BB",
      "agentReady": true,
      "rank": 129,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 5,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 79,
        "maintenance": 82,
        "payments": 75,
        "reliability": 58,
        "schema": 86,
        "security": 56,
        "transparency": 64
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 58,
          "points": 11.6,
          "reason": "Graded as a hosted service, on Steel Cloud. status.steel.dev runs on Better Stack with Steel API, Dashboard, Proxies and Connections components and 90 days of history (20). The Main API shows 99.762 per cent over 90 days. The page records a 4 hour 10 minute outage for domain and SSL problems on 22 July 2026, 5 hours 41 minutes of capacity errors on session creation on 23 August and 1 hour 55 minutes of failing session creation on 1 October, so several majors (0). Seven other entries include two streaming and recording problems of more than an hour on 23 and 25 September, during which Steel said the API worked normally. Limits are published per plan, 60 and 600 requests a minute, 10 and 100 concurrent sessions, and 20 a minute on Browser Tools (15). Browser Tools document 429 and a 503 marked safe to retry, the Agent Traces API says to wait for `Retry-After`, and the SDKs retry 408, 409, 429 and 5xx twice with backoff. No idempotency keys, though session creation accepts a caller-chosen `sessionId` (10). Support and uptime SLAs are listed for Enterprise only, with no terms published (3). The sessions API is not marked beta (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 86,
          "points": 13.98,
          "reason": "OpenAPI 3.0.3 at docs.steel.dev/openapi.json with 51 paths and 75 operations and the `steel-api-key` header scheme (25). llms.txt, llms-full.txt and a Markdown twin of every docs page (10). 65 of 75 operations carry a description, and the MCP server's tool descriptions say when to use each tool and when to pick another (16). Inputs are typed with enums, UUID formats and list limits of 1 to 100, but `timeout` and `concurrency` carry no real bounds and `useProxy` and `region` have no stated type (11). One shared error schema is attached to most operations and the docs have error tables for Browser Tools and Agent Traces. The spec holds one example, and 429 is declared on session creation only (11). Paths are versioned under /v1 and the changelog is public and numbered, with dates in page metadata. The spec's own version reads 0.0.1 (13)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 79,
          "points": 12.84,
          "reason": "Scrape returns only the formats asked for (HTML, cleaned HTML, Markdown or readability text), lists take `limit`, and the MCP server holds its 16 tool definitions to a 17,000 byte budget checked in CI, with a three-tool scrape profile (20). Sessions list by cursor with a `status` filter and a default page of 50, other lists take `limit` and `offset`, and traces filter by time and event type (17). Errors return `message`, `linkToDocs` and validation `context`, with documented 401 messages. No stable machine-readable error codes were found (15). No idempotency keys. A caller-chosen `sessionId`, `inactivityTimeout` and release-all help with retries and clean-up, and every MCP tool carries read-only, destructive or idempotent annotations (12). Session creation needs no parameters, and there are SDKs for Node and Python, with Rust and Go per Steel's blog (15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 56,
          "points": 9.8,
          "reason": "Named API keys, shown once, revoked by deletion, with last-used times and a rotation guide. A global key covers the organisation and can create keys bound to one project through `POST /v1/api-keys`. No per-permission scopes were found (22). The documented CDP connection passes the key as `apiKey` in the `wss://connect.steel.dev` URL, a secret in a query string (minus 10). No read-only key. Projects isolate sessions, credentials and profiles, stored credentials are typed into pages without being shown to the agent, browser action endpoints reject localhost and private addresses since changelog 038, and the MCP server has a scrape-only profile and hands the browser to a person before logins and payments (13). The MCP server fences page content as untrusted and strips hidden text, and its README warns about injection. The API docs carry no such guidance (10). Session logs, recordings, Agent Traces, per-session cost and exports to JSON or CSV give the operator a per-call trail (13). A Vanta trust centre whose contents did not render for us, a HIPAA-ready BAA and SSO on Scale, and a disclosure policy with response times for the MCP server. No security.txt, bug bounty or certification report was found (8)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 75,
          "points": 9.38,
          "reason": "x402 version 2 at x402.steel.dev for scrape, screenshot and PDF, in USDC on Base or Solana. An unpaid request on 8 October 2026 returned 402 with terms. Browser sessions, the main product, aren't covered, and the payment header names api.paysponge.com as the resource, so partial (20). Per-hour, per-GB and per-1,000-call prices published without login (20). Launch plan with $30 of one-time credit valid 90 days, and the quickstart says no card is required (20). An agent with a wallet gets a scrape, screenshot or PDF with no account, but a browser session needs a person to sign up or run the Stripe CLI, so we award 15 of 20."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 82,
          "points": 7.18,
          "reason": "Changelog 038 is dated 2 October 2026, and steel-browser's latest commit is 6 October (30). Changelog entries on 24 July, 18 and 25 September and 2 October 2026, plus steel-browser v0.5.4-beta on 25 August and MCP server 3.0.0 on 9 September (20). Public changelog, Discord and email support, and steel-browser merged ten fixes between 20 July and 6 October. GitHub issue reply times were not read (15). Official SDKs exist, but the newest stable releases are npm 0.18.0 from 16 March 2026 and PyPI 0.19.0 from 23 June, with previews in September, and the MCP server is not in the MCP registry (9). CI workflows in steel-browser and a test, byte-budget and conformance suite in the MCP server. Whether they pass was not read (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 64,
          "points": 5.6,
          "note": "editorial 52, provenance 75",
          "reason": "Graded on the cloud service, which is closed with published terms. The browser runtime steel-browser and the SDKs are Apache-2.0, and the MCP server and CLI are MIT (24). The privacy notice (5 February 2026) keeps data while an account exists, the pricing page gives 7 and 14 days of data retention, recordings can be turned off per session, and a DPA is linked as a Google Drive file. The terms date from 5 February 2025, the docs Legal page links to Google Docs copies, and the FAQ still describes pricing by concurrent sessions (14). No deprecation policy. Legacy plans stay available after the pricing change, and one docs note says a playback mode will be deprecated without a date (4). The privacy notice names Anthropic, OpenAI and Google Cloud AI as AI processors and says servers are in the United States, and the docs name one region, us-east. No subprocessor list was found outside the trust centre, which did not render for us (10)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Scrape returns only the formats asked for (HTML, cleaned HTML, Markdown or readability text), lists take `limit`, and the MCP server holds its 16 tool definitions to a 17,000 byte budget checked in CI, with a three-tool scrape profile (20). Sessions list by cursor with a `status` filter and a default page of 50, other lists take `limit` and `offset`, and traces filter by time and event type (17). Errors return `message`, `linkToDocs` and validation `context`, with documented 401 messages. No stable machine-readable error codes were found (15). No idempotency keys. A caller-chosen `sessionId`, `inactivityTimeout` and release-all help with retries and clean-up, and every MCP tool carries read-only, destructive or idempotent annotations (12). Session creation needs no parameters, and there are SDKs for Node and Python, with Rust and Go per Steel's blog (15).",
          "maintenance": "Changelog 038 is dated 2 October 2026, and steel-browser's latest commit is 6 October (30). Changelog entries on 24 July, 18 and 25 September and 2 October 2026, plus steel-browser v0.5.4-beta on 25 August and MCP server 3.0.0 on 9 September (20). Public changelog, Discord and email support, and steel-browser merged ten fixes between 20 July and 6 October. GitHub issue reply times were not read (15). Official SDKs exist, but the newest stable releases are npm 0.18.0 from 16 March 2026 and PyPI 0.19.0 from 23 June, with previews in September, and the MCP server is not in the MCP registry (9). CI workflows in steel-browser and a test, byte-budget and conformance suite in the MCP server. Whether they pass was not read (8).",
          "payments": "x402 version 2 at x402.steel.dev for scrape, screenshot and PDF, in USDC on Base or Solana. An unpaid request on 8 October 2026 returned 402 with terms. Browser sessions, the main product, aren't covered, and the payment header names api.paysponge.com as the resource, so partial (20). Per-hour, per-GB and per-1,000-call prices published without login (20). Launch plan with $30 of one-time credit valid 90 days, and the quickstart says no card is required (20). An agent with a wallet gets a scrape, screenshot or PDF with no account, but a browser session needs a person to sign up or run the Stripe CLI, so we award 15 of 20.",
          "reliability": "Graded as a hosted service, on Steel Cloud. status.steel.dev runs on Better Stack with Steel API, Dashboard, Proxies and Connections components and 90 days of history (20). The Main API shows 99.762 per cent over 90 days. The page records a 4 hour 10 minute outage for domain and SSL problems on 22 July 2026, 5 hours 41 minutes of capacity errors on session creation on 23 August and 1 hour 55 minutes of failing session creation on 1 October, so several majors (0). Seven other entries include two streaming and recording problems of more than an hour on 23 and 25 September, during which Steel said the API worked normally. Limits are published per plan, 60 and 600 requests a minute, 10 and 100 concurrent sessions, and 20 a minute on Browser Tools (15). Browser Tools document 429 and a 503 marked safe to retry, the Agent Traces API says to wait for `Retry-After`, and the SDKs retry 408, 409, 429 and 5xx twice with backoff. No idempotency keys, though session creation accepts a caller-chosen `sessionId` (10). Support and uptime SLAs are listed for Enterprise only, with no terms published (3). The sessions API is not marked beta (10).",
          "schema": "OpenAPI 3.0.3 at docs.steel.dev/openapi.json with 51 paths and 75 operations and the `steel-api-key` header scheme (25). llms.txt, llms-full.txt and a Markdown twin of every docs page (10). 65 of 75 operations carry a description, and the MCP server's tool descriptions say when to use each tool and when to pick another (16). Inputs are typed with enums, UUID formats and list limits of 1 to 100, but `timeout` and `concurrency` carry no real bounds and `useProxy` and `region` have no stated type (11). One shared error schema is attached to most operations and the docs have error tables for Browser Tools and Agent Traces. The spec holds one example, and 429 is declared on session creation only (11). Paths are versioned under /v1 and the changelog is public and numbered, with dates in page metadata. The spec's own version reads 0.0.1 (13).",
          "security": "Named API keys, shown once, revoked by deletion, with last-used times and a rotation guide. A global key covers the organisation and can create keys bound to one project through `POST /v1/api-keys`. No per-permission scopes were found (22). The documented CDP connection passes the key as `apiKey` in the `wss://connect.steel.dev` URL, a secret in a query string (minus 10). No read-only key. Projects isolate sessions, credentials and profiles, stored credentials are typed into pages without being shown to the agent, browser action endpoints reject localhost and private addresses since changelog 038, and the MCP server has a scrape-only profile and hands the browser to a person before logins and payments (13). The MCP server fences page content as untrusted and strips hidden text, and its README warns about injection. The API docs carry no such guidance (10). Session logs, recordings, Agent Traces, per-session cost and exports to JSON or CSV give the operator a per-call trail (13). A Vanta trust centre whose contents did not render for us, a HIPAA-ready BAA and SSO on Scale, and a disclosure policy with response times for the MCP server. No security.txt, bug bounty or certification report was found (8).",
          "transparency": "Graded on the cloud service, which is closed with published terms. The browser runtime steel-browser and the SDKs are Apache-2.0, and the MCP server and CLI are MIT (24). The privacy notice (5 February 2026) keeps data while an account exists, the pricing page gives 7 and 14 days of data retention, recordings can be turned off per session, and a DPA is linked as a Google Drive file. The terms date from 5 February 2025, the docs Legal page links to Google Docs copies, and the FAQ still describes pricing by concurrent sessions (14). No deprecation policy. Legacy plans stay available after the pricing change, and one docs note says a playback mode will be deprecated without a date (4). The privacy notice names Anthropic, OpenAI and Google Cloud AI as AI processors and says servers are in the United States, and the docs name one region, us-east. No subprocessor list was found outside the trust centre, which did not render for us (10)."
        },
        "sources": [
          {
            "what": "home page",
            "url": "https://steel.dev/",
            "seen": "2026-10-08"
          },
          {
            "what": "docs index for agents",
            "url": "https://docs.steel.dev/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing and limits",
            "url": "https://docs.steel.dev/overview/pricinglimits",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing page",
            "url": "https://steel.dev/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication",
            "url": "https://docs.steel.dev/overview/authentication",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI document",
            "url": "https://docs.steel.dev/openapi.json",
            "seen": "2026-10-08"
          },
          {
            "what": "API reference",
            "url": "https://steel.apidocumentation.com/api-reference",
            "seen": "2026-10-08"
          },
          {
            "what": "x402 integration",
            "url": "https://docs.steel.dev/integrations/x402",
            "seen": "2026-10-08"
          },
          {
            "what": "unpaid x402 request, 402 response",
            "url": "https://x402.steel.dev/v1/scrape",
            "seen": "2026-10-08"
          },
          {
            "what": "Stripe Projects",
            "url": "https://docs.steel.dev/overview/stripe-projects",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.steel.dev",
            "seen": "2026-10-08"
          },
          {
            "what": "status page JSON",
            "url": "https://status.steel.dev/index.json",
            "seen": "2026-10-08"
          },
          {
            "what": "incident history",
            "url": "https://status.steel.dev/incidents",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://docs.steel.dev/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "Browser Tools",
            "url": "https://docs.steel.dev/overview/browser-tools/overview",
            "seen": "2026-10-08"
          },
          {
            "what": "Agent Traces API",
            "url": "https://docs.steel.dev/overview/agent-traces/api",
            "seen": "2026-10-08"
          },
          {
            "what": "session lifecycle",
            "url": "https://docs.steel.dev/overview/sessions-api/session-lifecycle",
            "seen": "2026-10-08"
          },
          {
            "what": "session configuration and region",
            "url": "https://docs.steel.dev/overview/sessions-api/configuration",
            "seen": "2026-10-08"
          },
          {
            "what": "Credentials API",
            "url": "https://docs.steel.dev/overview/credentials-api/overview",
            "seen": "2026-10-08"
          },
          {
            "what": "self-hosted and cloud comparison",
            "url": "https://docs.steel.dev/overview/self-hosting/steel-local-vs-steel-cloud",
            "seen": "2026-10-08"
          },
          {
            "what": "quickstart",
            "url": "https://docs.steel.dev/overview/sessions-api/quickstart",
            "seen": "2026-10-08"
          },
          {
            "what": "Claude Code integration",
            "url": "https://docs.steel.dev/integrations/claude-code",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server source",
            "url": "https://github.com/steel-dev/steel-mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server releases",
            "url": "https://github.com/steel-dev/steel-mcp-server/releases",
            "seen": "2026-10-08"
          },
          {
            "what": "steel-browser source",
            "url": "https://github.com/steel-dev/steel-browser",
            "seen": "2026-10-08"
          },
          {
            "what": "Node SDK source",
            "url": "https://github.com/steel-dev/steel-node",
            "seen": "2026-10-08"
          },
          {
            "what": "Node SDK on npm",
            "url": "https://registry.npmjs.org/steel-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "Python SDK on PyPI",
            "url": "https://pypi.org/pypi/steel-sdk/json",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=steel",
            "seen": "2026-10-08"
          },
          {
            "what": "terms",
            "url": "https://steel.dev/terms",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy notice",
            "url": "https://steel.dev/privacy",
            "seen": "2026-10-08"
          },
          {
            "what": "FAQ",
            "url": "https://steel.dev/faq",
            "seen": "2026-10-08"
          },
          {
            "what": "docs Legal page",
            "url": "https://docs.steel.dev/overview/legal",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre",
            "url": "https://trust.steel.dev/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt, 404",
            "url": "https://steel.dev/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing update post",
            "url": "https://steel.dev/blog/pricing-update",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.org/domain/steel.dev",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the contents of the Vanta trust centre at trust.steel.dev (certifications, subprocessors, policies), which needs JavaScript and did not render for our reader",
          "unchecked: GitHub issue counts, reply times, CI results and the star count, because the GitHub API refused us for its rate limit and the issue pages did not parse. Steel's site states 7.8K stars for steel-browser",
          "unchecked: the DPA, linked from the privacy notice as a Google Drive file, was not opened",
          "unchecked: the Rust and Go SDKs, taken from Steel's blog index and not read in a registry",
          "Whether the Launch signup asks for a card. The quickstart says no credit card is required and the pricing page does not say",
          "Who operates x402.steel.dev. The 402 header names https://api.paysponge.com/v1/scrape as the resource and the docs do not mention a third party",
          "The authentication page says keys are created and deleted only in the dashboard, while the OpenAPI document has `POST /v1/api-keys` for project-bound keys",
          "The Node SDK repository has tags v0.19.0 and v0.20.0 (23 June 2026) that are not on npm, where `latest` is 0.18.0",
          "Steel's llms.txt calls its speed results independent benchmarks while linking to benchmark code in its own steel-dev/browserbench repository. We did not assess the claim and made no deduction",
          "The docs name us-east as the only region while the OpenAPI description of `region` lists six. The FAQ describes pricing by concurrent sessions, which the pricing page no longer does"
        ]
      },
      "negative": 0,
      "verdict": "The hosted API has a public OpenAPI document, per-unit prices, $30 of starting credit and x402 payment for scrape, screenshot and PDF calls. The status page records three API or session-creation incidents of more than an hour in 90 days, and the documented CDP connection puts the API key in the URL.",
      "bestFor": "Agents that need a real cloud browser with persistent profiles, stored logins, CAPTCHA solving and a human takeover path, and teams that want an open-source runtime they can also self-host.",
      "strengths": [
        "OpenAPI 3.0.3 document with 75 operations, llms.txt and a Markdown twin of every docs page",
        "x402 at x402.steel.dev for scrape, screenshot and PDF at $0.01 a call in USDC on Base or Solana, with no account",
        "Per-unit prices published without login, and $30 of one-time credit on the Launch plan",
        "Official MCP server with 16 annotated tools, a three-tool scrape profile and page content fenced as untrusted",
        "steel-browser, the browser runtime, is Apache-2.0 and self-hostable with Docker"
      ],
      "weaknesses": [
        "Three incidents of more than an hour hit the API or session creation in the 90 days to 8 October 2026, the longest 5 hours 41 minutes",
        "The documented CDP connection passes the API key as `apiKey` in the `wss://connect.steel.dev` URL",
        "x402 covers the three one-shot endpoints only, so a browser session needs an account and a key",
        "The MCP server is not on npm or in the MCP registry, and `mcp.steel.dev` is not live per its README",
        "No deprecation policy or security.txt found, and the trust centre did not render for our reader"
      ],
      "agentNotes": [
        "Use `POST /v1/scrape` for pages you only need to read. It starts no session and costs $5 per 1,000 calls, or $0.01 a call by x402",
        "Release every session with `POST /v1/sessions/{id}/release` and set `inactivityTimeout`. Browser time bills by the minute, rounded up",
        "Build the CDP URL as `wss://connect.steel.dev?apiKey=\u003ckey\u003e\u0026sessionId=\u003cid\u003e` and keep it out of logs, because it carries the key",
        "Launch sessions end after 15 minutes at most, and `timeout` cannot be changed on a live session",
        "CAPTCHA solving and Steel's managed proxies on Launch need $10 of paid balance. Free credit does not count"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "BB",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 70.4
        }
      ],
      "editorialScores": {
        "ergonomics": 79,
        "maintenance": 82,
        "payments": 75,
        "reliability": 58,
        "schema": 86,
        "security": 56,
        "transparency": 52
      },
      "provenanceScore": 75
    },
    "connect": {
      "install": "npm install steel-sdk",
      "http": "curl -X POST https://api.steel.dev/v1/scrape -H \"steel-api-key: YOUR_KEY\" -H \"Content-Type: application/json\" -d '{\"url\": \"https://example.com\"}'",
      "claudeCode": "claude mcp add steel -e STEEL_API_KEY=your-steel-api-key -- npx -y github:steel-dev/steel-mcp-server",
      "config": {
        "mcpServers": {
          "steel": {
            "args": [
              "-y",
              "github:steel-dev/steel-mcp-server"
            ],
            "command": "npx",
            "env": {
              "STEEL_API_KEY": "\u003cyour-steel-api-key\u003e"
            }
          }
        }
      },
      "x402": "curl -i -X POST https://x402.steel.dev/v1/scrape -H \"Content-Type: application/json\" -d '{\"url\": \"https://example.com\", \"format\": [\"markdown\"]}'"
    },
    "letme": {
      "capability": "https://letme.dev/browser.control",
      "tool": "https://letme.dev/steel"
    },
    "notable": [
      "x402 at https://x402.steel.dev for scrape, screenshot and PDF, $0.01 a call in USDC on Base or Solana with no account. Browser sessions aren't covered (https://docs.steel.dev/integrations/x402)",
      "The official MCP server has 16 tools in its default `browse` profile and three in `scrape`, all with read-only or destructive annotations. Version 3.0.0 is on the main branch from 9 September 2026, it is not on npm, and its README says `mcp.steel.dev` is not live yet (https://github.com/steel-dev/steel-mcp-server)",
      "steel-browser, the open-source runtime, is Apache-2.0 and runs one session at a time when self-hosted, without CAPTCHA solving, managed proxies, the Credentials API or the Files API (https://docs.steel.dev/overview/self-hosting/steel-local-vs-steel-cloud)",
      "status.steel.dev shows 99.762 per cent for the Main API over 90 days, with a 4 hour 10 minute outage on 22 July 2026, 5 hours 41 minutes of failed session creation on 23 August and 1 hour 55 minutes on 1 October (https://status.steel.dev)",
      "`stripe projects add steel/browser` creates a Steel account, a project and a project-bound `STEEL_API_KEY` from the Stripe CLI (https://docs.steel.dev/overview/stripe-projects)",
      "Stored credentials are encrypted per credential with AES-256-GCM under an organisation KMS key and typed into login pages without being shown to the agent, per the docs (https://docs.steel.dev/overview/credentials-api/overview)",
      "Steel runs browsers in one region, us-east, and the `region` parameter rejects any other value (https://docs.steel.dev/overview/sessions-api/configuration)"
    ],
    "area": "developer",
    "details": [
      {
        "label": "Surface graded",
        "value": "Steel Cloud, the hosted API at https://api.steel.dev with CDP at wss://connect.steel.dev. The open-source steel-browser and the MCP server are described but not graded separately"
      },
      {
        "label": "API",
        "value": "OpenAPI 3.0.3 with 51 paths and 75 operations under /v1. Sessions, Browser Tools (scrape, screenshot, PDF), Files, Profiles, Credentials, Extensions, Captchas, Projects, Secrets, Environments and Computers"
      },
      {
        "label": "MCP server",
        "value": "Official, MIT, stdio from GitHub with `npx -y github:steel-dev/steel-mcp-server`, Node 20 or later. 16 tools in the `browse` profile, 3 in `scrape`. Latest tagged release v2.0.1 on 24 August 2026, 3.0.0 on main. Not on npm, not in the MCP registry, no hosted endpoint yet"
      },
      {
        "label": "Free tier",
        "value": "Launch plan, $30 of one-time credit valid 90 days, 10 concurrent sessions, 15 minutes a session, 7-day data retention, up to 3 seats"
      },
      {
        "label": "Rate limits",
        "value": "60 requests a minute on Launch and 600 on Scale. Browser Tools 20 requests a minute per organisation. Concurrent sessions 10 on Launch, 100 on Scale, 1,000+ on Enterprise"
      },
      {
        "label": "Session limits",
        "value": "Default timeout 5 minutes. Maximum 15 minutes on Launch, 1 hour on Scale, up to 24 hours on Enterprise. `inactivityTimeout` releases an idle session early"
      },
      {
        "label": "Errors",
        "value": "JSON error body with `message`, optional `error`, `linkToDocs` and validation `context`. Browser Tools document 402, 408, 429 and 503, with 503 marked safe to retry. The SDKs retry 408, 409, 429 and 5xx twice with backoff"
      },
      {
        "label": "Machine payment",
        "value": "x402 version 2 at x402.steel.dev for /v1/scrape, /v1/screenshot and /v1/pdf, $0.01 a call, USDC on Base or Solana"
      },
      {
        "label": "SDKs and CLI",
        "value": "Node `steel-sdk` 0.18.0 on npm (16 March 2026, with 0.21.0 previews from September) and Python `steel-sdk` 0.19.0 on PyPI (23 June 2026), both generated by Stainless. Rust and Go SDKs per Steel's blog. CLI `@steel-dev/cli` 0.3.1 on npm, with 0.5.0 previews tagged on GitHub"
      },
      {
        "label": "Self-hosting",
        "value": "steel-browser, Apache-2.0, Docker image, latest tag v0.5.4-beta on 25 August 2026. One concurrent session, bring your own proxies"
      },
      {
        "label": "Observability",
        "value": "Live session viewer, recordings (can be turned off per session with `recording: false`), session logs, Agent Traces as JSON, and a per-session cost endpoint"
      },
      {
        "label": "Security",
        "value": "HIPAA-ready BAA and SSO on Scale and Enterprise per the pricing page. Vanta trust centre at trust.steel.dev. No security.txt"
      },
      {
        "label": "Region",
        "value": "Browsers run in us-east only per the session configuration docs. The privacy notice says servers are in the United States"
      }
    ],
    "unitPrices": [
      {
        "item": "Browser, Launch plan",
        "unit": "browser-hour",
        "usd": 0.1,
        "note": "Billed by the minute, rounded up"
      },
      {
        "item": "Browser, Scale plan",
        "unit": "browser-hour",
        "usd": 0.08
      },
      {
        "item": "Proxy traffic, Launch",
        "unit": "gb",
        "usd": 10
      },
      {
        "item": "Proxy traffic, Scale",
        "unit": "gb",
        "usd": 6
      },
      {
        "item": "Scrape, screenshot or PDF",
        "unit": "1k-requests",
        "usd": 5
      },
      {
        "item": "Scrape, screenshot or PDF by x402",
        "unit": "call",
        "usd": 0.01,
        "note": "USDC on Base or Solana, no account"
      },
      {
        "item": "CAPTCHA solves, Launch",
        "unit": "1k-requests",
        "usd": 3
      },
      {
        "item": "CAPTCHA solves, Scale",
        "unit": "1k-requests",
        "usd": 1
      },
      {
        "item": "Scale plan",
        "unit": "month",
        "usd": 250,
        "note": "$100 of usage credit each month"
      },
      {
        "item": "Dedicated IP, Scale",
        "unit": "month",
        "usd": 5,
        "note": "Per IP"
      }
    ],
    "provenance": {
      "legalEntity": "Nen Labs, Inc.",
      "domain": "steel.dev",
      "domainRegistered": "2024-07-22",
      "endpointOnVendorDomain": true,
      "terms": "https://steel.dev/terms",
      "privacy": "https://steel.dev/privacy",
      "statusPage": "https://status.steel.dev",
      "changelog": "https://docs.steel.dev/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The terms (last updated 5 February 2025) and the privacy notice (last updated 5 February 2026) name Nen Labs, Inc., 9450 SW Gemini Dr, PMB 34667, Beaverton, OR 97008, United States, and the terms choose Delaware law.",
        "The docs Legal page links to Google Docs copies of the terms and privacy policy and not to steel.dev/terms and steel.dev/privacy. We read the steel.dev pages.",
        "The API answers at api.steel.dev, CDP at connect.steel.dev and x402 at x402.steel.dev. The x402 payment header names api.paysponge.com as the resource.",
        "steel.dev/.well-known/security.txt and docs.steel.dev/.well-known/security.txt both return 404. The site footer's Security link goes to a Vanta trust centre at trust.steel.dev.",
        "RDAP for steel.dev gives a registration date of 2024-07-22.",
        "Changelog entries are numbered and carry dates in page metadata. Number 038 is dated 2 October 2026."
      ],
      "score": 75,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Nen Labs, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "steel.dev, registered 2024-07-22 (2 years)",
          "points": 7,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.steel.dev",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points",
          "points": 3.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.steel.dev",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://steel.dev/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-02-05",
          "words": 7003,
          "points": 3.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated February 5, 2025.",
              "says": "Last updated 2025-02-05"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Legal Terms and your use of the Services are governed by and construed in accordance with the laws of the State of Delaware applicable to agreements made and to be entirely performed within the State of Delaware, without regard to its conflict of law principles.",
              "says": "The law of the State of Delaware"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "NOTWITHSTANDING ANYTHING TO THE CONTRARY CONTAINED HEREIN, OUR LIABILITY TO YOU FOR ANY CAUSE WHATSOEVER AND REGARDLESS OF THE FORM OF THE ACTION, WILL AT ALL TIMES BE LIMITED TO THE LESSER OF THE AMOUNT PAID, IF ANY, BY YOU TO US DURING THE six (6) MONTH PERIOD PRIOR TO ANY CAUSE OF ACTION ARISING OR $5,000.00 USD.",
              "says": "Capped at the lesser of $5,000.00 and the fees paid in the 6 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Any breach of these Intellectual Property Rights will constitute a material breach of our Legal Terms and your right to use our Services will terminate immediately."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We will alert you about any changes by updating the \"Last updated\" date of these Legal Terms, and you waive any right to receive specific notice of each such change.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "The Services are not tailored to comply with industry-specific regulations (Health Insurance Portability and Accountability Act (HIPAA), Federal Information Security Management Act (FISMA), etc.), so if your interactions would be subjected to such laws, you may not use the Services."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "(5) you will not access the Services through automated or non-human means, whether through a bot, script or otherwise;",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "Use the Services as part of any effort to compete with us or otherwise use the Services and/or the Content for any revenue-generating endeavor or commercial enterprise.",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "We reserve the right to change, modify, or remove the contents of the Services at any time or for any reason at our sole discretion without notice.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "WE MAY TERMINATE YOUR USE OR PARTICIPATION IN THE SERVICES OR DELETE YOUR ACCOUNT AND ANY CONTENT OR INFORMATION THAT YOU POSTED AT ANY TIME, WITHOUT WARNING, IN OUR SOLE DISCRETION."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "If the Parties are unable to resolve a Dispute through informal negotiations, the Dispute (except those Disputes expressly excluded below) will be finally and exclusively resolved by binding arbitration."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Users agree not to use the Services to violate any website's terms of service, robots.txt or similar access restrictions.",
              "quote": "Use the Services to violate any website's terms of service, robots.txt, or similar access restrictions"
            },
            {
              "date": "2026-10-08",
              "text": "Users agree not to use a buying agent or purchasing agent to make purchases on the Services.",
              "quote": "Use a buying agent or purchasing agent to make purchases on the Services."
            },
            {
              "date": "2026-10-08",
              "text": "The Services may not be used for commercial endeavours unless the company specifically endorses or approves them.",
              "quote": "The Services may not be used in connection with any commercial endeavors except those that are specifically endorsed or approved by us."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://steel.dev/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-02-05",
          "words": 6919,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated February 5, 2026.",
              "says": "Last updated 2026-02-05"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Want to learn more about what we do with any information we collect?"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice unless otherwise required by law.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We may share information in specific situations and with specific categories of third parties."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We have not sold or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "In certain circumstances, you may also have the right to object to the processing of your personal information."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have questions or comments about your privacy rights, you may email us at compliance@nenlabs.xyz.",
              "says": "compliance@nenlabs.xyz"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "We have implemented measures to protect your personal information, including by using the European Commission's Standard Contractual Clauses for transfers of personal information between our group companies and between us and our third-party providers.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Input, output and personal information used with the AI products are shared with and processed by third-party AI service providers, named as Anthropic, OpenAI and Google Cloud AI.",
              "quote": "As outlined in this Privacy Notice, your input, output, and personal information will be shared with and processed by these AI Service Providers to enable your use of our AI Products for purposes outlined in \"What legal bases do we rely on to process your personal information?\""
            },
            {
              "date": "2026-10-08",
              "text": "Third parties and service providers may use online tracking technologies on the Services for analytics and advertising, including tailoring advertisements to a user's interests.",
              "quote": "We also permit third parties and service providers to use online tracking technologies on our Services for analytics and advertising, including to help manage and display advertisements, to tailor advertisements to your interests"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/steel.json",
    "live": {
      "slug": "steel",
      "probe": {
        "target": "https://api.steel.dev",
        "method": "get",
        "lastAt": "2026-10-08T19:08:59.395782577Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 266,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 435,
        "p95ms24h": 512,
        "samples24h": 42,
        "samples30d": 42,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 42,
            "ok": 42
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.steel.dev",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T17:51:13.678894526Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "steel-dev/steel-browser",
          "version": "v0.5.4-beta",
          "released": "2026-08-25",
          "seenAt": "2026-10-08T16:30:24.00662318Z"
        },
        {
          "registry": "npm",
          "name": "@steel-dev/cli",
          "version": "0.3.1",
          "seenAt": "2026-10-08T16:30:22.800432877Z"
        },
        {
          "registry": "npm",
          "name": "steel-sdk",
          "version": "0.18.0",
          "seenAt": "2026-10-08T16:30:21.796405435Z"
        },
        {
          "registry": "pypi",
          "name": "steel-sdk",
          "version": "0.19.0",
          "released": "2026-06-23",
          "seenAt": "2026-10-08T16:30:22.613655125Z"
        }
      ],
      "githubStars": 7756,
      "npmWeekly": 46988,
      "pypiWeekly": 63315,
      "securityTxt": {
        "url": "https://steel.dev/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:38:32.828125596Z"
      },
      "pages": [
        {
          "url": "https://docs.steel.dev/changelog",
          "kind": "changelog",
          "status": 404,
          "checkedAt": "2026-10-08T18:19:29.693209384Z",
          "changedAt": "0001-01-01T00:00:00Z"
        },
        {
          "url": "https://docs.steel.dev/overview/pricinglimits",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-08T18:19:31.90717024Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "b8c6356ee458"
        },
        {
          "url": "https://steel.dev/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:24:47.574475358Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "574556e30b0e"
        },
        {
          "url": "https://steel.dev/terms",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:24:50.029723662Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "d797ea62e1fb"
        }
      ],
      "updatedAt": "2026-10-08T19:08:59.395782577Z"
    }
  }
}
