Head to head · Browser automation · October 2026 research run

Skyvern vs Steel

Steel scores 70.4 (BB) on agent readiness against Skyvern's 63.1 (B), and leads in 3 of 7 scored categories. Skyvern leads on transparency & trust. Both do browser automation. Steel accepts x402. Skyvern doesn't.

Which one, for what

Skyvern B

Good for Agents that must finish a multi-step job on sites with logins, 2FA and forms, where stored credentials, saved workflows and cached scripts matter more than raw browser time.

Ahead on

  • Transparency & trust, 72 against 64

Watch for

Every API key and OAuth token has full organisation authority. The docs state there are no read-only, per-endpoint or per-resource keys

Steel BB

Good for Agents that need a real cloud browser with persistent profiles, stored logins, CAPTCHA solving and a human takeover path, and teams that want an open-source runtime they can also self-host.

Ahead on

  • Payments & pricing, 75 against 32

Also in its favour

  • Agent-ready, a grade of BB or better
  • An agent can pay per call over x402, with no account
  • No incidents deducted, where Skyvern loses 3 points for them

Watch for

Three incidents of more than an hour hit the API or session creation in the 90 days to 8 October 2026, the longest 5 hours 41 minutes

Score by category

CategoryWeight this runSkyvernSteelEdge
Reliability16%205758Steel +1
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28886Skyvern +2
Agent ergonomics13%16.27679Steel +3
Security & auth14%17.55956Skyvern +3
Payments & pricing10%12.53275Steel +43
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88582Skyvern +3
Transparency & trust7%8.87264Skyvern +8
Negative events≤15-30
Total63.1 · B70.4 · BB

Facts side by side

FactSkyvernSteel
KindHTTP APIHTTP API
VendorIkonomos Inc. (Skyvern)Nen Labs, Inc.
Hosted endpointhttps://api.skyvern.com/v1https://api.steel.dev
TransportsHTTP, Streamable HTTP, stdioHTTP, stdio
AuthOAuth or keyAPI key
PricingFreemiumFreemium
x402noyes, from $0.01/call
LicenceAGPL-3.0 for the open-source server, SDKs and MCP server. Skyvern Cloud is a proprietary service under Skyvern's terms, and its anti-bot measures aren't in the repositoryProprietary cloud service under Steel's terms. steel-browser and the Node and Python SDKs are Apache-2.0. The MCP server and the CLI are MIT
Tools exposed114none
Read-only variant documentednono
llms.txtyesyes
MCP registryio.github.Skyvern-AI/skyvernnot listed
Last release2026-10-012026-10-02
Terms last updated2026-02-272025-02-05
Privacy policy last updated2026-10-012026-02-05
Customer content may train modelsyes, with an opt-outnot found in the text
Terms restrict automated accessnot found in the textyes
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waiveryesyes
Popularity23k stars, 3.2k npm/wk, 1.6k PyPI/wk47k npm/wk, 63k PyPI/wk

Verdicts

Skyvern

The hosted MCP server annotates every tool as read-only or destructive and can advertise a 29 or 32-tool subset in place of 114, and the API has a written six-month deprecation policy. Every key and OAuth token carries full organisation authority, with no read-only or scoped credential, and no request rate limits are documented.

Steel

The hosted API has a public OpenAPI document, per-unit prices, $30 of starting credit and x402 payment for scrape, screenshot and PDF calls. The status page records three API or session-creation incidents of more than an hour in 90 days, and the documented CDP connection puts the API key in the URL.

Before you call either

Skyvern

  1. Connect to https://api.skyvern.com/mcp/x/lean or /x/operate, or send X-Skyvern-Scope, so the client loads 32 or 29 tools. The scope filters the list and does not limit permissions
  2. Use a separate Skyvern organisation for each blast radius. Any key or OAuth token can read and write stored credentials and delete workflows
  3. Never pass passwords to skyvern_act or skyvern_type. Store them as credentials and call skyvern_login
  4. Set max_steps on tasks, or x-max-steps-override on agent runs, to cap credits. A run that reaches the cap ends as timed_out
  5. On 503 from POST /v1/run/agents, wait Retry-After seconds. No run was created, so resubmitting is safe

Steel

  1. Use POST /v1/scrape for pages you only need to read. It starts no session and costs $5 per 1,000 calls, or $0.01 a call by x402
  2. Release every session with POST /v1/sessions/{id}/release and set inactivityTimeout. Browser time bills by the minute, rounded up
  3. Build the CDP URL as wss://connect.steel.dev?apiKey=<key>&sessionId=<id> and keep it out of logs, because it carries the key
  4. Launch sessions end after 15 minutes at most, and timeout cannot be changed on a live session
  5. CAPTCHA solving and Steel's managed proxies on Launch need $10 of paid balance. Free credit does not count

Questions

Which is better for AI agents, Skyvern or Steel?

Steel scores 70.4 (BB) on agent readiness against Skyvern's 63.1 (B), and leads in 3 of 7 scored categories. Skyvern leads on transparency & trust.

Do Skyvern and Steel need an API key?

Skyvern takes an API key or an OAuth sign-in. Steel needs an API key. An agent can also pay Steel per call over x402, with no account.

Can an agent call Skyvern and Steel without installing anything?

Yes. Skyvern has a hosted endpoint at https://api.skyvern.com/v1 and Steel at https://api.steel.dev.

Are Skyvern and Steel open source?

Yes. Skyvern is open source (AGPL-3.0 for the open-source server, SDKs and MCP server. Skyvern Cloud is a proprietary service under Skyvern's terms, and its anti-bot measures aren't in the repository). Steel is open source (Proprietary cloud service under Steel's terms. steel-browser and the Node and Python SDKs are Apache-2.0. The MCP server and the CLI are MIT).

Other comparisons with Skyvern or Steel

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.