Head to head · Browser automation · October 2026 research run

Steel vs TinyFish

Steel scores 70.4 (BB) on agent readiness against TinyFish's 67.7 (B), and leads in 4 of 7 scored categories. Both do browser automation. Steel accepts x402. TinyFish doesn't.

Which one, for what

Steel BB

Good for Agents that need a real cloud browser with persistent profiles, stored logins, CAPTCHA solving and a human takeover path, and teams that want an open-source runtime they can also self-host.

Ahead on

  • Payments & pricing, 75 against 55
  • Transparency & trust, 64 against 59

Also in its favour

  • Agent-ready, a grade of BB or better
  • An agent can pay per call over x402, with no account
  • Runs on your own machine
  • Open source

Watch for

Three incidents of more than an hour hit the API or session creation in the 90 days to 8 October 2026, the longest 5 hours 41 minutes

TinyFish B

Good for Agents that want one account for a goal-driven web agent, a raw CDP browser, and free search and fetch.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

The terms of 17 August 2026 allow Tiny Fish to train and improve its models on customer data. No opt-out was found in the reviewed pages

Score by category

CategoryWeight this runSteelTinyFishEdge
Reliability16%205860TinyFish +2
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28685Steel +1
Agent ergonomics13%16.27979even
Security & auth14%17.55657TinyFish +1
Payments & pricing10%12.57555Steel +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88280Steel +2
Transparency & trust7%8.86459Steel +5
Negative events≤1500
Total70.4 · BB67.7 · B

Facts side by side

FactSteelTinyFish
KindHTTP APIHTTP API
VendorNen Labs, Inc.Tiny Fish, Inc.
Hosted endpointhttps://api.steel.devhttps://agent.tinyfish.ai
TransportsHTTP, stdioHTTP
AuthAPI keyOAuth or key
PricingFreemiumFreemium
x402yes, from $0.01/callno
LicenceProprietary cloud service under Steel's terms. steel-browser and the Node and Python SDKs are Apache-2.0. The MCP server and the CLI are MITProprietary service under Tiny Fish's terms of service. The MCP proxy @tiny-fish/mcp and the cookbook are MIT. The SDK packages state no licence in npm or PyPI metadata
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listedai.tinyfish.agent/web-agent
Last release2026-10-022026-10-07
Terms last updated2025-02-052026-08-17
Privacy policy last updated2026-02-052025-12-14
Customer content may train modelsnot found in the textyes
Terms restrict automated accessyesyes
Terms restrict benchmarkingyesyes
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waiveryesyes
Popularity47k npm/wk, 63k PyPI/wk5.7k npm/wk, 6.5k PyPI/wk

Verdicts

Steel

The hosted API has a public OpenAPI document, per-unit prices, $30 of starting credit and x402 payment for scrape, screenshot and PDF calls. The status page records three API or session-creation incidents of more than an hour in 90 days, and the documented CDP connection puts the API key in the URL.

TinyFish

OpenAPI documents are published for five APIs, errors carry typed codes and request IDs, and Search and Fetch are free within daily allowances. The terms let Tiny Fish train its models on customer data, run creation takes no idempotency keys, and the status page shows an hour or more of downtime on several days for the Browser and Search APIs.

Before you call either

Steel

  1. Use POST /v1/scrape for pages you only need to read. It starts no session and costs $5 per 1,000 calls, or $0.01 a call by x402
  2. Release every session with POST /v1/sessions/{id}/release and set inactivityTimeout. Browser time bills by the minute, rounded up
  3. Build the CDP URL as wss://connect.steel.dev?apiKey=<key>&sessionId=<id> and keep it out of logs, because it carries the key
  4. Launch sessions end after 15 minutes at most, and timeout cannot be changed on a live session
  5. CAPTCHA solving and Steel's managed proxies on Launch need $10 of paid balance. Free credit does not count

TinyFish

  1. Check result as well as status. A run can be COMPLETED while the goal failed, with result.status set to failure
  2. Don't retry POST /v1/automation/run blindly after a timeout. There are no idempotency keys, so list runs first to avoid duplicates
  3. Use /v1/automation/run-async or /run-sse when a run may need cancelling. Runs started with the synchronous endpoint can't be cancelled
  4. Allow 60 seconds for Browser session creation, connect Playwright to cdp_url (not base_url), and DELETE the session when done because billing is per minute
  5. Never put passwords in goal, which is logged. Pass use_vault: true with credential_item_ids, or use_profile: true for saved login state

Questions

Which is better for AI agents, Steel or TinyFish?

Steel scores 70.4 (BB) on agent readiness against TinyFish's 67.7 (B), and leads in 4 of 7 scored categories.

Do Steel and TinyFish need an API key?

Steel needs an API key. TinyFish takes an API key or an OAuth sign-in. An agent can also pay Steel per call over x402, with no account.

Can an agent call Steel and TinyFish without installing anything?

Yes. Steel has a hosted endpoint at https://api.steel.dev and TinyFish at https://agent.tinyfish.ai.

Are Steel and TinyFish open source?

Steel is open source (Proprietary cloud service under Steel's terms. steel-browser and the Node and Python SDKs are Apache-2.0. The MCP server and the CLI are MIT). No open-source release is listed for TinyFish.

Other comparisons with Steel or TinyFish

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.