Steel

by Nen Labs, Inc. HTTP API in Browser automation

Hosted Local x402 Agent-ready

Nen Labs, Inc. · steel.dev since 2024 · status page · who's behind it

Steel runs cloud browser sessions for AI agents, controlled through a REST API, a CDP WebSocket, SDKs, a CLI and an official MCP server. Its browser runtime, steel-browser, is open source and can be self-hosted.

Good for Agents that need a real cloud browser with persistent profiles, stored logins, CAPTCHA solving and a human takeover path, and teams that want an open-source runtime they can also self-host.

Is this your product? Claim this listing or verify it

Assessment. The hosted API has a public OpenAPI document, per-unit prices, $30 of starting credit and x402 payment for scrape, screenshot and PDF calls. The status page records three API or session-creation incidents of more than an hour in 90 days, and the documented CDP connection puts the API key in the URL.

Facts

Transport
HTTP, stdio
Endpoint
https://api.steel.dev
Auth
API key
Pricing
Freemium · $0.01 / call
x402
Accepted · from $0.01/call
Licence
Proprietary cloud service under Steel's terms. steel-browser and the Node and Python SDKs are Apache-2.0. The MCP server and the CLI are MIT
Packages
npm steel-sdk
pypi steel-sdk
npm @steel-dev/cli
llms.txt
published
Last release
npm / week
47k
PyPI / week
63k
Surface graded
Steel Cloud, the hosted API at https://api.steel.dev with CDP at wss://connect.steel.dev. The open-source steel-browser and the MCP server are described but not graded separately
API
OpenAPI 3.0.3 with 51 paths and 75 operations under /v1. Sessions, Browser Tools (scrape, screenshot, PDF), Files, Profiles, Credentials, Extensions, Captchas, Projects, Secrets, Environments and Computers
MCP server
Official, MIT, stdio from GitHub with npx -y github:steel-dev/steel-mcp-server, Node 20 or later. 16 tools in the browse profile, 3 in scrape. Latest tagged release v2.0.1 on 24 August 2026, 3.0.0 on main. Not on npm, not in the MCP registry, no hosted endpoint yet
Free tier
Launch plan, $30 of one-time credit valid 90 days, 10 concurrent sessions, 15 minutes a session, 7-day data retention, up to 3 seats
Rate limits
60 requests a minute on Launch and 600 on Scale. Browser Tools 20 requests a minute per organisation. Concurrent sessions 10 on Launch, 100 on Scale, 1,000+ on Enterprise
Session limits
Default timeout 5 minutes. Maximum 15 minutes on Launch, 1 hour on Scale, up to 24 hours on Enterprise. inactivityTimeout releases an idle session early
Errors
JSON error body with message, optional error, linkToDocs and validation context. Browser Tools document 402, 408, 429 and 503, with 503 marked safe to retry. The SDKs retry 408, 409, 429 and 5xx twice with backoff
Machine payment
x402 version 2 at x402.steel.dev for /v1/scrape, /v1/screenshot and /v1/pdf, $0.01 a call, USDC on Base or Solana
SDKs and CLI
Node steel-sdk 0.18.0 on npm (16 March 2026, with 0.21.0 previews from September) and Python steel-sdk 0.19.0 on PyPI (23 June 2026), both generated by Stainless. Rust and Go SDKs per Steel's blog. CLI @steel-dev/cli 0.3.1 on npm, with 0.5.0 previews tagged on GitHub
Self-hosting
steel-browser, Apache-2.0, Docker image, latest tag v0.5.4-beta on 25 August 2026. One concurrent session, bring your own proxies
Observability
Live session viewer, recordings (can be turned off per session with recording: false), session logs, Agent Traces as JSON, and a per-session cost endpoint
Security
HIPAA-ready BAA and SSO on Scale and Enterprise per the pricing page. Vanta trust centre at trust.steel.dev. No security.txt
Region
Browsers run in us-east only per the session configuration docs. The privacy notice says servers are in the United States

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • OpenAPI 3.0.3 document with 75 operations, llms.txt and a Markdown twin of every docs page
  • x402 at x402.steel.dev for scrape, screenshot and PDF at $0.01 a call in USDC on Base or Solana, with no account
  • Per-unit prices published without login, and $30 of one-time credit on the Launch plan
  • Official MCP server with 16 annotated tools, a three-tool scrape profile and page content fenced as untrusted
  • steel-browser, the browser runtime, is Apache-2.0 and self-hostable with Docker

Weaknesses

  • Three incidents of more than an hour hit the API or session creation in the 90 days to 8 October 2026, the longest 5 hours 41 minutes
  • The documented CDP connection passes the API key as apiKey in the wss://connect.steel.dev URL
  • x402 covers the three one-shot endpoints only, so a browser session needs an account and a key
  • The MCP server is not on npm or in the MCP registry, and mcp.steel.dev is not live per its README
  • No deprecation policy or security.txt found, and the trust centre did not render for our reader

Before you call it notes for agents

  1. Use POST /v1/scrape for pages you only need to read. It starts no session and costs $5 per 1,000 calls, or $0.01 a call by x402
  2. Release every session with POST /v1/sessions/{id}/release and set inactivityTimeout. Browser time bills by the minute, rounded up
  3. Build the CDP URL as wss://connect.steel.dev?apiKey=<key>&sessionId=<id> and keep it out of logs, because it carries the key
  4. Launch sessions end after 15 minutes at most, and timeout cannot be changed on a live session
  5. CAPTCHA solving and Steel's managed proxies on Launch need $10 of paid balance. Free credit does not count

Who's behind it provenance 75/100

  • Legal entity namedNen Labs, Inc.20/20
  • Domain agesteel.dev, registered 2024-07-22 (2 years)7/15
  • Endpoint on the vendor's domainapi.steel.dev15/15
  • Terms of serviceread, states 6 of the 7 things a reader expects, and has 3 clauses that cost points3.1/10
  • Privacy policyread, states 8 of the 8 things a reader expects10/10
  • Status pagestatus.steel.dev10/10
  • Changelogpublished10/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service dated 2025-02-05, states 6 of 7, 5 to know

TL;DR Dated 2025-02-05. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on automated access, limits on benchmarking, changes without notice, cut-off without notice or for any reason and arbitration or a class action waiver.

Restricts automated accesscosts points
(5) you will not access the Services through automated or non-human means, whether through a bot, script or otherwise;

A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.

Restricts benchmarking or competitive usecosts points
Use the Services as part of any effort to compete with us or otherwise use the Services and/or the Content for any revenue-generating endeavor or commercial enterprise.

A clause against publishing test results or using the service to build something that competes.

Says the terms or the service can change without noticecosts points
We reserve the right to change, modify, or remove the contents of the Services at any time or for any reason at our sole discretion without notice.

A customer may not hear about a change before it applies.

Says access can be ended without notice or for any reason
WE MAY TERMINATE YOUR USE OR PARTICIPATION IN THE SERVICES OR DELETE YOUR ACCOUNT AND ANY CONTENT OR INFORMATION THAT YOU POSTED AT ANY TIME, WITHOUT WARNING, IN OUR SOLE DISCRETION.

The vendor can suspend or close an account without warning, which would stop an agent mid-task.

Requires arbitration or waives class actions
If the Parties are unable to resolve a Dispute through informal negotiations, the Dispute (except those Disputes expressly excluded below) will be finally and exclusively resolved by binding arbitration.

Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.

Gives the date it was last updated Last updated 2025-02-05
Last updated February 5, 2025.

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of the State of Delaware
These Legal Terms and your use of the Services are governed by and construed in accordance with the laws of the State of Delaware applicable to agreements made and to be entirely performed within the State of Delaware, without regard to its conflict of law principles.

Says where a dispute would be heard and under whose law.

States a limit on its liability Capped at the lesser of $5,000.00 and the fees paid in the 6 months before the claim
NOTWITHSTANDING ANYTHING TO THE CONTRARY CONTAINED HEREIN, OUR LIABILITY TO YOU FOR ANY CAUSE WHATSOEVER AND REGARDLESS OF THE FORM OF THE ACTION, WILL AT ALL TIMES BE LIMITED TO THE LESSER OF THE AMOUNT PAID, IF ANY, BY YOU TO US DURING THE six (6) MONTH PERIOD PRIOR TO ANY CAUSE OF ACTION ARISING OR $5,000.00 USD.

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
Any breach of these Intellectual Property Rights will constitute a material breach of our Legal Terms and your right to use our Services will terminate immediately.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Says it gives notice of a change
We will alert you about any changes by updating the "Last updated" date of these Legal Terms, and you waive any right to receive specific notice of each such change.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
The Services are not tailored to comply with industry-specific regulations (Health Insurance Portability and Accountability Act (HIPAA), Federal Information Security Management Act (FISMA), etc.), so if your interactions would be subjected to such laws, you may not use the Services.

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment

Not found in the text.

Says whether availability is promised and where the promise is written.

Users agree not to use the Services to violate any website's terms of service, robots.txt or similar access restrictions.
Use the Services to violate any website's terms of service, robots.txt, or similar access restrictions

Noted by a second reader on 2026-10-08.

Users agree not to use a buying agent or purchasing agent to make purchases on the Services.
Use a buying agent or purchasing agent to make purchases on the Services.

Noted by a second reader on 2026-10-08.

The Services may not be used for commercial endeavours unless the company specifically endorses or approves them.
The Services may not be used in connection with any commercial endeavors except those that are specifically endorsed or approved by us.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 7,003 words

Privacy policy dated 2026-02-05, states 8 of 8

TL;DR Dated 2026-02-05. States all 8 things a reader expects. The rules found no clause to flag.

Gives the date it was last updated Last updated 2026-02-05
Last updated February 5, 2026.

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
Want to learn more about what we do with any information we collect?

The basic statement a privacy policy exists to make.

Says how long data is kept For as long as needed, with no period named
In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice unless otherwise required by law.

Says when data sent to the service is deleted.

Says who else receives the data
We may share information in specific situations and with specific categories of third parties.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising Says it does not sell personal data
We have not sold or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months.

A plain statement either way.

Says what rights people have over their data
In certain circumstances, you may also have the right to object to the processing of your personal information.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact compliance@nenlabs.xyz
If you have questions or comments about your privacy rights, you may email us at compliance@nenlabs.xyz.

An address or officer to send a request to.

Says where data is transferred or stored Relies on standard contractual clauses
We have implemented measures to protect your personal information, including by using the European Commission's Standard Contractual Clauses for transfers of personal information between our group companies and between us and our third-party providers.

The countries data goes to and the safeguard used.

Input, output and personal information used with the AI products are shared with and processed by third-party AI service providers, named as Anthropic, OpenAI and Google Cloud AI.
As outlined in this Privacy Notice, your input, output, and personal information will be shared with and processed by these AI Service Providers to enable your use of our AI Products for purposes outlined in "What legal bases do we rely on to process your personal information?"

Noted by a second reader on 2026-10-08.

Third parties and service providers may use online tracking technologies on the Services for analytics and advertising, including tailoring advertisements to a user's interests.
We also permit third parties and service providers to use online tracking technologies on our Services for analytics and advertising, including to help manage and display advertisements, to tailor advertisements to your interests

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 6,919 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The terms (last updated 5 February 2025) and the privacy notice (last updated 5 February 2026) name Nen Labs, Inc., 9450 SW Gemini Dr, PMB 34667, Beaverton, OR 97008, United States, and the terms choose Delaware law.

The docs Legal page links to Google Docs copies of the terms and privacy policy and not to steel.dev/terms and steel.dev/privacy. We read the steel.dev pages.

The API answers at api.steel.dev, CDP at connect.steel.dev and x402 at x402.steel.dev. The x402 payment header names api.paysponge.com as the resource.

steel.dev/.well-known/security.txt and docs.steel.dev/.well-known/security.txt both return 404. The site footer's Security link goes to a Vanta trust centre at trust.steel.dev.

RDAP for steel.dev gives a registration date of 2024-07-22.

Changelog entries are numbered and carry dates in page metadata. Number 038 is dated 2 October 2026.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 16:44 UTC

Right nowUpHTTP 200 · 443 ms · 5 minutes ago
Uptime 24h100.0%15 probes
Uptime 30 days100.0%15 probes
p50 24h444 msget
p95 24h519 msopen endpoint

Probed every five minutes at https://api.steel.dev. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

  • Vendor status page unknown, no machine-readable status found · 1 hour ago
  • github steel-dev/steel-browser v0.5.4-beta, released 2026-08-25
  • npm @steel-dev/cli 0.3.1
  • npm steel-sdk 0.18.0
  • pypi steel-sdk 0.19.0, released 2026-06-23
  • GitHub stars 7.8k
  • npm downloads a week 47k
  • PyPI downloads a week 63k
  • security.txt none · 1 hour ago

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/steel.json

Notable

  • x402 at https://x402.steel.dev for scrape, screenshot and PDF, $0.01 a call in USDC on Base or Solana with no account. Browser sessions aren't covered source
  • The official MCP server has 16 tools in its default browse profile and three in scrape, all with read-only or destructive annotations. Version 3.0.0 is on the main branch from 9 September 2026, it is not on npm, and its README says mcp.steel.dev is not live yet source
  • steel-browser, the open-source runtime, is Apache-2.0 and runs one session at a time when self-hosted, without CAPTCHA solving, managed proxies, the Credentials API or the Files API source
  • status.steel.dev shows 99.762 per cent for the Main API over 90 days, with a 4 hour 10 minute outage on 22 July 2026, 5 hours 41 minutes of failed session creation on 23 August and 1 hour 55 minutes on 1 October source
  • stripe projects add steel/browser creates a Steel account, a project and a project-bound STEEL_API_KEY from the Stripe CLI source
  • Stored credentials are encrypted per credential with AES-256-GCM under an organisation KMS key and typed into login pages without being shown to the agent, per the docs source
  • Steel runs browsers in one region, us-east, and the region parameter rejects any other value source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 11.6
Graded as a hosted service, on Steel Cloud. status.steel.dev runs on Better Stack with Steel API, Dashboard, Proxies and Connections components and 90 days of history (20). The Main API shows 99.762 per cent over 90 days. The page records a 4 hour 10 minute outage for domain and SSL problems on 22 July 2026, 5 hours 41 minutes of capacity errors on session creation on 23 August and 1 hour 55 minutes of failing session creation on 1 October, so several majors (0). Seven other entries include two streaming and recording problems of more than an hour on 23 and 25 September, during which Steel said the API worked normally. Limits are published per plan, 60 and 600 requests a minute, 10 and 100 concurrent sessions, and 20 a minute on Browser Tools (15). Browser Tools document 429 and a 503 marked safe to retry, the Agent Traces API says to wait for Retry-After, and the SDKs retry 408, 409, 429 and 5xx twice with backoff. No idempotency keys, though session creation accepts a caller-chosen sessionId (10). Support and uptime SLAs are listed for Enterprise only, with no terms published (3). The sessions API is not marked beta (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 14.0
OpenAPI 3.0.3 at docs.steel.dev/openapi.json with 51 paths and 75 operations and the steel-api-key header scheme (25). llms.txt, llms-full.txt and a Markdown twin of every docs page (10). 65 of 75 operations carry a description, and the MCP server's tool descriptions say when to use each tool and when to pick another (16). Inputs are typed with enums, UUID formats and list limits of 1 to 100, but timeout and concurrency carry no real bounds and useProxy and region have no stated type (11). One shared error schema is attached to most operations and the docs have error tables for Browser Tools and Agent Traces. The spec holds one example, and 429 is declared on session creation only (11). Paths are versioned under /v1 and the changelog is public and numbered, with dates in page metadata. The spec's own version reads 0.0.1 (13).
Agent ergonomics 13%16.2 12.8
Scrape returns only the formats asked for (HTML, cleaned HTML, Markdown or readability text), lists take limit, and the MCP server holds its 16 tool definitions to a 17,000 byte budget checked in CI, with a three-tool scrape profile (20). Sessions list by cursor with a status filter and a default page of 50, other lists take limit and offset, and traces filter by time and event type (17). Errors return message, linkToDocs and validation context, with documented 401 messages. No stable machine-readable error codes were found (15). No idempotency keys. A caller-chosen sessionId, inactivityTimeout and release-all help with retries and clean-up, and every MCP tool carries read-only, destructive or idempotent annotations (12). Session creation needs no parameters, and there are SDKs for Node and Python, with Rust and Go per Steel's blog (15).
Security & auth 14%17.5 9.8
Named API keys, shown once, revoked by deletion, with last-used times and a rotation guide. A global key covers the organisation and can create keys bound to one project through POST /v1/api-keys. No per-permission scopes were found (22). The documented CDP connection passes the key as apiKey in the wss://connect.steel.dev URL, a secret in a query string (minus 10). No read-only key. Projects isolate sessions, credentials and profiles, stored credentials are typed into pages without being shown to the agent, browser action endpoints reject localhost and private addresses since changelog 038, and the MCP server has a scrape-only profile and hands the browser to a person before logins and payments (13). The MCP server fences page content as untrusted and strips hidden text, and its README warns about injection. The API docs carry no such guidance (10). Session logs, recordings, Agent Traces, per-session cost and exports to JSON or CSV give the operator a per-call trail (13). A Vanta trust centre whose contents did not render for us, a HIPAA-ready BAA and SSO on Scale, and a disclosure policy with response times for the MCP server. No security.txt, bug bounty or certification report was found (8).
Payments & pricing 10%12.5 9.4
x402 version 2 at x402.steel.dev for scrape, screenshot and PDF, in USDC on Base or Solana. An unpaid request on 8 October 2026 returned 402 with terms. Browser sessions, the main product, aren't covered, and the payment header names api.paysponge.com as the resource, so partial (20). Per-hour, per-GB and per-1,000-call prices published without login (20). Launch plan with $30 of one-time credit valid 90 days, and the quickstart says no card is required (20). An agent with a wallet gets a scrape, screenshot or PDF with no account, but a browser session needs a person to sign up or run the Stripe CLI, so we award 15 of 20.
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 7.2
Changelog 038 is dated 2 October 2026, and steel-browser's latest commit is 6 October (30). Changelog entries on 24 July, 18 and 25 September and 2 October 2026, plus steel-browser v0.5.4-beta on 25 August and MCP server 3.0.0 on 9 September (20). Public changelog, Discord and email support, and steel-browser merged ten fixes between 20 July and 6 October. GitHub issue reply times were not read (15). Official SDKs exist, but the newest stable releases are npm 0.18.0 from 16 March 2026 and PyPI 0.19.0 from 23 June, with previews in September, and the MCP server is not in the MCP registry (9). CI workflows in steel-browser and a test, byte-budget and conformance suite in the MCP server. Whether they pass was not read (8).
Transparency & trusteditorial 52, provenance 75 7%8.8 5.6
Graded on the cloud service, which is closed with published terms. The browser runtime steel-browser and the SDKs are Apache-2.0, and the MCP server and CLI are MIT (24). The privacy notice (5 February 2026) keeps data while an account exists, the pricing page gives 7 and 14 days of data retention, recordings can be turned off per session, and a DPA is linked as a Google Drive file. The terms date from 5 February 2025, the docs Legal page links to Google Docs copies, and the FAQ still describes pricing by concurrent sessions (14). No deprecation policy. Legacy plans stay available after the pricing change, and one docs note says a playback mode will be deprecated without a date (4). The privacy notice names Anthropic, OpenAI and Google Cloud AI as AI processors and says servers are in the United States, and the docs name one region, us-east. No subprocessor list was found outside the trust centre, which did not render for us (10).
Negative events≤15None recorded0
Total70.4 · BB

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 20 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Steel, or have the agent fetch /fixes/steel.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Steel

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/steel, the October 2026 research run, assessed 8 October 2026. Grade BB, 70.4 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Steel: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Reliability, 58 out of 100, up to 8.4 more on the total

Why it scored 58: Graded as a hosted service, on Steel Cloud. status.steel.dev runs on Better Stack with Steel API, Dashboard, Proxies and Connections components and 90 days of history (20). The Main API shows 99.762 per cent over 90 days. The page records a 4 hour 10 minute outage for domain and SSL problems on 22 July 2026, 5 hours 41 minutes of capacity errors on session creation on 23 August and 1 hour 55 minutes of failing session creation on 1 October, so several majors (0). Seven other entries include two streaming and recording problems of more than an hour on 23 and 25 September, during which Steel said the API worked normally. Limits are published per plan, 60 and 600 requests a minute, 10 and 100 concurrent sessions, and 20 a minute on Browser Tools (15). Browser Tools document 429 and a 503 marked safe to retry, the Agent Traces API says to wait for `Retry-After`, and the SDKs retry 408, 409, 429 and 5xx twice with backoff. No idempotency keys, though session creation accepts a caller-chosen `sessionId` (10). Support and uptime SLAs are listed for Enterprise only, with no terms published (3). The sessions API is not marked beta (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 2. Security & auth, 56 out of 100, up to 7.7 more on the total

Why it scored 56: Named API keys, shown once, revoked by deletion, with last-used times and a rotation guide. A global key covers the organisation and can create keys bound to one project through `POST /v1/api-keys`. No per-permission scopes were found (22). The documented CDP connection passes the key as `apiKey` in the `wss://connect.steel.dev` URL, a secret in a query string (minus 10). No read-only key. Projects isolate sessions, credentials and profiles, stored credentials are typed into pages without being shown to the agent, browser action endpoints reject localhost and private addresses since changelog 038, and the MCP server has a scrape-only profile and hands the browser to a person before logins and payments (13). The MCP server fences page content as untrusted and strips hidden text, and its README warns about injection. The API docs carry no such guidance (10). Session logs, recordings, Agent Traces, per-session cost and exports to JSON or CSV give the operator a per-call trail (13). A Vanta trust centre whose contents did not render for us, a HIPAA-ready BAA and SSO on Scale, and a disclosure policy with response times for the MCP server. No security.txt, bug bounty or certification report was found (8).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 3. Agent ergonomics, 79 out of 100, up to 3.4 more on the total

Why it scored 79: Scrape returns only the formats asked for (HTML, cleaned HTML, Markdown or readability text), lists take `limit`, and the MCP server holds its 16 tool definitions to a 17,000 byte budget checked in CI, with a three-tool scrape profile (20). Sessions list by cursor with a `status` filter and a default page of 50, other lists take `limit` and `offset`, and traces filter by time and event type (17). Errors return `message`, `linkToDocs` and validation `context`, with documented 401 messages. No stable machine-readable error codes were found (15). No idempotency keys. A caller-chosen `sessionId`, `inactivityTimeout` and release-all help with retries and clean-up, and every MCP tool carries read-only, destructive or idempotent annotations (12). Session creation needs no parameters, and there are SDKs for Node and Python, with Rust and Go per Steel's blog (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 4. Transparency & trust, 64 out of 100, up to 3.2 more on the total

Made of editorial 52, provenance 75.

Why it scored 64: Graded on the cloud service, which is closed with published terms. The browser runtime steel-browser and the SDKs are Apache-2.0, and the MCP server and CLI are MIT (24). The privacy notice (5 February 2026) keeps data while an account exists, the pricing page gives 7 and 14 days of data retention, recordings can be turned off per session, and a DPA is linked as a Google Drive file. The terms date from 5 February 2025, the docs Legal page links to Google Docs copies, and the FAQ still describes pricing by concurrent sessions (14). No deprecation policy. Legacy plans stay available after the pricing change, and one docs note says a playback mode will be deprecated without a date (4). The privacy notice names Anthropic, OpenAI and Google Cloud AI as AI processors and says servers are in the United States, and the docs name one region, us-east. No subprocessor list was found outside the trust centre, which did not render for us (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Domain age: steel.dev, registered 2024-07-22 (2 years) (7 of 15)
- Terms of service: read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points (3.1 of 10)
- security.txt: not found (0 of 10)

## 5. Payments & pricing, 75 out of 100, up to 3.1 more on the total

Why it scored 75: x402 version 2 at x402.steel.dev for scrape, screenshot and PDF, in USDC on Base or Solana. An unpaid request on 8 October 2026 returned 402 with terms. Browser sessions, the main product, aren't covered, and the payment header names api.paysponge.com as the resource, so partial (20). Per-hour, per-GB and per-1,000-call prices published without login (20). Launch plan with $30 of one-time credit valid 90 days, and the quickstart says no card is required (20). An agent with a wallet gets a scrape, screenshot or PDF with no account, but a browser session needs a person to sign up or run the Stripe CLI, so we award 15 of 20.

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 6. Schema & documentation, 86 out of 100, up to 2.3 more on the total

Why it scored 86: OpenAPI 3.0.3 at docs.steel.dev/openapi.json with 51 paths and 75 operations and the `steel-api-key` header scheme (25). llms.txt, llms-full.txt and a Markdown twin of every docs page (10). 65 of 75 operations carry a description, and the MCP server's tool descriptions say when to use each tool and when to pick another (16). Inputs are typed with enums, UUID formats and list limits of 1 to 100, but `timeout` and `concurrency` carry no real bounds and `useProxy` and `region` have no stated type (11). One shared error schema is attached to most operations and the docs have error tables for Browser Tools and Agent Traces. The spec holds one example, and 429 is declared on session creation only (11). Paths are versioned under /v1 and the changelog is public and numbered, with dates in page metadata. The spec's own version reads 0.0.1 (13).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 7. Maintenance & community, 82 out of 100, up to 1.6 more on the total

Why it scored 82: Changelog 038 is dated 2 October 2026, and steel-browser's latest commit is 6 October (30). Changelog entries on 24 July, 18 and 25 September and 2 October 2026, plus steel-browser v0.5.4-beta on 25 August and MCP server 3.0.0 on 9 September (20). Public changelog, Discord and email support, and steel-browser merged ten fixes between 20 July and 6 October. GitHub issue reply times were not read (15). Official SDKs exist, but the newest stable releases are npm 0.18.0 from 16 March 2026 and PyPI 0.19.0 from 23 June, with previews in September, and the MCP server is not in the MCP registry (9). CI workflows in steel-browser and a test, byte-budget and conformance suite in the MCP server. Whether they pass was not read (8).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: the contents of the Vanta trust centre at trust.steel.dev (certifications, subprocessors, policies), which needs JavaScript and did not render for our reader
- unchecked: GitHub issue counts, reply times, CI results and the star count, because the GitHub API refused us for its rate limit and the issue pages did not parse. Steel's site states 7.8K stars for steel-browser
- unchecked: the DPA, linked from the privacy notice as a Google Drive file, was not opened
- unchecked: the Rust and Go SDKs, taken from Steel's blog index and not read in a registry
- Whether the Launch signup asks for a card. The quickstart says no credit card is required and the pricing page does not say
- Who operates x402.steel.dev. The 402 header names https://api.paysponge.com/v1/scrape as the resource and the docs do not mention a third party
- The authentication page says keys are created and deleted only in the dashboard, while the OpenAPI document has `POST /v1/api-keys` for project-bound keys
- The Node SDK repository has tags v0.19.0 and v0.20.0 (23 June 2026) that are not on npm, where `latest` is 0.18.0
- Steel's llms.txt calls its speed results independent benchmarks while linking to benchmark code in its own steel-dev/browserbench repository. We did not assess the claim and made no deduction
- The docs name us-east as the only region while the OpenAPI description of `region` lists six. The FAQ describes pricing by concurrent sessions, which the pricing page no longer does

## Weaknesses

- Three incidents of more than an hour hit the API or session creation in the 90 days to 8 October 2026, the longest 5 hours 41 minutes
- The documented CDP connection passes the API key as `apiKey` in the `wss://connect.steel.dev` URL
- x402 covers the three one-shot endpoints only, so a browser session needs an account and a key
- The MCP server is not on npm or in the MCP registry, and `mcp.steel.dev` is not live per its README
- No deprecation policy or security.txt found, and the trust centre did not render for our reader

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Use `POST /v1/scrape` for pages you only need to read. It starts no session and costs $5 per 1,000 calls, or $0.01 a call by x402
- Release every session with `POST /v1/sessions/{id}/release` and set `inactivityTimeout`. Browser time bills by the minute, rounded up
- Build the CDP URL as `wss://connect.steel.dev?apiKey=<key>&sessionId=<id>` and keep it out of logs, because it carries the key
- Launch sessions end after 15 minutes at most, and `timeout` cannot be changed on a live session
- CAPTCHA solving and Steel's managed proxies on Launch need $10 of paid balance. Free credit does not count

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: the contents of the Vanta trust centre at trust.steel.dev (certifications, subprocessors, policies), which needs JavaScript and did not render for our reader
  • unchecked: GitHub issue counts, reply times, CI results and the star count, because the GitHub API refused us for its rate limit and the issue pages did not parse. Steel's site states 7.8K stars for steel-browser
  • unchecked: the DPA, linked from the privacy notice as a Google Drive file, was not opened
  • unchecked: the Rust and Go SDKs, taken from Steel's blog index and not read in a registry
  • Whether the Launch signup asks for a card. The quickstart says no credit card is required and the pricing page does not say
  • Who operates x402.steel.dev. The 402 header names https://api.paysponge.com/v1/scrape as the resource and the docs do not mention a third party
  • The authentication page says keys are created and deleted only in the dashboard, while the OpenAPI document has POST /v1/api-keys for project-bound keys
  • The Node SDK repository has tags v0.19.0 and v0.20.0 (23 June 2026) that are not on npm, where latest is 0.18.0
  • Steel's llms.txt calls its speed results independent benchmarks while linking to benchmark code in its own steel-dev/browserbench repository. We did not assess the claim and made no deduction
  • The docs name us-east as the only region while the OpenAPI description of region lists six. The FAQ describes pricing by concurrent sessions, which the pricing page no longer does

Sources 37

  1. home page steel.dev · seen 2026-10-08
  2. docs index for agents docs.steel.dev · seen 2026-10-08
  3. pricing and limits docs.steel.dev · seen 2026-10-08
  4. pricing page steel.dev · seen 2026-10-08
  5. authentication docs.steel.dev · seen 2026-10-08
  6. OpenAPI document docs.steel.dev · seen 2026-10-08
  7. API reference steel.apidocumentation.com · seen 2026-10-08
  8. x402 integration docs.steel.dev · seen 2026-10-08
  9. unpaid x402 request, 402 response x402.steel.dev · seen 2026-10-08
  10. Stripe Projects docs.steel.dev · seen 2026-10-08
  11. status page status.steel.dev · seen 2026-10-08
  12. status page JSON status.steel.dev · seen 2026-10-08
  13. incident history status.steel.dev · seen 2026-10-08
  14. changelog docs.steel.dev · seen 2026-10-08
  15. Browser Tools docs.steel.dev · seen 2026-10-08
  16. Agent Traces API docs.steel.dev · seen 2026-10-08
  17. session lifecycle docs.steel.dev · seen 2026-10-08
  18. session configuration and region docs.steel.dev · seen 2026-10-08
  19. Credentials API docs.steel.dev · seen 2026-10-08
  20. self-hosted and cloud comparison docs.steel.dev · seen 2026-10-08
  21. quickstart docs.steel.dev · seen 2026-10-08
  22. Claude Code integration docs.steel.dev · seen 2026-10-08
  23. MCP server source github.com · seen 2026-10-08
  24. MCP server releases github.com · seen 2026-10-08
  25. steel-browser source github.com · seen 2026-10-08
  26. Node SDK source github.com · seen 2026-10-08
  27. Node SDK on npm registry.npmjs.org · seen 2026-10-08
  28. Python SDK on PyPI pypi.org · seen 2026-10-08
  29. MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
  30. terms steel.dev · seen 2026-10-08
  31. privacy notice steel.dev · seen 2026-10-08
  32. FAQ steel.dev · seen 2026-10-08
  33. docs Legal page docs.steel.dev · seen 2026-10-08
  34. trust centre trust.steel.dev · seen 2026-10-08
  35. security.txt, 404 steel.dev · seen 2026-10-08
  36. pricing update post steel.dev · seen 2026-10-08
  37. domain registration rdap.org · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Freemium $0.01 / call Launch is $0 plus usage with $30 of one-time credit valid for 90 days, and the quickstart says no card is required. Browser time is $0.10 an hour on Launch and $0.08 on Scale ($250 a month with $100 of monthly credit), billed by the minute and rounded up. Proxy traffic is $10 or $6 a GB, CAPTCHA solves $3 or $1 per 1,000, and scrape, screenshot and PDF calls $5 per 1,000. CAPTCHA solving and managed proxies on Launch need $10 of paid balance. The same three calls cost $0.01 each by x402. Enterprise is priced through sales. Self-hosted steel-browser is free (https://docs.steel.dev/overview/pricinglimits, checked 2026-10-08).

Prices

ItemPriceUnitNote
Browser, Launch plan$0.10per browser-hourBilled by the minute, rounded up
Browser, Scale plan$0.08per browser-hour
Proxy traffic, Launch$10per GB of traffic
Proxy traffic, Scale$6per GB of traffic
Scrape, screenshot or PDF$5per 1,000 requests
Scrape, screenshot or PDF by x402$0.01per callUSDC on Base or Solana, no account
CAPTCHA solves, Launch$3per 1,000 requests
CAPTCHA solves, Scale$1per 1,000 requests
Scale plan$250per month (plan)$100 of usage credit each month
Dedicated IP, Scale$5per month (plan)Per IP

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/steel.xml, or this listing's score history at history.json.

Connect

Install

npm install steel-sdk

First request

curl -X POST https://api.steel.dev/v1/scrape -H "steel-api-key: YOUR_KEY" -H "Content-Type: application/json" -d '{"url": "https://example.com"}'

Claude Code

claude mcp add steel -e STEEL_API_KEY=your-steel-api-key -- npx -y github:steel-dev/steel-mcp-server

MCP client configuration

{
  "mcpServers": {
    "steel": {
      "args": [
        "-y",
        "github:steel-dev/steel-mcp-server"
      ],
      "command": "npx",
      "env": {
        "STEEL_API_KEY": "\u003cyour-steel-api-key\u003e"
      }
    }
  }
}

Pay per call with x402

curl -i -X POST https://x402.steel.dev/v1/scrape -H "Content-Type: application/json" -d '{"url": "https://example.com", "format": ["markdown"]}'

Through letme picks today, calling later

GET https://letme.dev/steel

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Browserless browserless.io, Inc.BB70.4browser.control browser.hosted browser.debug scraping.anti-bot scraping.proxies web.scrape pdf.generateno
Spider Spider (BAGELMEN LLC)BB74.1web.scrape web.fetch browser.hosted scraping.proxies scraping.anti-bot✓
Scrapfly Scrapfly (Joam Intelligence, LLC)B69.6web.scrape web.fetch browser.hosted scraping.proxies scraping.anti-botno
Hyperbrowser S2 Labs Inc.B66.9browser.control browser.hosted web.fetch web.scrape scraping.proxies✓
Browserbase BrowserbaseBB76.2browser.hosted browser.control web.fetch web.scrape✓
ZenRows ZenRowsBB74.8web.scrape browser.hosted scraping.proxies scraping.anti-botno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Steel on Anchor Terminal, BB, 70.4/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/steel"><img src="https://www.anchorterminal.com/badges/steel.svg" alt="Steel on Anchor Terminal" height="20"></a>
    [![Steel on Anchor Terminal](https://www.anchorterminal.com/badges/steel.svg)](https://www.anchorterminal.com/tools/steel)

    It counts on a page on steel.dev or one of its subdomains, or the README of github.com/steel-dev/steel-browser.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "steel", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.