# Steel
> Steel runs cloud browser sessions for AI agents, controlled through a REST API, a CDP WebSocket, SDKs, a CLI and an official MCP server. Its browser runtime, steel-browser, is open source and can be self-hosted.
- Canonical: https://www.anchorterminal.com/tools/steel
- Markdown: https://www.anchorterminal.com/tools/steel.md (~8,950 tokens)
- Slim: https://www.anchorterminal.com/tools/steel.min.md (~2,080 tokens, same facts, less prose, for token-sensitive contexts)
- JSON: https://www.anchorterminal.com/tools/steel.json (this page as data, same URL with Accept: application/json)
- Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt)
- API: https://www.anchorterminal.com/api/v1/index.json
- Updated: 2026-10-08
## Overview
**Grade BB · 70.4/100 · rank #129 of 629 · #5 in Browser automation · agent-ready · confidence medium**
## Assessment
The hosted API has a public OpenAPI document, per-unit prices, $30 of starting credit and x402 payment for scrape, screenshot and PDF calls. The status page records three API or session-creation incidents of more than an hour in 90 days, and the documented CDP connection puts the API key in the URL.
## Facts
| Field | Value |
| --- | --- |
| Vendor | Nen Labs, Inc. (https://steel.dev) |
| Kind | HTTP API |
| Category | Browser automation (https://www.anchorterminal.com/categories/browser) |
| Transport | HTTP, stdio |
| Endpoint | `https://api.steel.dev` |
| Auth | API key · Self-serve API key from the dashboard at app.steel.dev, sent in the `steel-api-key` header. Keys are named, shown once and revoked by deletion, and the dashboard shows when each was last used. A global key covers the whole organisation, and `POST /v1/api-keys` lets a global key create keys bound to one project. No per-permission scopes were found. CDP connections pass the key as the `apiKey` query parameter on `wss://connect.steel.dev`. The x402 endpoints need no key. A self-hosted steel-browser needs no key. |
| Pricing | Freemium ($0.01 / call) · Launch is $0 plus usage with $30 of one-time credit valid for 90 days, and the quickstart says no card is required. Browser time is $0.10 an hour on Launch and $0.08 on Scale ($250 a month with $100 of monthly credit), billed by the minute and rounded up. Proxy traffic is $10 or $6 a GB, CAPTCHA solves $3 or $1 per 1,000, and scrape, screenshot and PDF calls $5 per 1,000. CAPTCHA solving and managed proxies on Launch need $10 of paid balance. The same three calls cost $0.01 each by x402. Enterprise is priced through sales. Self-hosted steel-browser is free (https://docs.steel.dev/overview/pricinglimits, checked 2026-10-08). |
| x402 | Accepted · from $0.01/call · x402 version 2 on https://x402.steel.dev for scrape, screenshot and PDF at $0.01 a call in USDC on Base or Solana, with no account or API key (https://docs.steel.dev/integrations/x402). An unpaid POST to /v1/scrape on 2026-10-08 returned 402 with a payment-required header for 10000 base units on eip155:8453 and Solana mainnet. The header names https://api.paysponge.com/v1/scrape as the resource, so a third party appears to run the payment layer. Browser sessions and api.steel.dev aren't covered. |
| Licence | Proprietary cloud service under Steel's terms. steel-browser and the Node and Python SDKs are Apache-2.0. The MCP server and the CLI are MIT |
| Packages | npm: `steel-sdk`; pypi: `steel-sdk`; npm: `@steel-dev/cli` |
| Source | https://github.com/steel-dev/steel-browser |
| Docs | https://docs.steel.dev |
| llms.txt | https://docs.steel.dev/llms.txt |
| Last release | 2026-10-02 |
| npm downloads / week | 46,988 |
| PyPI downloads / week | 63,315 |
| Surface graded | Steel Cloud, the hosted API at https://api.steel.dev with CDP at wss://connect.steel.dev. The open-source steel-browser and the MCP server are described but not graded separately |
| API | OpenAPI 3.0.3 with 51 paths and 75 operations under /v1. Sessions, Browser Tools (scrape, screenshot, PDF), Files, Profiles, Credentials, Extensions, Captchas, Projects, Secrets, Environments and Computers |
| MCP server | Official, MIT, stdio from GitHub with `npx -y github:steel-dev/steel-mcp-server`, Node 20 or later. 16 tools in the `browse` profile, 3 in `scrape`. Latest tagged release v2.0.1 on 24 August 2026, 3.0.0 on main. Not on npm, not in the MCP registry, no hosted endpoint yet |
| Free tier | Launch plan, $30 of one-time credit valid 90 days, 10 concurrent sessions, 15 minutes a session, 7-day data retention, up to 3 seats |
| Rate limits | 60 requests a minute on Launch and 600 on Scale. Browser Tools 20 requests a minute per organisation. Concurrent sessions 10 on Launch, 100 on Scale, 1,000+ on Enterprise |
| Session limits | Default timeout 5 minutes. Maximum 15 minutes on Launch, 1 hour on Scale, up to 24 hours on Enterprise. `inactivityTimeout` releases an idle session early |
| Errors | JSON error body with `message`, optional `error`, `linkToDocs` and validation `context`. Browser Tools document 402, 408, 429 and 503, with 503 marked safe to retry. The SDKs retry 408, 409, 429 and 5xx twice with backoff |
| Machine payment | x402 version 2 at x402.steel.dev for /v1/scrape, /v1/screenshot and /v1/pdf, $0.01 a call, USDC on Base or Solana |
| SDKs and CLI | Node `steel-sdk` 0.18.0 on npm (16 March 2026, with 0.21.0 previews from September) and Python `steel-sdk` 0.19.0 on PyPI (23 June 2026), both generated by Stainless. Rust and Go SDKs per Steel's blog. CLI `@steel-dev/cli` 0.3.1 on npm, with 0.5.0 previews tagged on GitHub |
| Self-hosting | steel-browser, Apache-2.0, Docker image, latest tag v0.5.4-beta on 25 August 2026. One concurrent session, bring your own proxies |
| Observability | Live session viewer, recordings (can be turned off per session with `recording: false`), session logs, Agent Traces as JSON, and a per-session cost endpoint |
| Security | HIPAA-ready BAA and SSO on Scale and Enterprise per the pricing page. Vanta trust centre at trust.steel.dev. No security.txt |
| Region | Browsers run in us-east only per the session configuration docs. The privacy notice says servers are in the United States |
| Capabilities | browser.control, browser.hosted, browser.debug, web.scrape, web.fetch, scraping.proxies, scraping.anti-bot, pdf.generate |
| Tags | official, hosted, self-hosted, open-source, freemium, no-card, x402, openapi, llms-txt, mcp, python, typescript, proxies, status-page |
| JSON | https://www.anchorterminal.com/api/v1/tools/steel.json |
## Score breakdown (methodology v0.4, October 2026 research run)
Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points.
| Category | Weight | This run | Score (0–100) | Points |
| --- | --- | --- | --- | --- |
| Reliability | 16% | 20 | 58 | 11.6 |
| Performance | 10% | pending | pending | n/a |
| Schema & documentation | 13% | 16.2 | 86 | 14.0 |
| Agent ergonomics | 13% | 16.2 | 79 | 12.8 |
| Security & auth | 14% | 17.5 | 56 | 9.8 |
| Payments & pricing | 10% | 12.5 | 75 | 9.4 |
| Task success | 10% | pending | pending | n/a |
| Maintenance & community | 7% | 8.8 | 82 | 7.2 |
| Transparency & trust (editorial 52, provenance 75) | 7% | 8.8 | 64 | 5.6 |
| Negative events | up to −15 | up to −15 | none recorded | 0 |
| **Total** | | | | **70.4 → BB** |
### Why each score
- Reliability 58: Graded as a hosted service, on Steel Cloud. status.steel.dev runs on Better Stack with Steel API, Dashboard, Proxies and Connections components and 90 days of history (20). The Main API shows 99.762 per cent over 90 days. The page records a 4 hour 10 minute outage for domain and SSL problems on 22 July 2026, 5 hours 41 minutes of capacity errors on session creation on 23 August and 1 hour 55 minutes of failing session creation on 1 October, so several majors (0). Seven other entries include two streaming and recording problems of more than an hour on 23 and 25 September, during which Steel said the API worked normally. Limits are published per plan, 60 and 600 requests a minute, 10 and 100 concurrent sessions, and 20 a minute on Browser Tools (15). Browser Tools document 429 and a 503 marked safe to retry, the Agent Traces API says to wait for `Retry-After`, and the SDKs retry 408, 409, 429 and 5xx twice with backoff. No idempotency keys, though session creation accepts a caller-chosen `sessionId` (10). Support and uptime SLAs are listed for Enterprise only, with no terms published (3). The sessions API is not marked beta (10).
- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.
- Schema & documentation 86: OpenAPI 3.0.3 at docs.steel.dev/openapi.json with 51 paths and 75 operations and the `steel-api-key` header scheme (25). llms.txt, llms-full.txt and a Markdown twin of every docs page (10). 65 of 75 operations carry a description, and the MCP server's tool descriptions say when to use each tool and when to pick another (16). Inputs are typed with enums, UUID formats and list limits of 1 to 100, but `timeout` and `concurrency` carry no real bounds and `useProxy` and `region` have no stated type (11). One shared error schema is attached to most operations and the docs have error tables for Browser Tools and Agent Traces. The spec holds one example, and 429 is declared on session creation only (11). Paths are versioned under /v1 and the changelog is public and numbered, with dates in page metadata. The spec's own version reads 0.0.1 (13).
- Agent ergonomics 79: Scrape returns only the formats asked for (HTML, cleaned HTML, Markdown or readability text), lists take `limit`, and the MCP server holds its 16 tool definitions to a 17,000 byte budget checked in CI, with a three-tool scrape profile (20). Sessions list by cursor with a `status` filter and a default page of 50, other lists take `limit` and `offset`, and traces filter by time and event type (17). Errors return `message`, `linkToDocs` and validation `context`, with documented 401 messages. No stable machine-readable error codes were found (15). No idempotency keys. A caller-chosen `sessionId`, `inactivityTimeout` and release-all help with retries and clean-up, and every MCP tool carries read-only, destructive or idempotent annotations (12). Session creation needs no parameters, and there are SDKs for Node and Python, with Rust and Go per Steel's blog (15).
- Security & auth 56: Named API keys, shown once, revoked by deletion, with last-used times and a rotation guide. A global key covers the organisation and can create keys bound to one project through `POST /v1/api-keys`. No per-permission scopes were found (22). The documented CDP connection passes the key as `apiKey` in the `wss://connect.steel.dev` URL, a secret in a query string (minus 10). No read-only key. Projects isolate sessions, credentials and profiles, stored credentials are typed into pages without being shown to the agent, browser action endpoints reject localhost and private addresses since changelog 038, and the MCP server has a scrape-only profile and hands the browser to a person before logins and payments (13). The MCP server fences page content as untrusted and strips hidden text, and its README warns about injection. The API docs carry no such guidance (10). Session logs, recordings, Agent Traces, per-session cost and exports to JSON or CSV give the operator a per-call trail (13). A Vanta trust centre whose contents did not render for us, a HIPAA-ready BAA and SSO on Scale, and a disclosure policy with response times for the MCP server. No security.txt, bug bounty or certification report was found (8).
- Payments & pricing 75: x402 version 2 at x402.steel.dev for scrape, screenshot and PDF, in USDC on Base or Solana. An unpaid request on 8 October 2026 returned 402 with terms. Browser sessions, the main product, aren't covered, and the payment header names api.paysponge.com as the resource, so partial (20). Per-hour, per-GB and per-1,000-call prices published without login (20). Launch plan with $30 of one-time credit valid 90 days, and the quickstart says no card is required (20). An agent with a wallet gets a scrape, screenshot or PDF with no account, but a browser session needs a person to sign up or run the Stripe CLI, so we award 15 of 20.
- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.
- Maintenance & community 82: Changelog 038 is dated 2 October 2026, and steel-browser's latest commit is 6 October (30). Changelog entries on 24 July, 18 and 25 September and 2 October 2026, plus steel-browser v0.5.4-beta on 25 August and MCP server 3.0.0 on 9 September (20). Public changelog, Discord and email support, and steel-browser merged ten fixes between 20 July and 6 October. GitHub issue reply times were not read (15). Official SDKs exist, but the newest stable releases are npm 0.18.0 from 16 March 2026 and PyPI 0.19.0 from 23 June, with previews in September, and the MCP server is not in the MCP registry (9). CI workflows in steel-browser and a test, byte-budget and conformance suite in the MCP server. Whether they pass was not read (8).
- Transparency & trust 64: Graded on the cloud service, which is closed with published terms. The browser runtime steel-browser and the SDKs are Apache-2.0, and the MCP server and CLI are MIT (24). The privacy notice (5 February 2026) keeps data while an account exists, the pricing page gives 7 and 14 days of data retention, recordings can be turned off per session, and a DPA is linked as a Google Drive file. The terms date from 5 February 2025, the docs Legal page links to Google Docs copies, and the FAQ still describes pricing by concurrent sessions (14). No deprecation policy. Legacy plans stay available after the pricing change, and one docs note says a playback mode will be deprecated without a date (4). The privacy notice names Anthropic, OpenAI and Google Cloud AI as AI processors and says servers are in the United States, and the docs name one region, us-east. No subprocessor list was found outside the trust centre, which did not render for us (10).
Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/steel.md (JSON https://www.anchorterminal.com/fixes/steel.json)
### What we couldn't check
- unchecked: the contents of the Vanta trust centre at trust.steel.dev (certifications, subprocessors, policies), which needs JavaScript and did not render for our reader
- unchecked: GitHub issue counts, reply times, CI results and the star count, because the GitHub API refused us for its rate limit and the issue pages did not parse. Steel's site states 7.8K stars for steel-browser
- unchecked: the DPA, linked from the privacy notice as a Google Drive file, was not opened
- unchecked: the Rust and Go SDKs, taken from Steel's blog index and not read in a registry
- Whether the Launch signup asks for a card. The quickstart says no credit card is required and the pricing page does not say
- Who operates x402.steel.dev. The 402 header names https://api.paysponge.com/v1/scrape as the resource and the docs do not mention a third party
- The authentication page says keys are created and deleted only in the dashboard, while the OpenAPI document has `POST /v1/api-keys` for project-bound keys
- The Node SDK repository has tags v0.19.0 and v0.20.0 (23 June 2026) that are not on npm, where `latest` is 0.18.0
- Steel's llms.txt calls its speed results independent benchmarks while linking to benchmark code in its own steel-dev/browserbench repository. We did not assess the claim and made no deduction
- The docs name us-east as the only region while the OpenAPI description of `region` lists six. The FAQ describes pricing by concurrent sessions, which the pricing page no longer does
### Sources
- home page: (seen 2026-10-08)
- docs index for agents: (seen 2026-10-08)
- pricing and limits: (seen 2026-10-08)
- pricing page: (seen 2026-10-08)
- authentication: (seen 2026-10-08)
- OpenAPI document: (seen 2026-10-08)
- API reference: (seen 2026-10-08)
- x402 integration: (seen 2026-10-08)
- unpaid x402 request, 402 response: (seen 2026-10-08)
- Stripe Projects: (seen 2026-10-08)
- status page: (seen 2026-10-08)
- status page JSON: (seen 2026-10-08)
- incident history: (seen 2026-10-08)
- changelog: (seen 2026-10-08)
- Browser Tools: (seen 2026-10-08)
- Agent Traces API: (seen 2026-10-08)
- session lifecycle: (seen 2026-10-08)
- session configuration and region: (seen 2026-10-08)
- Credentials API: (seen 2026-10-08)
- self-hosted and cloud comparison: (seen 2026-10-08)
- quickstart: (seen 2026-10-08)
- Claude Code integration: (seen 2026-10-08)
- MCP server source: (seen 2026-10-08)
- MCP server releases: (seen 2026-10-08)
- steel-browser source: (seen 2026-10-08)
- Node SDK source: (seen 2026-10-08)
- Node SDK on npm: (seen 2026-10-08)
- Python SDK on PyPI: (seen 2026-10-08)
- MCP registry search: (seen 2026-10-08)
- terms: (seen 2026-10-08)
- privacy notice: (seen 2026-10-08)
- FAQ: (seen 2026-10-08)
- docs Legal page: (seen 2026-10-08)
- trust centre: (seen 2026-10-08)
- security.txt, 404: (seen 2026-10-08)
- pricing update post: (seen 2026-10-08)
- domain registration: (seen 2026-10-08)
## Who's behind it (provenance 75/100, checked 2026-10-08)
| Check | Finding | Points |
| --- | --- | --- |
| Legal entity named | Nen Labs, Inc. | 20/20 |
| Domain age | steel.dev, registered 2024-07-22 (2 years) | 7/15 |
| Endpoint on the vendor's domain | api.steel.dev | 15/15 |
| Terms of service | read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points | 3.1/10 |
| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |
| Status page | status.steel.dev | 10/10 |
| Changelog | published | 10/10 |
| security.txt | not found | 0/10 |
The terms (last updated 5 February 2025) and the privacy notice (last updated 5 February 2026) name Nen Labs, Inc., 9450 SW Gemini Dr, PMB 34667, Beaverton, OR 97008, United States, and the terms choose Delaware law.
The docs Legal page links to Google Docs copies of the terms and privacy policy and not to steel.dev/terms and steel.dev/privacy. We read the steel.dev pages.
The API answers at api.steel.dev, CDP at connect.steel.dev and x402 at x402.steel.dev. The x402 payment header names api.paysponge.com as the resource.
steel.dev/.well-known/security.txt and docs.steel.dev/.well-known/security.txt both return 404. The site footer's Security link goes to a Vanta trust centre at trust.steel.dev.
RDAP for steel.dev gives a registration date of 2024-07-22.
Changelog entries are numbered and carry dates in page metadata. Number 038 is dated 2 October 2026.
### Terms and privacy, as read
A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.
**Terms of service** (https://steel.dev/terms), read 2026-10-08, dated 2025-02-05, states 6 of the 7 things a reader expects.
- To know. Restricts automated access (costs points). "(5) you will not access the Services through automated or non-human means, whether through a bot, script or otherwise;"
- To know. Restricts benchmarking or competitive use (costs points). "Use the Services as part of any effort to compete with us or otherwise use the Services and/or the Content for any revenue-generating endeavor or commercial enterprise."
- To know. Says the terms or the service can change without notice (costs points). "We reserve the right to change, modify, or remove the contents of the Services at any time or for any reason at our sole discretion without notice."
- To know. Says access can be ended without notice or for any reason. "WE MAY TERMINATE YOUR USE OR PARTICIPATION IN THE SERVICES OR DELETE YOUR ACCOUNT AND ANY CONTENT OR INFORMATION THAT YOU POSTED AT ANY TIME, WITHOUT WARNING, IN OUR SOLE DISCRETION."
- To know. Requires arbitration or waives class actions. "If the Parties are unable to resolve a Dispute through informal negotiations, the Dispute (except those Disputes expressly excluded below) will be finally and exclusively resolved by binding arbitration."
- Gives the date it was last updated. Last updated 2025-02-05.
- Names the governing law or courts. The law of the State of Delaware.
- States a limit on its liability. Capped at the lesser of $5,000.00 and the fees paid in the 6 months before the claim.
- Says how changes to the terms are announced. Says it gives notice of a change.
- Not found in the text. Refers to a service level or uptime commitment.
- Also in the text (2026-10-08). Users agree not to use the Services to violate any website's terms of service, robots.txt or similar access restrictions. "Use the Services to violate any website's terms of service, robots.txt, or similar access restrictions"
- Also in the text (2026-10-08). Users agree not to use a buying agent or purchasing agent to make purchases on the Services. "Use a buying agent or purchasing agent to make purchases on the Services."
- Also in the text (2026-10-08). The Services may not be used for commercial endeavours unless the company specifically endorses or approves them. "The Services may not be used in connection with any commercial endeavors except those that are specifically endorsed or approved by us."
**Privacy policy** (https://steel.dev/privacy), read 2026-10-08, dated 2026-02-05, states 8 of the 8 things a reader expects.
- Gives the date it was last updated. Last updated 2026-02-05.
- Says how long data is kept. For as long as needed, with no period named.
- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.
- Gives a privacy contact. compliance@nenlabs.xyz.
- Says where data is transferred or stored. Relies on standard contractual clauses.
- Also in the text (2026-10-08). Input, output and personal information used with the AI products are shared with and processed by third-party AI service providers, named as Anthropic, OpenAI and Google Cloud AI. "As outlined in this Privacy Notice, your input, output, and personal information will be shared with and processed by these AI Service Providers to enable your use of our AI Products for purposes outlined in "What legal bases do we rely on to process your personal information?""
- Also in the text (2026-10-08). Third parties and service providers may use online tracking technologies on the Services for analytics and advertising, including tailoring advertisements to a user's interests. "We also permit third parties and service providers to use online tracking technologies on our Services for analytics and advertising, including to help manage and display advertisements, to tailor advertisements to your interests"
## Live (updated 2026-10-08 18:24 UTC)
- Right now: up, HTTP 200, 452 ms, checked 2026-10-08 18:20 UTC (get on `https://api.steel.dev`)
- Uptime 24h 100.0% (33 probes) · 30 days 100.0% (33 probes) · p50 443 ms · p95 519 ms
- Vendor status page: unknown, no machine-readable status found
- github `steel-dev/steel-browser` v0.5.4-beta, released 2026-08-25
- npm `@steel-dev/cli` 0.3.1
- npm `steel-sdk` 0.18.0
- pypi `steel-sdk` 0.19.0, released 2026-06-23
- security.txt: none
- Watching changelog
- Watching pricing
- Watching privacy
- Watching terms
- Always current: https://www.anchorterminal.com/api/v1/live/steel.json
## Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.
## Prices
| Item | Price | Unit | Note |
| --- | --- | --- | --- |
| Browser, Launch plan | $0.10 | per browser-hour | Billed by the minute, rounded up |
| Browser, Scale plan | $0.08 | per browser-hour | |
| Proxy traffic, Launch | $10 | per GB of traffic | |
| Proxy traffic, Scale | $6 | per GB of traffic | |
| Scrape, screenshot or PDF | $5 | per 1,000 requests | |
| Scrape, screenshot or PDF by x402 | $0.01 | per call | USDC on Base or Solana, no account |
| CAPTCHA solves, Launch | $3 | per 1,000 requests | |
| CAPTCHA solves, Scale | $1 | per 1,000 requests | |
| Scale plan | $250 | per month (plan) | $100 of usage credit each month |
| Dedicated IP, Scale | $5 | per month (plan) | Per IP |
Across all listings: https://www.anchorterminal.com/prices/index.md
## Strengths
- OpenAPI 3.0.3 document with 75 operations, llms.txt and a Markdown twin of every docs page
- x402 at x402.steel.dev for scrape, screenshot and PDF at $0.01 a call in USDC on Base or Solana, with no account
- Per-unit prices published without login, and $30 of one-time credit on the Launch plan
- Official MCP server with 16 annotated tools, a three-tool scrape profile and page content fenced as untrusted
- steel-browser, the browser runtime, is Apache-2.0 and self-hostable with Docker
## Weaknesses
- Three incidents of more than an hour hit the API or session creation in the 90 days to 8 October 2026, the longest 5 hours 41 minutes
- The documented CDP connection passes the API key as `apiKey` in the `wss://connect.steel.dev` URL
- x402 covers the three one-shot endpoints only, so a browser session needs an account and a key
- The MCP server is not on npm or in the MCP registry, and `mcp.steel.dev` is not live per its README
- No deprecation policy or security.txt found, and the trust centre did not render for our reader
## Before you call it (notes for agents)
1. Use `POST /v1/scrape` for pages you only need to read. It starts no session and costs $5 per 1,000 calls, or $0.01 a call by x402
2. Release every session with `POST /v1/sessions/{id}/release` and set `inactivityTimeout`. Browser time bills by the minute, rounded up
3. Build the CDP URL as `wss://connect.steel.dev?apiKey=&sessionId=` and keep it out of logs, because it carries the key
4. Launch sessions end after 15 minutes at most, and `timeout` cannot be changed on a live session
5. CAPTCHA solving and Steel's managed proxies on Launch need $10 of paid balance. Free credit does not count
## Connect
Install:
```bash
npm install steel-sdk
```
First request:
```bash
curl -X POST https://api.steel.dev/v1/scrape -H "steel-api-key: YOUR_KEY" -H "Content-Type: application/json" -d '{"url": "https://example.com"}'
```
Claude Code:
```bash
claude mcp add steel -e STEEL_API_KEY=your-steel-api-key -- npx -y github:steel-dev/steel-mcp-server
```
MCP client configuration:
```json
{
"mcpServers": {
"steel": {
"args": [
"-y",
"github:steel-dev/steel-mcp-server"
],
"command": "npx",
"env": {
"STEEL_API_KEY": "\u003cyour-steel-api-key\u003e"
}
}
}
}
```
Pay per call with x402:
```bash
curl -i -X POST https://x402.steel.dev/v1/scrape -H "Content-Type: application/json" -d '{"url": "https://example.com", "format": ["markdown"]}'
```
Through letme (picks today, calling later): https://letme.dev/steel. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md
## Similar tools
Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.
| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |
| --- | --- | --- | --- | --- | --- | --- |
| Anchor Browser | B | 67.3 | 196 | browser.control, browser.hosted, browser.debug, web.fetch, web.scrape, scraping.proxies, scraping.anti-bot, pdf.generate | no | https://www.anchorterminal.com/tools/anchor-browser.md |
| Browserless | BB | 70.4 | 128 | browser.control, browser.hosted, browser.debug, scraping.anti-bot, scraping.proxies, web.scrape, pdf.generate | no | https://www.anchorterminal.com/tools/browserless.md |
| Airtop | C | 55.3 | 453 | browser.control, browser.hosted, browser.debug, web.scrape, scraping.proxies, scraping.anti-bot | no | https://www.anchorterminal.com/tools/airtop.md |
| Spider | BB | 74.1 | 64 | web.scrape, web.fetch, browser.hosted, scraping.proxies, scraping.anti-bot | yes | https://www.anchorterminal.com/tools/spider-cloud.md |
| Scrapfly | B | 69.6 | 143 | web.scrape, web.fetch, browser.hosted, scraping.proxies, scraping.anti-bot | no | https://www.anchorterminal.com/tools/scrapfly.md |
| Hyperbrowser | B | 66.9 | 205 | browser.control, browser.hosted, web.fetch, web.scrape, scraping.proxies | yes | https://www.anchorterminal.com/tools/hyperbrowser.md |
## Panel reviews (0)
Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .
Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md
## Notable
- x402 at https://x402.steel.dev for scrape, screenshot and PDF, $0.01 a call in USDC on Base or Solana with no account. Browser sessions aren't covered (source: )
- The official MCP server has 16 tools in its default `browse` profile and three in `scrape`, all with read-only or destructive annotations. Version 3.0.0 is on the main branch from 9 September 2026, it is not on npm, and its README says `mcp.steel.dev` is not live yet (source: )
- steel-browser, the open-source runtime, is Apache-2.0 and runs one session at a time when self-hosted, without CAPTCHA solving, managed proxies, the Credentials API or the Files API (source: )
- status.steel.dev shows 99.762 per cent for the Main API over 90 days, with a 4 hour 10 minute outage on 22 July 2026, 5 hours 41 minutes of failed session creation on 23 August and 1 hour 55 minutes on 1 October (source: )
- `stripe projects add steel/browser` creates a Steel account, a project and a project-bound `STEEL_API_KEY` from the Stripe CLI (source: )
- Stored credentials are encrypted per credential with AES-256-GCM under an organisation KMS key and typed into login pages without being shown to the agent, per the docs (source: )
- Steel runs browsers in one region, us-east, and the `region` parameter rejects any other value (source: )
## Compare
- [Airtop vs Steel](https://www.anchorterminal.com/compare/airtop-vs-steel.md): C 55.3 vs BB 70.4
- [Anchor Browser vs Steel](https://www.anchorterminal.com/compare/anchor-browser-vs-steel.md): B 67.3 vs BB 70.4
- [Browser Use vs Steel](https://www.anchorterminal.com/compare/browser-use-vs-steel.md): BB 77.9 vs BB 70.4
- [Browserless vs Steel](https://www.anchorterminal.com/compare/browserless-vs-steel.md): BB 70.4 vs BB 70.4
- [Chrome DevTools MCP vs Steel](https://www.anchorterminal.com/compare/chrome-devtools-mcp-vs-steel.md): BB 77 vs BB 70.4
- [Hyperbrowser vs Steel](https://www.anchorterminal.com/compare/hyperbrowser-vs-steel.md): B 66.9 vs BB 70.4
- [Notte vs Steel](https://www.anchorterminal.com/compare/notte-vs-steel.md): B 63.2 vs BB 70.4
- [Playwright MCP vs Steel](https://www.anchorterminal.com/compare/playwright-mcp-vs-steel.md): B 67.6 vs BB 70.4
- [Puppeteer (archived MCP reference server) vs Steel](https://www.anchorterminal.com/compare/puppeteer-reference-server-archived-vs-steel.md): F 30.6 vs BB 70.4
- [Skyvern vs Steel](https://www.anchorterminal.com/compare/skyvern-vs-steel.md): B 63.1 vs BB 70.4
- [Browserbase vs Steel](https://www.anchorterminal.com/compare/browserbase-vs-steel.md): BB 76.2 vs BB 70.4
## Verify this listing
For the vendor. The badge or a plain link to this page verifies the listing, from a page on steel.dev or one of its subdomains, or the README of github.com/steel-dev/steel-browser. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "steel", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify
HTML badge:
```html
```
Markdown badge, for a README:
```markdown
[](https://www.anchorterminal.com/tools/steel)
```
Plain link:
```html
Steel on Anchor Terminal
```
## Share this listing
For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Steel is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.
- Dark: https://www.anchorterminal.com/assets/share/steel-dark.png
- Light: https://www.anchorterminal.com/assets/share/steel-light.png