# TinyFish (slim) > TinyFish is a hosted web agent platform from Tiny Fish, Inc. Agents call it through REST APIs for goal-driven automation, remote browser sessions over CDP, search, fetch and research, or through a remote MCP server with OAuth. - Full: https://www.anchorterminal.com/tools/tinyfish.md (~8,650 tokens) · this version ~2,080 tokens · JSON https://www.anchorterminal.com/tools/tinyfish.json · canonical https://www.anchorterminal.com/tools/tinyfish - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **B · 67.7/100 · rank #227 of 842 · #6 in Browser automation · not agent-ready · confidence medium** Assessment: OpenAPI documents are published for five APIs, errors carry typed codes and request IDs, and Search and Fetch are free within daily allowances. The terms let Tiny Fish train its models on customer data, run creation takes no idempotency keys, and the status page shows an hour or more of downtime on several days for the Browser and Search APIs. ## Facts - Kind: HTTP API · vendor: Tiny Fish, Inc. · category: Browser automation · legal entity: Tiny Fish, Inc. · provenance 85/100 - Endpoint: `https://agent.tinyfish.ai` (HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Tiny Fish's terms of service. The MCP proxy `@tiny-fish/mcp` and the cookbook are MIT. The SDK packages state no licence in npm or PyPI metadata - Probe metrics: not measured yet (probes haven't run) - Surface graded: The public REST APIs with their Python and TypeScript SDKs. The Agent, profile, vault and wallet routes are at https://agent.tinyfish.ai/v1 (28 operations) and the Browser API at https://api.browser.tinyfish.ai (3). The remote MCP server is noted alongside - Browser control: `POST https://api.browser.tinyfish.ai` returns `session_id`, `cdp_url` and `base_url`. Connect Playwright, Puppeteer or a CDP client to `cdp_url`. `DELETE /{session_id}` ends the session and is idempotent. Creation takes 10 to 30 seconds per the docs - Agent runs: `/v1/automation/run` (synchronous, can't be cancelled), `/run-async`, `/run-batch` and `/run-sse`. Lite or stealth browser, proxy country from US, GB, CA, DE, FR, JP and AU, optional `output_schema`, webhooks, and up to 150 steps by default - Free allowance: Search 12,000 requests a day and Fetch 1,000 URLs a day, reset at 00:00 UTC, working at a $0 balance. New accounts start with $8 of promotional wallet funds, no card required per the pricing page - Rate limits: Search 30 requests a minute and 500 an hour. Fetch 150 URLs a minute. Agent 2 concurrent runs. Browser 5 concurrent sessions. Higher limits by contract. Search and Fetch 429s carry `Retry-After` and `X-RateLimit-*` headers - Session limits: Browser sessions end after an inactivity timeout, `timeout_seconds` from 5 to 86,400, capped at 15 minutes on free accounts and 60 on paid. Sessions are isolated, and saved login state comes from Browser Context Profiles - Machine payment: Machine Payments Protocol on `POST /v1/wallet/top-up`, Stripe Shared Payment Token, $10 to $500 in whole cents, USD. Refills the prepaid wallet. Gradual rollout, API key needed. No x402 - MCP server: Remote, Streamable HTTP at `https://agent.tinyfish.ai/mcp`, OAuth 2.1, 28 tools per the repository reference. `@tiny-fish/mcp` 0.1.0 is a local proxy to it for API-key use (Node 22 or later, MIT). Registry name `ai.tinyfish.agent/web-agent` - SDKs: `tinyfish` 0.9.0 on PyPI (Python 3.11 or later) and `@tiny-fish/sdk` 0.8.0 on npm (Node 18 or later), both of 29 September 2026. `@tiny-fish/cli` 0.48.1 of 7 October 2026 (Node 24 or later) - Credentials for sites: 1Password and Bitwarden vault connections, opt-in per run with `use_vault` and limited with `credential_item_ids`. Browser Context Profiles save cookies and storage for reuse with `use_profile` - Data use: The terms allow Tiny Fish to review runs and to train and improve its models on customer data. The privacy policy states no retention periods. Enterprise data residency is agreed by contract per the enterprise page - Certifications: The terms and the pricing page cite ISO 27001. The trust centre at trust.tinyfish.ai is drawn by script and was unread - Prices: Agent step $0.016 per call; Browser session $0.12 per browser-hour; Search free per 1,000 requests; Fetch free per 1,000 pages; Monitor run $0.005 per call - Scores: Reliability 60, Performance pending, Schema & documentation 85, Agent ergonomics 79, Security & auth 57, Payments & pricing 55, Task success pending, Maintenance & community 80, Transparency & trust 59 · total over the 7 assessed categories - Why: Reliability, Graded as a hosted API. · Schema & documentation, Graded on the REST API. · Agent ergonomics, Fetch takes an output format, include and exclude selectors, a cache age and a per-URL timeout, and run reads choose whether screenshots com… · Security & auth, REST calls take an `X-API-Key` header. · Payments & pricing, `POST /v1/wallet/top-up` on agent.tinyfish.ai answers 402 with a Machine Payments Protocol challenge and takes a Stripe Shared Payment Token… · Maintenance & community, `@tiny-fish/cli` 0.48.1 was published to npm on 7 October 2026, and `@tiny-fish/sdk` 0.8.0 and `tinyfish` 0.9.0 on PyPI on 29 September (30)… · Transparency & trust, The platform is closed with published terms, effective 17 August 2026. The MCP proxy and cookbook are MIT, and the SDK packages state no lic… - Sources: 31, open questions: 10, both in the full twin - Capabilities: browser.control, browser.hosted, web.extract, web.fetch, web.search, search.research, scraping.proxies, scraping.anti-bot - JSON: https://www.anchorterminal.com/api/v1/tools/tinyfish.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/tinyfish.svg` or a link to https://www.anchorterminal.com/tools/tinyfish from a page on tinyfish.ai or one of its subdomains, or the README of github.com/tinyfish-io/tinyfish-mcp-server, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Check `result` as well as `status`. A run can be `COMPLETED` while the goal failed, with `result.status` set to `failure` 2. Don't retry `POST /v1/automation/run` blindly after a timeout. There are no idempotency keys, so list runs first to avoid duplicates 3. Use `/v1/automation/run-async` or `/run-sse` when a run may need cancelling. Runs started with the synchronous endpoint can't be cancelled 4. Allow 60 seconds for Browser session creation, connect Playwright to `cdp_url` (not `base_url`), and `DELETE` the session when done because billing is per minute 5. Never put passwords in `goal`, which is logged. Pass `use_vault: true` with `credential_item_ids`, or `use_profile: true` for saved login state ## Connect ```bash pip install -U tinyfish ``` ```bash curl -X POST https://agent.tinyfish.ai/v1/automation/run -H "X-API-Key: $TINYFISH_API_KEY" -H "Content-Type: application/json" -d '{"url": "https://example.com", "goal": "Extract the page title"}' ``` ```bash claude mcp add --transport http tinyfish https://agent.tinyfish.ai/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/tinyfish ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Spider | BB | 74.1 | web.extract, web.search, web.fetch, browser.hosted, scraping.proxies, scraping.anti-bot | https://www.anchorterminal.com/tools/spider-cloud.min.md | | Hyperbrowser | B | 66.9 | browser.control, browser.hosted, web.fetch, web.extract, web.search, scraping.proxies | https://www.anchorterminal.com/tools/hyperbrowser.min.md | | Notte | B | 63.2 | browser.control, browser.hosted, web.search, web.extract, scraping.proxies, scraping.anti-bot | https://www.anchorterminal.com/tools/notte.min.md | | Browserless | BB | 70.4 | browser.control, browser.hosted, scraping.anti-bot, scraping.proxies, web.search | https://www.anchorterminal.com/tools/browserless.min.md | | Steel | BB | 70.4 | browser.control, browser.hosted, web.fetch, scraping.proxies, scraping.anti-bot | https://www.anchorterminal.com/tools/steel.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)