Skip to content
Start here

Get a browser session ID.

POST/accounts/{account_id}/browser-rendering/devtools/browser

Acquires a browser and returns its session ID and websocket URL. Optionally accepts a JSON body with session guardrails to restrict outbound HTTP/S traffic.

Security
API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

Example:X-Auth-Email: user@example.com

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

Example:X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
Accepted Permissions (at least one required)
Browser Rendering Write
Path ParametersExpand Collapse
account_id: string

Account ID.

Query ParametersExpand Collapse
keep_alive: optional number

Keep-alive time in milliseconds.

maximum1200000
minimum10000
lab: optional boolean

Use experimental browser.

liveViewUrlExpiresInMs: optional number

How long the live view URL remains valid, in milliseconds (max 60 minutes). Only used when targets is true.

maximum3600000
minimum60000
recording: optional boolean
targets: optional boolean

Include browser targets in response.

Body ParametersJSONExpand Collapse
guardrails: optional object { allowedDomains, allowedDomainSets }
allowedDomains: optional array of string

Hostname patterns, max 50. Supports exact hosts (example.com) or a single * wildcard anywhere. Prefer *.example.com (subdomain wildcard) over *example.com (prefix wildcard) to avoid matching overbroad lookalikes like evilexample.com.

allowedDomainSets: optional array of string

Max 4 entries: curated preset names (common-cdns) and/or https URLs of newline-separated hostname lists.

ReturnsExpand Collapse
sessionId: string

Browser session ID.

webSocketDebuggerUrl: optional string

WebSocket URL for the session.

Get a browser session ID.

curl https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/browser-rendering/devtools/browser \
    -X POST \
    -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
{
  "sessionId": "sessionId",
  "webSocketDebuggerUrl": "webSocketDebuggerUrl"
}
Returns Examples
{
  "sessionId": "sessionId",
  "webSocketDebuggerUrl": "webSocketDebuggerUrl"
}