# Lightpanda 1.0: Out of Beta and Ready for Production

> Source: <https://lightpanda.io/blog/posts/lightpanda-1-0>
> Published: 2026-10-02 00:00:00+00:00

# Lightpanda 1.0: Out of Beta and Ready for Production

### Francis Bouvier

#### Cofounder & CEO

## TL;DR

After two years of hard work and 10,000 commits, Lightpanda is no longer in beta. It passes more than 1.7 million Web Platform Tests (WPT) subtests and now enforces CORS (Cross-Origin Resource Sharing) by default. It’s used in production by AI agents, search APIs, indexing and data extraction companies to retrieve billions of web pages every day.

The full changelog is in the [1.0.0 release notes](https://github.com/lightpanda-io/browser/releases/tag/1.0.0) .

## Why we built Lightpanda

Lightpanda started with a problem we lived with for years. At our previous company, we gathered data from over 20 million pages a day on a fleet of headless Chrome instances, and keeping it running was expensive and painful. So [we built the browser we wished we’d had](https://lightpanda.io/blog/posts/why-build-a-new-browser) .

Today you can drive it the way your stack already works: through Puppeteer, Playwright, Selenium, or ChromeDP. You can also install it straight into your project with `pip install lightpanda` or `npm install @lightpanda/browser`. For agents, we ship a native MCP server. You can also call it from the CLI to dump HTML, markdown or a semantic tree, or hand it a plain-English task in agent mode.

## Why Lightpanda is ready for production

Our browser engine is built from scratch from first principles: written in Zig, no graphical rendering, running the modern web’s JavaScript at a fraction of Chrome’s memory and CPU.

When we published the beta in November 2024, many sites wouldn’t load due to incomplete web API coverage. This is a continuous process (even for Chrome). But today, we are confident that you can depend on Lightpanda in production.

Two things had to be true before we dropped the beta label. Lightpanda had to run enough of the web platform that real sites work. It also had to enforce the security rules other browsers enforce, because it runs code you didn’t write.

## 1.7 million passing WPT subtests

Lightpanda passes 1,739,845 subtests of the [Web Platform Tests](https://web-platform-tests.org/) , the shared conformance suite browser vendors use to check that they implement web standards the same way. In November 2024, it passed 2,645. Every run is public on our [WPT dashboard](https://perf.lightpanda.io/wpt) .

### Where the growth came from

1. **November 2024 to March 2026:** API work on the[DOM](https://lightpanda.io/blog/posts/migrating-our-dom-to-zig)  , HTML, Fetch, URL, cookies and events took Lightpanda from 2,645 to roughly 290,000 passing subtests.
2. **April 2026:** the encoding/ suite started passing. It holds about 1.15 million subtests, mostly large generated tables of character mappings, so the count jumped in a few days.
3. **April to September 2026:** about 340,000 more from workers, Shadow DOM, IndexedDB, XPath, WebSockets and forms.

### How Lightpanda compares with Chrome and Firefox

For context, Chrome passes 2,184,491 subtests and Firefox passes 2,137,997, according to their [September 2026 runs on wpt.fyi](https://wpt.fyi/results/) . Lightpanda sits at about 80% of Chrome’s count.

Most of that gap comes from the choice we made on day one not to do graphical rendering. More than half of the subtests Chrome passes and Lightpanda doesn’t are in the CSS, editing and SVG suites, which test layout and painting.

## CORS is one part of a wider security push

### What CORS does

Starting with [Lightpanda 1.0](https://github.com/lightpanda-io/browser/releases/tag/1.0.0) , the browser enforces CORS on every `fetch()` and `XMLHttpRequest` a page makes. If a server hasn’t said a cross-origin page may read its response, the page can’t read it.

Every browser applies the **same-origin policy**: a script loaded from one origin (scheme, host and port) can’t read responses from another. [CORS](https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CORS)  is how a server relaxes that rule. It opts in with response headers such as `Access-Control-Allow-Origin`.

For requests that could change state, like a `PUT` or a request carrying custom headers, the browser first sends an `OPTIONS` request called a **preflight**. It only sends the real request if the server’s answer allows it. The rules are defined in the [Fetch standard](https://fetch.spec.whatwg.org/#http-cors-protocol) .

For a headless browser running inside your cloud network, often driven by an AI agent visiting pages nobody vetted, skipping these checks is an important security concern. A malicious page could call an internal service or an API the session is logged into, and read what comes back.

A dedicated headless browser already limits security risks, because it doesn’t carry the logged-in sessions of your everyday browser. We wrote more about [browser security in the age of AI agents](https://lightpanda.io/blog/posts/browser-security-in-the-age-of-ai-agents)  and why we think every agent deserves its own browser.

Lightpanda passes 371 of the 463 subtests in the cors/ suite, or 80%. We’re working through the remaining 92, and you can follow progress on the [dashboard](https://perf.lightpanda.io/wpt) .

### Other security fixes

In the past six months, we also shipped:

- **Opt-in resource loading (0.4.0):** iframes, workers and external stylesheets only load when you ask for them with`--load-resources` . Less of a page’s code runs unless your job needs it.
- **Authorization stripped on cross-origin redirects (0.4.0):** credentials you set for one host don’t follow a redirect to another.
- **Stricter cookies (0.2.9 to 0.4.1):** page JavaScript can’t modify HttpOnly cookies, SameSite=Strict holds on cross-site navigation, the SameSite=Lax exception only covers safe methods, and Set-Cookie domains that are public suffixes get rejected.
- **Network filtering (0.2.9 onward):**`--block-cidrs` and`--block-private-networks` keep the browser away from address ranges you choose, such as private subnets or cloud metadata endpoints.
- **Parser and protocol hardening:** fixes for CR/LF injection through the URL authority (0.3.1) and integer overflow in WebSocket message-length parsing (0.4.1), plus dozens of use-after-free and double-free fixes across releases.

We publish a [security policy](https://github.com/lightpanda-io/browser/blob/main/SECURITY.md)  for reporting vulnerabilities.

### Running the latest V8

Lightpanda 1.0 ships with V8 15.5.35.13, the latest stable release of the JavaScript engine behind Chrome and Node.js ([browser#3676](https://github.com/lightpanda-io/browser/pull/3676) , [zig-v8-fork#215](https://github.com/lightpanda-io/zig-v8-fork/pull/215) ). The upgrade means the security fixes that land in V8 also apply to Lightpanda.

V8 runs every line of JavaScript a page sends you, so keeping it current matters as much as CORS.

## Lightpanda in production

Companies use Lightpanda in production for AI agents, indexing, search and data extraction, some at more than 30 million pages a day each.

[Keenable](https://keenable.ai/blog/keenable-raised-26m-to-beat-google-in-the-agentic-search-market) , which builds web search for AI agents, runs Lightpanda for search and indexing. [Ilya Bogin](https://www.linkedin.com/in/ilya-bogin/) , Member of Technical Staff at Keenable, explains why:

When agents retrieve information from the web, they can often read it directly from HTML. But most of the valuable sites render content dynamically. More than 35% of our answers depend on them.

Rendering these pages is up to 400x more expensive than reading static HTML.

Lightpanda makes this scalable: 4x faster and 6x more cost-efficient than Chromium.

[DeveloperHub.io](https://developerhub.io)  moved its prerender service from headless Chrome to Lightpanda. Pages now serve 4x faster and load average dropped 10x. The scheduled restarts and CPU alarms went away with Chrome. Zaid Daba’een, their CEO, put it this way:

I’ve now completely switched to using Lightpanda, rewriting prerender entirely. This change serves pages 4x faster (a conservative estimate, it’s often closer to 6x) and lowering load average by 10x. Instances no longer require a restart, and I’m not receiving CPU alarms anymore.

The full story is in [How DeveloperHub.io cut prerender load by 10x](https://lightpanda.io/blog/posts/how-developerhub-io-cut-prerender-load-by-10x) .

## Built into agent frameworks

### Hermes Agent

[Hermes Agent](https://hermes-agent.nousresearch.com/docs/user-guide/features/browser#lightpanda-local-engine) , from Nous Research, lists Lightpanda as a local browser engine alongside cloud providers. Its docs explain why:

It starts instantly, runs 9x faster and uses 16x less memory than Chrome, which matters for agents that live on small VMs for long stretches.

Switching Hermes to Lightpanda takes three lines in `~/.hermes/config.yaml`:

```
browser:
  cloud_provider: local
  engine: lightpanda
```

Hermes then starts `lightpanda serve` itself, one process per session, so you don’t need Chromium or Node.js installed. For actions Lightpanda doesn’t support yet, such as screenshots, Hermes falls back to Chrome automatically.

### agent-browser

[agent-browser](https://github.com/vercel-labs/agent-browser) , the browser automation CLI for AI agents from Vercel, [runs on Lightpanda](https://agent-browser.dev/engines/lightpanda)  with one flag: `--engine lightpanda`. Pair it with its `batch` command and a separate `--session` per site, and you get several Lightpanda sessions working in parallel:

```
agent-browser --session rust-wiki --engine lightpanda batch "open https://en.wikipedia.org/wiki/Rust_(programming_language)" "get text body" &
agent-browser --session rust-home --engine lightpanda batch "open https://www.rust-lang.org" "get text body" &
wait
```

[Chris Tate](https://x.com/ctatedev/status/2041928222766399805)  from Vercel on the integration:

agent-browser + Lightpanda + batch + multi-session is a dangerous combo. Completed this benchmark task in 5.85s

## Try Lightpanda 1.0

Install it with the command below, or pick another method in the [installation guide](https://lightpanda.io/docs/run-locally/installation/one-liner) :

```
curl -fsSL https://pkg.lightpanda.io/install.sh | bash -s "1.0.0"
```

Pick a page your pipeline navigates today and fetch it:

```
lightpanda fetch --dump markdown https://your-site.example
```

If a page breaks, [open an issue with the URL](https://github.com/lightpanda-io/browser/issues) . DeveloperHub.io filed two before switching, and both were fixed before they moved production over.

Already running Lightpanda? We recommend you keep CORS enabled. If you have trouble with CORS, you can open an issue and use `--disable-features cors` in the meantime.

## What’s next?

Going out of beta does not mean our work is done. We’re working hard every day to increase Web API coverage and pass more WPT subtests.

Our DNA hasn’t changed: speed and memory will always be the priority. And now it matters more than ever. We want Lightpanda to be the default web browser in the era of AI agents and robots.

## FAQ

### What does it mean that Lightpanda is out of beta?

[Lightpanda 1.0](https://github.com/lightpanda-io/browser/releases/tag/1.0.0)  is the first release we consider stable enough to build production systems on. It passes 1,739,845 Web Platform Tests subtests and enforces CORS by default.

### What is CORS and why does a headless browser need it?

CORS (Cross-Origin Resource Sharing) is the mechanism servers use to tell browsers which other origins may read their responses. A browser runs JavaScript from the pages it loads, and that JavaScript can make its own requests. Without CORS, a page could read responses from internal services or other sites the session is logged into.

With CORS enabled in Lightpanda, navigations you drive over CDP, such as `page.goto()`, aren’t affected, but a cross-origin `fetch()` inside `page.evaluate()` now follows CORS rules, exactly as it does in Chrome. We recommend that you keep it on.

### How does Lightpanda compare with Chrome on Web Platform Tests?

Lightpanda [passes 1,739,845 subtests](https://perf.lightpanda.io/wpt) , about 80% of the [2,184,491 that Chrome passes on wpt.fyi](https://wpt.fyi/results/) . Most of the gap is in the CSS, editing and SVG suites, which test layout and painting. Lightpanda has no graphical rendering by design, so it doesn’t target those tests.

### Does Lightpanda render pages or take screenshots?

No. Lightpanda has no graphical rendering pipeline, which is one of the reasons it uses about [16x less memory than headless Chrome](https://github.com/lightpanda-io/demo/blob/main/BENCHMARKS.md) . `--dump png` and `--dump pdf` render the page’s markdown as a PNG or PDF. To see the page the way Lightpanda does, use `--dump markdown` or `--dump semantic_tree_text`, for roles, names, form values and what’s clickable.

### Francis Bouvier

#### Cofounder & CEO

Francis previously cofounded BlueBoard, an ecommerce analytics platform acquired by ChannelAdvisor in 2020. While running large automation systems he saw how limited existing browsers were for this kind of work. Lightpanda grew from his wish to give developers a faster and more reliable way to automate the web.
