{"slug": "why-your-ai-agents-can-t-reach-the-tools-you-re-signed-in-to-and-how-to-fix-it", "title": "Why your AI agents can't reach the tools you're signed in to, and how to fix it", "summary": "A developer has open-sourced Chrome Relay, a tool that lets CLI coding agents such as Claude Code, Codex, Cursor and Paseo drive background tabs in a user's everyday Chrome profile with existing logins intact. Chrome Relay runs an MV3 extension that uses Chrome's chrome.debugger API and a local relay at 127.0.0.1:9333 to expose a standard DevTools endpoint, avoiding the \"Allow remote debugging?\" prompt and keeping agent tabs inactive in a collapsed \"Agents\" tab group. The tool stops rather than entering credentials when a Google sign-in hop reaches a password, passkey or 2-step screen, and Chrome drops the extension's debugger on pages containing another extension's frame, including 1Password's login-form menu.", "body_md": "I usually have a lot of coding agents running on my Mac at once. Most don't need a browser. When one does, it tends to interrupt whatever I'm doing.\n\nAn agent would bring tabs to the front while I was typing, or Chrome would ask \"Allow remote debugging?\" Or the agent would use its own headless browser and have none of my logins. It couldn't open our admin console or a staging environment. Anything behind Google SSO was out, which ruled out most of what I needed it to check.\n\nI now use Chrome Relay to let Claude Code, Codex, Cursor and Paseo drive background tabs in my everyday Chrome, with my real logins, from the command line. Today I'm open-sourcing it.\n\n## What I needed\n\nI had four requirements for an agent's browser.\n\n- It had to work through a CLI. Every agent I use can run shell commands; some can't use a browser extension or an MCP server.\n- It had to use my actual Chrome profiles, already signed in. I didn't want to copy a profile or log into a fresh browser again.\n- It had to stay in the background. I'm working in the same Chrome, so a window coming forward or a dialog is an interruption. Focus has to stay where I put it.\n- It had to be fast. If a page check takes 20 seconds, agents stop doing them.\n\n## What I tried\n\nThe obvious options each failed at least one requirement.\n\nMost browser tools attach to Chrome's debugging port. That gets you the \"Allow remote debugging?\" prompt.\n\nI expected copying my Chrome profile into a separate browser to work. Google sessions are bound to the device, though. Copy the cookies to another browser and Google treats them as invalid. You're signed out of the apps you wanted to use.\n\nI also tried a Playwright extension and separate signed-in browsers. Each covered some of what I needed, but none met all four requirements.\n\nCodex's and Claude's own Chrome extensions use a small extension with Chrome's `chrome.debugger` API. That approach worked. Their extensions only talk to their own app, so I wanted to expose the same thing as a standard DevTools endpoint that any CLI agent could use.\n\n## How it works\n\nThe connection looks like this.\n\n```\nagent-browser (CLI) ──ws──▶ relay (127.0.0.1:9333) ──ws──▶ Chrome Relay extension ──chrome.debugger──▶ agent tab\n```\n\nThe extension is MV3 and loads once in each Chrome profile. It opens every agent tab as an inactive tab in a collapsed \"Agents\" tab group and runs DevTools commands through `chrome.debugger`. Without a debugging port, Chrome doesn't ask \"Allow remote debugging?\"\n\nThe relay is a small local service. It gives each agent its own DevTools endpoint and drops any command that would raise or focus the browser. An agent only sees the tabs it opened, so I can run many agents at once without them stepping on each other.\n\nI use the `chrome-relay` CLI for setup and to get a profile's connection URL. It also runs diagnostics and reads the audit trail.\n\nThe agent uses Vercel's `agent-browser` CLI, pointed at the relay.\n\n```\nagent-browser --cdp \"$(chrome-relay url you@company.com)\" open https://app.example.com/\nagent-browser snapshot -i     # the page's buttons, links and fields, each with a ref\nagent-browser click @e5\nagent-browser close\n```\n\nThe email picks the Chrome profile. I use my work profile for most things and an admin profile when an agent needs to check something in a console.\n\nPopups and \"open in new tab\" links become hidden tabs owned by the same agent. OAuth popups can still report back to the page that opened them.\n\nGoogle sign-in needs some handling too. When a site bounces through Google and the right account is already signed in, the extension clicks the account and Continue itself. Agents never type credentials. If the hop reaches a password, passkey or 2-step screen, it stops. The agent tells me to sign in in my own window.\n\n1Password causes a less obvious problem. Chrome drops an extension's debugger from any page containing another extension's frame, including 1Password's menu on a login form. The relay waits while the extension re-attaches. The agent's commands take a little longer.\n\nSpeed mattered most to me. A command takes about 0.15 s; opening a page takes about 0.6 s. My Chrome is already open, so there's no browser to launch.\n\n## Access and its limits\n\nI'm giving agents access to a browser where I'm signed in to everything. I want to know what can connect and what the agents did once they got in.\n\nEvery connection has to pass two checks. It needs the per-machine secret generated by setup, stored readable only by you. The connecting process also has to be Claude Code, Codex, Cursor or Paseo. The relay looks up the process and checks the markers those apps set on their child processes. Web pages are refused even if they have the secret.\n\nOnly your own copy of the extension can connect as the extension. The relay checks its origin and confirms that the connecting process is Chrome.\n\nThese checks keep other local tools and web pages out, and guard against accidents. Malware already running as you could read the secret and fake the markers, so this doesn't provide a boundary against it.\n\nChrome still shows its \"started debugging this browser\" bar while agents work, the same as with Codex's extension.\n\nEvery agent action goes into an audit log. It records pages and clicks, along with keys and the agent's own scripts. Screenshots and sign-in clicks are logged too. Typed text is stored only as a length; what an agent types never ends up in a log file. When an agent says it checked something, I can look up exactly what it did.\n\n## Try it\n\nIt's macOS and Chrome only for now. You need Node.js 20+ and `agent-browser` (`npm i -g agent-browser`). Setup takes about two minutes.\n\n```\ngit clone https://github.com/aindeev/agent-chrome-relay\ncd agent-chrome-relay\nbin/chrome-relay setup\n```\n\nIn each Chrome profile your agents should use, open `chrome://extensions`, turn on Developer mode, click \"Load unpacked\" and pick the `extension` folder. Run `chrome-relay doctor` to check everything. Or paste the setup prompt from the site into your agent and let it walk you through all of this.\n\nSetup also links a skill into Claude Code, so every repo knows how to use it. For Codex and Cursor, add one line to your global agent instructions pointing at the same skill file.\n\nTry it on a staging page after a deploy, or have your agent check an admin setting. A dashboard behind SSO works as a starting point too. Ask the agent to use your Chrome and keep working while it checks. Hit reply with what you pointed it at, or what broke.\n\nThe repo is MIT: [https://github.com/aindeev/agent-chrome-relay](https://github.com/aindeev/agent-chrome-relay). The site is [https://agent-chrome-relay.aindeev.com](https://agent-chrome-relay.aindeev.com). I'm on X at [@AlexeyIndeev](https://x.com/AlexeyIndeev) too.\n\nAlexey", "url": "https://wpnews.pro/news/why-your-ai-agents-can-t-reach-the-tools-you-re-signed-in-to-and-how-to-fix-it", "canonical_source": "https://read.aindeev.com/p/why-your-ai-agents-cant-reach-the", "published_at": "2026-10-10 08:23:10+00:00", "updated_at": "2026-10-10 08:40:45.781194+00:00", "lang": "en", "topics": ["ai-agents", "developer-tools", "ai-tools", "agent-protocols"], "entities": ["Chrome Relay", "Claude Code", "Codex", "Cursor", "Paseo", "Google", "Chrome", "1Password"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/why-your-ai-agents-can-t-reach-the-tools-you-re-signed-in-to-and-how-to-fix-it", "markdown": "https://wpnews.pro/news/why-your-ai-agents-can-t-reach-the-tools-you-re-signed-in-to-and-how-to-fix-it.md", "text": "https://wpnews.pro/news/why-your-ai-agents-can-t-reach-the-tools-you-re-signed-in-to-and-how-to-fix-it.txt", "jsonld": "https://wpnews.pro/news/why-your-ai-agents-can-t-reach-the-tools-you-re-signed-in-to-and-how-to-fix-it.jsonld"}}