My agents run on a rented server — no monitor, no desktop, no browser with me logged in. So when a task needs a site behind a login — a dashboard, a chatbot, a platform with no public interface — my server is standing outside the door.
I needed a way in. What I found was a ladder: every rung up gets you more automation and costs you more fragility.
Rung one was the AI browser agent. The obvious pick: a tool that points a model at a browser and lets it click around like a person. I installed one on the server and nothing worked. Commands timed out, or the browser started and the connection to the agent died mid-sentence. I spent a session convinced it was the browser build. It wasn’t. I swapped in three different versions of Chromium — the system one, the one Playwright downloads for itself, a community build — and the agent failed the same way on all three. The bug was in the layer connecting the agent to the browser, on this server’s processor architecture. Not a setting. A dead end.
Rung two was driving the browser directly. Plain Playwright — a scripted browser with no AI in the loop. Same three builds, and this time every one worked. That’s when the ladder made sense: the browser was never broken. The clever wrapper was. So the base of my setup became the dumbest thing available: a script that opens a page, clicks what I tell it to, and reports what it saw. No model guessing at buttons. It’s dull, and dull is the point — the same command does the same thing every time, and costs nothing to run.
Rung three is where logged-in sites actually open up. A scripted browser still arrives a stranger. What made it work was a tool that turns my logged-in browser tabs into terminal commands — an extension attaches to the browser I’m already signed into, so the site sees me, because it is me. No password ever leaves the browser. But it only works on the machine where I’m sitting.
Rung four is the cookie bridge — the honest workaround. I sign in on my laptop like a normal person, then copy the small file that proves it over to the server. The server presents it and the site lets it in. Two tools do the copying: one pulls cookies out of the browser, the other hands them to a script. The copying interrupts me for three to five seconds each time — the browser has to pause that long to unlock its cookie store. There’s a third approach I researched and didn’t take — it watches me use a site once, then writes a command-line tool that runs without a browser at all. Good for a server, more setup than I needed.
A copied cookie is a real credential — treat it like a password. That file is the whole session. Whoever has it is you, on that site, until it expires — and it will expire, usually within a couple of months, sometimes sooner. So: one cookie per site, never a file that carries everything. Nothing from a bank, a mailbox, or a social account I’d hate to lose. And the rule I’d apply to any password — don’t let it sit somewhere it doesn’t need to be, and assume you’ll replace it on a schedule.
Every rung up the ladder trades setup pain for fragility. The agent needed no script but hung. The script needs writing but never surprises me. The cookie bridge works everywhere and needs re-doing when it expires. Pick the lowest rung that works, and climb only when the rung below genuinely can’t reach.