Steel Review 2026: Browser Infrastructure for AI Agents and Pricing
A research-based Steel review covering features, pricing, privacy, limitations, alternatives, and a practical buyer test.

Bottom line
Steel is an open-source browser API and managed cloud runtime for AI agents, offering sessions, browser tools, proxies, CAPTCHA handling, persistent identity, and credential injection.
Editorial accountability
Who checked this guide
- Evaluation type
- Hands-on evaluation
- Last materially checked
- Evidence
- 4 listed sources
Hands-on testing is identified explicitly. Research-based coverage uses cited product documentation and other named sources; it does not imply every paid plan was used. Read the full methodology.
Editorial freshness
Pricing and material product claims were checked September 9, 2026.
Review evidence
What this guidance is based on
- Editorial basis
- Current first-party product, pricing, documentation, privacy, security, and terms material
- Review type
- Research-based product assessment
- Material review date
- September 9, 2026
- Buyer test
- Controlled workflow test covering quality, cost, privacy, permissions, reliability, and adoption risk
Important limits
- • DiscoverAI did not complete the proposed long-term paid deployment for this research-based review.
- • Features, prices, limits, rights, security controls, privacy terms, and provider data paths can change; verify the linked first-party pages before purchase.
In this guide
Short answer
Steel is a strong infrastructure candidate for developers who need browsers that agents can connect to through Playwright, Selenium, or computer-use models without operating the browser fleet themselves. Persistent profiles, replays, proxies, and credential injection address real production gaps. They also create a high-risk control surface: authenticated browser state can authorize money movement, messages, downloads, and data exposure, so tenant isolation and action policy matter as much as browser uptime.
Best for
- Developers deploying browser and computer-use agents
- Automations requiring persistent authenticated sessions
- Teams needing replayable managed browsers
Look elsewhere if
- Unauthorized automation or terms violations
- Consequential writes without human approval
- Simple HTTP extraction that does not need a browser
What Steel verifiably does
Steel provides managed browser sessions, Chrome DevTools connections, one-shot scrape, screenshot, and PDF endpoints, session replays, files, extensions, residential proxies, CAPTCHA solving, persistent profiles, dedicated IPs, and a beta credentials API that injects passwords and TOTP codes without returning secrets to the agent. SDKs cover TypeScript, Python, Rust, and Go, while integrations include common browser libraries and computer-use models. The core sessions product is open source and self-hostable.
Important limitations
A working browser does not make an agent authorized, correct, or compliant with a site's terms. Persistent profiles store cookies, local state, extensions, and potentially credentials; compromised prompts or tools can still perform harmful actions after login even if the raw secret is hidden. Costs span browser minutes, proxy traffic, CAPTCHA solves, tool calls, dedicated IPs, and the $250 Scale base. Launch retention is seven days, and sessions are limited to 15 minutes.
Steel pricing
Steel Launch is $0 plus usage with $30 in one-time credits valid for 90 days, ten concurrent sessions, and 15-minute sessions. Listed Launch rates include $0.10 per browser hour, $10 per GB of proxy bandwidth, $3 per 1,000 CAPTCHA solves, and $5 per 1,000 one-shot browser-tool calls. Scale is $250 monthly plus usage with $100 monthly credits, 100 concurrent sessions, one-hour sessions, and lower browser, proxy, and CAPTCHA rates. Enterprise is custom. Browser time is billed by the minute and rounded up. Reviewed September 9, 2026.
A fair buyer test
Run 500 approved tasks across public, authenticated, file-download, CAPTCHA, multi-tab, and failure-recovery cases. Use separate least-privilege test accounts and approval-gate every write. Measure completion, wrong-action and duplicate-action rates, credential exposure, tenant isolation, replay usefulness, profile corruption, blocked pages, proxy bandwidth, CAPTCHA solves, browser minutes, cold starts, p95 latency, and total cost per safely completed task. Inject prompt attacks and provider outages before production approval.
Final verdict
Steel earns a pilot for browser-agent teams that need observable, persistent cloud sessions and do not want to manage Chromium infrastructure. Start with read-only tasks, isolate one profile and identity per account, keep spending and domain allowlists tight, and treat credential injection as secret protection—not permission to let an agent act without review.
This is a research-based product assessment, not a claim of hands-on long-term testing. Product, pricing, privacy, security, ownership, and usage claims were checked against the first-party sources below on September 9, 2026. Verify current terms and run the proposed test with approved data before adoption.
Reusable trial worksheet
Test Steel before you commit
Turn this review’s buyer test into evidence. Your entries autosave only in this browser and are never added to shared shortlist links.
Confirm the tool meets every must-have workflow and stakeholder requirement.
Review starting point: Developers deploying browser and computer-use agents; Automations requiring persistent authenticated sessions; Teams needing replayable managed browsers
Run the same representative work you would use in production; do not score a polished demo.
Review starting point: Run 500 approved tasks across public, authenticated, file-download, CAPTCHA, multi-tab, and failure-recovery cases. Use separate least-privilege test accounts and approval-gate every write. Measure completion, wrong-action and duplicate-action rates, credential exposure, tenant isolation, replay usefulness, profile corruption, blocked pages, proxy bandwidth, CAPTCHA solves, browser minutes, cold starts, p95 latency, and total cost per safely completed task. Inject prompt attacks and provider outages before production approval.
Calculate the effective cost per accepted result, including usage, review, corrections, and required add-ons.
Review starting point: Steel Launch is $0 plus usage with $30 in one-time credits valid for 90 days, ten concurrent sessions, and 15-minute sessions. Listed Launch rates include $0.10 per browser hour, $10 per GB of proxy bandwidth, $3 per 1,000 CAPTCHA solves, and $5 per 1,000 one-shot browser-tool calls. Scale is $250 monthly plus usage with $100 monthly credits, 100 concurrent…
Define an acceptance threshold, test known answers and edge cases, and record every correction.
Review starting point: Editorial quality signals: features 4.3/5; AI quality 4.1/5. Validate these signals in your own work.
Verify what data enters the product, who can access it, how long it is retained, and whether it trains models.
Review starting point: Use approved low-risk data first. Check roles, consent, deletion, subprocessors, model-training settings, and the contract—not only the marketing page.
Test the real handoffs, permissions, failure states, and export path your team depends on.
Review starting point: Playwright, Selenium, OpenAI Computer Use, Claude Computer Use, Browser Use, CrewAI
Record training, governance, reliability, accessibility, ownership, and change-management risks before rollout.
Review starting point: Authenticated browser state creates significant security risk; Multiple meters can produce surprise costs; Entry sessions and retention are deliberately limited
Loading saved worksheet… · private to this device or your optional account
Community evidence
How verified users put Steel to work
Structured, editor-moderated experience—not star ratings. This complements our independent review and never changes its score.
No approved community evidence yet. Be the first verified user to contribute.
Sources and verification
Product details and claims were checked against the following primary sources.
Frequently asked questions
What is Steel used for?
Steel provides managed or self-hosted browsers for AI agents, including sessions, profiles, proxies, CAPTCHA handling, credentials, replay, and one-shot browser tools.
How much does Steel cost?
Launch is $0 plus usage with one-time credits, Scale is $250 monthly plus usage and monthly credits, and Enterprise is custom.
Is Steel open source?
Yes. Steel describes its core browser sessions product as open source and offers a Docker-based self-hosting path alongside its managed cloud.
Does Steel keep passwords away from AI agents?
Its beta Credentials API is designed to inject passwords and TOTP codes without exposing raw values, but authenticated sessions still need strict action permissions and isolation.
Found this useful?
Get the next one in your inbox.
One five-minute briefing a week: a meaningful change, a practical workflow, and a clearer tool decision—already filtered for lean teams.
Free · one email a week · unsubscribe any time
Recommended tool
Use Steel if this workflow fits your team
Open-source core with managed cloud option
Tools mentioned in this article
Steel
Run browser agents with managed sessions, proxies, profiles, credentials, replays, and observability
Steel is an open-source browser API and managed cloud runtime for AI agents, offering sessions, browser tools, proxies, CAPTCHA handling, persistent identity, and credential injection.
Browser Use
Open-source and cloud infrastructure for AI agents that navigate websites
Browser Use helps developers run web agents, remote browsers, profiles, proxies, and reusable skills, but reliability, credential custody, website rules, variable usage costs, and human approval are decisive.
E2B
Ephemeral cloud sandboxes for agents that execute code and use virtual computers
E2B isolates agent-generated code in disposable cloud environments, but network egress, secrets, persistence, images, concurrency, and usage cost still require production controls.
Read next
Recommended for you

AgentQL Review 2026: AI Web Extraction, Automation, and Pricing
A research-based AgentQL review covering features, pricing, privacy, limitations, alternatives, and a practical buyer test.
AgentQL is an AI-powered query language and developer toolkit for extracting structured web data and driving browser interactions through REST, Python, JavaScript, and Playwright.
Read guide
Browserbase Review 2026: Cloud Browsers for AI Agents
E2B Review 2026: AI Code Sandboxes, Pricing, Security, and Fit
Browser Use Review 2026: Pricing, Reliability, Privacy, and Fit