An open browser-agent core and managed session service with separately scoped functions, vaults and billing.
Agent & orchestrationopen source
Use Notte as a goal-driven browser agent or as managed browser infrastructure. The local open core and hosted SDK are distinct deployment paths; hosted credential and persona services are not assumed to ship with every local installation.
Teams combining scripted steps with a bounded browser agent
Developers needing managed sessions and documented credential substitution
LOOK ELSEWHERE WHEN
You require verified native desktop control
You need independently audited retention or isolation guarantees from these public pages
Fit recommendations are editorial interpretations of the documented architecture.
Documented capabilities
CAPABILITY
DOCUMENTED STATE
SOURCE
deployment — local-core
The open-core Python example runs a local browser session and requires the operator to supply LLM credentials; hosted NotteClient sessions use the Notte service.
runtime — sessions
Managed sessions expose CDP plus observe, execute and scrape methods; Python context managers and TypeScript use callbacks handle session cleanup.
observability — artifacts
Session documentation lists recordings, live view and browser profiles for debugging and state persistence; validate retention and access policy for the chosen account.
interaction — structured
Agent output can be constrained with a Pydantic response model; the repository also documents uploaded files and session downloads retrieved by file ID.
security / credentialControls — vault
The vault documentation describes replacing placeholder credentials at execution time, outside the LLM call; this is a vendor-described mechanism, not an independent guarantee against every data leak.
pricing — billing
Developer and Startup are monthly credit subscriptions; subscription credits expire each cycle while manual top-ups do not. LLM token costs and enabled proxies remain separate meters.
security / policy — disclosure
The security page publishes a responsible-disclosure channel and links a separate Trust Center; no certification or data-residency conclusion is inferred from this page.
Environment, deployment & control
Environment
browser
Full
desktop
Unknown
mobile
Unknown
Deployment
cloud
Full
local
Full
self Hosted
Unknown
Extensibility
api
Unknown
sdk
Full
mcp
Unknown
bring Your Own Model
Unknown
Control method
screenshots
Unknown
mouse Keyboard
Unknown
dom Or Accessibility
Partial
code Execution
Unknown
Unknown = insufficient public evidence; No evidence = an explicit negative record; N/A = does not apply to this layer.
Trust, oversight & limitations
Documented oversight
human Approval
Unknown
audit Logs
Unknown
sandboxing
Unknown
prompt Injection Defense
Unknown
credential Controls
Partial
Know the boundary
Public security pages describe vendor mechanisms, not an independent security audit. Region and retention details remain unknown.
No marketing reliability or benchmark ranking is imported. Model calls, proxy traffic and functions have distinct cost boundaries.
See Billing meters & conditions below for source dates, units and freshness. No unified calculator quote is available for this product; separately billed services are not a single total price.
Evidence, scope & unresolved questions
Stack classification: L2 / L4. Verified means the cited source supports the statement; it does not mean COMPUTER USE independently tested the product.
verified
status
The official repository provides an installable open core and a separately authenticated hosted SDK; this profile distinguishes both paths.
Verified against official documentation; not independently executed or security-certified.
notte ↗ · Verified Sep 29, 2026 · Recheck every 14 days
Billing meters & conditions
Each amount belongs to the named service, plan and unit. Subscription, runtime, steps and tokens cannot be ranked as a single cheapest price. Rates expire after 14 days; unresolved conflicts are excluded.