Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/reins-key.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
"@karnstack/reins": minor
"@reins/extension": minor
---

`reins key set|status|clear typesafe` stores a TypeSafe API key in `~/.reins/credentials.json` (readable only by you), after checking it with TypeSafe. The extension popup gains a Jev section to save, replace or remove the same key. This is the setup for `reins do`. On the extension side: the popup gains the Jev key section and its `reins:call` frame carries a per-call timeout for the slow key check.
12 changes: 7 additions & 5 deletions docs/CHROME_WEB_STORE.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ Each answer below fits its field's 1,000-character limit. Paste verbatim.
**Single purpose description**

```text
reins has one narrow purpose: let the user's own coding agent (software running on their machine) drive their own browser. A local companion daemon — installed by the user via the reins CLI (npm: @karnstack/reins) and bound to 127.0.0.1 — sends commands that this extension executes: list/open/close/focus/group tabs, navigate, click, type, fill forms, scroll, take screenshots, read page text, and read console messages and network requests for debugging. All communication is confined to the user's machine; the extension never contacts a remote server and never sends data anywhere except the user's own local daemon.
reins has one narrow purpose: let the user's own coding agent (software running on their machine) drive their own browser. A local companion daemon — installed by the user via the reins CLI (npm: @karnstack/reins) and bound to 127.0.0.1 — sends commands that this extension executes: list/open/close/focus/group tabs, navigate, click, type, fill forms, scroll, take screenshots, read page text, and read console messages and network requests for debugging. All communication is confined to the user's machine; the extension never contacts a remote server and never sends data anywhere except the user's own local daemon. Optionally, the user can paste an API key for TypeSafe (the service behind `reins do`) into the popup; the extension passes it once to the local daemon, which stores it on the user's machine. The extension never sends it anywhere else.
```

**debugger justification**
Expand Down Expand Up @@ -84,9 +84,11 @@ local agent in the *page* context via the DevTools Protocol — the same as the
user typing into the DevTools console — not remote code executed with extension
privileges.)

**Data usage** — check **none** of the collection boxes. The extension collects
nothing for the developer: no analytics, no telemetry, no remote servers. Page
data is only relayed to the user's own local daemon on 127.0.0.1. Tick all
**Data usage** — check only **Authentication information**: an optional API key
the user types in the popup, passed only to the local daemon. Leave every other
collection box unchecked. The extension collects nothing for the developer: no
analytics, no telemetry, no remote servers. Page data is only relayed to the
user's own local daemon on 127.0.0.1. Tick all
three certification checkboxes (no sale/transfer to third parties; no use
unrelated to the single purpose; no creditworthiness/lending use) — all
truthfully apply, and the form requires all three.
Expand Down Expand Up @@ -127,7 +129,7 @@ Take the reins of your real, logged-in browser from your coding agent.

reins lets AI coding agents — Claude Code, Cursor, Codex, GitHub Copilot, and any tool with a shell — drive the actual Chromium browser you already use, with all your sessions and logins intact. No separate automation profile, no launch flags, no signing in again. Your agent lists tabs, opens pages, clicks, types, fills forms, scrolls, screenshots, reads the page, runs JavaScript, and inspects console and network activity — right in your everyday browser.

Everything stays on your machine. The extension talks only to a small companion program running locally on 127.0.0.1. Nothing is ever sent to a remote server, and no page data leaves your computer.
Everything stays on your machine. The extension talks only to a small companion program running locally on 127.0.0.1. Nothing is sent to a remote server, and no page data leaves your computer, unless you opt in to reins do by saving a TypeSafe API key; then the local companion program (never the extension) sends page state to TypeSafe while a reins do run is working. See https://reins.tech/docs/security#reins-do for exactly what is sent.

HOW IT WORKS

Expand Down
26 changes: 24 additions & 2 deletions docs/PRIVACY.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# reins — Privacy Policy

_Last updated: 2026-09-26_
_Last updated: 2026-09-27_

reins is a browser extension that lets a **local** daemon on your own
machine (installed by you, via the `@karnstack/reins` CLI) drive your
Expand All @@ -19,13 +19,35 @@ browser. It is a developer tool; you install both halves yourself.

## What reins does NOT do

- No data is sent to the developer or to any remote server. There is no
- No data is sent to the developer. The only remote service reins can talk to
is TypeSafe, and only when you've opted in (see below). There is no
analytics, telemetry, tracking, or advertising of any kind.
- No data is sold or shared with third parties.
- Nothing is collected in the background: the extension only acts on explicit
commands sent through the reins CLI on your own machine.
- The extension loads no remote code.

## Optional: reins do with Jev

`reins do` is off until you save a TypeSafe API key (`reins key set typesafe`,
or the Jev section of the extension popup). The key is stored in
`~/.reins/credentials.json` on your machine (readable only by you). Only the
local reins daemon reads that file; the popup passes the key to the daemon
once when you save it.

While a `reins do` run is working, the **daemon** (not the extension) sends
this to `api.typesafe.ai`, under your own TypeSafe account:

- the goal you gave, and your `--fill` names and values
- the tab's URL and title
- visible text in the viewport (up to about 6,000 characters)
- labels, roles and current values of the page's interactive elements
- the run's last 10 actions

Never sent: password, file and hidden inputs. Nothing at all is sent unless you
saved a key and ran `reins do`. The extension itself still makes no remote
requests.

## Security

- The daemon accepts the extension's connection only from `127.0.0.1` and
Expand Down
22 changes: 21 additions & 1 deletion docs/SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -184,6 +184,25 @@ Two limits to keep in mind:
its own trail. The audit log is for review and debugging, not forensics
against a capable attacker.

## reins do and TypeSafe

`reins do` hands page state to TypeSafe's Jev model, which answers typed
multiple-choice questions: which operation, and which observed element. Jev
can only choose among elements reins actually read from the page; its output
never becomes a selector, coordinate or code. Page text can still try to
steer it (prompt injection), so:

- A click whose label contains a money, messaging or deletion word (buy, pay,
send, delete, …) stops the run unless the agent passed `--confirm` for that
label or the goal names it word for word. Unlabeled buttons stop too. This
is a heuristic, not a guarantee: other languages and odd labels can slip past.
- A run that moves to another site stops (`left_site`), and site permissions
still apply on every step (`full` required).
- Ctrl-C, a dead agent, `--timeout` or a daemon restart stop the run before its
next action.
- The key file is `~/.reins/credentials.json` (0600). The key is never
returned by any command, never logged, and never sent to a page.

## Hardening checklist

For running agents against a browser you care about, in rough order of
Expand Down Expand Up @@ -211,4 +230,5 @@ effect:
harness's job (Claude Code permissions, Cursor rules, …); reins governs
what reaches the browser.
- **Telemetry of any kind** — see [PRIVACY.md](PRIVACY.md): no data leaves
your machine.
your machine unless you opt in to `reins do` with a TypeSafe key (see
"reins do and TypeSafe" above).
Loading
Loading