Optional add-on

Optional: Browser

Let the agent read public web pages through a managed, sandboxed headless browser.

25 minAdvanced
Alice’s ask

The “What Are Competitors Doing?” request

Before a board meeting Alice asks: “What does this vendor say on their product page?” The database can't answer that. AgentCore Browser gives the agent a managed headless Chromium in the cloud, isolated from your runtime.

Platform

What the platform provisions for you

.env
ENABLE_BROWSER=true
terminal
uv run bootcamp.py deploy
  • Session permissions for your agent role on the AWS-managed aws.browser.v1
  • The browse_web tool, handed to your orchestrator automatically

Flags default to false and need stage 4 or higher. uv run bootcamp.py status shows CODE_INTERPRETER_ENABLED and BROWSER_ENABLED.

You

What you do as a developer

  1. Read the tool

    phase2/app/agent/sandbox_tools.py
    @tool
    def browse_web(url: str) -> str:
        """Open a public web page in a secure AgentCore Browser sandbox and return its title, final URL and visible text.
    
        Args:
            url: Full http(s) URL of the page to open.
        """
        if urlparse(url).scheme not in {"http", "https"}:
            return "Only http(s) URLs are supported."
        with browser_session(REGION, identifier=BROWSER_ID) as client:
            ws_url, headers = client.generate_ws_headers()
            signed = {name: value for name, value in headers.items() if name in SIGNED_HEADERS}
            with connect(ws_url, additional_headers=signed, max_size=None, open_timeout=CDP_TIMEOUT_SECONDS) as socket:
                page = read_page(CdpConnection(socket), url)
        return f"Title: {page['title']}\nURL: {page['url']}\n\n{page['text']}"

    No Playwright: the tool talks Chrome DevTools Protocol over the browser's SigV4-signed websocket (four CDP commands: open a tab, navigate, wait for load, read title and text). It returns the title, the final URL and the first 4,000 characters of visible text.

    terminal
    uv run bootcamp.py invoke "Open https://example.com and use the code interpreter to count the words in its first paragraph." --actor alice-chen
  2. Add a research specialist

    Challenge

    Add a research_agent specialist that reads public pages with browse_web and summarises them with the source URL, and register it with the orchestrator.

    Hint 1

    Same pattern as weather_agent, different tool. AgentCore Browser docs.

    Hint 2

    Import browse_web from sandbox_tools, pass tools=[browse_web], and put guardrails in the prompt: cite the URL, don't guess content the page didn't show.

    Solution
    phase2/app/agent/agent.py (inside build_specialists)
    from sandbox_tools import browse_web
    
    
    @tool
    def research_agent(question: str) -> str:
        """Research public web pages (product pages, news, docs) and summarise them with their URL.
    
        Args:
            question: What to find out, including the URL if known.
        """
        agent = Agent(
            model=make_model(),
            system_prompt="You research public web pages with browse_web. Cite the URL you used. Never guess page content.",
            tools=[browse_web],
            callback_handler=None,
        )
        return str(agent(question))
  3. Deploy and research

    terminal
    uv run bootcamp.py deploy
    uv run bootcamp.py invoke "Summarise https://aws.amazon.com/bedrock/agentcore/ in three bullets" --actor alice-chen
  4. Experiments

    • Compare browse_web with the weather agent's http_request: which pages need a real browser (JavaScript-rendered content)?
    • Only http(s) URLs are accepted. What else would you restrict (domains, page size) and where: prompt, tool or policy?
    • Check the cost of a browsing question with uv run bootcamp.py llm.

Check your work

With ENABLE_BROWSER=true, the stage 4 checks include an extra browser tool check (the agent must read the title of https://example.com with browse_web):

terminal
uv run bootcamp.py test --only 4
expected output (abridged)read only
[PASS] stage 4 ...
[PASS] stage 4 browser tool: The page title is "Example Domain".
terminal
uv run bootcamp.py invoke "Open https://example.com and tell me the page title." --actor alice-chen

Expected answer mentions Example Domain.

Under the hood

Both tools use the AWS-managed built-ins aws.codeinterpreter.v1 and aws.browser.v1. Every call starts a fresh, isolated sandbox session and stops it afterwards, so nothing leaks between participants or requests. When a flag is on, your agent role gets only the session permissions it needs, in the inline policy awsworkshop-<you>-sandbox-tools; the platform sets CODE_INTERPRETER_ENABLED / BROWSER_ENABLED on the runtime, and optional_tools() plus prompt_hints() hand the tools to the orchestrator with a one-line usage hint each.

phase2/app/agent/sandbox_tools.py
def optional_tools() -> list:
    """The sandbox tools this runtime is configured for (empty when both capabilities are off)."""
    tools = []
    if capability_enabled("CODE_INTERPRETER_ENABLED"):
        tools.append(run_python)
    if capability_enabled("BROWSER_ENABLED"):
        tools.append(browse_web)
    return tools