# KiteSurf Kitesurf (Cloudflare writes it with a lowercase "s") is a headless web browser that [[Cloudflare]] built for [[AI Agents]]. It runs entirely on top of [[Cloudflare Workers]], inside V8 isolates, and you use it through [[Cloudflare Browser Rendering|Browser Run]] (the product formerly called Browser Rendering) by adding `browser=kitesurf` to the usual endpoints. It was announced on August 6, 2026, during Agents Week, and it is free while in beta. The pitch fits in one sentence: an agent does not need tabs, themes, extensions, device sync or 60 fps scrolling, so why pay for a full desktop browser engine every time it reads a page? ## The problem it solves Agents need browsers. Many tasks fail without one. But engines like Chromium were designed for humans, and they burn so much memory and CPU that giving every agent its own instance gets expensive fast. Cloudflare argues this keeps large parts of the web reserved for the most capable (and most expensive) setups. What an agent cares about is different: token count, context window, scalability, performance and cost. Structured, machine-readable content matters. Pixel-perfect CSS does not. The threat model also changes, because an agent visits whatever the task points it at, and prompt injection and tool safety become first-order concerns (see [[Prompt injection]]). Cloudflare says the "should we build our own browser?" question came up internally for years and was shelved every time. It came back once Workers matured (Wasm support, [[Cloudflare Dynamic Workers|Dynamic Workers]], SQLite-backed [[Cloudflare Durable Objects]], Worker-to-Worker RPC, service bindings) and once Browser Run demand grew with AI. The team said yes 12 weeks before launch; the first commit landed in May 2026. ## How it works The starting point was a proof of concept: an AI agent ported Obscura, an open source headless engine written in [[Rust]] for AI automation, to Workers. It barely worked, and the team took it from there. The Obscura author later wrote on Hacker News that Kitesurf went its own way and is not simply Obscura running on Workers. The design rules they set up front: - **Tests drive the work.** The Web Platform Tests (WPT) gave AI coding agents clear goalposts for standards conformance, while humans handled architecture and review. Because WPT says nothing about real sites, they added multistep [[Puppeteer]] runs on real websites against both Chromium and Kitesurf, with visual regression checks at every step. - **Native Rust compiled to [[Web Assembly (WASM)|WebAssembly]]** with `wasm-bindgen`, avoiding Emscripten's emulation layers. - **Failures degrade, sessions survive.** Any fault becomes a blank frame or a missing element, never a dead session. - **Every page load is untrusted.** Each session starts fresh, and each component only gets the resources it strictly needs. - **Stateless wherever possible**, so a stuck component can be killed and replayed, and you can run a thousand at once. There are three main components, plus one gatekeeper for the network: - **Engine**: the only public-facing part. It speaks the [[Chrome DevTools Protocol (CDP)]] over WebSocket plus HTTP REST, and it is the only component that holds session state. Speaking CDP is the important bit: Puppeteer, [[Playwright]], chrome-remote-interface and the Chrome DevTools frontend all work against it unchanged. - **PageScript**: every page and every out-of-process iframe gets its own long-lived isolate, spun up with Dynamic Workers, holding a clean `globalThis` and the DOM. HTML and CSS parsing reuse parts of Blitz (a modular Rust rendering engine from Dioxus Labs) and Stylo (Firefox's CSS engine). Page scripts and `.wasm` files run inside that same isolate. Workers do not support `eval` natively, so evals go through Boa, a JavaScript engine written in Rust: a runtime running on a runtime. Cloudflare admits it's not optimal and plans to drop Boa once Workers gets native eval. - **PageRenderer**: turns the page scene into pixels with blitz-paint (and Parley for text shaping and line breaking), then returns a PNG, JPEG or PDF. The Engine calls it with a single `renderFrame()` over Workers RPC. It holds no page state, so the Engine can kill and relaunch it whenever a call fails or hangs. - **SandboxOutbound**: the only component allowed to touch the network (enforced by Dynamic Workers). It enforces CORS, injects browser-shaped headers, filters responses and keeps a separate cookie jar per page. Anything that fails policy gets a 403. ## Performance Cloudflare's numbers (medians of five Browser Run Quick Action runs over a 14-URL corpus, against a warm pool of Chromium): | Metric | Kitesurf | Chromium | Difference | | --- | --- | --- | --- | | CPU, screenshot | 380 ms | 1,173 ms | 3.1× less CPU | | CPU, HTML extraction | 229 ms | 877 ms | 3.8× less CPU | | Memory, screenshot | 57.8 MiB | 271.0 MiB | 4.7× less memory | | Memory, HTML extraction | 39.4 MiB | 273.7 MiB | 7.0× less memory | | Wall time, screenshot | 1,148 ms | 637 ms | 1.8× slower | | Wall time, HTML extraction | 820 ms | 472 ms | 1.7× slower | So Chromium wins the stopwatch (a warm JIT beats a cold software renderer, and most of the gap is rasterization and image encoding), while Kitesurf wins on the CPU and memory that drive the bill. That's the trade: slightly slower, much cheaper per session. Conformance moves fast too. The launch post claimed 215,000+ passing WPT tests; the docs page (last updated September 28, 2026) says over 235,000 subtests, with DOM at 97%, HTML 96%, Selection 99%, SVG 97%, Encoding 99%, CORS 95%, XHR 95% and URL 83%. And yes, it runs Doom. ## Availability and pricing - **Beta, free**, behind per-account limits. The Browser Run limits page doesn't list Kitesurf-specific numbers yet. - **Quick Actions**: add `browser=kitesurf` to any Quick Action endpoint (screenshot, content extraction, PDF and so on). - **CDP endpoint**: `wss://api.cloudflare.com/client/v4/accounts/<ACCOUNT_ID>/browser-run/devtools/browser?browser=kitesurf`. Existing Puppeteer, Playwright or chrome-remote-interface code keeps working. - **MCP clients**: point `chrome-devtools-mcp` at that endpoint with a Browser Run API token. Cloudflare's example config is for [[OpenCode]]. - **Playground**: kitesurf.dev (the launch URL, kitesurf.cloudflare.app, now redirects there). It embeds Chrome DevTools, and the Memory panel reports each isolate's WebAssembly footprint. - **Open source later.** Cloudflare says it will publish Kitesurf "once we're ready", so customers can deploy their own copy on their own accounts. No date. Once the beta ends, I'd expect it to follow Browser Run billing (browser hours plus concurrent browsers on Workers Paid), but Cloudflare hasn't announced Kitesurf pricing. ## Limits Kitesurf is not the right choice yet if you need to: - play video or render WebGL; - pass a bot-challenge handshake with real TLS fingerprints; - keep a long, authenticated session with persistent state. For those, use Browser Run's default Chromium. Rendering isn't pixel-perfect, and it implements a subset of CDP (enough for DOM and network inspection, according to Cloudflare). Known-good sites include TodoMVC (vanilla, React, Vue, Angular, Preact), Wikipedia, Hacker News, the Cloudflare blog and much of the Cloudflare dashboard. For anything else the advice is blunt: try it. It also doesn't hide. Browser Run traffic, Chromium or Kitesurf, is always identified as bot traffic by Cloudflare, uses a documented user agent and signs requests with Web Bot Auth. So no free pass through Cloudflare's own bot protection, which was the first question on Hacker News. ## How it fits with other Cloudflare services - **Product home**: [[Cloudflare Browser Rendering|Browser Run]]. Kitesurf is a second engine inside it. The default Chromium engine has run on [[Cloudflare Containers]] since May 2026. Kitesurf skips containers entirely and runs as isolates. - **Runtime**: [[Cloudflare Workers]], all of it: Dynamic Workers for the per-page sandboxes and the network gate, Workers RPC between Engine and PageRenderer, and Static Assets for fonts and images. - **Enablers**: SQLite-backed [[Cloudflare Durable Objects]] are among the platform primitives Cloudflare credits for making it feasible. - **Consumers**: agents built with the [[Cloudflare Agents SDK]] are the obvious users: anything that needs to read a page, extract HTML or grab a screenshot in bursts. - **Neighbor**: the [[Cloudflare Sandbox SDK]] handles the other agent need (running untrusted code in a container), while Kitesurf handles untrusted web pages. ## Community reactions The Hacker News thread (221 points, August 7, 2026) brought out a few useful points: - The Blitz author (nicoburns), who has been building it for 2.5 years, confirmed Kitesurf sits on it and said Cloudflare intends to upstream its patches. Others pointed out that Blitz itself is still labelled pre-alpha. - The person who started Selenium and Appium (hugs) asked for WebDriver BiDi support. Celso Martinho, one of the post's authors, replied that they are keeping a close eye on BiDi. - Two commenters noted that a V8 isolate protects the host from the page, not the agent from the page: a prompt injection doesn't need to escape the sandbox to make the agent misuse its own tools. - Some found it uncomfortable that the company selling bot protection now also sells agent browsers. Others compared it to PhantomJS and to Lightpanda, another headless browser built for agents. My take: watch the economics. A 4.7× to 7× memory cut per session changes how many browsers you can afford per agent. And the architecture (stateless isolates, one network gate, CDP compatibility) shows how far Workers has come since it was a place for small edge functions. What I don't know yet is how fast compatibility will catch up on messy real-world sites. ## References - Cloudflare blog, "Introducing Kitesurf: The agent-first browser that runs in V8 isolates on Cloudflare Workers" (Celso Martinho, Ruskin Constant, Rui Figueira, Luís Duarte; 2026-08-06): https://blog.cloudflare.com/kitesurf/ - Cloudflare docs, Browser Run, Kitesurf (updated 2026-09-28): https://developers.cloudflare.com/browser-run/kitesurf/ - Cloudflare docs, Browser Run pricing: https://developers.cloudflare.com/browser-run/pricing/ - Cloudflare docs, Browser Run limits: https://developers.cloudflare.com/browser-run/limits/ - Cloudflare docs, Browser Run changelog (no Kitesurf entry as of 2026-10-03): https://developers.cloudflare.com/browser-run/changelog/ - Cloudflare docs, Browser Run FAQ (bot detection): https://developers.cloudflare.com/browser-run/faq/ - Cloudflare docs, Dynamic Workers: https://developers.cloudflare.com/dynamic-workers/ - Cloudflare blog, "Browser Run: give your agents a browser" (rename from Browser Rendering, 2026-04-15): https://blog.cloudflare.com/browser-run-for-ai-agents/ - Cloudflare blog, "Browser Run: now running on Cloudflare Containers" (2026-05-13): https://blog.cloudflare.com/browser-run-containers/ - Kitesurf playground: https://kitesurf.dev/ - Benchmark corpus: https://kitesurf.dev/corpus.txt - Hacker News discussion: https://news.ycombinator.com/item?id=49208393 - TechCrunch, "Cloudflare launches Kitesurf, a browser built for AI agents" (Sarah Perez, 2026-08-07): https://techcrunch.com/2026/08/07/cloudflare-launches-kitesurf-a-browser-built-for-ai-agents/ - Blitz: https://github.com/DioxusLabs/blitz - Stylo: https://github.com/servo/stylo - Boa: https://boajs.dev/ - Obscura: https://github.com/h4ckf0r0day/obscura - Web Platform Tests: https://github.com/web-platform-tests/wpt ## Related - [[Cloudflare]] - [[Cloudflare Browser Rendering]] - [[Cloudflare Workers]] - [[Cloudflare Durable Objects]] - [[Cloudflare Containers]] - [[Cloudflare Agents SDK]] - [[Cloudflare Sandbox SDK]] - [[Cloudflare Dynamic Workers]] - [[Chrome DevTools Protocol (CDP)]] - [[WebMCP]] - [[Puppeteer]] - [[Playwright]] - [[Web Assembly (WASM)]] - [[Rust]] - [[AI Agents]] - [[Prompt injection]] - [[Vercel Agent Browser]] - [[Browser Use]]