Skip to content
Insights
Inside

Kitesurf: Cloudflare Built a Browser for Agents, Not Humans

Cloudflare's Kitesurf is a browser rebuilt in Rust and WebAssembly for AI agents. What the architecture gets right, where it falls short, and when to use it.

By Adam Maguire Wilson15 min read
On this page

Three numbers from Cloudflare's own benchmark table tell you most of what Kitesurf is for. A screenshot job that costs a warm Chromium instance 271 MiB of memory costs Kitesurf 58. Pulling the HTML out of the same pages takes 3.8 times less CPU. And Chromium still wins the stopwatch, by about 1.7 times, because a JIT that has already seen your page beats a cold software renderer every time. Cloudflare's bet is that the first two numbers are the ones that show up on your invoice.

Kitesurf is a browser built from scratch in Rust, compiled to WebAssembly, and run inside V8 isolates on Cloudflare Workers. It exists for AI agents rather than people, and it is free while in beta inside Browser Run, Cloudflare's hosted browser product. The announcement post is unusually honest about the trade-offs, which is one reason I think it deserves a proper read rather than a headline skim. I've been through it a few times now. Here is what I think matters, what I don't believe yet, and what I'd do about it if I were running agent workloads today.

Key Takeaways - Kitesurf is a from-scratch browser (Rust compiled to WebAssembly) running in V8 isolates on Cloudflare Workers, free in beta through Browser Run. It speaks the Chrome DevTools Protocol, so Puppeteer and Playwright work unchanged. - Against Chromium it uses 3.1 to 3.8 times less CPU and 4.7 to 7 times less memory on common agent tasks, while running roughly 1.7 times slower. CPU and memory are what providers bill on. - It was largely written by AI agents working against 215,000+ Web Platform Tests as their target, which is the most interesting engineering signal in the whole announcement. - It cannot play video, render WebGL, pass bot checks, or hold long authenticated sessions. Treat it as a disposable engine for stateless extraction, not a Chromium replacement. - The security posture is the real product: every page load is treated as hostile, one sandboxed component touches the network, and everything else is built to be thrown away.

What happened

On 6 August, Cloudflare announced Kitesurf, a browser it built in twelve weeks, first commit in May. The key facts, all from the announcement:

  • The whole browser is Rust compiled to WebAssembly via wasm-bindgen, no Emscripten emulation layers, running inside V8 isolates on Workers.

  • It passes 215,000+ Web Platform Tests, with hundreds more passing each week, and the coverage is concentrated where agents need it: CSS, DOM, HTML, selection, SVG, XHR.

  • It speaks the Chrome DevTools Protocol, so Puppeteer, Playwright, chrome-remote-interface and MCP clients that speak CDP all work by adding browser=kitesurf to the existing Browser Run endpoint.

  • It is free while in beta behind per-account limits, and Cloudflare has committed to open sourcing it so customers can run their own copy on their own accounts.

  • It already runs Doom, because of course it does. No infrastructure project at Cloudflare is finished until it runs Doom.

The framing quote is the one worth keeping: browser engines like Chromium "were built for humans, not agents, and they come with overhead that AI models simply do not need."

Kitesurf is a browser rebuilt from scratch in Rust and WebAssembly, running in V8 isolates on Cloudflare Workers and available free in beta through Browser Run. It passes 215,000+ Web Platform Tests and works with existing CDP clients such as Puppeteer and Playwright, per Cloudflare's announcement on 6 August 2026.

Why Chromium became the expensive line item

The demand side of this story is already settled. In McKinsey's 2025 State of AI survey, 62% of organisations said they were at least experimenting with AI agents, and LangChain's State of Agent Engineering report put 57% of respondents as having agents in production. A large share of those agents need to touch the web, and the web does not offer them an API. It offers them a browser.

The browser they get today is Chromium, an engine tuned for human eyeballs. Compositing, smooth scrolling, pixel-perfect text shaping, tabs, extensions, sync. An agent consuming a page as tokens and structure uses almost none of it. Chromium is a wonderful piece of engineering being used as a very expensive text extractor.

The market has already priced this. Browserbase, which sells managed Chromium sessions to agent developers, closed a $40 million Series B at a reported $300 million valuation in the first half of 2025, and Browser Use raised a $17 million seed round the same spring. These are real businesses built on a simple fact: running Chromium at agent scale is painful and expensive, so someone else will happily run it for you at a markup.

Cloudflare sells that same service. On the paid Browser Run tier you get ten browser-hours a month, then pay $0.09 per browser-hour after that. The single biggest input to that price is how much CPU and memory a browser session burns, which is exactly where Kitesurf's numbers land. This is margin engineering as much as browser engineering, and I mean that as a compliment.

Bar chart of Cloudflare's benchmark comparing Kitesurf with warm-pool Chromium across six metrics. Kitesurf uses 3.1 times less CPU for screenshots and 3.8 times less for HTML extraction, 4.7 times less memory for screenshots and 7 times less for HTML extraction, and is 1.8 and 1.7 times slower in wall time.

Cloudflare's own medians across a 14-URL corpus, comparing Kitesurf with a warm Chromium pool. Kitesurf wins on the resources that drive the bill and loses on the stopwatch, per the announcement.

One honest caveat on that table before anyone quotes it at me. The Chromium side is a warm pool that has already seen these pages, which is precisely why it wins on wall time. Cloudflare says so itself, and says most of the gap is rasterisation and JPEG/PNG encoding it plans to keep optimising. I'd treat the wall-time gap as real but shrinking, and the CPU and memory gap as structural.

AI agents that touch the web currently rent Chromium, an engine built for human rendering fidelity they never consume. Cloudflare's benchmarks show Kitesurf using 3.1 to 3.8 times less CPU and 4.7 to 7 times less memory than warm-pool Chromium on screenshot and extraction tasks, at roughly 1.7 times slower wall time. Browserbase's $40 million Series B shows the market was already charging a premium for Chromium's overhead.

The architecture, read as a practitioner

This is the section where the announcement earns its length. Kitesurf is three components plus a bouncer, and the division of labour is the design.

The Engine is the only public-facing piece. It terminates the CDP WebSocket and REST APIs and holds session state. Everything else is stateless, which matters more than it sounds: a stateless component is one you can kill the moment it stalls, run a thousand of at once, and never have to reconstruct. Cloudflare says any failure degrades to a blank frame or a missing element, never a dead session. That is the correct instinct for software that eats arbitrary hostile input all day.

PageScript is where the interesting platform dependency sits. Every page and out-of-process iframe gets its own long-lived isolate spun up through Dynamic Workers, with a clean globalThis and a DOM built from the parsed document. HTML parsing and CSS come from Blitz, the DioxusLabs rendering engine, and Stylo, Servo's CSS system, both Rust. Dynamic Workers only went into open beta in March, promising isolate starts in single-digit milliseconds, roughly 100 times faster to boot than containers by Cloudflare's own count, and it says plainly that Kitesurf "simply wouldn't have been possible" before it. I believe that. Per-page isolates with no global concurrency limit is the whole trick.

PageRenderer turns the computed page into pixels: it pulls the scene from PageScript, rasterises with blitz-paint and Parley, and returns a buffer over Workers' built-in RPC as a JPEG, PNG or PDF. Because it holds no page state, the Engine can kill and relaunch it on any stuck call. Disposable renderers, retryable renders.

Then there's the eval problem, my favourite honest detail in the post. Workers doesn't support native eval, and you can't spin up a second isolate for it because it wouldn't share globalThis. So Kitesurf runs Boa, a JavaScript engine written in Rust, compiled to Wasm, inside the V8 isolate. A JavaScript runtime running on a JavaScript runtime to handle the occasional eval. It's ugly, they say it's ugly, and it's scheduled for deletion the moment native eval lands. That's how you ship.

And the meta-story, which I'd file under things worth paying attention to. Kitesurf was substantially written by AI agents. The initial port of obscura, the Rust headless engine Cloudflare credits as inspiration, was done with an agent looping against a plan. Scaling from prototype to browser was done by pointing agents at the Web Platform Tests as goalposts, with humans curating the feature order, doing the architecture, and reviewing approaches. Two hundred and fifteen thousand passing tests as the definition of done. This is the clearest worked example I've seen of the pattern I keep describing to clients: agents write the code, humans hold the spec. The same split shows up in how I think about agentic architecture more broadly.

Kitesurf's architecture isolates every page in its own V8 isolate via Dynamic Workers, parses with Blitz and Stylo from the Rust ecosystem, rasterises in a stateless renderer, and handles eval through the Boa JavaScript engine compiled to WebAssembly. Cloudflare reports the browser was largely built by AI agents working against the Web Platform Tests suite, with humans responsible for architecture and review.

The threat model is the real product

Here is where I think most coverage will undersell what Cloudflare actually built. The uncomfortable fact about agentic browsers came out of Brave's security research on Perplexity's Comet in August 2025: instructions hidden in a Reddit comment were enough to turn a "summarise this page" request into the agent fetching the user's email and one-time passcode. The same-origin policy and CORS, the two load-bearing walls of web security, do very little once the entity browsing is acting with your authenticated privileges. Brave's October follow-up showed injections arriving through screenshots, and Anthropic published its own prompt-injection mitigations for browser use in November.

Consumer agentic browsers amplify this by design: the whole point of Comet or Atlas is that the agent inherits your logged-in sessions. Kitesurf's posture is the opposite. Every page load is untrusted input. Every session starts fresh, with cookies kept in per-page jars. Nothing touches the network except one sandboxed component, SandboxOutbound, which enforces CORS, filters responses, and returns a 403 for anything off policy, and that restriction is enforced by the platform rather than by the application being well-behaved.

To be clear about what this does and doesn't solve. Prompt injection at the model layer is still the model's problem; if a page tells your agent to do something stupid, no browser architecture stops the agent from wanting to. What Kitesurf limits is the blast radius: what the page can reach, what the session can leak, what survives a crash. For anyone building agents that browse on behalf of strangers, that distinction is most of the job, and it belongs in the same conversation as agent governance generally.

Agentic browser security research in 2025, including Brave's analysis of Perplexity Comet, showed that same-origin policy and CORS offer little protection once an agent browses with a user's authenticated privileges. Kitesurf's answer is architectural: every page load is treated as hostile, sessions start fresh, and network access is denied by default except through one sandboxed fetcher, per Cloudflare's announcement.

What Kitesurf can't do, and when to reach for it

Cloudflare's own list of exclusions is admirably blunt: no video, no WebGL, no negotiating bot-challenge handshakes with real TLS fingerprints, no ten-minute authenticated sessions with persistent state. For any of that you stay on the default Chromium pool. Add the 1.7 times wall-time penalty and CDP coverage that is still a subset, and the shape of the thing becomes clear. Kitesurf is an ephemeral engine that exists for the duration of a task, then vanishes.

It's also not the only team with this idea. Lightpanda, a Paris startup, is building a from-scratch browser in Zig that speaks CDP and claims, by its own benchmarks, eleven times faster execution and nine times less memory than headless Chrome; it raised a pre-seed round led by ISAI in June 2025. The not-Chromium thesis is a real category now. Kitesurf's particular difference is that it isn't a fleet of browsers you rent from a new vendor. It's a browser compiled into the isolate platform a lot of us already deploy on, with an open-source release promised so you can eventually run it on your own account. That's a distribution advantage, not just an engineering one.

Advisory matrix of which browser fits which agent workload. One-shot screenshots, PDFs and HTML extraction are a good fit for Kitesurf. Multi-step form flows and complex single-page apps are worth testing. Video, WebGL, bot-protected sites and long authenticated sessions belong on Chromium.

An advisory assessment from the announced capabilities, not a measurement: which agent workloads fit Kitesurf today and which stay on Chromium. The exclusions (video, WebGL, bot challenges, persistent sessions) are Cloudflare's own list.

What to do now

If you build or run agents, three steps, in order.

  1. Today: open the public playground Cloudflare links from the announcement, paste in a URL you actually use, and watch it render. The injected Chrome DevTools view shows you the DOM, console and per-isolate memory footprint, which is the cheapest way to build intuition for what this thing is.

  2. This week: take one representative extraction workload and run it through Browser Run's Quick Actions twice, once default and once with browser=kitesurf. Compare CPU milliseconds and memory, not wall time. Your corpus will differ from Cloudflare's fourteen URLs, and the honest number is the one measured on your own pages.

  3. This month: if the numbers hold, route stateless one-shot jobs to Kitesurf and keep anything session-shaped on Chromium. That split is likely to be the steady state for a while.

Two things not to do. Don't migrate production session automation yet; beta conformance on complex enterprise apps is unproven, whatever TodoMVC says. And don't read "passes 215,000 WPT tests" as "renders the web". WPT measures standards conformance, which is why Cloudflare also runs visual regression tests against Chromium on real sites. The gap between the two is where your edge cases live. If you're still at the stage of choosing your first agent stack, the wider build-versus-buy question is covered in Build vs Buy AI Agents.

FAQ

Is Kitesurf free to use?

Yes, while in beta, behind per-account limits. Kitesurf rides on Browser Run's existing plans: the Workers Free tier includes ten minutes of browser time a day, and paid plans bundle ten browser-hours a month then charge $0.09 per browser-hour, per the pricing page. What pricing looks like after beta hasn't been announced.

Does Kitesurf work with Playwright and Puppeteer?

Yes. Kitesurf speaks the Chrome DevTools Protocol, so Puppeteer, Playwright, chrome-remote-interface and MCP clients that speak CDP connect to the existing Browser Run endpoint with one change: add browser=kitesurf to the request. Your client code doesn't change.

What's the difference between Kitesurf and Browserbase?

Browserbase sells managed Chromium sessions as a hosted service, with the overhead and fidelity of a full browser. Kitesurf is a from-scratch engine inside Cloudflare Workers that trades fidelity and wall time for much lower CPU and memory per session, aimed at stateless agent tasks. If you need persistent logins, media or bot-check navigation, that's Chromium territory, whether self-run or bought from Browserbase. If you need cheap screenshots and extraction at burst scale, Kitesurf is built for exactly that.

When will Kitesurf be open source?

Cloudflare has committed to open sourcing it, with the stated goal of letting customers deploy their own copy on their own accounts, but gave no date beyond "hopefully soon". Given the project is twelve weeks old, I'd treat the commitment as genuine and the timeline as unknown.

The bottom line

Kitesurf is twelve weeks old and it shows, in both directions. The limits are real, the wall-time penalty is real, and nobody should be ripping Chromium out of a production pipeline this quarter. But the bet underneath it, that agents deserve a browser shaped like agents rather than like people, looks less like a bet and more like the start of a category. Cloudflare has the distribution, the isolate platform, and now the cheapest engine in the segment it created. The part I'll be watching is whether the open-source release lands, because a browser anyone can run on their own Workers account is a different proposition from one you rent by the hour.

If you're weighing up where browsers sit in your own agent stack, that's a conversation I have with clients regularly. Get in touch.

Sources

  • Cloudflare, "Introducing Kitesurf: The agent-first browser that runs in V8 isolates on Cloudflare Workers": https://blog.cloudflare.com/kitesurf/ (published 2026-08-06, retrieved 2026-08-28)

  • Cloudflare, Browser Run documentation: https://developers.cloudflare.com/browser-run/ (retrieved 2026-08-28)

  • Cloudflare, Browser Run pricing: https://developers.cloudflare.com/browser-run/pricing/ (retrieved 2026-08-28)

  • Cloudflare, "Sandboxing AI agents, 100x faster" (Dynamic Workers open beta): https://blog.cloudflare.com/dynamic-workers/ (retrieved 2026-08-28)

  • McKinsey, "The State of AI 2025": https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai-2025 (published 2025-11-05, retrieved 2026-08-28)

  • LangChain, "State of Agent Engineering": https://www.langchain.com/state-of-agent-engineering (retrieved 2026-08-28)

  • Sacra, "Browserbase research": https://sacra.com/research/browserbase/ (retrieved 2026-08-28)

  • TechCrunch, "Browser Use raises $17M": https://techcrunch.com/2025/03/23/browser-use-the-tool-making-it-easier-for-ai-agents-to-navigate-websites-raises-17m/ (published 2025-03-23, retrieved 2026-08-28)

  • Brave, "Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet": https://brave.com/blog/comet-prompt-injection/ (published 2025-08-20, retrieved 2026-08-28)

  • Brave, "Unseeable prompt injections in screenshots": https://brave.com/blog/unseeable-prompt-injections/ (published 2025-10-21, retrieved 2026-08-28)

  • Anthropic, "Mitigating the risk of prompt injections in browser use": https://www.anthropic.com/research/prompt-injection-defenses (published 2025-11, retrieved 2026-08-28)

  • Lightpanda, "Lightpanda raises pre-seed": https://lightpanda.io/blog/posts/lightpanda-raises-preseed (published 2025-06-10, retrieved 2026-08-28)

  • Lightpanda, homepage benchmark claims: https://lightpanda.io/ (retrieved 2026-08-28)

  • DioxusLabs, Blitz: https://github.com/DioxusLabs/blitz (retrieved 2026-08-28)

  • Boa, JavaScript engine in Rust: https://github.com/boa-dev/boa (retrieved 2026-08-28)

  • Web Platform Tests: https://web-platform-tests.org/ (retrieved 2026-08-28)

  • Wikimedia Commons, cover image "Kitesurfing in Sweden" (CC0): https://commons.wikimedia.org/w/index.php?curid=142794310 (retrieved 2026-08-28)

Keep reading

Agent Field Notes

Get the next issue.

Agent harnesses, runtimes, security and governance, explained for the people who have to operate them.

Facing a decision like this?

We run architecture reviews, governance assessments and version-pinned framework evaluations for teams making consequential agent decisions.

About the author

Adam Maguire Wilson

Founder and independent advisor on AI agent systems.

adam.mw