Chrome Relay drives your signed-in Chrome from a coding agent
Chrome Relay, released on 10 October by Alexey Indeev, is an MIT-licensed Mac tool that lets a coding agent open background tabs inside your everyday Chrome profile, carrying your real logins, and the project reports 151 stars in its first day on GitHub.
Image: GitHub
Why it mattersAn agent that cannot sign in on your behalf cannot touch most work tools, and a local relay that reuses your own Chrome profile avoids the password, passkey and two-step prompts a headless browser cannot answer.
A coding agent asked to check a dashboard behind a company sign-in usually stops at the login page, because a headless browser cannot answer a passkey prompt or a two-step code. Chrome Relay routes the agent through the Chrome window you already use, in a hidden tab, with the cookies and sessions already there.
Alexey Indeev, co-founder and CTO of Spare, published the project on 10 October 2026 under the MIT licence. The repository shows 151 stars after its first day and ranks fourth on Trendshift's daily list on 10 October. It runs on macOS.
How it works
The project ships three parts. A Chrome extension, loaded unpacked into every Chrome profile that should be reachable, opens an inactive tab inside a collapsed "Agents" tab group and runs DevTools commands against it through chrome.debugger. A local relay process, installed as a LaunchAgent at 127.0.0.1:9333, speaks WebSocket to the extension and to each connected agent. A CLI exposes the setup, a connection URL, a doctor command and an audit log reader.
Each agent sees only the tabs it opened. The relay refuses any connection that arrives with a browser Origin header, so a web page cannot drive the extension even if it steals the setup secret. The extension's ID is pinned at setup, so a different unpacked extension cannot pretend to be it.
Which agents can connect
Two checks run on every connection. The first is a per-Mac secret written to ~/.chrome-relay/token at setup and embedded in the URL the CLI prints. The second checks that the connecting process came from Claude Code, Codex, Cursor or Paseo, by looking up its parent processes and the environment markers those apps set on their children. Indeev notes in the README that this keeps unrelated local tools and web pages out, and that it is not a boundary against malware already running as the user, which could read the secret and fake the markers.
Sign-ins and audit
When a site redirects through a Google account chooser and the right account is already signed in, the extension clicks the account and the Continue or Allow screens itself. A password, passkey or two-step screen stops the sign-in, and the agent gets a SIGN-IN NEEDED reply so a person can finish the sign-in in the real window. Which Google account a site uses comes from a per-profile mapping that the relay fills in after each successful sign-in.
Every agent action lands in ~/.chrome-relay/audit/YYYY-MM-DD.jsonl: who connected, which pages opened, every click position, the agent's own scripts, screenshots, uploads, pop-ups and blocked pages. Typed text is recorded only as a character count, and URLs lose their query string.
Source
aindeev/agent-chrome-relay by Alexey Indeev.
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.

