explainx.ai0k
TrendingAI News TodayPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

follow on google

Add explainx.ai as a preferred source

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

community

Join the community

learn

mind: share how you thinkpathways — start freeworkshopsbootcampscoursescompare Explainxcertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsmdx readeragentsllmsdesignsdictionarypeopleagi trackerfelony benchranks

company

aboutvisionmissionteaminstructorsteach on explainxpartnershipscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportcontactprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

explainx.ai

On this page

  • TL;DR: the questions people are asking
  • Gumloop Agent Browsers: use the site like a person does
  • AgentID: let agents be agents
  • Why identity may beat impersonation
  • Security questions to ask before using either
  • A decision guide
  • A note on terms of service and ethics
  • What this means for what you build or pay
  • Related reading
← Back to blog

explainx / blog

Agents Without APIs: Gumloop Agent Browsers and AgentMail's AgentID Explained

AI Agents, Gumloop, AgentMail, Authentication, AI Tools

Gumloop launched Agent Browsers for sites without APIs, and AgentMail launched AgentID, an OIDC sign-in for agents. How each works and the risks of both.

Oct 7, 2026·8 min read·Yash Thakker
add explainx.ai
go deep
Agents Without APIs: Gumloop Agent Browsers and AgentMail's AgentID Explained

How does an AI agent use a website? For years the answer was "through an API," and when there is none, "badly." This week, two launches took different routes around the problem. Gumloop released Agent Browsers, which let agents operate real browsers on sites with no API. AgentMail launched AgentID, an OpenID Connect provider that gives an agent its own verified sign-in identity.

They are complementary, and together they sketch two possible futures for how agents access the web: the agent pretends to be a person with a vault of logins, or the agent shows up as an agent with an identity. This post explains both, what is known, and the security questions to ask. We worked from vendor documentation and press coverage and have not tested either product.

Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.

TL;DR: the questions people are asking

table · 3 cols
QuestionGumloop Agent BrowsersAgentID
What is it?Real browser sessions for agentsSign-in identity for agents (OIDC)
SolvesSites with no API or MCPAgents proving who they are to apps
CredentialsPassword vault, agent never sees themNo shared secret; keypair per agent
CostNot stated in coverageFree for apps; agents need an AgentMail inbox
IntegrationGumloop platformTwo OIDC values, no SDK
Key riskAnti-bot defenses, vault securityAdoption, accountability

Gumloop Agent Browsers: use the site like a person does

Gumloop builds a multiplayer agent platform where anyone at a company can build agents with a model and integrations of their choice while IT controls access. Agent Browsers extend that to sites that offer no MCP connection or API. Per the launch coverage, agents open a real browser and click, type, upload and pull data from any site a team already uses.

The notable piece is credential handling. Gumloop provides a password vault built for agents: logins are saved once, or connected through 1Password, and the agent signs in without ever seeing the credential. That matters because the standard failure of a browser agent is that it reads and exposes a password, whether through a prompt injection or a bad log. If the agent never holds the secret, that class of leak shrinks.

What this does not solve is the arms race. A site that detects automation can block or challenge the agent, as we have seen with consumer agents, including Amazon's block on Meta's Muse and the reports of web tasks suddenly failing that we discussed in our agent teams opinion piece. Terms of service also matter: a business that automates a vendor's portal should check that the vendor allows it.

AgentID: let agents be agents

AgentID takes the opposite approach. Instead of an agent impersonating a user in a browser, it gives the agent its own identity that apps can verify. AgentMail describes it as an OpenID Connect provider that lets an agent sign in to any app with its own verified email identity.

How it works, per AgentMail's documentation:

  1. Enrollment. Once per browser, the agent generates a keypair. The private key is non-extractable and is a P-256 key, so it cannot be copied out.
  2. Sign-in. On each login, the agent signs a fresh, server-generated transaction. The app verifies the signature against published public keys, so no shared secret travels.
  3. Token. The app receives an ES256-signed ID token containing a stable sub derived from the agent's inbox, the agent's verified email, a unique jti to prevent replay, and, for registered apps, an owner_email identifying the accountable human.

The owner_email field is the interesting design choice. It ties every agent to a person or organization responsible for it, which is the missing link in most agent deployments: when an agent does something wrong, who answers for it? Apps can add AgentID as a custom OIDC provider in Clerk, Supabase, Auth0, Better Auth or Auth.js with two configuration values, an issuer (https://auth.agentid.com) and a client ID, and no SDK. The button reads "Sign in with AgentID." It is free for applications, and agents need an AgentMail inbox. It launched publicly on October 6, 2026.

AgentMail distinguishes AgentID from enterprise tools such as Microsoft Entra Agent ID, which governs agents inside a company's own tenant. AgentID is for agents acting across organizations.

Why identity may beat impersonation

Consider what each model implies for a website.

table · 3 cols
ModelWhat the site seesSite's options
Browser impersonationA browser that looks like a humanDetect and block, or tolerate silently
Agent identityA signed, labeled agent with an accountable ownerAllow, rate limit, require approval, or deny, per agent

Identity gives sites something they currently lack: a clean way to say yes. A site that cannot tell a helpful agent from a scraper blocks both. A site that can verify who owns an agent can grant it a narrow lane. That is the "agent lane" we predicted in our opinion piece, and AgentID is an early concrete attempt. The same instinct appears in the push for open standards for personal agents, as in our coverage of the personal agent protocol from Meta, Sierra and partners.

The catch is adoption. Identity only helps if sites support it, and most do not yet. Until they do, browsers fill the gap.

Security questions to ask before using either

For a browser-with-vault product:

  • Where is the vault hosted, and who can read entries? How does it handle 1Password connections and revocation?
  • Can I scope an agent to specific sites and actions, and log every action?
  • What happens when an agent encounters a prompt injection on a page? Does the vault prevent it from exfiltrating anything it should not?
  • Do the target sites allow automated access under their terms?
  • Can the agent be paused instantly?

For an agent identity provider:

  • How are agents verified before they get an inbox and keys? Can anyone create thousands of agent identities?
  • What is the revocation path if a key is compromised?
  • Does the owner field reflect a verified person or organization, or just an email address?
  • What does an app do with an unregistered agent?
  • How does the provider handle abuse, such as agents used for spam or fraud?

For agent security in general, a cheap screening layer helps, as in our write-up of Security-One, but least privilege and logging remain the foundation.

A decision guide

  • Your target app has an API or MCP server: use it. It is sturdier than either option.
  • No API, internal tool you control: a browser agent with a vault can work, and you can add the agent identity yourself later.
  • No API, third-party site: read its terms, expect breakage and keep a human fallback.
  • You build an app and want to welcome agents: consider adding an agent sign-in option and decide what narrow permissions an agent identity should receive.
  • You run agents at scale: insist on per-agent identity, per-action logging and instant revocation, regardless of vendor.

A note on terms of service and ethics

Letting an agent operate a website as a person raises questions beyond security. Many sites prohibit automated access in their terms, and some regulated services require that an actual authorized person acts. Using a vault and a real browser does not change what the contract says. For internal tools you own, the question is easy. For vendor portals, check the terms or ask the vendor, since some will approve automation and even offer a sanctioned route. Where agents act on a person's behalf, such as submitting forms or placing orders, keep a record of what was done and by whom, so accountability does not disappear into the automation. An agent identity with an owner field is one way to keep that record clean, and a good habit is to review those records every month.

What this means for what you build or pay

If you build internal automations, Agent Browsers can unlock systems that no one will ever build an API for, at the cost of fragility. If you build apps, AgentID is a cheap experiment: two configuration values to see whether agent traffic shows up and whether you want to treat it differently from humans. The deeper trend is that the web is slowly learning to distinguish agents from people, and the products that make that distinction explicit and accountable are likely to age better than those that try to blend in.

Related reading

  • Agent teams are the new org chart
  • Amazon blocks Meta's Muse from shopping
  • Personal agent protocol from Meta, Sierra and partners
  • Meta opens Muse to developer connectors
  • Security-One: screening agent tool calls
  • Is ChatGPT Dots safe to leave unattended?
  • Apple tightens Full Disk Access for AI agents

Primary: Gumloop's Agent Browsers announcement · AgentMail, "AgentID: Sign-In for AI Agents" and "What is an Agent ID?" (launched October 6, 2026)

Details are accurate as of October 7, 2026 and come from vendor documentation and press coverage. We have not tested either product, and pricing, limits and supported providers may change.

Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

View Yash Thakker in People in AI →

Related posts

Oct 6, 2026

Gamma 5: An Agent-Driven Rebuild Aimed at Killing the "AI Smell" in Slides

Gamma launched Gamma 5 on October 6, 2026: a rebuilt platform with an agent that writes custom code and draws shapes, a freeform editor, thousands of templates and about 20 connectors. The stated goal is to remove the repetitive look of AI-made decks. Here is what changed, how to evaluate it, and what the launch does not tell you.

Jun 29, 2026

video-use: Edit Videos With Claude Code — No Premiere Pro Needed

video-use is an open-source skill for Claude Code (and Codex, Hermes, Openclaw) that edits videos via natural language — no timeline scrubbing, no NLE menus. It reads footage as transcript text, reasons over word-level timestamps, calls ffmpeg, self-evaluates every cut, and outputs final.mp4. 11.6k GitHub stars in two months. Here is the full setup and how it works.

Jun 28, 2026

Langflow vs n8n vs Make vs Flowise: Which No-Code AI Builder Should You Use in 2026?

Four serious tools now compete for the same territory: no-code and low-code AI workflow building. Langflow, n8n, Make, and Flowise are not interchangeable. This comparison breaks down what each tool actually does well, where each one falls short, and gives you a three-question framework to pick the right one for what you are building in 2026.