Claude in Chrome: What the Extension Can Do and How to Stay Safe
Claude in Chrome lets Claude read, click and type in your browser, using the accounts you are already signed in to. What it can do, how its site permissions and approval modes work, what Anthropic says about prompt injection, and the habits that keep it safe.
8 min read
Claude in Chrome is Anthropic’s browser extension that lets Claude read the page you are on and act in it: click, type, fill forms, open and switch tabs, and work across several sites in one task. It is available on every paid Claude plan, runs from a side panel in Chrome, and can also be driven from Claude Cowork and Claude Code. Because it works with your existing logins, it can reach anything you can, which is its use and its risk. Anthropic’s own help pages say it is guarded by safety classifiers but still risky, and that the chance of a prompt-injection attack is not zero. Use it with a separate browser profile, on sites you trust, and keep the approval setting on asking first for anything that matters.
What the extension is
Anthropic’s guide to getting started with Claude in Chrome (opens in a new tab) describes it as an extension that lets Claude read, click and navigate websites alongside you. You install it from the Chrome Web Store, sign in with your Claude account, grant its permissions and pin it to the toolbar. Clicking the icon opens Claude in a side panel that stays open while you browse. The tabs Claude works in are gathered into their own coloured tab group, so you can tell its tabs from yours.
Who can use it
- Plans: Pro, Max, Team and Enterprise. Anthropic announced on 26 August 2026 that Claude in Chrome is generally available (opens in a new tab) on every paid plan.
- Browser: the help centre says Google Chrome only; it is not supported on other Chromium-based browsers or on mobile.
- The side panel: on Max and Team plans it runs as a Cowork session, so conversations are saved and can be picked up on other devices. This is rolling out to Pro. On Enterprise it needs the admin to enable Cowork in the cloud; until then it uses the classic panel.
- Team and Enterprise: an admin decides whether the extension is enabled at all, and can restrict which sites Claude may use with allowlists and blocklists.
If you mainly want Cowork to use a browser, there is also a browser built into the Claude Desktop app. It needs nothing installed and does not see your saved logins unless you import them, which makes it the more cautious choice for tasks that need no account.
What it can do
- Read: the text of the page, and screenshots of the tabs it is working in, to decide what to do next. It can also read the browser console, network requests and page structure, which is useful for debugging.
- Navigate: open, close and switch tabs, follow links, and work across every tab you drag into its group.
- Fill: type into fields, complete forms, and upload an image you give it to a form or attachment field.
- Act: click buttons and run multi-step workflows, carrying on while you switch tabs as long as Chrome is open, with a notification when it finishes or needs you.
- Repeat: save a prompt that works as a shortcut, run it by typing “/”, and schedule shortcuts daily, weekly, monthly or annually. In the classic side panel you can also record yourself doing a workflow for Claude to repeat.
- Sign in without seeing the password: 1Password for Claude, in beta on macOS, fills logins directly so the credential never enters Claude’s context.
The permission model
Two layers decide what Claude may do: an approval mode for the task, and permissions per site. The permissions guide (opens in a new tab) sets out both.
- Manually approve: Claude asks before each action. In the Cowork side panel it first proposes a plan naming the sites it will use and its approach; once you approve the plan it acts within it and asks before going further.
- Automatically approve: the default in the Cowork side panel. Claude keeps working and a safety check reviews each action before it runs, blocking what looks unsafe and pausing to ask you when needed. If it keeps hitting blocks it switches back to asking for each step. It uses more of your usage limit.
- Skip all approvals: no pauses and no automatic check. Anthropic says to use it only when you completely trust every action, connector, file and app involved.
When Claude reaches a site it needs permission for, you choose “Allow this action” for one action, “Always allow actions on this site” for ongoing access, or decline. Anthropic calls the single-action choice the safest and warns that with always-allow Claude may take unintended actions across the site. You can review which sites have always-allow, revoke them and see your permission history on the extension’s Permissions page.
Some rules hold in every mode. Claude asks before entering potentially sensitive information into a page and before changing permission settings. It will not make purchases or financial transactions, handle card or ID data, download files from untrusted sources, delete things permanently, execute trades or give investment advice, or carry out instructions it finds in emails or web content. Some high-risk sites are blocked entirely, and it asks before opening financial sites.
Prompt injection: what Anthropic says
The main risk is not Claude misunderstanding you. It is someone else’s instructions reaching Claude through what it reads, known as indirect prompt injection. Anthropic’s page on using Claude in Chrome safely (opens in a new tab) gives the example of an ordinary-looking email or to-do list carrying invisible text that tells Claude to retrieve your bank statements and share them. Its protections are layered: training Claude to refuse such instructions, classifiers that scan incoming content, a check on every action before it runs, site permissions, blocked site categories and confirmations for high-risk actions. The same page is plain that the risk is not zero and that novel attacks may emerge that its evaluations did not cover.
Anthropic’s research post on mitigating prompt injections in browser use (opens in a new tab) (November 2025) explains why browsers are hard: every page, embedded document, advert and script is a possible carrier, and a browser agent can navigate, fill forms, click and download. It says no browser agent is immune to prompt injection. The general controls for browser and computer-use agents are in AI agent security best practices; the version that arrives through connected tools is in MCP security risks.
There is a second, quieter risk. Claude takes screenshots of the tabs it works in, and whatever is visible becomes part of the conversation. It cannot filter out sensitive content it sees, and side panel sessions are saved to your history.
Safe-use habits
- Give it its own Chrome profile, signed in only to the sites its jobs need, with no banking, health or government accounts.
- Start on sites you trust. Avoid unfamiliar sites and pages full of other people’s content until you know how it behaves.
- Stay on Manually approve for new sites and for anything that sends messages, changes records or touches money. Use always-allow only for sites you completely trust, and prune that list.
- Do not open the side panel while sensitive documents are on screen, and keep it away from legal, medical, financial and regulated data altogether, as Anthropic advises. It is not available to organisations covered by HIPAA.
- Write specific prompts: the site, the task, the stopping point. Vague goals give it room to wander.
- Stop the task if it starts discussing unrelated topics, visiting sites you did not mention or asking for sensitive information. Anthropic names these as signs of a possible injection.
- On Team and Enterprise plans, ask your admin for a restrictive allowlist so Claude works only on approved tools.
Claude in Chrome and Claude Code
The same extension gives Claude Code a browser. The Claude Code documentation (opens in a new tab) describes a build, test and debug loop: Claude changes the code, opens the page, reads console errors and page state, and fixes what it finds. You start a session with claude --chrome, or run /chrome to check the connection, manage permissions and turn it on by default. Enabling it by default loads the browser tools into every session, which uses more context.
claude --chrome # then, in the session Open localhost:3000, submit the sign-up form with an invalid email, and tell me whether the error message appears. Check the console too.
- It shares your browser’s login state and opens its own tabs in a visible window. When it meets a login page or CAPTCHA it pauses for you.
- Site permissions are inherited from the extension, so the list you manage there governs Claude Code too.
- It needs a direct Anthropic plan and a
/loginsign-in; it stays off with an API key, and is not available through third-party cloud providers. - Claude Code’s documentation says the integration works with Chrome and Edge, and detects the extension in other Chromium browsers. It is not supported in WSL.
When the browser is the wrong door
A browser agent acts as you. In the site’s own records, what Claude clicked is what you clicked, with your full rights. That is fine for reading and for one-off chores, and poor for work that repeats in the same tool, where you want the agent to have its own narrower access and its own name in the log.
Task boards are a common case. Rather than letting Claude click through fenbs in your browser, connect it over MCP: the connection carries only the scopes you tick, read, write and comment, every change it makes is recorded in History as “Claude via” you, and revoking that one token under Settings stops it without signing you out. Keep the browser for the sites that have no such door.
Related
Connecting Claude to a board without the browser: Claude integration and the MCP setup guide. What an assistant token can and cannot do: assistant tokens and scopes. Browser tasks inside Cowork: Claude Cowork examples.