Manus AI Agent: What It Does and Its Limits

Manus is a general AI agent that works on its own virtual computer: it plans a task, browses, writes code and files, and hands back a finished result. How it works, where it can reach, how it compares with what used to be ChatGPT agent, and the limits to plan around.

8 min read

Manus is a general-purpose AI agent: you describe an outcome, and it plans the steps, carries them out on a virtual computer in the cloud, and returns a finished piece of work such as a report, a slide deck, a spreadsheet, a website or working code. It is not tied to one job the way a coding agent is. It can browse the web, run code, install software, use connected apps through MCP, and, if you allow it, work in your own browser or on folders on your own computer. Its limits are the usual ones for an autonomous agent, plus a few of its own: every Agent-mode task spends credits, websites can block its cloud browser, anything it signs in to it can act on as you, and the company has been through an ownership change in 2026 that touched some users’ data.

What Manus is, and what changed in 2026

Manus’s own welcome page (opens in a new tab) describes it as “an autonomous general AI agent designed to complete tasks and deliver results,” and explains the difference from a chatbot: it “operates in a complete sandbox environment—a virtual computer with internet access, a persistent file system, and the ability to install software and create custom tools.” That sandbox is why it can keep working through a long task without you assembling the pieces.

Two pieces of recent history matter if you are evaluating it. Meta announced it was acquiring Manus in December 2025. In August 2026, Manus’s note to its users (opens in a new tab) said the company is returning to independent operation and, to comply with regulatory requirements, deleted data generated by certain users on or after December 29, 2025, on August 23 and 24, 2026, after a window in which affected users could back it up. Then, on September 28, 2026, Manus announced Manus 2.0, which it describes as a new architecture rather than a version bump, with a new agent framework called Cascade, a redesigned desktop app called Manus Studio, and expanded automations.

How the Manus agent works

You start a task with a prompt, optionally inside a project. A project holds a master instruction and a knowledge base of files that every new task in it inherits, so recurring work such as a weekly competitor summary does not need its setup repeated. Projects and tasks are private by default; inviting a colleague to a project shares the instruction and files, not your tasks.

There are two ways to talk to it. According to the Manus Help Center’s page on Chat mode and Agent mode (opens in a new tab), Chat mode is for quick answers and discussion and does not consume credits, while Agent mode plans and completes larger jobs such as websites, slides and videos, and does consume credits. That page still names Manus 1.6 agents (Lite on the free plan; Lite, 1.6 and Max on paid plans), while the September 28 announcement introduces Manus 2.0. The two had not been reconciled as of September 30, 2026, so check the model menu in the app rather than trusting either name.

For work made of many similar items, Wide Research splits the job into independent sub-tasks and gives each one its own agent with a fresh context, running in parallel, then assembles the results. Manus suggests it for things like comparing dozens of products or researching a long list of prospects, and says it is not the right choice for a single analysis, for steps that depend on each other, or for fewer than about ten items.

Where Manus can reach

  • Its cloud browser: it visits sites, clicks, fills in forms and extracts data. You can sign in to accounts there and the sessions persist across tasks until you log out under Settings → Cloud Browser → Logged-in Accounts. Manus’s cloud browser page (opens in a new tab) notes it runs from data center IP addresses, so some sites respond with CAPTCHAs or extra checks; when that happens you Take Over, complete the check, and hand control back.
  • Your own browser: the Browser Operator extension, recommended for Chrome and Edge, lets Manus act in your browser using the sessions you are already signed in to. Your computer has to stay on and online while it works.
  • Your own computer: the desktop app’s My Computer feature, on macOS and Windows, gives Manus access only to folders you add. Its desktop documentation (opens in a new tab) says every command it tries to run locally needs your approval, with Allow Once or Always Allow.
  • A persistent machine: Cloud Computer is a dedicated cloud machine that stays on for bots, scripts and scheduled jobs, unlike the per-task sandbox, which ends with the session.
  • On a schedule or a trigger: automations run a task at set times, when an event happens in a connected source such as GitHub, Gmail or Notion, or as a workflow you describe in plain language.

Connecting Manus to your tools

Manus uses MCP for its integrations. Prebuilt connectors, available on all plans, include Gmail, Google Calendar, Google Drive, Notion, HubSpot, Stripe, GitHub and Hugging Face; you sign in with OAuth and then mention the app in your prompt. For anything else, Manus’s page on custom MCP servers (opens in a new tab) says to go to Settings → Integrations → Custom MCP Servers, choose Add Server, and give a name, the server’s HTTPS URL and its credentials, such as an API key or bearer token. Manus then checks it can reach the server and lists its tools. There is also a REST API for starting tasks from your own software. What MCP is in general is in the MCP glossary entry.

Manus vs ChatGPT agent

The comparison people search for has changed shape. OpenAI’s help center now says ChatGPT agent is no longer available and points to ChatGPT Work for longer, multi-step tasks; the history and the replacement are covered in ChatGPT agent mode. So the fair comparison today is Manus against ChatGPT Work, and structurally the two are closer than they are different:

  • Both are general agents aimed at a finished deliverable rather than a chat answer, and both run tasks in the cloud with a browser and code execution.
  • Both can also work on your own machine through a desktop app, and both can act in your signed-in browser through an extension.
  • Manus puts more emphasis on parallel work (Wide Research), on building and hosting websites and apps, and on always-on cloud machines and automations.
  • ChatGPT Work sits inside ChatGPT, next to your existing chats, projects and connected apps, and on business plans follows the permissions your workspace sets for those apps.

If your team already runs on one of them, the switching cost is usually the deciding factor, not a feature list. For the wider category, see what agentic AI is.

The limits to plan around

  • Credits: Agent-mode tasks are billed by complexity, so a long or open-ended task costs more than you might guess. Manus’s own advice is to be specific, batch similar requests and check intermediate results. Plans are Free, Pro and Team; see Manus for current terms.
  • Blocked sites: the cloud browser cannot get past advanced bot protection on its own and will stop for you at CAPTCHAs, text codes and MFA.
  • It acts as you: a persistent cloud-browser login, the Browser Operator or Always Allow on your computer each let the agent do anything you could do there. Web pages it reads can carry instructions aimed at it; see indirect prompt injection.
  • Unstated approvals: the custom MCP documentation does not say whether each tool call is approved first, so give a connected server only the permissions you are happy for it to use unattended.
  • Your data: given the 2026 ownership change and the data deletion that came with it, read Manus’s current terms and keep your own copies of anything important.
  • Finished is not the same as correct: a polished report or site can still be wrong. Verifying AI-generated work covers how to check it.

Giving Manus a task list instead of a prompt

Manus is good at finishing a task and less suited to being the place where a team’s list of tasks lives: tasks are private by default, and a finished task is a result, not a record of what is left. fenbs is a small task board that people and AI assistants share. Each task has a note saying what and why, a plan, and a test status with notes, and sits in one of four lanes, To Do, Next Up, In Progress and Completed. Because Manus accepts a custom MCP server with a bearer token, you can connect it with a token you issue in fenbs under Settings, with a name, the scopes you choose and an optional expiry:

Manus: Settings → Integrations → Custom MCP Servers
Name:           fenbs
Server URL:     https://fenbs.ai/api/mcp
Authentication: Bearer token issued in fenbs (name, scopes, optional expiry)

Then ask Manus to read the next task in Next Up, do it, and comment on the task with what it produced. History records each change under the token’s name, and revoking the token ends access. Keep the scopes narrow: fenbs offers read, write and comment, so an agent that only needs to report back gets read and comment, not write. The token also holds your role on the board, and the narrower of the two wins. fenbs has no due dates, sprints or settable assignee, so it will not schedule the work for you; it keeps the list, and the rules on the Decisions and rules page that every connected assistant reads first.

Related

Connecting a board safely: how to give an AI agent access to your project board and the MCP docs. What replaced ChatGPT agent: ChatGPT agent mode. Before you let any agent loose: how to keep an AI agent from wrecking your board.

Questions people ask.

What is the Manus AI agent?

Manus is a general-purpose AI agent that works on its own virtual computer in the cloud. You describe an outcome, and it plans the steps, browses, runs code and returns a finished result such as a report, slides, a spreadsheet or a website.

Is Manus AI free?

There is a free plan with a limited monthly credit allowance. Chat mode does not use credits; Agent-mode tasks do, and paid Pro and Team plans add more credits and more capable agents. Check Manus for current terms.

Is Manus owned by Meta?

Meta announced it was acquiring Manus in December 2025. In August 2026 Manus told users it is returning to independent operation and, to meet regulatory requirements, deleted data generated by certain users on or after December 29, 2025, after giving them time to back it up.

How is Manus different from ChatGPT agent?

ChatGPT agent is no longer available; OpenAI now points users to ChatGPT Work. Manus and ChatGPT Work are both general agents that run tasks in the cloud and can use your own computer or browser. Manus adds parallel Wide Research, website building and hosting, and always-on cloud machines.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.