Someone posted on Hacker News about building an AI browser agent to automate Reddit, and the detail that stuck with me wasn’t the build. It was the reason. Official API access wasn’t available to them. Not too expensive, not rate-limited into uselessness. Just not grantable.

That’s a different failure mode than price, and I think it’s the more common one now.

Approval queues are the new paywall

Pricing you can argue with. You can find budget, downgrade a plan, split a cost with a teammate. But an application form that sits in a queue for six weeks and comes back with a polite no has no lever attached to it.

Look at what’s actually behind a form right now: X’s API tiers, Reddit’s commercial access, most enterprise SaaS reporting endpoints, LinkedIn basically anything. Then there’s the enormous category that never had an API to gate. Your company’s expense tool. The supplier portal your ops team lives in. Some state licensing database that was last redesigned when jQuery was a reasonable choice.

For all of these you have working credentials. You log in every day. The data renders on your screen. And the machine-readable path to that same data is either locked, priced for a company with a procurement department, or was never built.

So people reach for a scraper, and the scraper walks in as nobody

The default workaround is a headless browser on a server somewhere. Playwright in a container, maybe one of the hosted browser-agent platforms that had a launch cluster this same week, most of them open source, most of them autoscaling, all of them running on hardware that has never seen your cookies.

Every one of those sessions starts logged out. So now you’re solving a problem you didn’t have: piping credentials into a remote box, storing a session token where it probably shouldn’t live, handling the 2FA prompt, then losing all of it when the site rotates something and the whole session goes stale at 3am. I wrote more about that gap in why cloud browser agents can’t see your tabs, and the short version is that the login wall isn’t a bug you engineer around. It’s the entire distance between the two approaches.

An agent running inside the Chrome you already use doesn’t cross that distance. There isn’t one. The site sees your session, your cookies, your user agent, your residential IP, because it is your session.

What this looks like in practice

Say the gated thing is a vendor dashboard with a report you need weekly, and the vendor sells API access as an add-on to a tier three levels above yours.

You open the report in a tab. You’re already logged in, because you logged in on Monday like always. Then you open Dassi in the side panel and describe what you want: read this table, get every row, follow the pagination to the end, give me name, invoice number, amount, and status as CSV.

The agent reads the rendered page the way you do. It sees the DOM, clicks “next,” waits for the rows to load, keeps going until the pagination runs out. Nothing about the traffic looks unusual to the vendor, because nothing about it is unusual: it’s a logged-in user paging through their own report at roughly human speed. When it’s done you get the CSV, and no access request was ever filed.

Same shape works for a lot of things. Pulling the last 200 support tickets out of a helpdesk that only exports PDFs. Reading a supplier portal’s order status into a table you can actually diff against last week. Collecting your own post history from a platform whose export tool has been “coming soon” since 2023. Dassi is free, runs in the side panel, and you can point it at whatever tab you’ve got open — it’s on the Chrome Web Store if you want to try it against something ugly.

The part where I ruin it

Your session is not a skeleton key.

What you don’t get

You only get what your own account can already see. If the dashboard hides a field from your role, the agent hides it too. No privilege escalation, no hidden endpoints, no seeing other tenants’ rows.

Rate limits still apply, and they apply harder, because you’re one user with one IP and the site’s abuse detection is tuned for exactly that. Hammering pagination at ten pages a second is a good way to get a temporary block on the account you use for actual work.

Terms of service still apply. Plenty of sites explicitly prohibit automated access regardless of whether you’re authenticated, and “my browser did it” is not a clever legal theory. Read the terms for anything you don’t own. For your own company’s internal tools this is usually a non-issue; for third-party platforms it’s genuinely worth five minutes.

And it’s slower than an API. Much slower. If a real endpoint exists and you can get approved for it, get approved for it. Browser automation is what you do when the API isn’t there, not when it’s there and mildly annoying.

Which, honestly, is most of the time now. The approval queue has quietly become the default state of the web, and the funniest part is that everyone building agents to route around it keeps building them on servers that have to knock on the door and ask to be let in. The door’s already open. You’re standing in it.