Skip to main content
Browserbase recommends that you deploy Stagehand as a Browserbase Function. The Function runs next to its browser session on Browserbase, and it reads your API key from an encrypted project secret. You do not need a separate server, a Chrome binary, or a secrets store. Stagehand also runs on other platforms. If Functions is not a good fit for you, see Other deployment options.

Prerequisites

  • A Browserbase API key from Settings
  • Node.js 22.18 or later and pnpm
  • The browse CLI:

Deploy a Stagehand Function

These steps start from a template project. The template contains a starter Function that you replace with your own Stagehand code before you publish.
1

Initialize a Functions project

The initializer installs Stagehand and creates a starter Stagehand Function in index.ts.
2

Upload the Stagehand extension

Stagehand needs its extension in the browser session, and a session cannot get an extension after it starts. Upload the extension one time for your project:
In index.ts, replace your-extension-id with the id from the output.
3

Replace the starter Function

This is the starter Function in index.ts. Replace the template with the Stagehand code that you want to deploy. Keep the defineFn call. If you change the name my-function, use the new name in the steps that follow.
Stagehand doesn’t need a model API key, and when you omit it, Stagehand uses the Model Gateway. Browserbase charges for the tokens.
4

Test locally

Export your key, then start the development server:
In another terminal, invoke the Function by the name that you gave to defineFn:
5

Publish

The output contains builtFunctions. Copy the id of my-function. This is the Function ID.
You’re looking for builtFunctions[].id for this step.
If the build fails, open the build in the Browserbase dashboard to see the build logs.
6

Create and attach the secret

Create a project secret for your Browserbase API key. The name of the secret is the key in context.secrets:
The CLI encrypts the value on your machine before it sends it. Copy the id of the secret, then attach it to the Function:
The list output must show the secret. Attached secrets take effect on the next invocation.
7

Invoke the Function

The command waits for the invocation and prints its result. You can also invoke the Function from the Browserbase dashboard.

Troubleshooting

  • function or secret not found when you attach a secret: an ID is incorrect. Use browse cloud secrets list to verify your secret IDs and the Functions dashboard to verify your Function ID.
  • Secret "BROWSERBASE_API_KEY" is not set: the secret is not attached to this Function. Run browse functions secrets list <functionId> to view attached secrets and browse functions secrets attach <functionId> <secretId> to attach the missing secret.

Features

  • No local browsers needed: Browserbase provides the browser, so your Function ships without a Chrome binary.
  • Encrypted secrets: your API key stays in a Browserbase project secret, and the Function reads it from context.secrets.
  • No model provider setup: the Model Gateway picks a model for each call, and Browserbase charges for the tokens. You only need your Browserbase API key.

Other deployment options

Run Stagehand on Browserbase inside a Vercel Function. This guide shows a minimal HTTP endpoint you can call directly or on a schedule.
Every request to this endpoint opens a Browserbase session and spends model tokens. Vercel serves production deployments publicly, so gate the handler before you deploy it. The handlers below reject any request that does not present Authorization: Bearer $CRON_SECRET, the same header Vercel sends on cron invocations.
1

Install Vercel CLI

To download and install Vercel CLI, run one of the following commands:
2

Project layout

Create the structure with:
3

api/run.ts (Node.js runtime)

4

package.json

5

tsconfig.json

6

vercel.json

See Vercel’s configuring functions docs for more details.
7

Link your project

Link your local folder to a Vercel project before configuring environment variables:
8

Environment variables

Never commit secrets. Add variables via the Vercel CLI, then read them in your handler and pass them where you launch the browser and create the Stagehand client. CRON_SECRET is the secret the handler compares against the Authorization header, and Vercel sends it automatically when a cron job invokes the function:
Using the Model Gateway means BROWSERBASE_API_KEY is the only secret you need to deploy.
See also: Browser Configuration for details on required variables.
9

Test locally

Replicate the Vercel environment locally to exercise your Function before deploying. Run from the project root.
10

Deploy

11

Execute the function

Every request needs Authorization: Bearer $CRON_SECRET. Requests without it get a 401 and never reach Browserbase.
12

Configure protection bypass for automation

If the deployment also sits behind Vercel Deployment Protection, create a Protection Bypass for Automation so scripted callers can reach it:
  1. Generate a 32-character secret (you can use openssl rand -hex 16)
  2. Go to your project in Vercel
  3. Navigate to Settings, then Deployment Protection
  4. Add the secret to “Protection Bypass for Automation”
Then invoke the function with the bypass header:
13

Optional: cron on Vercel

Hit the same endpoint on a schedule by extending vercel.json. Cron invocations arrive as GET requests carrying Authorization: Bearer $CRON_SECRET, so the handler’s secret check passes without extra configuration:
Features
  • No local browsers needed with a Browserbase browser. Browserbase provides the browsers, so your function ships without a Chrome binary.
  • Fast functionality: Offload browser work to Browserbase and return JSON promptly.
  • Long-running tasks: Raise maxDuration and/or consider Edge runtime limits depending on plan.
  • Cheap repeat runs: Turn on server-side caching so scheduled invocations replay recorded actions instead of paying for inference every hour.