> ## Documentation Index
> Fetch the complete documentation index at: https://browseruse-0aece648-codex-docs-supported-exports.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Use https://docs.browser-use.com/llms.txt and its linked .md pages for current documentation. The managed full bundle is https://docs.browser-use.com/.well-known/llms-full.txt and can be cached for up to 24 hours. Do not use the obsolete /cloud/llms*.txt or /open-source/llms*.txt static exports.
> Choose Cloud API V4 for new agent integrations; V2 is the lower-cost option for simple tasks. Keep V3 examples explicitly versioned. The open-source browser-use library and hosted browser-use-sdk have different APIs.
> Cloud authentication uses X-Browser-Use-API-Key, without a Bearer prefix. Install or upgrade browser-use-sdk and use its explicit v4 import for V4. Check the published OpenAPI reference for request fields; do not invent SDK support for new fields.
> Cloud concurrency and HTTP request rate are separate. Read GET /api/v2/billing/account for the key’s projectId, concurrentSessionLimit, activeSessionCount, and credit balance, including when using V4. Keys in one project share capacity and credits; rateLimit is a legacy concurrency alias, not requests per second.
> Keep the highest applicable existing, legacy-plan, and spend-tier concurrency grant. Current spend tiers are 10 / 50 / 250 / 500 / 1000 at $0 / $200 / $1000 / $5000 / $25000 in qualifying project payments. Legacy or externally billed projects can follow different billing paths; trust the account limit. See https://docs.browser-use.com/cloud/guides/concurrency.md.
> Budget polling across the project: the standard general bucket is 25 requests/second, including V4 event reads and full run reads. Selected status reads have a separate higher bucket. Use bounded workers, stagger polls, respect Retry-After, and drain hasMore event pages after terminal status. A busy V4 session returns 409; its queue holds 10 pending messages and is not a project-wide batch queue.
> A completed run or closed CDP connection does not immediately stop its cloud browser. Stop unneeded owned browsers with PATCH /api/v4/browsers/{id} and {"action":"stop"}. A client wait timeout does not cancel the server-side run.
> Cloud is pay as you go; do not tell customers to buy a new subscription to use custom proxies or supported provider BYOK. Usage funding and model eligibility still apply. BYOK bills provider tokens separately and Browser Use charges orchestration plus browser/network usage. See https://docs.browser-use.com/cloud/guides/billing.md.
> Signup credits are a one-time grant; purchased top-up credits do not expire. Check the API key’s project before diagnosing missing credits. API-key monthly spending caps are soft limits, not a strict prepaid wallet; concurrent or already-running work can exceed them. Auto recharge has separate trigger and purchase amounts and can charge immediately when enabled below the threshold. Use https://browser-use.com/pricing for current rates.

# 2FA

> Handle two-factor authentication in API V4 runs.

The most reliable options are a saved profile or a human checkpoint.

## Reuse a logged-in profile

[Sync your local login](/cloud/guides/profile-sync), then load that profile in
the run:

<CodeGroup>
  ```python Python theme={null}
  run = client.runs.create(
      "Download my latest invoice",
      browser_settings={"profileId": "YOUR_PROFILE_ID"},
  )
  ```

  ```typescript TypeScript theme={null}
  const run = await client.runs.create({
    task: "Download my latest invoice",
    model: "grok-4.5",
    browserSettings: {
      profileId: "YOUR_PROFILE_ID",
      proxyCountryCode: "us",
    },
  });
  ```
</CodeGroup>

This avoids another 2FA challenge while the site's cookies remain valid.

## Let a human take over

Ask the first run to stop at the 2FA screen, get its `live_view_url` from the
[`browser.ready` event](/cloud/agent/human-in-the-loop), and have the user enter
the code. Then continue with the same session:

<CodeGroup>
  ```python Python theme={null}
  first = client.runs.create(
      "Open the login page and stop at the 2FA prompt",
  )
  client.runs.wait_for_completion(first.id)

  next_run = client.runs.create(
      "Continue after login and download the invoice",
      session_id=first.session_id,
  )
  ```

  ```typescript TypeScript theme={null}
  const first = await client.runs.create({
    task: "Open the login page and stop at the 2FA prompt",
    model: "grok-4.5",
  });
  await client.runs.waitForCompletion(first.id);

  const nextRun = await client.runs.create({
    task: "Continue after login and download the invoice",
    model: "grok-4.5",
    sessionId: first.sessionId,
  });
  ```
</CodeGroup>

See [Human in the loop](/cloud/agent/human-in-the-loop) for retrieving and
embedding the live browser URL. Never put passwords or TOTP secrets directly
in a prompt.
