New features, fixes and breaking changes in Boxline, newest first.
New
CAPTCHAs: we tell you, and wait for a person
When a page in a session shows a CAPTCHA that needs a person, Boxline now notices it and hands over to a person. It does not solve CAPTCHAs. Read CAPTCHAs for the details.
Recognised: reCAPTCHA, hCaptcha, Cloudflare Turnstile and the “Just a moment…” page, DataDome, Arkose and HUMAN press-and-hold. Only visible, unanswered challenges count; invisible widgets and checks that pass by themselves are not reported.
Sessions have attention (the CAPTCHA waiting, or null), and log captcha events when one is detected and when it is cleared.
New captcha option on POST /v1/sessions and PATCH /v1/sessions/:id: "ask" (default) or "ignore".
Agent runs pause with handover.by: "captcha" and continue by themselves once a person has solved it in the live view; they fail after 5 minutes if nobody does. Plain-English steps wait up to 4 minutes, then fail with captcha_timeout. Failed action results now carry a code when there is one.
Fetch returns captcha, screenshot and PDF send an x-page-captcha header, and crawl pages have captcha.
SDKs: session.waitForHuman(), session.onCaptcha() and captcha on crawl pages (TypeScript), session.wait_for_human() and captcha= on sessions.create and session.update (Python).
proxy can be a list of up to 10 rules. Each rule is a proxy, or { "type": "none" } to go straight out, with an optional domainPattern (a regular expression on the site’s host name). The first match wins; no match goes straight out.
Each proxy in a list keeps its own sticky IP; POST /v1/sessions/:id/proxy/rotate gives them all new ones.
proxy: true is short for a residential proxy in the US.
Agent runs take proxy for the session they create.
Lists work on new sessions, PATCH /v1/sessions/:id, agent runs, fetch, screenshot, PDF, extract and crawl.
New error reason bad_route in the X-Boxline-Proxy-Error header.
SDKs: TypeScript ProxyOption is true, one proxy or a list of ProxyRule; Python’s proxy= takes True, a dict or a list of dicts.
New
Proxies: residential, datacenter and your own, per session and per request
Sessions can now send their traffic through a proxy. Read the Proxies guide for the details.
proxy on POST /v1/sessions: residential (by country, US state or city), datacenter (by country), or your own http:// or https:// proxy. Its password is stored encrypted and never returned.
Sticky IPs by default for sessions and crawls, and a new IP on demand with POST /v1/sessions/:id/proxy/rotate.
Change or remove the proxy of a running session with PATCH /v1/sessions/:id.
scope: "all" sends the shell’s traffic (curl, pip, git) through the proxy too.
The same proxy option on fetch, screenshot, PDF, extract (rotating IPs by default) and crawl (one IP per crawl).
Pause, resume and move keep the proxy, and the IP while the provider still has it.
Proxy data is billed per GB, with a monthly allowance per plan; your own proxy has no data charge. GET /v1/usage reports proxy data.
SDKs: setProxy and rotateProxy (TypeScript), set_proxy and rotate_proxy (Python). The MCP server’s session_create takes proxyType, proxyCountry and proxyCity.
Launch
Private beta
Boxline is open in private beta. Read the announcement for the background. Available today:
Sessions with a Chrome browser (Playwright, Puppeteer or raw CDP) and a live view.
Optional bash shell with Python and Node included, persistent sessions, streaming exec and an interactive terminal.
Shared /workspace disk with read, write, list, delete and wait-for-file endpoints; browser downloads land in /workspace/downloads.
Warm-pool starts, session move, and pause and resume.
Contexts for keeping logins between sessions, and cookie export for reusing a browser login from the shell.
Actions API, Fetch API and Agent API.
MCP server and TypeScript SDK.
Per-second billing with Free, Hobby, Startup and Scale plans.
Coming soon: residential proxies, desktop (computer-use) sessions and GPU sessions.