{"id":"816bb9f2-9341-4ce8-9227-ec259e422abb","entityType":"agent","slug":"clawhub-luigi-agosti-pinchtab","name":"Pinchtab","canonicalUrl":"https://www.xpersona.co/agent/clawhub-luigi-agosti-pinchtab","canonicalPath":"/agent/clawhub-luigi-agosti-pinchtab","generatedAt":"2026-10-09T20:29:02.427Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Control a headless or headed Chrome browser via Pinchtab's HTTP API. Use for web automation, scraping, form filling, navigation, and multi-tab workflows. Pin... Skill: Pinchtab Owner: luigi-agosti Summary: Control a headless or headed Chrome browser via Pinchtab's HTTP API. Use for web automation, scraping, form filling, navigation, and multi-tab workflows. Pin... Tags: latest:0.7.6 Version history: v0.7.6 | 2026-02-26T09:55:15.108Z | user Release v0.7.6 v0.7.5 | 2026-02-26T02:17:44.758Z | user Release v0.7.5 v0.7.4 | 2026-02-26T00:48:59.285Z | user Release v0.7.4 v0.7.3 | 2","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 562 downloads reported by the source. Last updated 4/15/2026.","installCommand":"clawhub skill install kn75yfbg457nxg5e8yeh2ngtx9817sam:pinchtab","sourceUrl":"https://clawhub.ai/luigi-agosti/pinchtab","homepage":"https://clawhub.ai/luigi-agosti/pinchtab","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/luigi-agosti/pinchtab","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":55,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Control a headless or headed Chrome browser via Pinchtab's HTTP API. Use for web automation, scraping, form filling, navigation, and multi-tab workflows. Pin..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"stars":null,"forks":null,"downloads":562,"packageName":null,"latestVersion":"0.7.6","tractionLabel":"562 downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-03-01T04:39:01.292Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-03-01T04:39:01.292Z","lastIndexedAt":null,"nextCrawlAt":"2026-03-02T04:39:01.292Z","lastVerifiedAt":null,"highlights":[{"version":"0.7.6","createdAt":"2026-02-26T09:55:15.108Z","changelog":"Release v0.7.6","fileCount":6,"zipByteSize":9790},{"version":"0.7.5","createdAt":"2026-02-26T02:17:44.758Z","changelog":"Release v0.7.5","fileCount":6,"zipByteSize":9790},{"version":"0.7.4","createdAt":"2026-02-26T00:48:59.285Z","changelog":"Release v0.7.4","fileCount":null,"zipByteSize":null},{"version":"0.7.3","createdAt":"2026-02-26T00:36:06.721Z","changelog":"Release v0.7.3","fileCount":null,"zipByteSize":null},{"version":"0.7.2","createdAt":"2026-02-26T00:20:11.755Z","changelog":"Release v0.7.2","fileCount":null,"zipByteSize":null},{"version":"0.7.1","createdAt":"2026-02-25T22:13:03.096Z","changelog":"Release v0.7.1","fileCount":null,"zipByteSize":null},{"version":"0.7.0","createdAt":"2026-02-25T07:46:14.817Z","changelog":"Release v0.7.0","fileCount":null,"zipByteSize":null},{"version":"0.6.2","createdAt":"2026-02-22T23:09:20.389Z","changelog":"Release v0.6.2","fileCount":null,"zipByteSize":null}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install kn75yfbg457nxg5e8yeh2ngtx9817sam:pinchtab","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-luigi-agosti-pinchtab/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-luigi-agosti-pinchtab/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-luigi-agosti-pinchtab/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-luigi-agosti-pinchtab/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-luigi-agosti-pinchtab/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-luigi-agosti-pinchtab/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T20:29:02.426Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-luigi-agosti-pinchtab/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-luigi-agosti-pinchtab/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-luigi-agosti-pinchtab/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-luigi-agosti-pinchtab/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"Skill: Pinchtab\n\nOwner: luigi-agosti\n\nSummary: Control a headless or headed Chrome browser via Pinchtab's HTTP API. Use for web automation, scraping, form filling, navigation, and multi-tab workflows. Pin...\n\nTags: latest:0.7.6\n\nVersion history:\n\nv0.7.6 | 2026-02-26T09:55:15.108Z | user\n\nRelease v0.7.6\n\nv0.7.5 | 2026-02-26T02:17:44.758Z | user\n\nRelease v0.7.5\n\nv0.7.4 | 2026-02-26T00:48:59.285Z | user\n\nRelease v0.7.4\n\nv0.7.3 | 2026-02-26T00:36:06.721Z | user\n\nRelease v0.7.3\n\nv0.7.2 | 2026-02-26T00:20:11.755Z | user\n\nRelease v0.7.2\n\nv0.7.1 | 2026-02-25T22:13:03.096Z | user\n\nRelease v0.7.1\n\nv0.7.0 | 2026-02-25T07:46:14.817Z | user\n\nRelease v0.7.0\n\nv0.6.2 | 2026-02-22T23:09:20.389Z | user\n\nRelease v0.6.2\n\nv0.6.1 | 2026-02-21T14:39:16.807Z | user\n\nRelease v0.6.1\n\nv0.6.0 | 2026-02-21T12:26:19.495Z | user\n\nRelease v0.6.0\n\nv0.5.1 | 2026-02-20T14:10:07.348Z | user\n\nRelease v0.5.1\n\nv0.5.0 | 2026-02-20T13:58:55.600Z | user\n\nRelease v0.5.0\n\nv0.4.0 | 2026-02-17T13:37:26.622Z | user\n\nRelease v0.4.0\n\nv0.3.1 | 2026-02-15T18:57:01.246Z | user\n\nRelease v0.3.1\n\nv0.3.0 | 2026-02-15T17:53:04.242Z | user\n\nRelease v0.3.0\n\nArchive index:\n\nArchive v0.7.6: 6 files, 9790 bytes\n\nFiles: references/api.md (7387b), references/env.md (2336b), references/profiles.md (2758b), SKILL.md (6286b), TRUST.md (2553b), _meta.json (127b)\n\nFile v0.7.6:SKILL.md\n\n---\nname: pinchtab\ndescription: >\n  Control a headless or headed Chrome browser via Pinchtab's HTTP API. Use for web automation,\n  scraping, form filling, navigation, and multi-tab workflows. Pinchtab exposes the accessibility\n  tree as flat JSON with stable refs — optimized for AI agents (low token cost, fast).\n  Use when the task involves: browsing websites, filling forms, clicking buttons, extracting\n  page text, taking screenshots, or any browser-based automation. Requires a running Pinchtab\n  instance (Go binary).\nhomepage: https://pinchtab.com\nmetadata:\n  openclaw:\n    emoji: \"🦀\"\n    requires:\n      bins: [\"pinchtab\"]\n      env:\n        - name: BRIDGE_TOKEN\n          secret: true\n          optional: true\n          description: \"Bearer auth token for Pinchtab API\"\n        - name: BRIDGE_PORT\n          optional: true\n          description: \"HTTP port (default: 9867)\"\n        - name: BRIDGE_HEADLESS\n          optional: true\n          description: \"Run Chrome headless (true/false)\"\n---\n\n# Pinchtab\n\nFast, lightweight browser control for AI agents via HTTP + accessibility tree.\n\n**Security Note:** Pinchtab runs a local Chrome browser under your control. It does not access your credentials, exfiltrate data, or connect to external services. All interactions stay local unless you explicitly navigate to external sites. Binary distributed via [GitHub releases](https://github.com/pinchtab/pinchtab/releases) with checksums. See [TRUST.md](TRUST.md) for full security model and VirusTotal flag explanation.\n\n## Quick Start (Agent Workflow)\n\nThe 30-second pattern for browser tasks:\n\n```bash\n# 1. Start Pinchtab (runs forever, local on :9867)\npinchtab &\n\n# 2. In your agent, follow this loop:\n#    a) Navigate to a URL\n#    b) Snapshot the page (get refs like e0, e5, e12)\n#    c) Act on a ref (click e5, type e12 \"search text\")\n#    d) Snapshot again to see the result\n#    e) Repeat step c-d until done\n```\n\n**That's it.** Refs are stable—you don't need to re-snapshot before every action. Only snapshot when the page changes significantly.\n\n## Setup\n\n```bash\n# Headless (default) — no visible window\npinchtab &\n\n# Headed — visible Chrome window for human debugging\nBRIDGE_HEADLESS=false pinchtab &\n\n# With auth token\nBRIDGE_TOKEN=\"your-secret-token\" pinchtab &\n\n# Custom port\nBRIDGE_PORT=8080 pinchtab &\n\n# Dashboard/orchestrator — profile manager + tab launcher\npinchtab dashboard &\n```\n\nDefault: **port 9867**, no auth required (local). Set `BRIDGE_TOKEN` for remote access.\n\nFor advanced setup, see [references/profiles.md](references/profiles.md) and [references/env.md](references/env.md).\n\n## What a Snapshot Looks Like\n\nAfter calling `/snapshot`, you get the page's accessibility tree as JSON—flat list of elements with refs:\n\n```json\n{\n  \"refs\": [\n    {\"id\": \"e0\", \"role\": \"link\", \"text\": \"Sign In\", \"selector\": \"a[href='/login']\"},\n    {\"id\": \"e1\", \"role\": \"textbox\", \"label\": \"Email\", \"selector\": \"input[name='email']\"},\n    {\"id\": \"e2\", \"role\": \"button\", \"text\": \"Submit\", \"selector\": \"button[type='submit']\"}\n  ],\n  \"text\": \"... readable text version of page ...\",\n  \"title\": \"Login Page\"\n}\n```\n\nThen you act on refs: `click e0`, `type e1 \"user@example.com\"`, `press e2 Enter`.\n\n## Core Workflow\n\nThe typical agent loop:\n\n1. **Navigate** to a URL\n2. **Snapshot** the accessibility tree (get refs)\n3. **Act** on refs (click, type, press)\n4. **Snapshot** again to see results\n\nRefs (e.g. `e0`, `e5`, `e12`) are cached per tab after each snapshot — no need to re-snapshot before every action unless the page changed significantly.\n\n### Quick examples\n\n```bash\npinchtab nav https://example.com\npinchtab snap -i -c                    # interactive + compact\npinchtab click e5\npinchtab type e12 hello world\npinchtab press Enter\npinchtab text                          # readable text (~1K tokens)\npinchtab text | jq .text               # pipe to jq\npinchtab ss -o page.jpg                # screenshot\npinchtab eval \"document.title\"         # run JavaScript\npinchtab pdf -o page.pdf               # export PDF\n```\n\nFor the full HTTP API (curl examples, download, upload, cookies, stealth, batch actions), see [references/api.md](references/api.md).\n\n## Token Cost Guide\n\n| Method | Typical tokens | When to use |\n|---|---|---|\n| `/text` | ~800 | Reading page content |\n| `/snapshot?filter=interactive` | ~3,600 | Finding buttons/links to click |\n| `/snapshot?diff=true` | varies | Multi-step workflows (only changes) |\n| `/snapshot?format=compact` | ~56-64% less | One-line-per-node, best efficiency |\n| `/snapshot` | ~10,500 | Full page understanding |\n| `/screenshot` | ~2K (vision) | Visual verification |\n\n**Strategy**: Start with `?filter=interactive&format=compact`. Use `?diff=true` on subsequent snapshots. Use `/text` when you only need readable content. Full `/snapshot` only when needed.\n\n## Agent Optimization\n\n**Validated Feb 2026**: Testing with AI agents revealed a critical pattern for reliable, token-efficient scraping.\n\n**See the full guide:** [docs/agent-optimization.md](../../docs/agent-optimization.md)\n\n### Quick Summary\n\n**The 3-second pattern** — wait after navigate before snapshot:\n\n```bash\ncurl -X POST http://localhost:9867/navigate \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"url\": \"https://example.com\"}' && \\\nsleep 3 && \\\ncurl http://localhost:9867/snapshot | jq '.nodes[] | select(.name | length > 15) | .name'\n```\n\n**Token savings:** 93% reduction (3,842 → 272 tokens) when using prescriptive instructions vs. exploratory agent approach.\n\nFor detailed findings, system prompt templates, and site-specific notes, see [docs/agent-optimization.md](../../docs/agent-optimization.md).\n\n## Tips\n\n- **Always pass `tabId` explicitly** when working with multiple tabs\n- Refs are stable between snapshot and actions — no need to re-snapshot before clicking\n- After navigation or major page changes, take a new snapshot for fresh refs\n- Pinchtab persists sessions — tabs survive restarts (disable with `BRIDGE_NO_RESTORE=true`)\n- Chrome profile is persistent — cookies/logins carry over between runs\n- Use `BRIDGE_BLOCK_IMAGES=true` or `\"blockImages\": true` on navigate for read-heavy tasks\n- **Wait 3+ seconds after navigate before snapshot** — Chrome needs time to render 2000+ accessibility tree nodes\n\nFile v0.7.6:_meta.json\n\n{\n  \"ownerId\": \"kn75yfbg457nxg5e8yeh2ngtx9817sam\",\n  \"slug\": \"pinchtab\",\n  \"version\": \"0.7.6\",\n  \"publishedAt\": 1772099715108\n}\n\nFile v0.7.6:references/api.md\n\n# Pinchtab API Reference\n\nBase URL for all examples: `http://localhost:9867`\n\n> **CLI alternative:** All endpoints have CLI equivalents. Use `pinchtab help` for the full list. Examples are shown as `# CLI:` comments below.\n\n## Navigate\n\n```bash\n# CLI: pinchtab nav https://example.com [--new-tab] [--block-images]\ncurl -X POST /navigate \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"url\": \"https://example.com\"}'\n\n# With options: custom timeout, block images, open in new tab\ncurl -X POST /navigate \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"url\": \"https://example.com\", \"timeout\": 60, \"blockImages\": true, \"newTab\": true}'\n```\n\n## Snapshot (accessibility tree)\n\n```bash\n# CLI: pinchtab snap [-i] [-c] [-d] [-s main] [--max-tokens 2000]\n# Full tree\ncurl /snapshot\n\n# Interactive elements only (buttons, links, inputs) — much smaller\ncurl \"/snapshot?filter=interactive\"\n\n# Limit depth\ncurl \"/snapshot?depth=5\"\n\n# Smart diff — only changes since last snapshot (massive token savings)\ncurl \"/snapshot?diff=true\"\n\n# Text format — indented tree, ~40-60% fewer tokens than JSON\ncurl \"/snapshot?format=text\"\n\n# Compact format — one-line-per-node, 56-64% fewer tokens than JSON (recommended)\ncurl \"/snapshot?format=compact\"\n\n# YAML format\ncurl \"/snapshot?format=yaml\"\n\n# Scope to CSS selector (e.g. main content only)\ncurl \"/snapshot?selector=main\"\n\n# Truncate to ~N tokens\ncurl \"/snapshot?maxTokens=2000\"\n\n# Combine for maximum efficiency\ncurl \"/snapshot?format=compact&selector=main&maxTokens=2000&filter=interactive\"\n\n# Disable animations before capture\ncurl \"/snapshot?noAnimations=true\"\n\n# Write to file\ncurl \"/snapshot?output=file&path=/tmp/snapshot.json\"\n```\n\nReturns flat JSON array of nodes with `ref`, `role`, `name`, `depth`, `value`, `nodeId`.\n\n**Token optimization**: Use `?format=compact` for best token efficiency. Add `?filter=interactive` for action-oriented tasks (~75% fewer nodes). Use `?selector=main` to scope to relevant content. Use `?maxTokens=2000` to cap output. Use `?diff=true` on multi-step workflows to see only changes. Combine all params freely.\n\n## Act on elements\n\n```bash\n# CLI: pinchtab click e5 / pinchtab type e12 hello / pinchtab press Enter\n# Click by ref\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"click\", \"ref\": \"e5\"}'\n\n# Type into focused element (click first, then type)\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"click\", \"ref\": \"e12\"}'\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"type\", \"ref\": \"e12\", \"text\": \"hello world\"}'\n\n# Press a key\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"press\", \"key\": \"Enter\"}'\n\n# Focus an element\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"focus\", \"ref\": \"e3\"}'\n\n# Fill (set value directly, no keystrokes)\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"fill\", \"selector\": \"#email\", \"text\": \"user@example.com\"}'\n\n# Hover (trigger dropdowns/tooltips)\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"hover\", \"ref\": \"e8\"}'\n\n# Select dropdown option (by value or visible text)\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"select\", \"ref\": \"e10\", \"value\": \"option2\"}'\n\n# Scroll to element\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"scroll\", \"ref\": \"e20\"}'\n\n# Scroll by pixels (infinite scroll pages)\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"scroll\", \"scrollY\": 800}'\n\n# Click and wait for navigation (link clicks)\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"click\", \"ref\": \"e5\", \"waitNav\": true}'\n```\n\n## Batch actions\n\n```bash\n# Execute multiple actions in sequence\ncurl -X POST /actions -H 'Content-Type: application/json' \\\n  -d '{\"actions\":[{\"kind\":\"click\",\"ref\":\"e3\"},{\"kind\":\"type\",\"ref\":\"e3\",\"text\":\"hello\"},{\"kind\":\"press\",\"key\":\"Enter\"}]}'\n\n# Stop on first error (default: false)\ncurl -X POST /actions -H 'Content-Type: application/json' \\\n  -d '{\"tabId\":\"TARGET_ID\",\"actions\":[...],\"stopOnError\":true}'\n```\n\n## Extract text\n\n```bash\n# CLI: pinchtab text [--raw]\n# Readability mode (default) — strips nav/footer/ads\ncurl /text\n\n# Raw innerText\ncurl \"/text?mode=raw\"\n```\n\nReturns `{url, title, text}`. Cheapest option (~1K tokens for most pages).\n\n## PDF export\n\n```bash\n# CLI: pinchtab pdf [-o file.pdf] [--landscape] [--scale 0.8]\n# Returns base64 JSON\ncurl /pdf\n\n# Raw PDF bytes\ncurl \"/pdf?raw=true\" -o page.pdf\n\n# Save to disk\ncurl \"/pdf?output=file&path=/tmp/page.pdf\"\n\n# Landscape with custom scale\ncurl \"/pdf?landscape=true&scale=0.8&raw=true\" -o page.pdf\n```\n\nWraps `Page.printToPDF`. Prints background graphics by default.\n\n## Download files\n\n```bash\n# Returns base64 JSON by default (uses browser session/cookies/stealth)\ncurl \"/download?url=https://site.com/report.pdf\"\n\n# Raw bytes (pipe to file)\ncurl \"/download?url=https://site.com/image.jpg&raw=true\" -o image.jpg\n\n# Save directly to disk\ncurl \"/download?url=https://site.com/export.csv&output=file&path=/tmp/export.csv\"\n```\n\n## Upload files\n\n```bash\n# Upload a local file to a file input\ncurl -X POST \"/upload?tabId=TAB_ID\" -H \"Content-Type: application/json\" \\\n  -d '{\"selector\": \"input[type=file]\", \"paths\": [\"/tmp/photo.jpg\"]}'\n\n# Upload base64-encoded data\ncurl -X POST /upload -H \"Content-Type: application/json\" \\\n  -d '{\"selector\": \"#avatar-input\", \"files\": [\"data:image/png;base64,iVBOR...\"]}'\n```\n\nSets files on `<input type=file>` elements via CDP. Fires `change` events. Selector defaults to `input[type=file]` if omitted.\n\n## Screenshot\n\n```bash\n# CLI: pinchtab ss [-o file.jpg] [-q 80]\ncurl \"/screenshot?raw=true\" -o screenshot.jpg\ncurl \"/screenshot?raw=true&quality=50\" -o screenshot.jpg\n```\n\n## Evaluate JavaScript\n\n```bash\n# CLI: pinchtab eval \"document.title\"\ncurl -X POST /evaluate -H 'Content-Type: application/json' \\\n  -d '{\"expression\": \"document.title\"}'\n```\n\n## Tab management\n\n```bash\n# CLI: pinchtab tabs / pinchtab tabs new <url> / pinchtab tabs close <id>\n# List tabs\ncurl /tabs\n\n# Open new tab\ncurl -X POST /tab -H 'Content-Type: application/json' \\\n  -d '{\"action\": \"new\", \"url\": \"https://example.com\"}'\n\n# Close tab\ncurl -X POST /tab -H 'Content-Type: application/json' \\\n  -d '{\"action\": \"close\", \"tabId\": \"TARGET_ID\"}'\n```\n\nMulti-tab: pass `?tabId=TARGET_ID` to snapshot/screenshot/text, or `\"tabId\"` in POST body.\n\n## Tab locking (multi-agent)\n\n```bash\n# Lock a tab (default 30s timeout, max 5min)\ncurl -X POST /tab/lock -H 'Content-Type: application/json' \\\n  -d '{\"tabId\": \"TARGET_ID\", \"owner\": \"agent-1\", \"timeoutSec\": 60}'\n\n# Unlock\ncurl -X POST /tab/unlock -H 'Content-Type: application/json' \\\n  -d '{\"tabId\": \"TARGET_ID\", \"owner\": \"agent-1\"}'\n```\n\nLocked tabs show `owner` and `lockedUntil` in `/tabs`. Returns 409 on conflict.\n\n## Cookies\n\n```bash\n# Get cookies for current page\ncurl /cookies\n\n# Set cookies\ncurl -X POST /cookies -H 'Content-Type: application/json' \\\n  -d '{\"url\":\"https://example.com\",\"cookies\":[{\"name\":\"session\",\"value\":\"abc123\"}]}'\n```\n\n## Stealth\n\n```bash\n# Check stealth status and score\ncurl /stealth/status\n\n# Rotate browser fingerprint\ncurl -X POST /fingerprint/rotate -H 'Content-Type: application/json' \\\n  -d '{\"os\":\"windows\"}'\n# os: \"windows\", \"mac\", or omit for random\n```\n\n## Health check\n\n```bash\ncurl /health\n```\n\nFile v0.7.6:references/env.md\n\n# Pinchtab Environment Variables\n\n## Core runtime\n\n| Var | Default | Description |\n|---|---|---|\n| `BRIDGE_BIND` | `127.0.0.1` | Bind address. Set `0.0.0.0` for network access |\n| `BRIDGE_PORT` | `9867` | HTTP port |\n| `BRIDGE_HEADLESS` | `true` | Run Chrome headless |\n| `BRIDGE_TOKEN` | (none) | Bearer auth token (recommended with `0.0.0.0`) |\n| `BRIDGE_PROFILE` | `~/.pinchtab/chrome-profile` | Chrome profile dir |\n| `BRIDGE_STATE_DIR` | `~/.pinchtab` | State/session storage |\n| `BRIDGE_NO_RESTORE` | `false` | Skip tab restore on startup |\n| `BRIDGE_STEALTH` | `light` | Stealth level: `light` or `full` |\n| `BRIDGE_MAX_TABS` | `20` | Max open tabs (0 = unlimited) |\n| `BRIDGE_BLOCK_IMAGES` | `false` | Block image loading |\n| `BRIDGE_BLOCK_MEDIA` | `false` | Block all media (images + fonts + CSS + video) |\n| `BRIDGE_NO_ANIMATIONS` | `false` | Disable CSS animations/transitions |\n| `BRIDGE_TIMEZONE` | (none) | Force browser timezone (IANA tz) |\n| `BRIDGE_CHROME_VERSION` | `144.0.7559.133` | Chrome version for fingerprint rotation |\n| `BRIDGE_USER_AGENT` | (none) | Custom User-Agent string; also overrides Sec-Ch-Ua client hints via CDP |\n| `CHROME_BINARY` | (auto) | Path to Chrome/Chromium binary |\n| `CHROME_FLAGS` | (none) | Extra Chrome flags (space-separated) |\n| `BRIDGE_CONFIG` | `~/.pinchtab/config.json` | Path to config JSON file |\n| `BRIDGE_TIMEOUT` | `15` | Action timeout (seconds) |\n| `BRIDGE_NAV_TIMEOUT` | `30` | Navigation timeout (seconds) |\n| `CDP_URL` | (none) | Connect to existing Chrome DevTools |\n| `BRIDGE_NO_DASHBOARD` | `false` | Disable dashboard endpoints on instance processes |\n\n## CLI client\n\n| Var | Default | Description |\n|---|---|---|\n| `PINCHTAB_URL` | `http://localhost:9867` | Pinchtab server URL for CLI commands |\n| `PINCHTAB_TOKEN` | (none) | Auth token for CLI (sent as `Authorization: Bearer`) |\n\n## Dashboard mode (`pinchtab dashboard`)\n\n| Var | Default | Description |\n|---|---|---|\n| `PINCHTAB_AUTO_LAUNCH` | `false` | Auto-launch default profile at startup |\n| `PINCHTAB_DEFAULT_PROFILE` | `default` | Profile name for auto-launch |\n| `PINCHTAB_DEFAULT_PORT` | `9867` | Port for auto-launched profile |\n| `PINCHTAB_HEADED` | (unset) | If set, auto-launched profile is headed |\n| `PINCHTAB_DASHBOARD_URL` | `http://localhost:$BRIDGE_PORT` | Base URL for `pinchtab connect` |\n\nFile v0.7.6:references/profiles.md\n\n# Profile Management (Dashboard Mode)\n\nWhen running `pinchtab dashboard`, profiles are managed via the dashboard API on port 9867.\n\n## List profiles\n\n```bash\ncurl http://localhost:9867/profiles\n```\n\nReturns array of profiles with `id`, `name`, `accountEmail`, `useWhen`, etc.\n\n## Start a profile\n\n```bash\n# Auto-allocate port (recommended)\ncurl -X POST http://localhost:9867/profiles/<ID>/start\n\n# With specific port and headless mode\ncurl -X POST http://localhost:9867/profiles/<ID>/start \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"port\": \"9868\", \"headless\": true}'\n\n# Short alias\ncurl -X POST http://localhost:9867/start/<ID>\n```\n\nReturns instance info including allocated `port`. Use that port for all subsequent API calls.\n\n## Stop a profile\n\n```bash\ncurl -X POST http://localhost:9867/profiles/<ID>/stop\n\n# Short alias\ncurl -X POST http://localhost:9867/stop/<ID>\n```\n\n## Check instance status\n\n```bash\n# By profile ID (recommended)\ncurl http://localhost:9867/profiles/<ID>/instance\n\n# By profile name\ncurl http://localhost:9867/profiles/My%20Profile/instance\n```\n\n## Launch by name\n\n```bash\ncurl -X POST http://localhost:9867/instances/launch \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"name\": \"work\", \"port\": \"9868\"}'\n```\n\n## CLI usage with profiles\n\nThe CLI doesn't have profile subcommands yet — use `curl` for profile management.\nOnce a profile instance is running, point the CLI at it:\n\n```bash\n# Get the instance port, then use CLI\nPINCHTAB_URL=http://localhost:9868 pinchtab snap -i\n```\n\n## Typical agent flow\n\n```bash\n# 1. List profiles\nPROFILES=$(curl -s http://localhost:9867/profiles)\n\n# 2. Start profile (auto-allocates port)\nINSTANCE=$(curl -s -X POST http://localhost:9867/profiles/$PROFILE_ID/start)\nPORT=$(echo $INSTANCE | jq -r .port)\n\n# 3. Use the instance\ncurl -X POST http://localhost:$PORT/navigate -H 'Content-Type: application/json' \\\n  -d '{\"url\": \"https://mail.google.com\"}'\ncurl http://localhost:$PORT/snapshot?maxTokens=4000\n\n# 4. Stop when done\ncurl -s -X POST http://localhost:9867/profiles/$PROFILE_ID/stop\n```\n\n## Profile IDs\n\nEach profile gets a stable 12-char hex ID (SHA-256 of name, truncated) stored in `profile.json`. IDs are URL-safe and never change — use them instead of names in automation.\n\n## Headed mode\n\nHeaded mode = real visible Chrome window managed by Pinchtab.\n\n- Human can log in, pass 2FA/captcha, validate state\n- Agent calls HTTP APIs against the same running instance\n- Session state persists in profile directory (cookies/storage carry over)\n\nRecommended human + agent flow:\n\n```bash\n# Human starts dashboard and sets up profile\npinchtab dashboard\n\n# Agent resolves the profile endpoint\nPINCHTAB_BASE_URL=\"$(pinchtab connect <profile-name>)\"\ncurl \"$PINCHTAB_BASE_URL/health\"\n```\n\nFile v0.7.6:TRUST.md\n\n# Pinchtab Security & Trust\n\n**TL;DR**: Pinchtab is a local, sandboxed browser control tool. It does not phone home, steal credentials, or exfiltrate data. Source code is public; binaries are signed and published via GitHub.\n\n## What Pinchtab Does\n\n- Launches a Chrome browser (local, under your control)\n- Exposes navigation, clicking, typing, and page inspection via HTTP API\n- Extracts the page's accessibility tree (for AI agents)\n- Runs screenshots, PDFs, and JavaScript evaluation\n\n**All of this stays local.** No telemetry. No external API calls (except to sites you navigate to).\n\n## What Pinchtab Does NOT Do\n\n- ❌ Doesn't access your saved passwords/credentials (Chrome sandboxing)\n- ❌ Doesn't exfiltrate data to remote servers\n- ❌ Doesn't inject ads, malware, or miners\n- ❌ Doesn't track browsing or send analytics\n- ❌ Doesn't modify system files outside its state directory (`~/.pinchtab`)\n\n## Builds & Verification\n\nEvery release includes **checksums** alongside binaries:\n\n```bash\n# After downloading, verify:\nsha256sum -c checksums.txt\n```\n\nBinaries are built automatically from tagged commits via GitHub Actions (publicly visible at https://github.com/pinchtab/pinchtab/actions).\n\n## Open Source\n\n- **Source**: https://github.com/pinchtab/pinchtab (Apache 2.0)\n- **Releases**: https://github.com/pinchtab/pinchtab/releases\n- **Latest**: v0.7.0 (Feb 2026)\n\nIf you're concerned, audit the source—it's 12MB, zero external dependencies, mostly Go stdlib.\n\n## VirusTotal Flag\n\nPinchtab may trigger heuristic scanners on VirusTotal because:\n\n- ✓ It launches Chrome (subprocess execution — flagged by AV heuristics)\n- ✓ It runs JavaScript evaluation (eval-like operations)\n- ✓ It makes HTTP requests (network activity)\n\nThese are **intentional design features**, not security flaws. Your browser does all three things by default.\n\n**False positives are common for development tools.** If you're concerned, verify the checksum against the [official GitHub release](https://github.com/pinchtab/pinchtab/releases) before running.\n\n## Sandboxing\n\nPinchtab runs a separate Chrome process with:\n\n- Isolated profile directory (default: `~/.pinchtab`)\n- No access to your user's home files (unless you explicitly navigate to `file://` URLs)\n- Standard Chrome security model (site isolation, CSP, etc.)\n\nSet `BRIDGE_PROFILE_DIR` to use a custom directory if needed.\n\n## Questions?\n\n- Source code: https://github.com/pinchtab/pinchtab\n- Issues/security reports: https://github.com/pinchtab/pinchtab/issues\n- Docs: https://pinchtab.com\n\nArchive v0.7.5: 6 files, 9790 bytes\n\nFiles: references/api.md (7387b), references/env.md (2336b), references/profiles.md (2758b), SKILL.md (6286b), TRUST.md (2553b), _meta.json (127b)\n\nFile v0.7.5:SKILL.md\n\n---\nname: pinchtab\ndescription: >\n  Control a headless or headed Chrome browser via Pinchtab's HTTP API. Use for web automation,\n  scraping, form filling, navigation, and multi-tab workflows. Pinchtab exposes the accessibility\n  tree as flat JSON with stable refs — optimized for AI agents (low token cost, fast).\n  Use when the task involves: browsing websites, filling forms, clicking buttons, extracting\n  page text, taking screenshots, or any browser-based automation. Requires a running Pinchtab\n  instance (Go binary).\nhomepage: https://pinchtab.com\nmetadata:\n  openclaw:\n    emoji: \"🦀\"\n    requires:\n      bins: [\"pinchtab\"]\n      env:\n        - name: BRIDGE_TOKEN\n          secret: true\n          optional: true\n          description: \"Bearer auth token for Pinchtab API\"\n        - name: BRIDGE_PORT\n          optional: true\n          description: \"HTTP port (default: 9867)\"\n        - name: BRIDGE_HEADLESS\n          optional: true\n          description: \"Run Chrome headless (true/false)\"\n---\n\n# Pinchtab\n\nFast, lightweight browser control for AI agents via HTTP + accessibility tree.\n\n**Security Note:** Pinchtab runs a local Chrome browser under your control. It does not access your credentials, exfiltrate data, or connect to external services. All interactions stay local unless you explicitly navigate to external sites. Binary distributed via [GitHub releases](https://github.com/pinchtab/pinchtab/releases) with checksums. See [TRUST.md](TRUST.md) for full security model and VirusTotal flag explanation.\n\n## Quick Start (Agent Workflow)\n\nThe 30-second pattern for browser tasks:\n\n```bash\n# 1. Start Pinchtab (runs forever, local on :9867)\npinchtab &\n\n# 2. In your agent, follow this loop:\n#    a) Navigate to a URL\n#    b) Snapshot the page (get refs like e0, e5, e12)\n#    c) Act on a ref (click e5, type e12 \"search text\")\n#    d) Snapshot again to see the result\n#    e) Repeat step c-d until done\n```\n\n**That's it.** Refs are stable—you don't need to re-snapshot before every action. Only snapshot when the page changes significantly.\n\n## Setup\n\n```bash\n# Headless (default) — no visible window\npinchtab &\n\n# Headed — visible Chrome window for human debugging\nBRIDGE_HEADLESS=false pinchtab &\n\n# With auth token\nBRIDGE_TOKEN=\"your-secret-token\" pinchtab &\n\n# Custom port\nBRIDGE_PORT=8080 pinchtab &\n\n# Dashboard/orchestrator — profile manager + tab launcher\npinchtab dashboard &\n```\n\nDefault: **port 9867**, no auth required (local). Set `BRIDGE_TOKEN` for remote access.\n\nFor advanced setup, see [references/profiles.md](references/profiles.md) and [references/env.md](references/env.md).\n\n## What a Snapshot Looks Like\n\nAfter calling `/snapshot`, you get the page's accessibility tree as JSON—flat list of elements with refs:\n\n```json\n{\n  \"refs\": [\n    {\"id\": \"e0\", \"role\": \"link\", \"text\": \"Sign In\", \"selector\": \"a[href='/login']\"},\n    {\"id\": \"e1\", \"role\": \"textbox\", \"label\": \"Email\", \"selector\": \"input[name='email']\"},\n    {\"id\": \"e2\", \"role\": \"button\", \"text\": \"Submit\", \"selector\": \"button[type='submit']\"}\n  ],\n  \"text\": \"... readable text version of page ...\",\n  \"title\": \"Login Page\"\n}\n```\n\nThen you act on refs: `click e0`, `type e1 \"user@example.com\"`, `press e2 Enter`.\n\n## Core Workflow\n\nThe typical agent loop:\n\n1. **Navigate** to a URL\n2. **Snapshot** the accessibility tree (get refs)\n3. **Act** on refs (click, type, press)\n4. **Snapshot** again to see results\n\nRefs (e.g. `e0`, `e5`, `e12`) are cached per tab after each snapshot — no need to re-snapshot before every action unless the page changed significantly.\n\n### Quick examples\n\n```bash\npinchtab nav https://example.com\npinchtab snap -i -c                    # interactive + compact\npinchtab click e5\npinchtab type e12 hello world\npinchtab press Enter\npinchtab text                          # readable text (~1K tokens)\npinchtab text | jq .text               # pipe to jq\npinchtab ss -o page.jpg                # screenshot\npinchtab eval \"document.title\"         # run JavaScript\npinchtab pdf -o page.pdf               # export PDF\n```\n\nFor the full HTTP API (curl examples, download, upload, cookies, stealth, batch actions), see [references/api.md](references/api.md).\n\n## Token Cost Guide\n\n| Method | Typical tokens | When to use |\n|---|---|---|\n| `/text` | ~800 | Reading page content |\n| `/snapshot?filter=interactive` | ~3,600 | Finding buttons/links to click |\n| `/snapshot?diff=true` | varies | Multi-step workflows (only changes) |\n| `/snapshot?format=compact` | ~56-64% less | One-line-per-node, best efficiency |\n| `/snapshot` | ~10,500 | Full page understanding |\n| `/screenshot` | ~2K (vision) | Visual verification |\n\n**Strategy**: Start with `?filter=interactive&format=compact`. Use `?diff=true` on subsequent snapshots. Use `/text` when you only need readable content. Full `/snapshot` only when needed.\n\n## Agent Optimization\n\n**Validated Feb 2026**: Testing with AI agents revealed a critical pattern for reliable, token-efficient scraping.\n\n**See the full guide:** [docs/agent-optimization.md](../../docs/agent-optimization.md)\n\n### Quick Summary\n\n**The 3-second pattern** — wait after navigate before snapshot:\n\n```bash\ncurl -X POST http://localhost:9867/navigate \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"url\": \"https://example.com\"}' && \\\nsleep 3 && \\\ncurl http://localhost:9867/snapshot | jq '.nodes[] | select(.name | length > 15) | .name'\n```\n\n**Token savings:** 93% reduction (3,842 → 272 tokens) when using prescriptive instructions vs. exploratory agent approach.\n\nFor detailed findings, system prompt templates, and site-specific notes, see [docs/agent-optimization.md](../../docs/agent-optimization.md).\n\n## Tips\n\n- **Always pass `tabId` explicitly** when working with multiple tabs\n- Refs are stable between snapshot and actions — no need to re-snapshot before clicking\n- After navigation or major page changes, take a new snapshot for fresh refs\n- Pinchtab persists sessions — tabs survive restarts (disable with `BRIDGE_NO_RESTORE=true`)\n- Chrome profile is persistent — cookies/logins carry over between runs\n- Use `BRIDGE_BLOCK_IMAGES=true` or `\"blockImages\": true` on navigate for read-heavy tasks\n- **Wait 3+ seconds after navigate before snapshot** — Chrome needs time to render 2000+ accessibility tree nodes\n\nFile v0.7.5:_meta.json\n\n{\n  \"ownerId\": \"kn75yfbg457nxg5e8yeh2ngtx9817sam\",\n  \"slug\": \"pinchtab\",\n  \"version\": \"0.7.5\",\n  \"publishedAt\": 1772072264758\n}\n\nFile v0.7.5:references/api.md\n\n# Pinchtab API Reference\n\nBase URL for all examples: `http://localhost:9867`\n\n> **CLI alternative:** All endpoints have CLI equivalents. Use `pinchtab help` for the full list. Examples are shown as `# CLI:` comments below.\n\n## Navigate\n\n```bash\n# CLI: pinchtab nav https://example.com [--new-tab] [--block-images]\ncurl -X POST /navigate \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"url\": \"https://example.com\"}'\n\n# With options: custom timeout, block images, open in new tab\ncurl -X POST /navigate \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"url\": \"https://example.com\", \"timeout\": 60, \"blockImages\": true, \"newTab\": true}'\n```\n\n## Snapshot (accessibility tree)\n\n```bash\n# CLI: pinchtab snap [-i] [-c] [-d] [-s main] [--max-tokens 2000]\n# Full tree\ncurl /snapshot\n\n# Interactive elements only (buttons, links, inputs) — much smaller\ncurl \"/snapshot?filter=interactive\"\n\n# Limit depth\ncurl \"/snapshot?depth=5\"\n\n# Smart diff — only changes since last snapshot (massive token savings)\ncurl \"/snapshot?diff=true\"\n\n# Text format — indented tree, ~40-60% fewer tokens than JSON\ncurl \"/snapshot?format=text\"\n\n# Compact format — one-line-per-node, 56-64% fewer tokens than JSON (recommended)\ncurl \"/snapshot?format=compact\"\n\n# YAML format\ncurl \"/snapshot?format=yaml\"\n\n# Scope to CSS selector (e.g. main content only)\ncurl \"/snapshot?selector=main\"\n\n# Truncate to ~N tokens\ncurl \"/snapshot?maxTokens=2000\"\n\n# Combine for maximum efficiency\ncurl \"/snapshot?format=compact&selector=main&maxTokens=2000&filter=interactive\"\n\n# Disable animations before capture\ncurl \"/snapshot?noAnimations=true\"\n\n# Write to file\ncurl \"/snapshot?output=file&path=/tmp/snapshot.json\"\n```\n\nReturns flat JSON array of nodes with `ref`, `role`, `name`, `depth`, `value`, `nodeId`.\n\n**Token optimization**: Use `?format=compact` for best token efficiency. Add `?filter=interactive` for action-oriented tasks (~75% fewer nodes). Use `?selector=main` to scope to relevant content. Use `?maxTokens=2000` to cap output. Use `?diff=true` on multi-step workflows to see only changes. Combine all params freely.\n\n## Act on elements\n\n```bash\n# CLI: pinchtab click e5 / pinchtab type e12 hello / pinchtab press Enter\n# Click by ref\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"click\", \"ref\": \"e5\"}'\n\n# Type into focused element (click first, then type)\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"click\", \"ref\": \"e12\"}'\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"type\", \"ref\": \"e12\", \"text\": \"hello world\"}'\n\n# Press a key\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"press\", \"key\": \"Enter\"}'\n\n# Focus an element\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"focus\", \"ref\": \"e3\"}'\n\n# Fill (set value directly, no keystrokes)\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"fill\", \"selector\": \"#email\", \"text\": \"user@example.com\"}'\n\n# Hover (trigger dropdowns/tooltips)\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"hover\", \"ref\": \"e8\"}'\n\n# Select dropdown option (by value or visible text)\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"select\", \"ref\": \"e10\", \"value\": \"option2\"}'\n\n# Scroll to element\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"scroll\", \"ref\": \"e20\"}'\n\n# Scroll by pixels (infinite scroll pages)\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"scroll\", \"scrollY\": 800}'\n\n# Click and wait for navigation (link clicks)\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"click\", \"ref\": \"e5\", \"waitNav\": true}'\n```\n\n## Batch actions\n\n```bash\n# Execute multiple actions in sequence\ncurl -X POST /actions -H 'Content-Type: application/json' \\\n  -d '{\"actions\":[{\"kind\":\"click\",\"ref\":\"e3\"},{\"kind\":\"type\",\"ref\":\"e3\",\"text\":\"hello\"},{\"kind\":\"press\",\"key\":\"Enter\"}]}'\n\n# Stop on first error (default: false)\ncurl -X POST /actions -H 'Content-Type: application/json' \\\n  -d '{\"tabId\":\"TARGET_ID\",\"actions\":[...],\"stopOnError\":true}'\n```\n\n## Extract text\n\n```bash\n# CLI: pinchtab text [--raw]\n# Readability mode (default) — strips nav/footer/ads\ncurl /text\n\n# Raw innerText\ncurl \"/text?mode=raw\"\n```\n\nReturns `{url, title, text}`. Cheapest option (~1K tokens for most pages).\n\n## PDF export\n\n```bash\n# CLI: pinchtab pdf [-o file.pdf] [--landscape] [--scale 0.8]\n# Returns base64 JSON\ncurl /pdf\n\n# Raw PDF bytes\ncurl \"/pdf?raw=true\" -o page.pdf\n\n# Save to disk\ncurl \"/pdf?output=file&path=/tmp/page.pdf\"\n\n# Landscape with custom scale\ncurl \"/pdf?landscape=true&scale=0.8&raw=true\" -o page.pdf\n```\n\nWraps `Page.printToPDF`. Prints background graphics by default.\n\n## Download files\n\n```bash\n# Returns base64 JSON by default (uses browser session/cookies/stealth)\ncurl \"/download?url=https://site.com/report.pdf\"\n\n# Raw bytes (pipe to file)\ncurl \"/download?url=https://site.com/image.jpg&raw=true\" -o image.jpg\n\n# Save directly to disk\ncurl \"/download?url=https://site.com/export.csv&output=file&path=/tmp/export.csv\"\n```\n\n## Upload files\n\n```bash\n# Upload a local file to a file input\ncurl -X POST \"/upload?tabId=TAB_ID\" -H \"Content-Type: application/json\" \\\n  -d '{\"selector\": \"input[type=file]\", \"paths\": [\"/tmp/photo.jpg\"]}'\n\n# Upload base64-encoded data\ncurl -X POST /upload -H \"Content-Type: application/json\" \\\n  -d '{\"selector\": \"#avatar-input\", \"files\": [\"data:image/png;base64,iVBOR...\"]}'\n```\n\nSets files on `<input type=file>` elements via CDP. Fires `change` events. Selector defaults to `input[type=file]` if omitted.\n\n## Screenshot\n\n```bash\n# CLI: pinchtab ss [-o file.jpg] [-q 80]\ncurl \"/screenshot?raw=true\" -o screenshot.jpg\ncurl \"/screenshot?raw=true&quality=50\" -o screenshot.jpg\n```\n\n## Evaluate JavaScript\n\n```bash\n# CLI: pinchtab eval \"document.title\"\ncurl -X POST /evaluate -H 'Content-Type: application/json' \\\n  -d '{\"expression\": \"document.title\"}'\n```\n\n## Tab management\n\n```bash\n# CLI: pinchtab tabs / pinchtab tabs new <url> / pinchtab tabs close <id>\n# List tabs\ncurl /tabs\n\n# Open new tab\ncurl -X POST /tab -H 'Content-Type: application/json' \\\n  -d '{\"action\": \"new\", \"url\": \"https://example.com\"}'\n\n# Close tab\ncurl -X POST /tab -H 'Content-Type: application/json' \\\n  -d '{\"action\": \"close\", \"tabId\": \"TARGET_ID\"}'\n```\n\nMulti-tab: pass `?tabId=TARGET_ID` to snapshot/screenshot/text, or `\"tabId\"` in POST body.\n\n## Tab locking (multi-agent)\n\n```bash\n# Lock a tab (default 30s timeout, max 5min)\ncurl -X POST /tab/lock -H 'Content-Type: application/json' \\\n  -d '{\"tabId\": \"TARGET_ID\", \"owner\": \"agent-1\", \"timeoutSec\": 60}'\n\n# Unlock\ncurl -X POST /tab/unlock -H 'Content-Type: application/json' \\\n  -d '{\"tabId\": \"TARGET_ID\", \"owner\": \"agent-1\"}'\n```\n\nLocked tabs show `owner` and `lockedUntil` in `/tabs`. Returns 409 on conflict.\n\n## Cookies\n\n```bash\n# Get cookies for current page\ncurl /cookies\n\n# Set cookies\ncurl -X POST /cookies -H 'Content-Type: application/json' \\\n  -d '{\"url\":\"https://example.com\",\"cookies\":[{\"name\":\"session\",\"value\":\"abc123\"}]}'\n```\n\n## Stealth\n\n```bash\n# Check stealth status and score\ncurl /stealth/status\n\n# Rotate browser fingerprint\ncurl -X POST /fingerprint/rotate -H 'Content-Type: application/json' \\\n  -d '{\"os\":\"windows\"}'\n# os: \"windows\", \"mac\", or omit for random\n```\n\n## Health check\n\n```bash\ncurl /health\n```\n\nFile v0.7.5:references/env.md\n\n# Pinchtab Environment Variables\n\n## Core runtime\n\n| Var | Default | Description |\n|---|---|---|\n| `BRIDGE_BIND` | `127.0.0.1` | Bind address. Set `0.0.0.0` for network access |\n| `BRIDGE_PORT` | `9867` | HTTP port |\n| `BRIDGE_HEADLESS` | `true` | Run Chrome headless |\n| `BRIDGE_TOKEN` | (none) | Bearer auth token (recommended with `0.0.0.0`) |\n| `BRIDGE_PROFILE` | `~/.pinchtab/chrome-profile` | Chrome profile dir |\n| `BRIDGE_STATE_DIR` | `~/.pinchtab` | State/session storage |\n| `BRIDGE_NO_RESTORE` | `false` | Skip tab restore on startup |\n| `BRIDGE_STEALTH` | `light` | Stealth level: `light` or `full` |\n| `BRIDGE_MAX_TABS` | `20` | Max open tabs (0 = unlimited) |\n| `BRIDGE_BLOCK_IMAGES` | `false` | Block image loading |\n| `BRIDGE_BLOCK_MEDIA` | `false` | Block all media (images + fonts + CSS + video) |\n| `BRIDGE_NO_ANIMATIONS` | `false` | Disable CSS animations/transitions |\n| `BRIDGE_TIMEZONE` | (none) | Force browser timezone (IANA tz) |\n| `BRIDGE_CHROME_VERSION` | `144.0.7559.133` | Chrome version for fingerprint rotation |\n| `BRIDGE_USER_AGENT` | (none) | Custom User-Agent string; also overrides Sec-Ch-Ua client hints via CDP |\n| `CHROME_BINARY` | (auto) | Path to Chrome/Chromium binary |\n| `CHROME_FLAGS` | (none) | Extra Chrome flags (space-separated) |\n| `BRIDGE_CONFIG` | `~/.pinchtab/config.json` | Path to config JSON file |\n| `BRIDGE_TIMEOUT` | `15` | Action timeout (seconds) |\n| `BRIDGE_NAV_TIMEOUT` | `30` | Navigation timeout (seconds) |\n| `CDP_URL` | (none) | Connect to existing Chrome DevTools |\n| `BRIDGE_NO_DASHBOARD` | `false` | Disable dashboard endpoints on instance processes |\n\n## CLI client\n\n| Var | Default | Description |\n|---|---|---|\n| `PINCHTAB_URL` | `http://localhost:9867` | Pinchtab server URL for CLI commands |\n| `PINCHTAB_TOKEN` | (none) | Auth token for CLI (sent as `Authorization: Bearer`) |\n\n## Dashboard mode (`pinchtab dashboard`)\n\n| Var | Default | Description |\n|---|---|---|\n| `PINCHTAB_AUTO_LAUNCH` | `false` | Auto-launch default profile at startup |\n| `PINCHTAB_DEFAULT_PROFILE` | `default` | Profile name for auto-launch |\n| `PINCHTAB_DEFAULT_PORT` | `9867` | Port for auto-launched profile |\n| `PINCHTAB_HEADED` | (unset) | If set, auto-launched profile is headed |\n| `PINCHTAB_DASHBOARD_URL` | `http://localhost:$BRIDGE_PORT` | Base URL for `pinchtab connect` |\n\nFile v0.7.5:references/profiles.md\n\n# Profile Management (Dashboard Mode)\n\nWhen running `pinchtab dashboard`, profiles are managed via the dashboard API on port 9867.\n\n## List profiles\n\n```bash\ncurl http://localhost:9867/profiles\n```\n\nReturns array of profiles with `id`, `name`, `accountEmail`, `useWhen`, etc.\n\n## Start a profile\n\n```bash\n# Auto-allocate port (recommended)\ncurl -X POST http://localhost:9867/profiles/<ID>/start\n\n# With specific port and headless mode\ncurl -X POST http://localhost:9867/profiles/<ID>/start \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"port\": \"9868\", \"headless\": true}'\n\n# Short alias\ncurl -X POST http://localhost:9867/start/<ID>\n```\n\nReturns instance info including allocated `port`. Use that port for all subsequent API calls.\n\n## Stop a profile\n\n```bash\ncurl -X POST http://localhost:9867/profiles/<ID>/stop\n\n# Short alias\ncurl -X POST http://localhost:9867/stop/<ID>\n```\n\n## Check instance status\n\n```bash\n# By profile ID (recommended)\ncurl http://localhost:9867/profiles/<ID>/instance\n\n# By profile name\ncurl http://localhost:9867/profiles/My%20Profile/instance\n```\n\n## Launch by name\n\n```bash\ncurl -X POST http://localhost:9867/instances/launch \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"name\": \"work\", \"port\": \"9868\"}'\n```\n\n## CLI usage with profiles\n\nThe CLI doesn't have profile subcommands yet — use `curl` for profile management.\nOnce a profile instance is running, point the CLI at it:\n\n```bash\n# Get the instance port, then use CLI\nPINCHTAB_URL=http://localhost:9868 pinchtab snap -i\n```\n\n## Typical agent flow\n\n```bash\n# 1. List profiles\nPROFILES=$(curl -s http://localhost:9867/profiles)\n\n# 2. Start profile (auto-allocates port)\nINSTANCE=$(curl -s -X POST http://localhost:9867/profiles/$PROFILE_ID/start)\nPORT=$(echo $INSTANCE | jq -r .port)\n\n# 3. Use the instance\ncurl -X POST http://localhost:$PORT/navigate -H 'Content-Type: application/json' \\\n  -d '{\"url\": \"https://mail.google.com\"}'\ncurl http://localhost:$PORT/snapshot?maxTokens=4000\n\n# 4. Stop when done\ncurl -s -X POST http://localhost:9867/profiles/$PROFILE_ID/stop\n```\n\n## Profile IDs\n\nEach profile gets a stable 12-char hex ID (SHA-256 of name, truncated) stored in `profile.json`. IDs are URL-safe and never change — use them instead of names in automation.\n\n## Headed mode\n\nHeaded mode = real visible Chrome window managed by Pinchtab.\n\n- Human can log in, pass 2FA/captcha, validate state\n- Agent calls HTTP APIs against the same running instance\n- Session state persists in profile directory (cookies/storage carry over)\n\nRecommended human + agent flow:\n\n```bash\n# Human starts dashboard and sets up profile\npinchtab dashboard\n\n# Agent resolves the profile endpoint\nPINCHTAB_BASE_URL=\"$(pinchtab connect <profile-name>)\"\ncurl \"$PINCHTAB_BASE_URL/health\"\n```\n\nFile v0.7.5:TRUST.md\n\n# Pinchtab Security & Trust\n\n**TL;DR**: Pinchtab is a local, sandboxed browser control tool. It does not phone home, steal credentials, or exfiltrate data. Source code is public; binaries are signed and published via GitHub.\n\n## What Pinchtab Does\n\n- Launches a Chrome browser (local, under your control)\n- Exposes navigation, clicking, typing, and page inspection via HTTP API\n- Extracts the page's accessibility tree (for AI agents)\n- Runs screenshots, PDFs, and JavaScript evaluation\n\n**All of this stays local.** No telemetry. No external API calls (except to sites you navigate to).\n\n## What Pinchtab Does NOT Do\n\n- ❌ Doesn't access your saved passwords/credentials (Chrome sandboxing)\n- ❌ Doesn't exfiltrate data to remote servers\n- ❌ Doesn't inject ads, malware, or miners\n- ❌ Doesn't track browsing or send analytics\n- ❌ Doesn't modify system files outside its state directory (`~/.pinchtab`)\n\n## Builds & Verification\n\nEvery release includes **checksums** alongside binaries:\n\n```bash\n# After downloading, verify:\nsha256sum -c checksums.txt\n```\n\nBinaries are built automatically from tagged commits via GitHub Actions (publicly visible at https://github.com/pinchtab/pinchtab/actions).\n\n## Open Source\n\n- **Source**: https://github.com/pinchtab/pinchtab (Apache 2.0)\n- **Releases**: https://github.com/pinchtab/pinchtab/releases\n- **Latest**: v0.7.0 (Feb 2026)\n\nIf you're concerned, audit the source—it's 12MB, zero external dependencies, mostly Go stdlib.\n\n## VirusTotal Flag\n\nPinchtab may trigger heuristic scanners on VirusTotal because:\n\n- ✓ It launches Chrome (subprocess execution — flagged by AV heuristics)\n- ✓ It runs JavaScript evaluation (eval-like operations)\n- ✓ It makes HTTP requests (network activity)\n\nThese are **intentional design features**, not security flaws. Your browser does all three things by default.\n\n**False positives are common for development tools.** If you're concerned, verify the checksum against the [official GitHub release](https://github.com/pinchtab/pinchtab/releases) before running.\n\n## Sandboxing\n\nPinchtab runs a separate Chrome process with:\n\n- Isolated profile directory (default: `~/.pinchtab`)\n- No access to your user's home files (unless you explicitly navigate to `file://` URLs)\n- Standard Chrome security model (site isolation, CSP, etc.)\n\nSet `BRIDGE_PROFILE_DIR` to use a custom directory if needed.\n\n## Questions?\n\n- Source code: https://github.com/pinchtab/pinchtab\n- Issues/security reports: https://github.com/pinchtab/pinchtab/issues\n- Docs: https://pinchtab.com","readmeExcerpt":"Skill: Pinchtab Owner: luigi-agosti Summary: Control a headless or headed Chrome browser via Pinchtab's HTTP API. Use for web automation, scraping, form filling, navigation, and multi-tab workflows. Pin... Tags: latest:0.7.6 Version history: v0.7.6 | 2026-02-26T09:55:15.108Z | user Release v0.7.6 v0.7.5 | 2026-02-26T02:17:44.758Z | user Release v0.7.5 v0.7.4 | 2026-02-26T00:48:59.285Z | user Release v0.7.4 v0.7.3 | 2","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"# 1. Start Pinchtab (runs forever, local on :9867)\npinchtab &\n\n# 2. In your agent, follow this loop:\n#    a) Navigate to a URL\n#    b) Snapshot the page (get refs like e0, e5, e12)\n#    c) Act on a ref (click e5, type e12 \"search text\")\n#    d) Snapshot again to see the result\n#    e) Repeat step c-d until done"},{"language":"bash","snippet":"# Headless (default) — no visible window\npinchtab &\n\n# Headed — visible Chrome window for human debugging\nBRIDGE_HEADLESS=false pinchtab &\n\n# With auth token\nBRIDGE_TOKEN=\"your-secret-token\" pinchtab &\n\n# Custom port\nBRIDGE_PORT=8080 pinchtab &\n\n# Dashboard/orchestrator — profile manager + tab launcher\npinchtab dashboard &"},{"language":"json","snippet":"{\n  \"refs\": [\n    {\"id\": \"e0\", \"role\": \"link\", \"text\": \"Sign In\", \"selector\": \"a[href='/login']\"},\n    {\"id\": \"e1\", \"role\": \"textbox\", \"label\": \"Email\", \"selector\": \"input[name='email']\"},\n    {\"id\": \"e2\", \"role\": \"button\", \"text\": \"Submit\", \"selector\": \"button[type='submit']\"}\n  ],\n  \"text\": \"... readable text version of page ...\",\n  \"title\": \"Login Page\"\n}"},{"language":"bash","snippet":"pinchtab nav https://example.com\npinchtab snap -i -c                    # interactive + compact\npinchtab click e5\npinchtab type e12 hello world\npinchtab press Enter\npinchtab text                          # readable text (~1K tokens)\npinchtab text | jq .text               # pipe to jq\npinchtab ss -o page.jpg                # screenshot\npinchtab eval \"document.title\"         # run JavaScript\npinchtab pdf -o page.pdf               # export PDF"},{"language":"bash","snippet":"curl -X POST http://localhost:9867/navigate \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"url\": \"https://example.com\"}' && \\"},{"language":"bash","snippet":"curl http://localhost:9867/snapshot | jq '.nodes[] | select(.name | length > 15) | .name'"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: pinchtab\ndescription: >\n  Control a headless or headed Chrome browser via Pinchtab's HTTP API. Use for web automation,\n  scraping, form filling, navigation, and multi-tab workflows. Pinchtab exposes the accessibility\n  tree as flat JSON with stable refs — optimized for AI agents (low token cost, fast).\n  Use when the task involves: browsing websites, filling forms, clicking buttons, extracting\n  page text, taking screenshots, or any browser-based automation. Requires a running Pinchtab\n  instance (Go binary).\nhomepage: https://pinchtab.com\nmetadata:\n  openclaw:\n    emoji: \"🦀\"\n    requires:\n      bins: [\"pinchtab\"]\n      env:\n        - name: BRIDGE_TOKEN\n          secret: true\n          optional: true\n          description: \"Bearer auth token for Pinchtab API\"\n        - name: BRIDGE_PORT\n          optional: true\n          description: \"HTTP port (default: 9867)\"\n        - name: BRIDGE_HEADLESS\n          optional: true\n          description: \"Run Chrome headless (true/false)\"\n---\n\n# Pinchtab\n\nFast, lightweight browser control for AI agents via HTTP + accessibility tree.\n\n**Security Note:** Pinchtab runs a local Chrome browser under your control. It does not access your credentials, exfiltrate data, or connect to external services. All interactions stay local unless you explicitly navigate to external sites. Binary distributed via [GitHub releases](https://github.com/pinchtab/pinchtab/releases) with checksums. See [TRUST.md](TRUST.md) for full security model and VirusTotal flag explanation.\n\n## Quick Start (Agent Workflow)\n\nThe 30-second pattern for browser tasks:\n\n```bash\n# 1. Start Pinchtab (runs forever, local on :9867)\npinchtab &\n\n# 2. In your agent, follow this loop:\n#    a) Navigate to a URL\n#    b) Snapshot the page (get refs like e0, e5, e12)\n#    c) Act on a ref (click e5, type e12 \"search text\")\n#    d) Snapshot again to see the result\n#    e) Repeat step c-d until done\n```\n\n**That's it.** Refs are stable—you don't need to re-snapshot before every action. Only snapshot when the page changes significantly.\n\n## Setup\n\n```bash\n# Headless (default) — no visible window\npinchtab &\n\n# Headed — visible Chrome window for human debugging\nBRIDGE_HEADLESS=false pinchtab &\n\n# With auth token\nBRIDGE_TOKEN=\"your-secret-token\" pinchtab &\n\n# Custom port\nBRIDGE_PORT=8080 pinchtab &\n\n# Dashboard/orchestrator — profile manager + tab launcher\npinchtab dashboard &\n```\n\nDefault: **port 9867**, no auth required (local). Set `BRIDGE_TOKEN` for remote access.\n\nFor advanced setup, see [references/profiles.md](references/profiles.md) and [references/env.md](references/env.md).\n\n## What a Snapshot Looks Like\n\nAfter calling `/snapshot`, you get the page's accessibility tree as JSON—flat list of elements with refs:\n\n```json\n{\n  \"refs\": [\n    {\"id\": \"e0\", \"role\": \"link\", \"text\": \"Sign In\", \"selector\": \"a[href='/login']\"},\n    {\"id\": \"e1\", \"role\": \"textbox\", \"label\": \"Email\", \"selector\": \"input[name='email']\"},\n    {\"id\": \"e2\", \"role\": \"button\", \"text\": \"Submit"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn75yfbg457nxg5e8yeh2ngtx9817sam\",\n  \"slug\": \"pinchtab\",\n  \"version\": \"0.7.6\",\n  \"publishedAt\": 1772099715108\n}"},{"path":"references/api.md","content":"# Pinchtab API Reference\n\nBase URL for all examples: `http://localhost:9867`\n\n> **CLI alternative:** All endpoints have CLI equivalents. Use `pinchtab help` for the full list. Examples are shown as `# CLI:` comments below.\n\n## Navigate\n\n```bash\n# CLI: pinchtab nav https://example.com [--new-tab] [--block-images]\ncurl -X POST /navigate \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"url\": \"https://example.com\"}'\n\n# With options: custom timeout, block images, open in new tab\ncurl -X POST /navigate \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"url\": \"https://example.com\", \"timeout\": 60, \"blockImages\": true, \"newTab\": true}'\n```\n\n## Snapshot (accessibility tree)\n\n```bash\n# CLI: pinchtab snap [-i] [-c] [-d] [-s main] [--max-tokens 2000]\n# Full tree\ncurl /snapshot\n\n# Interactive elements only (buttons, links, inputs) — much smaller\ncurl \"/snapshot?filter=interactive\"\n\n# Limit depth\ncurl \"/snapshot?depth=5\"\n\n# Smart diff — only changes since last snapshot (massive token savings)\ncurl \"/snapshot?diff=true\"\n\n# Text format — indented tree, ~40-60% fewer tokens than JSON\ncurl \"/snapshot?format=text\"\n\n# Compact format — one-line-per-node, 56-64% fewer tokens than JSON (recommended)\ncurl \"/snapshot?format=compact\"\n\n# YAML format\ncurl \"/snapshot?format=yaml\"\n\n# Scope to CSS selector (e.g. main content only)\ncurl \"/snapshot?selector=main\"\n\n# Truncate to ~N tokens\ncurl \"/snapshot?maxTokens=2000\"\n\n# Combine for maximum efficiency\ncurl \"/snapshot?format=compact&selector=main&maxTokens=2000&filter=interactive\"\n\n# Disable animations before capture\ncurl \"/snapshot?noAnimations=true\"\n\n# Write to file\ncurl \"/snapshot?output=file&path=/tmp/snapshot.json\"\n```\n\nReturns flat JSON array of nodes with `ref`, `role`, `name`, `depth`, `value`, `nodeId`.\n\n**Token optimization**: Use `?format=compact` for best token efficiency. Add `?filter=interactive` for action-oriented tasks (~75% fewer nodes). Use `?selector=main` to scope to relevant content. Use `?maxTokens=2000` to cap output. Use `?diff=true` on multi-step workflows to see only changes. Combine all params freely.\n\n## Act on elements\n\n```bash\n# CLI: pinchtab click e5 / pinchtab type e12 hello / pinchtab press Enter\n# Click by ref\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"click\", \"ref\": \"e5\"}'\n\n# Type into focused element (click first, then type)\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"click\", \"ref\": \"e12\"}'\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"type\", \"ref\": \"e12\", \"text\": \"hello world\"}'\n\n# Press a key\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"press\", \"key\": \"Enter\"}'\n\n# Focus an element\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"focus\", \"ref\": \"e3\"}'\n\n# Fill (set value directly, no keystrokes)\ncurl -X POST /action -H 'Content-Type: application/json' \\\n  -d '{\"kind\": \"fill\", \"selector\": \"#email\", \"text\": \"user@example.com\"}'\n\n# Hover (trigger drop"},{"path":"references/env.md","content":"# Pinchtab Environment Variables\n\n## Core runtime\n\n| Var | Default | Description |\n|---|---|---|\n| `BRIDGE_BIND` | `127.0.0.1` | Bind address. Set `0.0.0.0` for network access |\n| `BRIDGE_PORT` | `9867` | HTTP port |\n| `BRIDGE_HEADLESS` | `true` | Run Chrome headless |\n| `BRIDGE_TOKEN` | (none) | Bearer auth token (recommended with `0.0.0.0`) |\n| `BRIDGE_PROFILE` | `~/.pinchtab/chrome-profile` | Chrome profile dir |\n| `BRIDGE_STATE_DIR` | `~/.pinchtab` | State/session storage |\n| `BRIDGE_NO_RESTORE` | `false` | Skip tab restore on startup |\n| `BRIDGE_STEALTH` | `light` | Stealth level: `light` or `full` |\n| `BRIDGE_MAX_TABS` | `20` | Max open tabs (0 = unlimited) |\n| `BRIDGE_BLOCK_IMAGES` | `false` | Block image loading |\n| `BRIDGE_BLOCK_MEDIA` | `false` | Block all media (images + fonts + CSS + video) |\n| `BRIDGE_NO_ANIMATIONS` | `false` | Disable CSS animations/transitions |\n| `BRIDGE_TIMEZONE` | (none) | Force browser timezone (IANA tz) |\n| `BRIDGE_CHROME_VERSION` | `144.0.7559.133` | Chrome version for fingerprint rotation |\n| `BRIDGE_USER_AGENT` | (none) | Custom User-Agent string; also overrides Sec-Ch-Ua client hints via CDP |\n| `CHROME_BINARY` | (auto) | Path to Chrome/Chromium binary |\n| `CHROME_FLAGS` | (none) | Extra Chrome flags (space-separated) |\n| `BRIDGE_CONFIG` | `~/.pinchtab/config.json` | Path to config JSON file |\n| `BRIDGE_TIMEOUT` | `15` | Action timeout (seconds) |\n| `BRIDGE_NAV_TIMEOUT` | `30` | Navigation timeout (seconds) |\n| `CDP_URL` | (none) | Connect to existing Chrome DevTools |\n| `BRIDGE_NO_DASHBOARD` | `false` | Disable dashboard endpoints on instance processes |\n\n## CLI client\n\n| Var | Default | Description |\n|---|---|---|\n| `PINCHTAB_URL` | `http://localhost:9867` | Pinchtab server URL for CLI commands |\n| `PINCHTAB_TOKEN` | (none) | Auth token for CLI (sent as `Authorization: Bearer`) |\n\n## Dashboard mode (`pinchtab dashboard`)\n\n| Var | Default | Description |\n|---|---|---|\n| `PINCHTAB_AUTO_LAUNCH` | `false` | Auto-launch default profile at startup |\n| `PINCHTAB_DEFAULT_PROFILE` | `default` | Profile name for auto-launch |\n| `PINCHTAB_DEFAULT_PORT` | `9867` | Port for auto-launched profile |\n| `PINCHTAB_HEADED` | (unset) | If set, auto-launched profile is headed |\n| `PINCHTAB_DASHBOARD_URL` | `http://localhost:$BRIDGE_PORT` | Base URL for `pinchtab connect` |"},{"path":"references/profiles.md","content":"# Profile Management (Dashboard Mode)\n\nWhen running `pinchtab dashboard`, profiles are managed via the dashboard API on port 9867.\n\n## List profiles\n\n```bash\ncurl http://localhost:9867/profiles\n```\n\nReturns array of profiles with `id`, `name`, `accountEmail`, `useWhen`, etc.\n\n## Start a profile\n\n```bash\n# Auto-allocate port (recommended)\ncurl -X POST http://localhost:9867/profiles/<ID>/start\n\n# With specific port and headless mode\ncurl -X POST http://localhost:9867/profiles/<ID>/start \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"port\": \"9868\", \"headless\": true}'\n\n# Short alias\ncurl -X POST http://localhost:9867/start/<ID>\n```\n\nReturns instance info including allocated `port`. Use that port for all subsequent API calls.\n\n## Stop a profile\n\n```bash\ncurl -X POST http://localhost:9867/profiles/<ID>/stop\n\n# Short alias\ncurl -X POST http://localhost:9867/stop/<ID>\n```\n\n## Check instance status\n\n```bash\n# By profile ID (recommended)\ncurl http://localhost:9867/profiles/<ID>/instance\n\n# By profile name\ncurl http://localhost:9867/profiles/My%20Profile/instance\n```\n\n## Launch by name\n\n```bash\ncurl -X POST http://localhost:9867/instances/launch \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"name\": \"work\", \"port\": \"9868\"}'\n```\n\n## CLI usage with profiles\n\nThe CLI doesn't have profile subcommands yet — use `curl` for profile management.\nOnce a profile instance is running, point the CLI at it:\n\n```bash\n# Get the instance port, then use CLI\nPINCHTAB_URL=http://localhost:9868 pinchtab snap -i\n```\n\n## Typical agent flow\n\n```bash\n# 1. List profiles\nPROFILES=$(curl -s http://localhost:9867/profiles)\n\n# 2. Start profile (auto-allocates port)\nINSTANCE=$(curl -s -X POST http://localhost:9867/profiles/$PROFILE_ID/start)\nPORT=$(echo $INSTANCE | jq -r .port)\n\n# 3. Use the instance\ncurl -X POST http://localhost:$PORT/navigate -H 'Content-Type: application/json' \\\n  -d '{\"url\": \"https://mail.google.com\"}'\ncurl http://localhost:$PORT/snapshot?maxTokens=4000\n\n# 4. Stop when done\ncurl -s -X POST http://localhost:9867/profiles/$PROFILE_ID/stop\n```\n\n## Profile IDs\n\nEach profile gets a stable 12-char hex ID (SHA-256 of name, truncated) stored in `profile.json`. IDs are URL-safe and never change — use them instead of names in automation.\n\n## Headed mode\n\nHeaded mode = real visible Chrome window managed by Pinchtab.\n\n- Human can log in, pass 2FA/captcha, validate state\n- Agent calls HTTP APIs against the same running instance\n- Session state persists in profile directory (cookies/storage carry over)\n\nRecommended human + agent flow:\n\n```bash\n# Human starts dashboard and sets up profile\npinchtab dashboard\n\n# Agent resolves the profile endpoint\nPINCHTAB_BASE_URL=\"$(pinchtab connect <profile-name>)\"\ncurl \"$PINCHTAB_BASE_URL/health\"\n```"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Control a headless or headed Chrome browser via Pinchtab's HTTP API. Use for web automation, scraping, form filling, navigation, and multi-tab workflows. Pin... Skill: Pinchtab Owner: luigi-agosti Summary: Control a headless or headed Chrome browser via Pinchtab's HTTP API. Use for web automation, scraping, form filling, navigation, and multi-tab workflows. Pin... Tags: latest:0.7.6 Version history: v0.7.6 | 2026-02-26T09:55:15.108Z | user Release v0.7.6 v0.7.5 | 2026-02-26T02:17:44.758Z | user Release v0.7.5 v0.7.4 | 2026-02-26T00:48:59.285Z | user Release v0.7.4 v0.7.3 | 2","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1391,"uniquenessScore":46,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T20:29:02.427Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}