Someone wants to help
They have your claim code and are waiting for your OK.
Approval
Pending helpers
No pending requests
Egress
Home agent
Optional: run a small app on your PC so cloud sessions use your IP. Uses your sb_… key — no separate token.
- On your home/office PC: install Node.js LTS if needed
- Open the
home-agentfolder → double-click Start-Home-Agent.bat - Paste your
sb_…license key · leave the window open - This badge turns Online · create a profile with Egress = Home / regional IP
Agent online. When starting a session, pick Home / regional IP under Egress.
Live view
What the helper sees
Ready when you are
Open a session to see the shared browser here.
Pause locks helper input at the gateway. End revokes access instantly.
Files for the helper: expand More options below → Shared folder (upload), or they use Choose file → Shared in the browser.
More options
Activity
Recent events
Waiting for activity…
Files
Shared folder
Shared
Downloads
- —
Operator
Remote helper
runbook
Tunnel → create → link → revoke. Keep the tunnel (or VPS) up while the helper is connected. Laptop sleep kills Docker and the share.
-
1
Start the stack
Docker Desktop running, then from the project folder:
docker compose up --build -dDashboard:
npx serve . -p 3000→ openhttp://127.0.0.1:3000(prefer 127.0.0.1 over localhost). -
2
Expose a public URL
Quick tunnel (no Cloudflare account). Keep the window open:
powershell -ExecutionPolicy Bypass -File scripts/start-quick-tunnel.ps1Script registers
PUBLIC_BASE_URLwith the gateway. Banner should say Remote helper access is live. For always-on access, deploy gateway + Docker to a VPS instead. -
3
Create profile & log in
Command → Create profile → pick a Customer plan:
- View — read-only stream, 1h sessions (lower cost)
- Assist — full control, normal stream, 3h links (standard)
- Live — full control + GStreamer H.264 WebRTC (remote desktop — not native Meet)
Open Helper View (or the share link yourself), log into the target site once. Cookies stay in the volume. Put files the helper needs in Session vault → Shared (downloads go to Downloads in the same profile).
-
4
Share the sealed link
Select the profile → Link. Duration and security defaults come from the plan (View = 1h, Assist/Live = 3h). Keep claim code + owner approve on unless you have a reason to loosen them. Send the URL and tell them the claim code on a call. Approve only their Pending claim.
-
5
Revoke when done
Select the profile → Revoke access now (or Revoke on the card). Helper stream dies immediately. Resume later if you need the same cookies; Delete wipes the volume.
Home egress (optional)
For residential IP: copy the Home agent command from the dashboard egress panel (or run via SSH tunnel — see docs). Create the profile with Home Gateway tunnel mode.
Direct vs Home: Default cloud IP works for most US/global sites. Use Home when the target expects your office/residential geo (EU banks, local portals).
Secrets before public
Set OWNER_SECRET, SECRET_KEY, and AGENT_TOKEN in .env. Lab defaults in the dashboard config must not ship on a public tunnel.
System
Built for sealed delegation
ShadowBrowser targets the two failure modes of remote help: datacenter IP detection and uncontrolled machine access. Cookies stay in the volume. Helpers get a stream — not your passwords.
Hybrid tunneling
Cloud Chromium exits through your home agent over TLS. Banks and social sites see your residential IP, ISP, and geo — not a VPS fingerprint.
Live stream
KasmVNC / WebRTC pipes the virtual display to the helper’s browser. No install on their side — open the sealed link and work.
DOM sanitization
Proxy strips password autofill, blocks sensitive actions, and fences chrome:// settings so helpers cannot escalate into credentials.
Isolated profiles
Each profile is a Docker container with its own volume. Log in once; cookies persist. Revoke kills the share without wiping the profile.
Customer plans
View (read-only, normal stream) · Assist (full control, normal) · Live (full + WebRTC meeting). Each plan sets permissions, stream quality, and link TTL automatically.
Your News Feed
Logged in as: Oluwafemi Adebayo Adeyemi
Oluwafemi Adebayo Adeyemi
Cloud Security Architect | Tech Lead
About
Building secure, scalable, and persistent cloud browser sessions to revolutionize delegated workflows and remote operations without compromise.
Inbox Messages
Account Settings
Security & Credentials
⚠️ Password: ••••••••••••••••• (Disabled in Remote Session)
You are logged in through an authorized delegated session. Passwords and credentials cannot be read, changed, or revealed.
Session Information
Session IP: 12.84.192.4 (Comcast Residential Network)
Host Region: US-East-1 AWS Cloud