agent37-hermes template drives that browser headless: the agent opens pages, clicks, fills forms, and reads what comes back, with nothing for you to watch. Build the desktop recipe instead and the same browser runs on a screen you can open in a tab, watch live, and take control of when a site needs a human.
Paste this into your coding agent
Browsing with no screen
Nothing to configure:agent37-hermes ships Chromium and a browser tool, so “book me a table” or “pull the pricing off these five sites” works from the first chat turn. See Chat.
The agent also has the rest of the machine. It can install software with apt-get, run scripts, and serve its own ports, as itself or through exec as root:
curl
Add a desktop
hermes-vnc-desktop is the stock Hermes image plus a view: a visible Chromium that the agent’s browser tool drives, and noVNC serving that screen on port6901. Everything the stock template does still happens, because the recipe wraps the stock entrypoint rather than replacing it: the managed model, app connections, web search, and the agent37 CLI the agent uses to schedule itself.
Build it into a workspace template once. The build runs on Agent37, so you don’t need Docker:
curl
--default-port 3737 makes the create wait for the gateway, so the instance is ready to chat when it returns. The desktop adds nothing to the bill: a running instance is priced by its shape, not by what runs inside.
Open the desktop
Mint a signed URL for port6901 and change the path from / to /vnc.html, keeping the token:
curl
&view_only=1 to watch without controlling. Ask the agent to browse something and watch it work.
Embed it in your own app
Load the noVNC client in your own page and connect its WebSocket straight to the instance, with the signed token in the query string. That connection needs no cookie, so it works from your origin in every browser. Your server mints the token for the signed-in user’s own instance and hands the browser only a WebSocket URL:node
About the token
- It grants full control.
viewOnlyis a setting in your page, not a permission: anyone holding the token can connect a VNC client that clicks and types. Mint it only for the instance’s owner. - It cannot be revoked. Keep
ttl_secondsat60, the minimum. The token only has to be valid when the socket opens, an open socket keeps working after it expires, and every reconnect mints a fresh one. - Opening it wakes a sleeping instance. The edge holds the connection while the instance restores, and the screen comes back as the agent left it.
Worth knowing
- The login survives. Chromium keeps a persistent profile on the instance’s home volume, so a sign-in you finish during a takeover stays signed in across restarts, updates, and sleep, and the agent’s browser uses the same profile.
- Auto-sleep works. The desktop and the visible Chromium survive the checkpoint and restore, with the page the agent left open. Connect the view only while it is on screen: it streams even when nothing changes, and that traffic counts as activity, so an open view keeps the instance awake.
- Give it room. The default 2 vCPU / 4 GB works; use 4 / 8 if the agent opens heavy pages.
- Ports.
6901serves noVNC. VNC (5900) and DevTools (9222) stay on loopback inside the instance. - Screen size is 1440x900. Add
ENV AGENT37_SCREEN_GEOMETRY=1920x1080x24to the Dockerfile for another size. - Crons work as on
agent37-hermes, with one difference: on a workspace template, set"agent": "hermes"when you create one, or the run records itssession_idonly once the turn finishes. See Crons. - Telegram webhook ports are wired at create on
agent37-hermesonly, so a Telegram bot on this template polls and needsauto_sleepoff. See Public ports.