Plain AI Daily

Claude in Chrome Explained: Which Plan You Need and What It Will Not Do

By 13 min read

Claude in Chrome is a Chrome extension that clicks, types and fills forms on real websites for you, and it acts without asking first by default. It is on every paid Claude plan and not on the free one, so the cheapest way in is Claude Pro at $17 a month on annual billing. Anthropic called it generally available in August 2026; its help centre now calls the Chrome side panel a beta.

Claude in Chrome is a browser extension that lets Claude work inside your own Chrome window: it reads the page you are on, clicks links, types text, fills in forms, and moves between tabs using the logins you are already signed in with. Anthropic made it generally available on August 26, 2026 after a year of staged testing, and changed the default behaviour at the same time. It no longer asks permission for every single action.

The two questions that decide whether this matters to you: it is not on the free plan, and it is Chrome-on-a-computer only.

What "generally available" actually means here, because the plan gate loosened a while ago and a lot of write-ups still describe the 2025 version. Anthropic keeps a dated update log on its original pilot post:

DateWhat Anthropic said
August 25, 2025Pilot opens to 1,000 Max plan users by waitlist
November 24, 2025"Now available to all Max plan subscribers," still in beta
December 18, 2025"Now available to Pro, Team, and Enterprise plans" -- "ready to expand to all paid plans"
August 26, 2026Generally available, and Claude starts acting without per-action approval

So the August 26, 2026 news is the change in how much it does on its own, not a new price or a new plan. If you have been paying for Claude Pro since the winter, you already had access.

One caveat on the words "end of the beta", because Anthropic does not say it consistently. Its launch post says generally available. All three of its Claude in Chrome help articles carry the same sentence, re-read on October 5, 2026, and it reads: "Claude in Chrome is available for all paid plans (Pro, Max, Team, and Enterprise). It's available in Claude Cowork and Claude Code, and in beta in the Chrome browser." The get-started article words it as "in beta in the Chrome side panel". So by Anthropic's own documentation the Chrome panel is still labelled a beta more than a month after the GA post. That does not change the price, the plans or what it can do, all of which we re-verified the same day, but it is the right expectation to carry in: treat the Chrome panel as a product Anthropic is still changing under you.

Key Takeaways

  • Not free. Anthropic's launch post says Claude in Chrome is "now generally available on every paid Claude plan," and claude.com/pricing marks it as not included on Free. Cheapest entry is Claude Pro at $17/month on annual billing ($200 up front) or $20 billed monthly.
  • It now acts on its own by default. The big change on August 26 is that Claude "can now also take actions autonomously in the browser, instead of needing approval for every one." A safety classifier checks each action before it runs.
  • Anthropic's own two surfaces disagree on whether it is still a beta. The launch post says generally available; all three Claude in Chrome help articles, re-read on October 5, 2026, say it is available in Claude Cowork and Claude Code "and in beta in the Chrome browser". Nothing about the price or the plan gate is in doubt; the label is.
  • There is an off switch, and it is one drop-down. Switch the mode to Manually approve and Claude goes back to asking before every click.
  • Chrome on a computer, nothing else. Anthropic states it "doesn't run on other Chromium browsers or on mobile yet," so no Edge, no Brave, no Arc, no phone.
  • It cannot spend your money. Purchases, financial transactions, trades, and handling card or ID data are on Anthropic's prohibited list regardless of what permissions you grant.
  • It can see whatever is on screen. Claude screenshots the tabs it works in, and Anthropic says it "can't filter sensitive content out of what it sees." Anthropic's own advice is to run it in a separate Chrome profile.
  • Leaving it on auto costs you more usage. Anthropic notes that automatic mode "consumes more of your usage limit than the other modes," because the safety check runs on every action.

Which Claude Plans Include It

Every paid plan, and no free plan. Anthropic states this twice, in the launch post and in its help centre ("available for all paid plans (Pro, Max, Team, and Enterprise)"), and the plan comparison table on its pricing page shows the same split. This is the whole answer for most readers: if you are on free Claude, Claude in Chrome is not something you can turn on.

PlanPriceClaude in Chrome
Free$0No
Pro$17/mo billed annually ($200 up front), $20 monthlyYes
Max 5xMax starts at $100/mo; Anthropic publishes one starting price for both stepsYes
Max 20xAs aboveYes
TeamPer seat, business pricingYes
EnterpriseContact salesYes, if your admin enables it

Decoded from the plan comparison matrix on claude.com/pricing, re-checked September 8, 2026 and unchanged: Free is the only column with a cross. The plan bullets that appear above that table do not mention Chrome at all, so the matrix is the surface that answers this question.

One caveat worth knowing before you upgrade, and it is not resolved. Anthropic's setup article was revised on August 26, 2026 and still says Claude in Chrome is available "in Claude Cowork and Claude Code, and in beta in the Chrome side panel." It then draws a line most write-ups miss: "On Max and Team plans, the side panel runs as a Claude Cowork session, and this is rolling out to Pro plans." On Enterprise the side panel runs as a Cowork session once an admin enables Cowork in the cloud. So if you pay for Pro today, which side panel you get depends on where that rollout has reached, and the two behave differently. Anthropic publishes no date for it.

What changed (September 5, 2026): re-verified every load-bearing fact on this page against Anthropic's own surfaces. The prices, the plan split, the prohibited-actions list and the Chrome-only restriction had not moved. Two things had: the setup article was revised on August 26 rather than August 12, and its "in the coming weeks" wording is gone. This section and the permission-mode table below were corrected to match. [Superseded on October 5, 2026: the "in the coming weeks" wording is back. All three help articles now read "this is rolling out to Pro plans in the coming weeks" about the Cowork side panel. The September 5 reading was correct on the day.]

What It Actually Does for You

It operates websites that do not have a Claude integration. That is the specific gap Anthropic says it built this for: "internal dashboards, legacy systems, and vendor portals" that will never appear in a connector list. Instead of you copying information out of a web page and into Claude, Claude goes to the page.

In practice that means:

TaskWhat Claude does
Reading across tabsDrag tabs into Claude's tab group and it can view and act on all of them at once, so it can compare or summarise what you have open
Filling in formsTypes into fields on a real site using your existing login, then pauses before anything it flags as sensitive
Familiar sitesAnthropic says Claude has built-in knowledge of Slack, Google Calendar, Gmail, Google Docs and GitHub, so "schedule a meeting" works without step-by-step directions
Recurring jobsScheduled tasks run daily, weekly, monthly or annually from the clock icon in the extension panel
Signing inWith 1Password for Claude, Anthropic says 1Password fills the credential directly so "Claude never sees your password or one-time code." That integration is in beta on macOS

You install it from the Chrome Web Store, sign in with your Claude account, and pin it. The extension asks for a long permission list, including debugger, which is the one that lets Claude click and type rather than just read. Anthropic publishes a plain-English reason for each permission in its setup article.

The Change That Matters: It Acts Without Asking

Through the beta, the headline restriction was that Claude checked with you before each action. Now Claude can keep working, screen each action itself, block anything it judges unsafe, and stop to ask only when something needs you.

Which mode you start in depends on which side panel you have. Anthropic's permissions guide is specific about this and it is easy to misread: "Automatically approve" is the default in the Cowork side panel, which is what Max and Team plans get, and what Pro plans are being rolled onto. In the classic side panel, "Manually approve" still builds a plan you approve up front, listing the websites Claude may touch, and Anthropic says Claude "will not deviate from the stated plan without requesting your permission first." Check the drop-down before you assume either way.

There are three modes, and you pick from a drop-down on the chat input:

ModeWhat happensUse it when
Manually approveClaude pauses before every action; you choose Allow or DenyAnything involving money, messages sent as you, or a site you do not know
Automatically approveClaude works continuously and checks each of its own actions for safety before running itOrdinary research, comparison and form-filling
Skip all approvalsClaude does not pause and nothing checks its actionsAlmost never. Anthropic's own wording: only when "you completely trust every action, connector, file, app, etc."

Two practical notes Anthropic buries in the permissions guide. First, the side panel remembers whichever mode you pick and uses it for future sessions, so switching to Manually approve once is enough. Second, automatic mode uses up more of your plan's usage limit than the other two, because Claude runs an extra safety check on every action. If you hit limits on Pro, that is a reason to switch.

What Anthropic Blocks It From Doing

There is a hard list, and it applies no matter what permissions you grant. This is the part worth reading if the phrase "AI that clicks things in my browser" makes you nervous.

Prohibited outright:

  • Making purchases or financial transactions
  • Creating accounts
  • Handling sensitive credit card or ID data
  • Executing financial trades or investment transactions
  • Providing investment or financial advice
  • Permanent deletions, including emptying trash and deleting emails, files or messages
  • Downloading files from untrusted sources
  • Modifying system files
  • Completing instructions from emails or web content

There is now one documented way round the credential problem. Anthropic's safety article, as of October 5, 2026, adds: "With 1Password for Claude, Claude can complete tasks that require signing in without handling the credential itself. 1Password fills the login directly, and your passwords and one-time codes never enter Claude's context." If you already use 1Password, that is the difference between Claude being locked out of anything behind a login and Claude getting in without your password passing through it.

Always requires your explicit approval, even in automatic mode: modifying permissions settings, granting authorisations, and entering potentially sensitive information into a website. Anthropic also blocks Claude from adult sites and known piracy sites outright, and says Claude "asks for permission before accessing financial sites."

To see or revoke what you have already allowed, click the extension icon, then the three dots, then Extension settings, which opens the Permissions page listing your approved sites and your permission history.

The Risk Anthropic Will Not Talk You Out Of

Prompt injection, and Anthropic says so directly rather than reassuring you. The attack is simple to describe: a web page, email or document contains hidden instructions, Claude reads them as if they came from you, and acts on them. Anthropic's own example is a hidden line in an email telling Claude to forward your other emails to an attacker.

What it has done about it, from the launch post: two classifiers, one screening incoming page content for injections and one reviewing each action against what you originally asked for, plus continued training against a growing library of real attacks. On its current evaluation, using attacks written by professional red-teamers, attacks that reached the model succeeded 17.6% of the time against the older Opus 4.5 and 3.8% against Opus 5 before those extra safeguards. With the classifiers running, Anthropic reports no successful attacks against Sonnet 5, Opus 5 or Mythos 5, and 0.3% against Fable 5.

Anthropic's safety help article now gives a different figure, and it is the newer surface. Re-read on October 5, 2026, when it stamped itself "Updated today", it says: "Our testing shows that Claude Opus 4.8 demonstrates significantly stronger prompt injection robustness than previous models. Our current configuration reduces attack success rates to less than 0.08% against our internal testing that combines known effective attack techniques." Less than 0.08% is a small number and it is not zero, so read the launch post's "no successful attacks" as a result for one evaluation on one set of models rather than as the current state. Anthropic has not reconciled the two pages, and the model it names there is not one of the three the launch post tested.

And then it says the thing that should govern how you use it: "The risk is not zero. Novel attacks may emerge that our evaluations didn't cover, and a successful one could lead to outcomes like data exfiltration."

The other exposure has nothing to do with attackers. Claude works by screenshotting the tabs it is in, so anything visible in one of those tabs becomes part of the conversation, and Anthropic states that Claude "can't filter sensitive content out of what it sees." Its own recommendations are worth following literally:

  • Use a separate Chrome profile with no access to banking, healthcare or government accounts.
  • Do not open the side panel on a page showing something you would not want stored with the session, because side panel sessions are saved to your history and can be reopened on your other devices.
  • Do not use it to manage financial accounts, legal documents, medical information, or work accounts holding sensitive company data. Anthropic lists all four under "what to avoid."

Anthropic also notes that Claude in Chrome "isn't available to organizations covered by HIPAA."

Should You Pay for It?

Get it if you already pay for Claude, or if a chunk of your week is spent moving information between web pages that will never talk to each other: a supplier portal, an old ticketing system, an internal dashboard, a form you refill every month. That is the job it is built for, and no free chatbot does it.

Skip it if you are on free Claude and this is the only reason you would upgrade. A $20 monthly subscription to watch an AI fill in forms is a lot to spend on a feature you are advised not to point at anything sensitive, on one browser, on one kind of device. Try the free plan's ordinary Claude first and see whether the browser part is really your bottleneck.

If you want the browser-agent idea without a subscription, the honest answer is that there mostly is not one: every mainstream browser agent sits behind a paid plan today. We compare the shipped ones in what an AI agent actually is, in plain terms, and the wider paid-plan question in which AI chatbot should you pay for.

Sources

Corrections and Updates

October 5, 2026: this page said in its summary and lede that August 26 was "the end of the beta", and its FAQ said Anthropic "reports no successful attacks against Sonnet 5 or Opus 5 in its latest test". Neither holds against Anthropic's help centre as re-read that day. All three Claude in Chrome help articles say the product is "in beta in the Chrome browser", and the safety article, stamped "Updated today", gives "less than 0.08%" rather than zero and names a model the launch post did not test. The summary, lede, Key Takeaways, FAQ and the prompt-injection section now carry both surfaces and say which is newer. The price ($17 a month annual, $20 monthly), the Free-plan exclusion and the full prohibited-actions list were re-verified the same day and had not moved.

Keep up without the jargon

Frequently Asked Questions

Is Claude in Chrome free?

No. Anthropic says it is generally available on every paid Claude plan, and the plan comparison on claude.com/pricing marks it as not included on the free plan. The cheapest way in is Claude Pro at $17 a month billed annually, or $20 billed monthly.

Can Claude in Chrome buy things or move my money?

No. Anthropic's permissions guide lists purchases and financial transactions as prohibited regardless of your settings, along with creating accounts, handling credit card or ID data, executing trades, and permanent deletions like emptying a trash folder or deleting emails.

How do I stop Claude from acting without asking me?

Open the drop-down on the chat input in the Chrome side panel and pick Manually approve. Claude then pauses before every action and you choose Allow or Deny. Anthropic says the side panel remembers your choice for future sessions.

Does Claude in Chrome work in Edge, Brave, or on my phone?

No. Anthropic's help centre says it is not supported on other Chromium-based browsers or on mobile devices, and the launch post repeats it. You also still need the Claude desktop app for anything involving files on your own computer.

Can Claude see my bank details if I have a tab open?

Potentially. Anthropic says Claude takes screenshots of the tabs it is working in and cannot filter sensitive content out of what it sees. It recommends a separate Chrome profile with no access to banking, healthcare or government accounts.

Is it safe from hidden instructions on web pages?

Safer than it was, but not safe, and Anthropic's two surfaces give different numbers. Its launch post reported no successful attacks against Sonnet 5, Opus 5 or Mythos 5 with its two classifiers running. Its safety help article, updated October 5, 2026, instead says its current configuration 'reduces attack success rates to less than 0.08%'. Both state the risk is not zero.

Get the plain-English AI brief

One email. What changed in AI and what it means for you.