Credential boundaries
API keys, cookies, proxy credentials, provider tokens, and browser connection details stay outside public result payloads.
Public-safe controls, explicit runtime ownership, and audit evidence are part of the collection path, not an afterthought.
API keys, cookies, proxy credentials, provider tokens, and browser connection details stay outside public result payloads.
Public targets and redirects pass server-owned URL and egress validation before acquisition.
Product, Admin, Ops, and public API surfaces keep explicit route and role boundaries.
Profile leases, capacity admission, health, release, cooldown, and cleanup remain behind the browser gateway.
Request IDs, engine attempts, fallback reasons, quality decisions, and cost units support investigation without exposing raw secrets.
Timeouts, response limits, retry budgets, crawl scope, and queue ownership reduce uncontrolled work.
Normalized output, status, diagnostics, and request IDs.
Credentials, profiles, proxies, CDP details, and raw provider state.
Review the public API contract, then validate your intended workflow against the available controls and result fields.